Privacy Policy

Last Updated:

📢 Effective Date – This policy is effective as of 22 February 2026. We are committed to transparency and will notify you of any material changes via email or in‑app notifications.

1. Purpose of This Policy

This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you interact with our platform (the “Service”). Our goal is to help you make informed decisions about your data, in full compliance with applicable privacy laws, including the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and other global standards.

Key Principles

  • Lawfulness, Fairness, and Transparency – We process your data only on valid legal grounds and in a clear manner.
  • Purpose Limitation – We collect data only for specified, explicit, and legitimate purposes.
  • Data Minimisation – We collect only what is strictly necessary for the intended purpose.
  • Accuracy & Accountability – We keep your data accurate and take responsibility for its protection.

1.1 Policy Objectives

This policy serves the following objectives:

  • Inform you about what data we gather and why.
  • Outline your rights regarding your personal data.
  • Explain how we protect your information from unauthorised access or loss.
  • Describe our retention and deletion practices.
  • Detail how we share data with third parties.

1.1.1 Scope of the Policy

This policy applies to all users of our website, mobile applications, and any associated online services, regardless of the device or access method.

1.1.2 Who This Policy Applies To

  • Registered account holders
  • Guest users / visitors
  • Business partners and vendors who interact with our platform
  • Anyone who contacts our support team

1.2 Policy Updates

We review this policy regularly to reflect changes in technology, legal requirements, and our operational practices.

  • Revision History – A detailed changelog is maintained and available upon request. Major changes are summarised here.
  • Notification of Changes – We will notify you via the email address associated with your account or through a prominent notice on our website at least 30 days before any material changes take effect.

2. Information We Collect

To provide, improve, and personalise our services, we collect several categories of information. The table below summarises the main types:

CategoryExamplesPurpose
Identity DataFull name, username, date of birth, genderAccount creation, personalisation, legal compliance (age verification)
Contact DataEmail address, phone number, postal addressCommunication, support, account recovery, marketing (with consent)
Financial DataPayment card details, billing address, transaction historyProcess payments, prevent fraud, issue refunds
Technical DataIP address, browser type, device IDs, operating system, log dataSecurity, analytics, performance monitoring, debugging
Usage DataPages viewed, time spent, clicks, search queries, interaction patternsImprove user experience, feature optimisation, content recommendations
Location DataApproximate geolocation (derived from IP) or precise (if consented)Personalise content, comply with regional regulations, targeted offers

2.1 Data Categories

2.1.1 Personal Data

We define Personal Data as any information that identifies or could reasonably be used to identify an individual. This includes:

  • Identifiers – name, email, phone, account ID.
  • Characteristics – age, gender, preferences.
  • Financial information – payment instruments.
  • Communications – messages, support tickets, feedback.

2.1.2 Technical Data

Technical data is automatically collected via cookies, web beacons, and server logs. It does not directly identify you but is essential for security and performance.

  • IP address – used for geolocation and network diagnostics.
  • Browser fingerprint – helps detect fraudulent logins.
  • Device identifiers – to remember your preferences.

2.2 Collection Methods

2.2.1 Direct Collection

You directly provide data when you:

  • Create an account or fill out forms.
  • Subscribe to newsletters or promotional offers.
  • Make a purchase or request a service.
  • Contact customer support.
  • Participate in surveys or contests.

2.2.2 Automated Collection

We and our trusted partners use:

  • Cookies (see Section 5).
  • Tracking pixels – to analyse email open rates and conversion.
  • Log files – to capture system activity and error reports.
  • Third‑party analytics (e.g., Google Analytics) – to aggregate usage trends.

3. How We Use Your Information

We process your data only for the purposes described below, each supported by a valid legal basis (e.g., performance of a contract, legitimate interest, consent, or legal obligation).

3.1 Primary Uses

3.1.1 Service Delivery

  • Account management – create, maintain, and authenticate your profile.
  • Transaction processing – handle orders, payments, and deliveries.
  • Customer support – respond to your queries and resolve issues.
  • Security – verify identity, prevent fraud, and enforce our terms.

3.1.2 Service Improvements

  • Performance monitoring – ensure the platform runs smoothly and loads quickly.
  • Bug fixes – diagnose and correct technical errors.
  • Feature development – tailor new functionalities to user needs.
  • Personalisation – recommend content and offers based on your behaviour.

