Privacy Policy
Last Updated:
📢 Effective Date – This policy is effective as of 22 February 2026. We are committed to transparency and will notify you of any material changes via email or in‑app notifications.
1. Purpose of This Policy
This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you interact with our platform (the “Service”). Our goal is to help you make informed decisions about your data, in full compliance with applicable privacy laws, including the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and other global standards.
Key Principles
- Lawfulness, Fairness, and Transparency – We process your data only on valid legal grounds and in a clear manner.
- Purpose Limitation – We collect data only for specified, explicit, and legitimate purposes.
- Data Minimisation – We collect only what is strictly necessary for the intended purpose.
- Accuracy & Accountability – We keep your data accurate and take responsibility for its protection.
1.1 Policy Objectives
This policy serves the following objectives:
- Inform you about what data we gather and why.
- Outline your rights regarding your personal data.
- Explain how we protect your information from unauthorised access or loss.
- Describe our retention and deletion practices.
- Detail how we share data with third parties.
1.1.1 Scope of the Policy
This policy applies to all users of our website, mobile applications, and any associated online services, regardless of the device or access method.
1.1.2 Who This Policy Applies To
- Registered account holders
- Guest users / visitors
- Business partners and vendors who interact with our platform
- Anyone who contacts our support team
1.2 Policy Updates
We review this policy regularly to reflect changes in technology, legal requirements, and our operational practices.
- Revision History – A detailed changelog is maintained and available upon request. Major changes are summarised here.
- Notification of Changes – We will notify you via the email address associated with your account or through a prominent notice on our website at least 30 days before any material changes take effect.
2. Information We Collect
To provide, improve, and personalise our services, we collect several categories of information. The table below summarises the main types:
| Category | Examples | Purpose |
|---|---|---|
| Identity Data | Full name, username, date of birth, gender | Account creation, personalisation, legal compliance (age verification) |
| Contact Data | Email address, phone number, postal address | Communication, support, account recovery, marketing (with consent) |
| Financial Data | Payment card details, billing address, transaction history | Process payments, prevent fraud, issue refunds |
| Technical Data | IP address, browser type, device IDs, operating system, log data | Security, analytics, performance monitoring, debugging |
| Usage Data | Pages viewed, time spent, clicks, search queries, interaction patterns | Improve user experience, feature optimisation, content recommendations |
| Location Data | Approximate geolocation (derived from IP) or precise (if consented) | Personalise content, comply with regional regulations, targeted offers |
2.1 Data Categories
2.1.1 Personal Data
We define Personal Data as any information that identifies or could reasonably be used to identify an individual. This includes:
- Identifiers – name, email, phone, account ID.
- Characteristics – age, gender, preferences.
- Financial information – payment instruments.
- Communications – messages, support tickets, feedback.
2.1.2 Technical Data
Technical data is automatically collected via cookies, web beacons, and server logs. It does not directly identify you but is essential for security and performance.
- IP address – used for geolocation and network diagnostics.
- Browser fingerprint – helps detect fraudulent logins.
- Device identifiers – to remember your preferences.
2.2 Collection Methods
2.2.1 Direct Collection
You directly provide data when you:
- Create an account or fill out forms.
- Subscribe to newsletters or promotional offers.
- Make a purchase or request a service.
- Contact customer support.
- Participate in surveys or contests.
2.2.2 Automated Collection
We and our trusted partners use:
- Cookies (see Section 5).
- Tracking pixels – to analyse email open rates and conversion.
- Log files – to capture system activity and error reports.
- Third‑party analytics (e.g., Google Analytics) – to aggregate usage trends.
Sensitive Data – We do not intentionally collect special categories of data (e.g., health, racial/ethnic origin, political opinions, biometrics) unless you explicitly provide them for a specific purpose (e.g., accessibility accommodations). If you choose to share such data, we will treat it with additional safeguards.
3. How We Use Your Information
We process your data only for the purposes described below, each supported by a valid legal basis (e.g., performance of a contract, legitimate interest, consent, or legal obligation).
3.1 Primary Uses
3.1.1 Service Delivery
- Account management – create, maintain, and authenticate your profile.
- Transaction processing – handle orders, payments, and deliveries.
- Customer support – respond to your queries and resolve issues.
- Security – verify identity, prevent fraud, and enforce our terms.
3.1.2 Service Improvements
- Performance monitoring – ensure the platform runs smoothly and loads quickly.
