Privacy Policy
Introduction
This Privacy Policy explains how personal data is collected, used, and protected when you access or use the service. It applies to all methods of interaction, including web, mobile, and API. Your use of the service constitutes acceptance of these terms. Please check this policy regularly for updates.
Data Collection Methods
We collect information you explicitly provide—such as email addresses and profile details—along with data automatically generated through server logs, cookies, and device identifiers. Only non-sensitive categories of data are gathered; sensitive information (e.g., financial, medical) is never requested. Each data collection point clearly states its purpose. Users retain control over optional data via opt-in settings.
Purpose & Legal Basis
Personal data is processed to authenticate user sessions, maintain security, and provide customer support. Aggregate, anonymized metrics guide product improvements and infrastructure scaling. Processing is based on contractual necessity and legitimate interests (e.g., fraud prevention). Explicit consent is required for optional features such as personalized recommendations and advanced analytics.
Cookies & Tracking
Essential cookies are used to maintain login sessions and secure data exchanges. Non-essential analytics cookies are inactive until you enable them. Advertising or third-party tracking cookies are never deployed without separate, explicit consent. Cookie management options are available via your browser or account dashboard.
Security Measures
Data in transit is protected by end-to-end encryption (e.g., TLS 1.2+). Data at rest is encrypted using robust algorithms (e.g., AES-256) with hardware-backed key management. Access is restricted by role-based controls and multi-factor authentication. Regular penetration tests and vulnerability assessments identify and remediate potential security gaps.
User Rights
You have the right to access, correct, or delete your personal data at any time by submitting a request through your account settings or support portal. We process valid requests within 30 days, subject to applicable legal requirements. Data required for compliance or dispute resolution may be retained in anonymized form. You may also revoke any consent for optional processing without affecting essential services.
Data Retention
Personal data is retained only as long as necessary to fulfill its original purpose, typically no more than 18 months from last user activity. After the retention period, records are securely deleted or permanently anonymized. Backup copies are purged within 90 days after active retention expires. Retention schedules are reviewed annually.
Breach Response
In the event of a confirmed data breach involving personal data, affected users will be notified within 72 hours of breach verification. Notifications include the breach’s scope, types of data involved, and recommended mitigation steps. Regulatory bodies will be informed in compliance with applicable laws. A post-incident review ensures process improvements.
Automated Decision-Making
Automated algorithms may analyze anonymized data for security and performance monitoring. Any automated decision that materially affects your account will trigger a notification, and you may request human review. Non-critical personalization features operate only with your consent. All algorithmic processes are documented for auditing.
Third-Party Processors
We share data only with essential third-party providers under strict data protection agreements (e.g., hosting, payment gateways, email delivery). Providers are regularly audited to ensure compliance with our privacy standards. No personal data is sold or shared for marketing. All data transfers are logged and auditable.
Policy Revisions
This policy is updated at least once per year or as required by legal or operational changes. Significant amendments are announced via in-service notifications and email at least 14 days before taking effect. Continued use of the service after the effective date signifies acceptance. Archived versions remain accessible upon request.