3.2 Secondary Uses

3.2.1 Analytics and Research

  • Aggregate and anonymise usage data to understand broader trends.
  • Conduct A/B testing to optimise user interfaces.
  • Publish anonymised statistics for industry research (without identifying individuals).

3.2.2 Marketing Communications

  • Send newsletters, promotions, and event invites – only with your explicit consent.
  • Deliver targeted ads through third‑party networks (you can opt out at any time).
  • Retargeting – show you relevant ads on other websites after you leave our platform.

Your Choices – You can update your marketing preferences at any time via your account settings or by clicking “Unsubscribe” in any marketing email. We will respect your decision within 48 hours.

4. Data Protection and Security

We employ industry‑standard security measures to protect your data against unauthorised access, accidental loss, or destruction. Our security program includes administrative, technical, and physical safeguards.

4.1 Security Infrastructure

4.1.1 Encryption Standards

  • In transit – All data transmitted between your device and our servers is encrypted using TLS 1.3 (or higher).
  • At rest – Sensitive fields (e.g., passwords, payment details) are encrypted using AES‑256 encryption.
  • End‑to‑end – For certain high‑risk interactions (e.g., password reset), we apply additional encryption layers.

4.1.2 Access Controls

  • Role‑based access – Only authorised employees can access your data, and only to the extent necessary for their job.
  • Multi‑factor authentication – All administrative accounts require MFA.
  • Regular audits – We review access logs and revoke privileges promptly upon role changes.

4.2 Incident Response

4.2.1 Breach Notification

In the unlikely event of a data breach that affects your personal information:

  • We will notify you within 72 hours of becoming aware, as required by GDPR.
  • We will also notify the relevant supervisory authorities without undue delay.
  • The notification will describe the nature of the breach, likely consequences, and steps we have taken.

4.2.2 Mitigation Procedures

  • Immediate containment – isolate affected systems.
  • Forensic investigation – determine root cause.
  • Remediation – patch vulnerabilities and enhance controls.
  • Continuous monitoring – implement additional surveillance to prevent recurrence.
Visual Guide
Schematic diagram of our layered security architecture – showing firewalls, encryption layers, access control gates, and monitoring dashboards.
Video Explanation
Short animated explainer on how we protect your data – 1 min, available on our Security page.

5. Cookies and Tracking

Cookies are small text files stored on your device that help us recognise you, remember your preferences, and improve your experience. We use both first‑party (set by us) and third‑party (set by partners) cookies.

TypePurposeStored DataDuration
EssentialEnable core functionalities (login, shopping cart, security)Session identifiers, user IDSession / Persistent
PreferencesRemember your language, region, accessibility settingsLocale, timezone, UI choicesUp to 1 year
AnalyticsCollect aggregated usage statistics to improve our servicesPages visited, referral sourcesUp to 2 years
Marketing / AdDeliver personalised advertisements and measure campaign effectivenessBehavioural data, click patternsUp to 1 year

5.1.1 Essential Cookies

These cookies are strictly necessary for the service to function. They cannot be disabled without breaking the platform.

5.1.2 Analytics Cookies

We use tools like Google Analytics and Mixpanel to track user interactions in a de‑identified manner. You can opt out of these via our cookie consent banner or browser plugins.

5.2.1 Browser Controls

You can control and delete cookies through your browser settings. Most browsers allow you to:

  • Block all cookies (may affect usability).
  • Delete existing cookies.
  • Set preferences for specific sites.

How to Manage Cookies – Chrome: Settings → Privacy & Security → Cookies and other site data. Firefox: Options → Privacy & Security → Cookies and Site Data. Safari: Preferences → Privacy → Block all cookies.

When you first visit our site, a cookie consent banner appears. You can:

  • Accept all – allow all categories.
  • Customise – choose which types to allow.
  • Reject non‑essential – only essential cookies will be set.

Your preferences are stored for 6 months; you can change them anytime via the “Cookie Settings” link in the footer.

6. Data Retention and Deletion

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including satisfying any legal, accounting, or reporting requirements. When data is no longer needed, we securely delete or anonymise it.