- Bug fixes – diagnose and correct technical errors.
- Feature development – tailor new functionalities to user needs.
- Personalisation – recommend content and offers based on your behaviour.
3.2 Secondary Uses
3.2.1 Analytics and Research
- Aggregate and anonymise usage data to understand broader trends.
- Conduct A/B testing to optimise user interfaces.
- Publish anonymised statistics for industry research (without identifying individuals).
3.2.2 Marketing Communications
- Send newsletters, promotions, and event invites – only with your explicit consent.
- Deliver targeted ads through third‑party networks (you can opt out at any time).
- Retargeting – show you relevant ads on other websites after you leave our platform.
Your Choices – You can update your marketing preferences at any time via your account settings or by clicking “Unsubscribe” in any marketing email. We will respect your decision within 48 hours.
4. Data Protection and Security
We employ industry‑standard security measures to protect your data against unauthorised access, accidental loss, or destruction. Our security program includes administrative, technical, and physical safeguards.
4.1 Security Infrastructure
4.1.1 Encryption Standards
- In transit – All data transmitted between your device and our servers is encrypted using TLS 1.3 (or higher).
- At rest – Sensitive fields (e.g., passwords, payment details) are encrypted using AES‑256 encryption.
- End‑to‑end – For certain high‑risk interactions (e.g., password reset), we apply additional encryption layers.
4.1.2 Access Controls
- Role‑based access – Only authorised employees can access your data, and only to the extent necessary for their job.
- Multi‑factor authentication – All administrative accounts require MFA.
- Regular audits – We review access logs and revoke privileges promptly upon role changes.
4.2 Incident Response
4.2.1 Breach Notification
In the unlikely event of a data breach that affects your personal information:
- We will notify you within 72 hours of becoming aware, as required by GDPR.
- We will also notify the relevant supervisory authorities without undue delay.
- The notification will describe the nature of the breach, likely consequences, and steps we have taken.
4.2.2 Mitigation Procedures
- Immediate containment – isolate affected systems.
- Forensic investigation – determine root cause.
- Remediation – patch vulnerabilities and enhance controls.
- Continuous monitoring – implement additional surveillance to prevent recurrence.
5. Cookies and Tracking
Cookies are small text files stored on your device that help us recognise you, remember your preferences, and improve your experience. We use both first‑party (set by us) and third‑party (set by partners) cookies.
5.1 Cookie Types
| Type | Purpose | Stored Data | Duration |
|---|---|---|---|
| Essential | Enable core functionalities (login, shopping cart, security) | Session identifiers, user ID | Session / Persistent |
| Preferences | Remember your language, region, accessibility settings | Locale, timezone, UI choices | Up to 1 year |
| Analytics | Collect aggregated usage statistics to improve our services | Pages visited, referral sources | Up to 2 years |
| Marketing / Ad | Deliver personalised advertisements and measure campaign effectiveness | Behavioural data, click patterns | Up to 1 year |
5.1.1 Essential Cookies
These cookies are strictly necessary for the service to function. They cannot be disabled without breaking the platform.
5.1.2 Analytics Cookies
We use tools like Google Analytics and Mixpanel to track user interactions in a de‑identified manner. You can opt out of these via our cookie consent banner or browser plugins.
5.2 Management
5.2.1 Browser Controls
You can control and delete cookies through your browser settings. Most browsers allow you to:
- Block all cookies (may affect usability).
- Delete existing cookies.
- Set preferences for specific sites.
How to Manage Cookies – Chrome: Settings → Privacy & Security → Cookies and other site data. Firefox: Options → Privacy & Security → Cookies and Site Data. Safari: Preferences → Privacy → Block all cookies.
5.2.2 Consent Preferences
When you first visit our site, a cookie consent banner appears. You can:
- Accept all – allow all categories.
- Customise – choose which types to allow.
- Reject non‑essential – only essential cookies will be set.
Your preferences are stored for 6 months; you can change them anytime via the “Cookie Settings” link in the footer.
Do Not Track – Our platform currently does not respond to “Do Not Track” signals from browsers because there is no consistent industry standard. However, you can still manage cookies via the methods above.
6. Data Retention and Deletion
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including satisfying any legal, accounting, or reporting requirements. When data is no longer needed, we securely delete or anonymise it.
