Privacy policy

Version of [DATE]. Effective from the moment of publication.

This Policy sets out how [COMPANY NAME] processes and protects the personal data of individuals who use the client account and the services. By registering and continuing to use the service you confirm that you have read the Policy and agree with the described processing.

1. Data controller

  • Legal name: [FULL LEGAL NAME]
  • Registration number: [NUMBER]
  • Registered address: [ADDRESS]
  • Email for data protection requests: privacy@example.com
  • Person responsible for processing: [POSITION, CONTACT]

2. Definitions

Personal data - information relating to an identified or identifiable individual. Data subject - the individual the data relates to. Processing - collection, recording, structuring, storage, alteration, retrieval, use, transfer, anonymisation, blocking and erasure of personal data.

3. Categories of data

Category Content Source
Account data Login, email address, password as an irreversible hash, interface language, appearance, two-factor authentication flag Provided by the subject at registration
Individual data Full name, country, city, phone number Provided by the subject
Organisation representative data Legal name, tax number, legal address, contact person Provided by the subject
Financial data Invoice numbers and amounts, payments, balance operations, selected payment method, date and status of payment Generated while using the service
Technical data IP address, device type, operating system, browser, sign-in date and time, action log Collected automatically
Correspondence Support tickets, messages and attached files Provided by the subject

The controller does not collect special categories of data: racial or ethnic origin, political opinions, religious beliefs, health or sex life. Full payment card details are neither requested nor stored, they are processed by the payment provider.

4. Purposes of processing

  1. Registration, creation and maintenance of the account, identification at sign-in.
  2. Conclusion and performance of the contract: providing services, keeping the balance, issuing invoices, accepting payments, refunds.
  3. Service notifications about services, invoices and tickets sent by email.
  4. Security: detection and prevention of unauthorised access, keeping the action log and sign-in history.
  5. Compliance with statutory duties: accounting, taxation, replies to lawful requests of the authorities.
  6. Handling of requests, claims and disputes.

The data is not used for automated decisions producing legal effects, nor for advertising profiling.

5. Legal grounds

  • The consent given at registration by accepting the terms and this Policy.
  • Performance of the contract to which the subject is a party.
  • Statutory requirements, including accounting, taxation and anti money laundering rules.
  • Legitimate interests of the controller in securing the service and preventing fraud, where they do not override the rights of the subject.

6. Consent and its withdrawal

Consent is given by ticking the box in the registration form. The moment of consent is recorded in the system with the date and time. Consent may be withdrawn at any time by a request to privacy@example.com or from the client account. Withdrawal terminates the services for which the processing is required; data that must be retained by law is kept until the statutory term expires.

7. Sharing with third parties

  • payment providers and banks - to process payments and refunds;
  • infrastructure and communication providers that operate the service, under confidentiality terms;
  • email and messaging providers - to deliver service notifications;
  • public authorities - on the grounds and in the manner set by law.

The controller does not sell personal data and does not share it for advertising.

8. Cross-border transfers

The data is stored on servers located in [COUNTRY]. Where a transfer to another country is required to provide the service, it takes place only if that country ensures an adequate level of protection or on the basis of a separate consent of the subject.

9. Retention periods

Category Retention
Account data and profile While the account exists and [TERM] after its deletion
Invoices, payments, balance operations The term set by law for accounting documents, at least [TERM]
Action log, sign-in history, device records [TERM], after which the records are deleted automatically
Support tickets and attachments [TERM] from the date the ticket is closed

10. Security measures

  • staff access follows the least privilege principle and is limited by roles;
  • staff actions with client data are recorded in the log, including work on behalf of a client;
  • passwords are stored as irreversible hashes, the channel is encrypted;
  • two-factor authentication is available for staff accounts;
  • backups are made with restricted access to the copies.

11. Rights of the subject

  1. to obtain information about the controller and about the data held;
  2. to request rectification and completion of the data;
  3. to request blocking of the data where the processing conditions are breached;
  4. to request erasure of data processed unlawfully;
  5. to withdraw the consent;
  6. to lodge a complaint with the supervisory authority or the court.

Requests are sent to privacy@example.com or from the client account. The reply is provided within [TERM] from the day the request is received. The controller may ask for information confirming the identity of the applicant.

12. Incident notification

If unauthorised access to personal data is detected, the controller eliminates the breach, notifies the affected subjects and, where the law requires it, the supervisory authority within the statutory term.

13. Cookies

The service uses cookies described on a separate page Cookies.

14. Changes to the Policy

A new version is published on this page with the date. In case of significant changes a notice is sent to the email address given in the account at least [TERM] before the changes take effect.