6.1 Retention Periods

Retention periods vary depending on the type of data and the purpose of processing. The table below outlines our standard and legal retention schedules:

Data CategoryRetention PeriodRationale
Account Data (name, email, profile)Until you delete your account + 30-day grace periodTo maintain your profile and preferences while you are an active user.
Transaction & Billing Data7 yearsTo comply with tax, audit, and financial reporting laws.
Usage & Analytics DataUp to 26 months (aggregated after 6 months)To improve our service and understand user behaviour trends.
Support Tickets & Chat Logs3 yearsTo resolve disputes, track issues, and train support staff.
Marketing Consent RecordsUntil you withdraw consent + 2 yearsTo demonstrate compliance and honour your preferences.
Server Logs (IP, timestamps)6 monthsFor security investigations and performance diagnostics.

6.1.1 Standard Retention

For most personal data, we apply the principle of data minimisation and retain information only for the duration of your active relationship with us. After account closure, we initiate a 30‑day grace period during which you can reactivate your account; after that, routine deletion begins.

Certain data must be retained for longer periods due to legal obligations, such as:

  • Tax and accounting records – typically 7 years (varies by jurisdiction).
  • Anti‑fraud and anti‑money laundering checks – up to 5 years.
  • Litigation or regulatory investigations – until the matter is fully resolved.

6.2 Deletion Process

6.2.1 Account Deletion

You can request account deletion at any time via your account settings or by contacting support. The process works as follows:

  1. You submit a deletion request (we may ask you to verify your identity).
  2. We deactivate your account immediately – you cannot log in.
  3. A 30‑day recovery window opens; you can cancel the deletion within this period.
  4. After 30 days, we permanently delete all personal data except what we must retain for legal reasons.
  5. You receive a confirmation email once deletion is complete.

⚠️ Account deletion is irreversible. All your content, messages, and settings will be permanently removed. Please export any data you wish to keep before initiating deletion.

6.2.2 Secure Data Disposal

We use multiple secure disposal methods to ensure data cannot be recovered:

  • Digital data – overwritten with random patterns (DoD 5220.22‑M standard) or cryptographically erased.
  • Physical media – shredded, degaussed, or incinerated in certified facilities.
  • Backup copies – purged in alignment with the same retention schedule.
Visual Guide
Illustration of our secure data destruction lifecycle – from request to final purge.

7. Disclosure to Third Parties

We never sell your personal data to third parties. However, we do share data with select partners and service providers who enable us to deliver and improve our platform. All recipients are bound by strict confidentiality and data protection obligations.

7.1 Disclosure Circumstances

7.1.1 Service Providers

We engage trusted third parties to perform essential functions on our behalf. These include:

Service TypeExamples of ProvidersData SharedPurpose
Cloud InfrastructureAWS, Google CloudAll data processed by the platformHosting, storage, and scaling
Payment ProcessingStripe, PayPalPayment details, billing address, transaction amountProcess payments and prevent fraud
Email & NotificationsSendGrid, MailchimpEmail address, name, preferencesSend transactional emails and marketing (with consent)
Analytics & MonitoringGoogle Analytics, DatadogUsage data, IP address (anonymised), performance logsMonitor performance and improve user experience
Customer SupportZendeskName, email, support ticket contentManage and respond to support inquiries

We may disclose your information to law enforcement, regulators, or other authorities if:

  • Required by applicable law, court order, or legal process.
  • Necessary to protect our rights, property, or safety (or those of our users).
  • To investigate or prevent fraud, security breaches, or illegal activity.

7.2 Third-Party Processing

7.2.1 Data Processors

All third‑party processors are carefully vetted and sign Data Processing Agreements (DPAs) that require them to:

  • Process data only for our instructed purposes.
  • Implement appropriate security measures.
  • Assist us with data subject rights requests.
  • Notify us promptly of any data breaches.

7.2.2 Data Sub-processors

Some of our processors use sub‑processors (e.g., AWS uses subcontractors for data centre maintenance). We maintain a list of all sub‑processors and ensure they meet our security and privacy standards. You can request the current list by contacting our DPO.

We regularly review our third‑party vendors and update our sub‑processor list. Any material changes will be communicated via this policy or direct notice.