6.1 Retention Periods
Retention periods vary depending on the type of data and the purpose of processing. The table below outlines our standard and legal retention schedules:
| Data Category | Retention Period | Rationale |
|---|---|---|
| Account Data (name, email, profile) | Until you delete your account + 30-day grace period | To maintain your profile and preferences while you are an active user. |
| Transaction & Billing Data | 7 years | To comply with tax, audit, and financial reporting laws. |
| Usage & Analytics Data | Up to 26 months (aggregated after 6 months) | To improve our service and understand user behaviour trends. |
| Support Tickets & Chat Logs | 3 years | To resolve disputes, track issues, and train support staff. |
| Marketing Consent Records | Until you withdraw consent + 2 years | To demonstrate compliance and honour your preferences. |
| Server Logs (IP, timestamps) | 6 months | For security investigations and performance diagnostics. |
6.1.1 Standard Retention
For most personal data, we apply the principle of data minimisation and retain information only for the duration of your active relationship with us. After account closure, we initiate a 30‑day grace period during which you can reactivate your account; after that, routine deletion begins.
6.1.2 Legal Retention
Certain data must be retained for longer periods due to legal obligations, such as:
- Tax and accounting records – typically 7 years (varies by jurisdiction).
- Anti‑fraud and anti‑money laundering checks – up to 5 years.
- Litigation or regulatory investigations – until the matter is fully resolved.
Legal Hold – If your data is subject to a legal hold (e.g., court order, pending litigation), we will retain it beyond the standard periods until the hold is lifted. You will be notified if such a hold applies to you.
6.2 Deletion Process
6.2.1 Account Deletion
You can request account deletion at any time via your account settings or by contacting support. The process works as follows:
- You submit a deletion request (we may ask you to verify your identity).
- We deactivate your account immediately – you cannot log in.
- A 30‑day recovery window opens; you can cancel the deletion within this period.
- After 30 days, we permanently delete all personal data except what we must retain for legal reasons.
- You receive a confirmation email once deletion is complete.
⚠️ Account deletion is irreversible. All your content, messages, and settings will be permanently removed. Please export any data you wish to keep before initiating deletion.
6.2.2 Secure Data Disposal
We use multiple secure disposal methods to ensure data cannot be recovered:
- Digital data – overwritten with random patterns (DoD 5220.22‑M standard) or cryptographically erased.
- Physical media – shredded, degaussed, or incinerated in certified facilities.
- Backup copies – purged in alignment with the same retention schedule.
7. Disclosure to Third Parties
We never sell your personal data to third parties. However, we do share data with select partners and service providers who enable us to deliver and improve our platform. All recipients are bound by strict confidentiality and data protection obligations.
7.1 Disclosure Circumstances
7.1.1 Service Providers
We engage trusted third parties to perform essential functions on our behalf. These include:
| Service Type | Examples of Providers | Data Shared | Purpose |
|---|---|---|---|
| Cloud Infrastructure | AWS, Google Cloud | All data processed by the platform | Hosting, storage, and scaling |
| Payment Processing | Stripe, PayPal | Payment details, billing address, transaction amount | Process payments and prevent fraud |
| Email & Notifications | SendGrid, Mailchimp | Email address, name, preferences | Send transactional emails and marketing (with consent) |
| Analytics & Monitoring | Google Analytics, Datadog | Usage data, IP address (anonymised), performance logs | Monitor performance and improve user experience |
| Customer Support | Zendesk | Name, email, support ticket content | Manage and respond to support inquiries |
7.1.2 Legal Requirements
We may disclose your information to law enforcement, regulators, or other authorities if:
- Required by applicable law, court order, or legal process.
- Necessary to protect our rights, property, or safety (or those of our users).
- To investigate or prevent fraud, security breaches, or illegal activity.
Government Requests – We will only disclose data when legally compelled. We will notify you of such requests unless we are prohibited by law or the request relates to an ongoing investigation.
7.2 Third-Party Processing
7.2.1 Data Processors
All third‑party processors are carefully vetted and sign Data Processing Agreements (DPAs) that require them to:
- Process data only for our instructed purposes.
- Implement appropriate security measures.
- Assist us with data subject rights requests.
- Notify us promptly of any data breaches.
7.2.2 Data Sub-processors
Some of our processors use sub‑processors (e.g., AWS uses subcontractors for data centre maintenance). We maintain a list of all sub‑processors and ensure they meet our security and privacy standards. You can request the current list by contacting our DPO.
