Privacy Policy -
Introduction and Scope
This Privacy Policy explains how personal data is collected, used, retained and shared in connection with the services provided by the operator of this service ("we", "us", "our"). This policy applies to all customers in the area covered by the applicable data protection laws, including the European Union and the European Economic Area (EU/EEA), and to all personal data processed in relation to those customers.
Data Controller
For the purposes of the General Data Protection Regulation (GDPR), the organization operating the services is the data controller for personal data collected in connection with those services. We determine the purposes and means of processing personal data collected through our systems.
Data We Collect
We collect and process different categories of personal data depending on the relationship with you and the services used. Typical categories include:
- Identity and account data: name, username, account identifiers, profile information.
- Contact data: email address, billing address, and other contact details.
- Transactional data: records of services used, purchases, billing and payment records.
- Technical and usage data: IP addresses, device identifiers, log files, cookies and analytics data used to operate and improve the service.
- Support and correspondence: records of customer service requests, communications, and related notes.
- Legal and compliance data: information required to meet legal obligations, prevent fraud or misuse, and to comply with regulatory requirements.
Lawful Bases for Processing
We rely on one or more lawful bases under the GDPR when processing personal data. The applicable lawful basis will depend on the purpose of the processing. Common lawful bases we rely on include:
- Performance of a contract: processing necessary to provide, maintain, and manage services you have requested, to fulfill contractual commitments and to perform transactions.
- Legal obligation: processing required to comply with applicable laws, tax or accounting regulations, court orders or other legal processes.
- Consent: where you have given clear consent for specific processing activities, such as marketing communications or the use of certain cookies. You may withdraw consent at any time.
- Legitimate interests: processing necessary for our legitimate business interests when those interests are not overridden by your rights and freedoms. Examples include improving services, preventing fraud, network and information security, and direct communications related to service maintenance.
How We Use Personal Data
We use personal data to:
- Provide, maintain and improve our services;
- Process transactions and manage billing, subscriptions and accounts;
- Provide customer support, respond to questions and resolve disputes;
- Comply with legal obligations, regulatory requests and internal policies;
- Protect our rights and prevent misuse, fraud or illegal activities;
- Perform analytics and diagnostics to enhance performance and user experience;
- Send relevant service communications, updates and, where consented, marketing messages.
Data Retention
We retain personal data only for as long as necessary to accomplish the purposes set out in this Privacy Policy, including to meet contractual obligations, resolve disputes, enforce agreements and comply with legal requirements. Retention criteria include:
- Account data: retained for the duration of the business relationship and for a reasonable period after termination to address account closure, dispute resolution and potential legal claims;
- Transactional and billing records: retained in accordance with applicable tax and accounting laws, typically for a period of up to seven (7) years where required by local law;
- Support and correspondence: retained for as long as necessary to provide support and maintain records of communications;
- Analytics and log data: retained for operational and security purposes for periods that vary depending on the type of log and applicable legal requirements; where feasible, we aggregate or anonymize data to reduce retention of personal identifiers.
If you request deletion of your account or personal data, we will delete or anonymize your personal data within a reasonable period, subject to retention required to satisfy legal obligations or to preserve evidence of compliance with our obligations.
Processors and Third Parties
We may share personal data with trusted third-party processors that perform services on our behalf, such as payment processors, hosting providers, analytics and monitoring services, customer support platforms, and legal or professional advisors. These third parties act under our instructions and are bound by contractual obligations to protect the personal data and to process it only for the purposes we specify.
Categories of processors:
- Cloud hosting and infrastructure providers;
- Payment and billing vendors;
- Customer relationship and support platforms;
- Analytics and monitoring service providers;
- Legal, audit and professional services.
Sub-processors: Where we engage sub-processors, we maintain records of such parties and require equivalent contractual safeguards to ensure GDPR-level protections. You can review processor categories where such information is made available to you through your account or service documentation.
International Transfers
Some processors we use may be located outside the EU/EEA. When personal data is transferred to countries without an adequacy decision by the European Commission, we implement appropriate safeguards such as standard contractual clauses (SCCs), and where applicable additional measures to protect your data, in line with GDPR requirements.
Security Measures
We implement technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These measures include encryption, access controls, regular security assessments, staff training and contractually enforced data protection obligations with processors. While we strive to protect your data, no system can be guaranteed completely secure.
Your Rights
Under the GDPR, you have rights in relation to your personal data. These include the right to:
- Access: obtain confirmation whether we process your personal data and to receive a copy of that data;
- Rectification: request correction of inaccurate or incomplete data;
- Erasure: request deletion of your personal data where there is no overriding legal basis for its retention;
- Restriction: request limitation of processing in certain circumstances;
- Data portability: receive certain personal data in a structured, commonly used and machine-readable format and transmit it to another controller where technically feasible;
- Objection: object to processing based on legitimate interests or direct marketing, including profiling related to direct marketing;
- Withdraw consent: withdraw consent for processing where consent is the lawful basis, without affecting processing carried out prior to withdrawal;
- Lodge a complaint: lodge a complaint with a supervisory authority if you consider our processing of your personal data infringes applicable data protection laws.
Note: Some rights may be subject to limitations or conditions under applicable law, including where processing is necessary to comply with legal obligations or to establish, exercise or defend legal claims.
How to Exercise Your Rights
You may exercise your rights using the channels we provide in your account settings, within the user interface of our service, or through the data protection or privacy section of the service documentation provided to customers. We will respond to requests in accordance with applicable law and within statutory timeframes. Where we need additional information to verify your identity, we may request specific information to process your request securely.
Automated Decision-Making and Profiling
We do not engage in solely automated decision-making, including profiling, that produces legal effects or similarly significantly affects you without human intervention. If we implement automated decision-making in the future that would have such effects, we will provide you with information about the logic involved, the significance and the envisaged consequences and preserve any rights required under the GDPR.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal obligations, or services. Material changes will be notified to customers through appropriate channels. Continued use of our services after changes take effect constitutes acceptance of the revised policy.
Definitions and Additional Information
Where terms used in this policy are defined in the GDPR, those definitions apply. For detailed information about processors, data categories, specific retention periods for particular services, and additional safeguards for international transfers, please refer to the service-specific documentation available to customers through the product interface or account materials.
Effective date: This Privacy Policy is effective as of the date provided in your account documentation or when first presented to you. It applies to all customers in the area indicated above and to the processing of their personal data by us and our contracted processors.
End of Policy.