8. International Data Transfers

Our platform operates globally, which means your data may be transferred to and processed in countries outside your jurisdiction (including the US, EU, and Asia). We ensure that all such transfers comply with applicable data protection laws.

8.1 Cross-Border Transfers

8.1.1 Transfer Safeguards

For transfers from the EEA, UK, or Switzerland to non‑adequate countries, we rely on:

  • Standard Contractual Clauses (SCCs) adopted by the European Commission.
  • UK International Data Transfer Addendum (for UK transfers).
  • Additional supplementary measures (e.g., encryption, pseudonymisation) to mitigate risks.

8.1.2 Compliance Measures

We regularly conduct Transfer Impact Assessments (TIAs) to evaluate the legal environment of recipient countries. We maintain internal policies to ensure ongoing compliance with evolving regulations, such as the GDPR, CCPA, and LGPD.

8.2 Adequacy Decisions

8.2.1 EU Adequacy

The European Commission has recognised certain countries as providing “adequate” levels of data protection. When we transfer data to such countries (e.g., Japan, South Korea, UK), no additional safeguards are required. You can find the full adequacy list on the European Commission's website.

8.2.2 Standard Contractual Clauses

For all other international transfers, we incorporate the EU SCCs into our contracts with vendors and partners. We also implement the necessary organisational and technical measures to ensure an equivalent level of protection. Copies of these clauses are available upon request.

Video Explanation
Brief explainer video on how we safely transfer data across borders – 2 min.

9. Legal Basis for Processing (GDPR)

For individuals in the European Economic Area (EEA), the UK, and Switzerland, we process your data only on one or more of the following legal bases. This section helps you understand which basis applies to each processing activity.

9.1 Processing Grounds

Processing ActivityLegal BasisExplanation
Account creation and authenticationPerformance of a contractNecessary to provide our service as requested by you.
Payment processing and billingPerformance of a contractNecessary to complete your transactions.
Customer support and dispute resolutionPerformance of a contract / Legitimate interestTo fulfil our service obligations and ensure user satisfaction.
Service improvements and analyticsLegitimate interestTo optimise and enhance our platform for all users.
Marketing and promotional emailsConsentYou have actively opted in; you can withdraw at any time.
Fraud prevention and securityLegitimate interest / Legal obligationTo protect our users and comply with anti‑fraud laws.
Legal compliance (tax, court orders)Legal obligationRequired by applicable laws and regulations.

We ask for your explicit consent before processing your data for certain purposes, such as sending marketing communications, storing non‑essential cookies, or processing sensitive data. You have the right to withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

9.1.2 Legitimate Interests

We rely on our legitimate business interests to process data when such interests are not overridden by your rights and freedoms. These interests include:

  • Keeping our platform secure and up‑to‑date.
  • Analysing usage to improve user engagement.
  • Enforcing our terms of service and protecting against abuse.
  • Business continuity and disaster recovery.

We always perform a balancing test to ensure our interests are proportionate and respect your privacy.

9.2 Special Category Data

9.2.1 Sensitive Data

We do not actively collect special category data (e.g., race, ethnicity, political opinions, health, biometrics, sexual orientation). If you voluntarily provide such data (e.g., in support messages), we will treat it with enhanced security and process it only if:

  • You have given explicit consent for one or more specific purposes.
  • It is necessary for the establishment, exercise, or defence of legal claims.
  • It is necessary for reasons of substantial public interest, with a proper legal basis.

Whenever we process sensitive data, we obtain your explicit, unambiguous consent via a separate opt‑in mechanism. You can withdraw this consent anytime, and we will cease processing for that purpose.

You have the right to object to processing based on legitimate interests at any time. Use the contact details in Section 14 to submit your objection.

10. Children's Privacy

We take children's privacy very seriously and comply with the Children's Online Privacy Protection Act (COPPA) in the US, the GDPR age‑related provisions in Europe, and similar laws globally.

10.1 Protection Measures

10.1.1 Age Restrictions

Our platform is not directed at children under the following age limits:

  • EEA, UK, and Switzerland – minimum age is 16 (or lower if your country's law allows, but never below 13).
  • United States – minimum age is 13 (under COPPA).
  • Other countries – we apply the age of 13 as a baseline, or higher if local law requires.