We regularly review our third‑party vendors and update our sub‑processor list. Any material changes will be communicated via this policy or direct notice.
8. International Data Transfers
Our platform operates globally, which means your data may be transferred to and processed in countries outside your jurisdiction (including the US, EU, and Asia). We ensure that all such transfers comply with applicable data protection laws.
8.1 Cross-Border Transfers
8.1.1 Transfer Safeguards
For transfers from the EEA, UK, or Switzerland to non‑adequate countries, we rely on:
- Standard Contractual Clauses (SCCs) adopted by the European Commission.
- UK International Data Transfer Addendum (for UK transfers).
- Additional supplementary measures (e.g., encryption, pseudonymisation) to mitigate risks.
8.1.2 Compliance Measures
We regularly conduct Transfer Impact Assessments (TIAs) to evaluate the legal environment of recipient countries. We maintain internal policies to ensure ongoing compliance with evolving regulations, such as the GDPR, CCPA, and LGPD.
8.2 Adequacy Decisions
8.2.1 EU Adequacy
The European Commission has recognised certain countries as providing “adequate” levels of data protection. When we transfer data to such countries (e.g., Japan, South Korea, UK), no additional safeguards are required. You can find the full adequacy list on the European Commission's website.
8.2.2 Standard Contractual Clauses
For all other international transfers, we incorporate the EU SCCs into our contracts with vendors and partners. We also implement the necessary organisational and technical measures to ensure an equivalent level of protection. Copies of these clauses are available upon request.
US transfers – While we rely on SCCs, we also implement additional protections (such as data minimisation and regular compliance audits) to address concerns raised by Schrems II and subsequent guidance.
9. Legal Basis for Processing (GDPR)
For individuals in the European Economic Area (EEA), the UK, and Switzerland, we process your data only on one or more of the following legal bases. This section helps you understand which basis applies to each processing activity.
9.1 Processing Grounds
| Processing Activity | Legal Basis | Explanation |
|---|---|---|
| Account creation and authentication | Performance of a contract | Necessary to provide our service as requested by you. |
| Payment processing and billing | Performance of a contract | Necessary to complete your transactions. |
| Customer support and dispute resolution | Performance of a contract / Legitimate interest | To fulfil our service obligations and ensure user satisfaction. |
| Service improvements and analytics | Legitimate interest | To optimise and enhance our platform for all users. |
| Marketing and promotional emails | Consent | You have actively opted in; you can withdraw at any time. |
| Fraud prevention and security | Legitimate interest / Legal obligation | To protect our users and comply with anti‑fraud laws. |
| Legal compliance (tax, court orders) | Legal obligation | Required by applicable laws and regulations. |
9.1.1 Consent
We ask for your explicit consent before processing your data for certain purposes, such as sending marketing communications, storing non‑essential cookies, or processing sensitive data. You have the right to withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
9.1.2 Legitimate Interests
We rely on our legitimate business interests to process data when such interests are not overridden by your rights and freedoms. These interests include:
- Keeping our platform secure and up‑to‑date.
- Analysing usage to improve user engagement.
- Enforcing our terms of service and protecting against abuse.
- Business continuity and disaster recovery.
We always perform a balancing test to ensure our interests are proportionate and respect your privacy.
9.2 Special Category Data
9.2.1 Sensitive Data
We do not actively collect special category data (e.g., race, ethnicity, political opinions, health, biometrics, sexual orientation). If you voluntarily provide such data (e.g., in support messages), we will treat it with enhanced security and process it only if:
- You have given explicit consent for one or more specific purposes.
- It is necessary for the establishment, exercise, or defence of legal claims.
- It is necessary for reasons of substantial public interest, with a proper legal basis.
9.2.2 Explicit Consent
Whenever we process sensitive data, we obtain your explicit, unambiguous consent via a separate opt‑in mechanism. You can withdraw this consent anytime, and we will cease processing for that purpose.
You have the right to object to processing based on legitimate interests at any time. Use the contact details in Section 14 to submit your objection.
10. Children's Privacy
We take children's privacy very seriously and comply with the Children's Online Privacy Protection Act (COPPA) in the US, the GDPR age‑related provisions in Europe, and similar laws globally.
10.1 Protection Measures
10.1.1 Age Restrictions
Our platform is not directed at children under the following age limits:
- EEA, UK, and Switzerland – minimum age is 16 (or lower if your country's law allows, but never below 13).