We do not knowingly collect personal data from children below these thresholds. If we become aware that we have inadvertently collected such data, we will delete it promptly.

10.1.2 Parent or Guardian Rights

If you are a parent or legal guardian and believe your child under the applicable age has provided us with personal data, you have the right to:

  • Request access to, or deletion of, your child's data.
  • Revoke any consent previously given on behalf of your child.
  • Request that we stop collecting or using your child's data.

We will verify your identity and relationship to the child before taking any action.

10.2 Verification Processes

For services that may involve children (e.g., educational features), we implement a verifiable parental consent process. This may include:

  • Emailing parents with a consent form.
  • Requiring a credit card or government‑issued ID for verification.
  • Using knowledge‑based authentication questions.
  • Video call verification for high‑risk cases.

10.2.2 Age Verification

We may use age‑verification tools (e.g., AI‑based estimation, date‑of‑birth entry) during sign‑up. If we cannot reliably verify age, we will restrict the account or require additional parental confirmation.

Visual Guide
Flowchart of our parental consent and age verification process.

We encourage parents to monitor their children's online activities and educate them about safe internet practices. For additional resources, please refer to our Safety Centre.

11. Your User Rights

Depending on your location and applicable data protection laws (including GDPR, CCPA, CPRA, and LGPD), you have certain rights regarding your personal data. We are committed to facilitating these rights in a transparent and timely manner. All requests are free of charge, although we may charge a reasonable fee for manifestly unfounded, excessive, or repetitive requests.

11.1 Rights Overview

The table below summarises your key data protection rights and what they mean in practice:

RightWhat It MeansHow to Exercise
Right to AccessYou can request a copy of all personal data we hold about you.Submit a Subject Access Request (SAR) via your account or email.
Right to RectificationYou can correct inaccurate or incomplete data.Edit your profile directly or contact support.
Right to Erasure (Right to be Forgotten)You can request deletion of your data when it's no longer needed.Use 'Delete Account' feature or submit a deletion request.
Right to Restrict ProcessingYou can ask us to temporarily stop processing your data (e.g., while a dispute is resolved).Send a formal restriction request with details.
Right to Data PortabilityYou can receive your data in a structured, machine‑readable format (e.g., JSON) and transfer it to another controller.Request an export via account settings or support.
Right to ObjectYou can object to processing based on legitimate interests or direct marketing.Update marketing preferences or submit an objection form.
Right to Withdraw ConsentYou can withdraw any consent you previously gave at any time.Adjust settings or contact us.
Right to ComplainYou have the right to lodge a complaint with your local Data Protection Authority.Contact your national DPA directly (details in Section 14).

11.1.1 Access and Correction

You can access and correct most of your personal data directly through your account dashboard. This includes your name, email, phone number, billing addresses, and communication preferences. For data not editable via the interface, please contact our support team. We will provide you with a copy of your data in a commonly used electronic format within 30 days of verification.

11.1.2 Data Portability

Where technically feasible, you can request that we transfer your data directly to another service provider. We support exports in JSON and CSV formats. This right applies only to data you provided to us, processed by automated means, and based on your consent or contract performance.

11.2 Exercising Rights

11.2.1 Request Submission

To exercise any of your rights, you can:

  • Visit your account's Privacy Center (preferred and fastest method).
  • Email us at privacy@yourplatform.com with the subject line "Data Rights Request".
  • Call our dedicated privacy hotline (number available in the Contact section).
  • Mail us at the postal address provided in Section 14.

When submitting a request, please provide sufficient information to help us locate your data (e.g., account email, user ID) and clarify which right(s) you are exercising. We may ask for additional verification to prevent unauthorised access.

Identity Verification – To protect your privacy, we will verify your identity using at least two factors (e.g., email confirmation plus a security code sent to your phone). This helps ensure we do not disclose your data to the wrong person.

11.2.2 Response Timeline

We aim to respond to all legitimate requests within:

  • 30 calendar days for GDPR/UK requests (extendable by 60 additional days for complex cases).
  • 45 calendar days for CCPA/CPRA requests (California).
  • We will notify you if we need an extension and explain the reason.

If we cannot fulfill your request (e.g., we cannot verify your identity, or the request conflicts with legal obligations), we will explain the reasons in writing. You have the right to escalate or appeal our decision.

Visual Guide
Visual guide to the user rights request process – from submission to resolution.
Video Explanation
Step‑by‑step tutorial on how to download your data and manage privacy settings – 3 min.

12. Updates to This Policy

Our privacy practices evolve as technology, legal requirements, and our business operations change. We are committed to keeping this policy current and transparent. Any changes will be communicated clearly, and we will always respect your rights and preferences.

12.1 Policy Revisions

12.1.1 Notification Process

When we update this policy, we use the following notification channels:

  • Email – Sent to the primary email address on your account for material changes (e.g., new data uses, changes to retention periods, or new third‑party sharing).
  • In‑app / website banner – A prominent notice will appear when you log in or visit our homepage.
  • Policy page update – The "Last Updated" date at the top of this page will be revised, and a summary of changes will be included in a changelog section.

We provide notice at least 30 days before major changes take effect, allowing you time to review and, if necessary, withdraw consent or close your account.

12.1.2 Effective Date

The "Last Updated" date at the top of the policy indicates when the latest version became effective. Minor updates (e.g., clarifications, typographical corrections, or non‑substantive changes) may take effect immediately without prior notice, but we will always update the date.

12.2 User Acknowledgment

12.2.1 Acceptance of Changes

By continuing to use our services after the effective date of any changes, you acknowledge that you have read and understood the updated policy. If you do not agree with the changes, you have the option to:

  • Delete your account before the new policy takes effect.
  • Object to specific processing activities (e.g., new marketing uses).
  • Contact us to discuss your concerns.

12.2.2 Continued Use

Your continued use of the platform after the updated policy becomes effective constitutes your acceptance of the revised terms. If you are a user subject to GDPR or CCPA and we require your explicit consent for new processing purposes, we will obtain it separately before proceeding.

We encourage you to review this policy periodically. You can always find the latest version on our website. We also maintain a public changelog summarising each revision for full transparency.

13. Governing Law

This Privacy Policy is governed by and construed in accordance with the laws of the jurisdiction where our headquarters are located, as well as any applicable international privacy regulations that protect your rights. We are committed to upholding the highest global standards of data protection.

13.1 Applicable Jurisdiction

13.1.1 Local Laws

Our primary establishment is in the European Union (Ireland) for GDPR purposes, and we also have legal entities in the United States and Singapore. Depending on your location:

RegionPrimary Governing LawSupervisory Authority
European Economic Area (EEA) & UKGDPR (EU) 2016/679 & UK GDPRData Protection Commission (Ireland) / ICO (UK)
United States (California)CCPA / CPRACalifornia Privacy Protection Agency (CPPA)
BrazilLGPD (Lei Geral de Proteção de Dados)ANPD (Autoridade Nacional de Proteção de Dados)
Other Global UsersIrish GDPR (as our main establishment)Local DPA where applicable

If you are located outside these regions, we will apply the local laws that are most protective of your privacy and ensure compliance with any mandatory local provisions.

13.1.2 Dispute Resolution

We are committed to resolving any privacy concerns you may have. Our dispute resolution process is as follows:

  1. Internal Review – Contact our Data Protection Officer (DPO) with your complaint. We will investigate and respond within 30 days.
  2. Alternative Dispute Resolution – If we cannot resolve the issue, we will offer mediation or arbitration through a certified privacy dispute resolution service.
  3. Regulatory Complaint – You have the right to lodge a complaint with your local supervisory authority. For EU users, the lead authority is the Irish Data Protection Commission (DPC).

13.2 Regulatory Compliance

13.2.1 Data Protection Authorities

We proactively cooperate with data protection authorities worldwide. Our lead supervisory authority is the Irish Data Protection Commission (DPC). We also register with the ICO (UK) and other agencies where required. You can contact them directly if you are unsatisfied with our response.

13.2.2 Industry Standards

We adhere to recognised privacy frameworks and certifications, including:

  • ISO 27701 (Privacy Information Management).
  • EU‑US Data Privacy Framework (where applicable, with pending certification).
  • APEC Cross‑Border Privacy Rules (CBPR) system for Asia‑Pacific transfers.
Visual Guide
Certification badges – showing our commitment to international privacy standards.