- United States – minimum age is 13 (under COPPA).
- Other countries – we apply the age of 13 as a baseline, or higher if local law requires.
We do not knowingly collect personal data from children below these thresholds. If we become aware that we have inadvertently collected such data, we will delete it promptly.
10.1.2 Parent or Guardian Rights
If you are a parent or legal guardian and believe your child under the applicable age has provided us with personal data, you have the right to:
- Request access to, or deletion of, your child's data.
- Revoke any consent previously given on behalf of your child.
- Request that we stop collecting or using your child's data.
We will verify your identity and relationship to the child before taking any action.
10.2 Verification Processes
10.2.1 Parental Consent
For services that may involve children (e.g., educational features), we implement a verifiable parental consent process. This may include:
- Emailing parents with a consent form.
- Requiring a credit card or government‑issued ID for verification.
- Using knowledge‑based authentication questions.
- Video call verification for high‑risk cases.
10.2.2 Age Verification
We may use age‑verification tools (e.g., AI‑based estimation, date‑of‑birth entry) during sign‑up. If we cannot reliably verify age, we will restrict the account or require additional parental confirmation.
Reporting Underage Users – If you suspect a user is underage without proper consent, please report it immediately to our support team. We will investigate and take appropriate action, including account suspension and data deletion.
We encourage parents to monitor their children's online activities and educate them about safe internet practices. For additional resources, please refer to our Safety Centre.
11. Your User Rights
Depending on your location and applicable data protection laws (including GDPR, CCPA, CPRA, and LGPD), you have certain rights regarding your personal data. We are committed to facilitating these rights in a transparent and timely manner. All requests are free of charge, although we may charge a reasonable fee for manifestly unfounded, excessive, or repetitive requests.
11.1 Rights Overview
The table below summarises your key data protection rights and what they mean in practice:
| Right | What It Means | How to Exercise |
|---|---|---|
| Right to Access | You can request a copy of all personal data we hold about you. | Submit a Subject Access Request (SAR) via your account or email. |
| Right to Rectification | You can correct inaccurate or incomplete data. | Edit your profile directly or contact support. |
| Right to Erasure (Right to be Forgotten) | You can request deletion of your data when it's no longer needed. | Use 'Delete Account' feature or submit a deletion request. |
| Right to Restrict Processing | You can ask us to temporarily stop processing your data (e.g., while a dispute is resolved). | Send a formal restriction request with details. |
| Right to Data Portability | You can receive your data in a structured, machine‑readable format (e.g., JSON) and transfer it to another controller. | Request an export via account settings or support. |
| Right to Object | You can object to processing based on legitimate interests or direct marketing. | Update marketing preferences or submit an objection form. |
| Right to Withdraw Consent | You can withdraw any consent you previously gave at any time. | Adjust settings or contact us. |
| Right to Complain | You have the right to lodge a complaint with your local Data Protection Authority. | Contact your national DPA directly (details in Section 14). |
11.1.1 Access and Correction
You can access and correct most of your personal data directly through your account dashboard. This includes your name, email, phone number, billing addresses, and communication preferences. For data not editable via the interface, please contact our support team. We will provide you with a copy of your data in a commonly used electronic format within 30 days of verification.
11.1.2 Data Portability
Where technically feasible, you can request that we transfer your data directly to another service provider. We support exports in JSON and CSV formats. This right applies only to data you provided to us, processed by automated means, and based on your consent or contract performance.
11.2 Exercising Rights
11.2.1 Request Submission
To exercise any of your rights, you can:
- Visit your account's Privacy Center (preferred and fastest method).
- Email us at privacy@yourplatform.com with the subject line "Data Rights Request".
- Call our dedicated privacy hotline (number available in the Contact section).
- Mail us at the postal address provided in Section 14.
When submitting a request, please provide sufficient information to help us locate your data (e.g., account email, user ID) and clarify which right(s) you are exercising. We may ask for additional verification to prevent unauthorised access.
Identity Verification – To protect your privacy, we will verify your identity using at least two factors (e.g., email confirmation plus a security code sent to your phone). This helps ensure we do not disclose your data to the wrong person.
11.2.2 Response Timeline
We aim to respond to all legitimate requests within:
- 30 calendar days for GDPR/UK requests (extendable by 60 additional days for complex cases).
- 45 calendar days for CCPA/CPRA requests (California).