14. Contact Information

We welcome your questions, concerns, and feedback regarding this Privacy Policy or our data practices. Our dedicated privacy team is here to help you.

14.1 Contact Methods

14.1.1 Email Support

For general privacy inquiries, rights requests, or data protection questions, please email us at:

  • General Privacy – privacy@yourplatform.com
  • Data Subject Requests (Access, Erasure, Portability) – dpo@yourplatform.com (preferred for formal requests)
  • Marketing Opt‑out – unsubscribe@yourplatform.com

14.1.2 Postal Address

You may also send written correspondence to our legal headquarters:

  • EU Office (Data Controller): YourPlatform Ltd., 123 Data Street, Dublin 2, D02 XY12, Ireland
  • US Office (for CCPA matters): YourPlatform Inc., 456 Privacy Avenue, San Francisco, CA 94105, USA
  • APAC Office: YourPlatform Pte Ltd., 789 Technology Blvd, Singapore 018989

When contacting us by post, please include your account email address and a clear description of your request or concern. This helps us process your inquiry faster and more accurately.

14.2 Data Protection Officer

14.2.1 DPO Contact

We have appointed a qualified Data Protection Officer (DPO) who oversees our privacy strategy and compliance. You can reach our DPO directly for any matter related to the processing of your personal data:

  • Name: Dr. Aisha Patel
  • Email: dpo@yourplatform.com (preferred)
  • Phone: +353 1 234 5678 (Mon–Fri, 9 AM – 5 PM GMT)

14.2.2 Inquiries and Complaints

If you are not satisfied with our response, you have the right to escalate your complaint to the relevant supervisory authority. For EU users, the Irish Data Protection Commission is our lead authority:

  • Irish Data Protection Commission – www.dataprotection.ie
  • UK Information Commissioner's Office – www.ico.org.uk
  • California Privacy Protection Agency – cppa.ca.gov

We aim to resolve all complaints within 30 days. If your issue is complex, we will notify you and provide a revised timeline. Your trust is important to us.

Video Explanation
Welcome message from our DPO explaining our commitment to privacy – 2 min.

15. Definitions

To help you understand this Privacy Policy, we have defined key terms below. These definitions are consistent with major data protection regulations including the GDPR and CCPA.

15.1 Technical Terms

15.1.1 Platform Terminology

TermDefinition
Platform / ServiceOur websites, mobile applications, APIs, and any associated online services operated by us.
AccountA registered user profile created to access our services, requiring authentication.
User / YouAny individual who interacts with our platform, whether as a registered user, guest, or visitor.
ContentAny information, text, media, or data submitted, posted, or displayed on our platform by users.
DeviceAny computer, smartphone, tablet, or other electronic equipment used to access our platform.

15.1.2 Security Terminology

TermDefinition
EncryptionThe process of converting data into a coded form to prevent unauthorised access. We use AES‑256 for data at rest and TLS 1.3 for data in transit.
PseudonymisationReplacing identifiers with a pseudonym to reduce the linkability of data to an individual, while allowing data analysis.
AnonymisationData processing that permanently and irreversibly removes all identifiers so that individuals cannot be re‑identified.
Data BreachA security incident leading to the accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of personal data.
MFA (Multi‑Factor Authentication)A security method requiring two or more verification factors to access an account.

15.2.1 Personal Data Definition

Under GDPR Article 4(1), 'personal data' means any information relating to an identified or identifiable natural person. This includes, but is not limited to:

  • A name, an identification number, location data, or an online identifier.
  • One or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that person.
  • For CCPA, it also includes any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household.

15.2.2 Processing Definition

Under GDPR Article 4(2), 'processing' means any operation or set of operations performed on personal data, whether by automated means or not. This includes:

  • Collection, recording, organisation, structuring, storage, adaptation or alteration.
  • Retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available.
  • Alignment or combination, restriction, erasure or destruction.

Our processing always aligns with the principles of lawfulness, fairness, and transparency, and we maintain records of all processing activities as required by law.

Thank you for taking the time to understand our Privacy Policy. We are dedicated to protecting your data and ensuring your rights are respected. If you have any further questions, please do not hesitate to reach out using the contact methods provided in Section 14.