- We will notify you if we need an extension and explain the reason.
If we cannot fulfill your request (e.g., we cannot verify your identity, or the request conflicts with legal obligations), we will explain the reasons in writing. You have the right to escalate or appeal our decision.
Authorised Agents – Under CCPA, you may designate an authorised agent to submit requests on your behalf. We will require written proof of authorization and may still verify your identity directly.
12. Updates to This Policy
Our privacy practices evolve as technology, legal requirements, and our business operations change. We are committed to keeping this policy current and transparent. Any changes will be communicated clearly, and we will always respect your rights and preferences.
12.1 Policy Revisions
12.1.1 Notification Process
When we update this policy, we use the following notification channels:
- Email – Sent to the primary email address on your account for material changes (e.g., new data uses, changes to retention periods, or new third‑party sharing).
- In‑app / website banner – A prominent notice will appear when you log in or visit our homepage.
- Policy page update – The "Last Updated" date at the top of this page will be revised, and a summary of changes will be included in a changelog section.
We provide notice at least 30 days before major changes take effect, allowing you time to review and, if necessary, withdraw consent or close your account.
12.1.2 Effective Date
The "Last Updated" date at the top of the policy indicates when the latest version became effective. Minor updates (e.g., clarifications, typographical corrections, or non‑substantive changes) may take effect immediately without prior notice, but we will always update the date.
12.2 User Acknowledgment
12.2.1 Acceptance of Changes
By continuing to use our services after the effective date of any changes, you acknowledge that you have read and understood the updated policy. If you do not agree with the changes, you have the option to:
- Delete your account before the new policy takes effect.
- Object to specific processing activities (e.g., new marketing uses).
- Contact us to discuss your concerns.
12.2.2 Continued Use
Your continued use of the platform after the updated policy becomes effective constitutes your acceptance of the revised terms. If you are a user subject to GDPR or CCPA and we require your explicit consent for new processing purposes, we will obtain it separately before proceeding.
We encourage you to review this policy periodically. You can always find the latest version on our website. We also maintain a public changelog summarising each revision for full transparency.
13. Governing Law
This Privacy Policy is governed by and construed in accordance with the laws of the jurisdiction where our headquarters are located, as well as any applicable international privacy regulations that protect your rights. We are committed to upholding the highest global standards of data protection.
13.1 Applicable Jurisdiction
13.1.1 Local Laws
Our primary establishment is in the European Union (Ireland) for GDPR purposes, and we also have legal entities in the United States and Singapore. Depending on your location:
| Region | Primary Governing Law | Supervisory Authority |
|---|---|---|
| European Economic Area (EEA) & UK | GDPR (EU) 2016/679 & UK GDPR | Data Protection Commission (Ireland) / ICO (UK) |
| United States (California) | CCPA / CPRA | California Privacy Protection Agency (CPPA) |
| Brazil | LGPD (Lei Geral de Proteção de Dados) | ANPD (Autoridade Nacional de Proteção de Dados) |
| Other Global Users | Irish GDPR (as our main establishment) | Local DPA where applicable |
If you are located outside these regions, we will apply the local laws that are most protective of your privacy and ensure compliance with any mandatory local provisions.
13.1.2 Dispute Resolution
We are committed to resolving any privacy concerns you may have. Our dispute resolution process is as follows:
- Internal Review – Contact our Data Protection Officer (DPO) with your complaint. We will investigate and respond within 30 days.
- Alternative Dispute Resolution – If we cannot resolve the issue, we will offer mediation or arbitration through a certified privacy dispute resolution service.
- Regulatory Complaint – You have the right to lodge a complaint with your local supervisory authority. For EU users, the lead authority is the Irish Data Protection Commission (DPC).
Class Action Waiver – To the extent permitted by law, you agree to resolve any disputes on an individual basis and waive the right to participate in class actions or collective proceedings.
13.2 Regulatory Compliance
13.2.1 Data Protection Authorities
We proactively cooperate with data protection authorities worldwide. Our lead supervisory authority is the Irish Data Protection Commission (DPC). We also register with the ICO (UK) and other agencies where required. You can contact them directly if you are unsatisfied with our response.
13.2.2 Industry Standards
We adhere to recognised privacy frameworks and certifications, including:
- ISO 27701 (Privacy Information Management).
- EU‑US Data Privacy Framework (where applicable, with pending certification).
- APEC Cross‑Border Privacy Rules (CBPR) system for Asia‑Pacific transfers.
14. Contact Information
We welcome your questions, concerns, and feedback regarding this Privacy Policy or our data practices. Our dedicated privacy team is here to help you.
14.1 Contact Methods
14.1.1 Email Support
For general privacy inquiries, rights requests, or data protection questions, please email us at:
- General Privacy – privacy@yourplatform.com
- Data Subject Requests (Access, Erasure, Portability) – dpo@yourplatform.com (preferred for formal requests)
- Marketing Opt‑out – unsubscribe@yourplatform.com
14.1.2 Postal Address
You may also send written correspondence to our legal headquarters:
- EU Office (Data Controller): YourPlatform Ltd., 123 Data Street, Dublin 2, D02 XY12, Ireland
- US Office (for CCPA matters): YourPlatform Inc., 456 Privacy Avenue, San Francisco, CA 94105, USA
- APAC Office: YourPlatform Pte Ltd., 789 Technology Blvd, Singapore 018989
When contacting us by post, please include your account email address and a clear description of your request or concern. This helps us process your inquiry faster and more accurately.
14.2 Data Protection Officer
14.2.1 DPO Contact
We have appointed a qualified Data Protection Officer (DPO) who oversees our privacy strategy and compliance. You can reach our DPO directly for any matter related to the processing of your personal data:
- Name: Dr. Aisha Patel
- Email: dpo@yourplatform.com (preferred)
- Phone: +353 1 234 5678 (Mon–Fri, 9 AM – 5 PM GMT)
14.2.2 Inquiries and Complaints
If you are not satisfied with our response, you have the right to escalate your complaint to the relevant supervisory authority. For EU users, the Irish Data Protection Commission is our lead authority:
- Irish Data Protection Commission – www.dataprotection.ie
- UK Information Commissioner's Office – www.ico.org.uk
- California Privacy Protection Agency – cppa.ca.gov
We aim to resolve all complaints within 30 days. If your issue is complex, we will notify you and provide a revised timeline. Your trust is important to us.
15. Definitions
To help you understand this Privacy Policy, we have defined key terms below. These definitions are consistent with major data protection regulations including the GDPR and CCPA.
15.1 Technical Terms
15.1.1 Platform Terminology
| Term | Definition |
|---|---|
| Platform / Service | Our websites, mobile applications, APIs, and any associated online services operated by us. |
| Account | A registered user profile created to access our services, requiring authentication. |
| User / You | Any individual who interacts with our platform, whether as a registered user, guest, or visitor. |
| Content | Any information, text, media, or data submitted, posted, or displayed on our platform by users. |
| Device | Any computer, smartphone, tablet, or other electronic equipment used to access our platform. |
15.1.2 Security Terminology
| Term | Definition |
|---|---|
| Encryption | The process of converting data into a coded form to prevent unauthorised access. We use AES‑256 for data at rest and TLS 1.3 for data in transit. |
| Pseudonymisation | Replacing identifiers with a pseudonym to reduce the linkability of data to an individual, while allowing data analysis. |
| Anonymisation | Data processing that permanently and irreversibly removes all identifiers so that individuals cannot be re‑identified. |
| Data Breach | A security incident leading to the accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of personal data. |
| MFA (Multi‑Factor Authentication) | A security method requiring two or more verification factors to access an account. |
15.2 Legal Definitions
15.2.1 Personal Data Definition
Under GDPR Article 4(1), 'personal data' means any information relating to an identified or identifiable natural person. This includes, but is not limited to:
- A name, an identification number, location data, or an online identifier.
- One or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that person.
- For CCPA, it also includes any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household.
15.2.2 Processing Definition
Under GDPR Article 4(2), 'processing' means any operation or set of operations performed on personal data, whether by automated means or not. This includes:
- Collection, recording, organisation, structuring, storage, adaptation or alteration.
- Retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available.
- Alignment or combination, restriction, erasure or destruction.
Our processing always aligns with the principles of lawfulness, fairness, and transparency, and we maintain records of all processing activities as required by law.
These definitions are provided for general informational purposes. In case of any conflict, the definitions in the applicable data protection laws (e.g., GDPR, CCPA) shall prevail.
Thank you for taking the time to understand our Privacy Policy. We are dedicated to protecting your data and ensuring your rights are respected. If you have any further questions, please do not hesitate to reach out using the contact methods provided in Section 14.