Legal / draft
Privacy Policy
Draft for legal review. The controller identity, privacy contact, processors, retention schedule and transfer assessment must be completed before live sales.
Controller and contact
The controller is [LEGAL ENTITY NAME], [REGISTERED OFFICE ADDRESS]. Privacy requests should be sent to [PRIVACY CONTACT EMAIL]. If a data protection officer or UK/EU representative is required, identify them here: [DPO OR REPRESENTATIVE DETAILS].
Information we use
We collect information you provide, information created by your orders and account, security/session identifiers, and limited device or request information needed to operate and protect the service. Do not submit social-media passwords or unnecessary sensitive personal data.
| Data | Purpose | Basis |
|---|---|---|
| Account and contact details | Create and secure an account, verify email, provide support | Contract; legal obligation where applicable |
| Order target and delivery information | Process an order, troubleshoot delivery, prevent misuse | Contract; legitimate interests |
| Payment and tax metadata | Confirm payment, issue records, prevent fraud and meet accounting duties | Contract; legal obligation; legitimate interests |
| Security and session data | Protect accounts, rate-limit abuse, investigate incidents | Legitimate interests; legal obligation |
| Optional support-chat data | Answer a support conversation after optional consent or when necessary for an active support request | Consent or contract, depending on the final provider setup |
Recipients and international transfers
We use selected providers for hosting, email delivery, authentication, payment processing and optional support. Name each provider and its role in the final processor list. If information is transferred outside the UK or EEA, document the applicable adequacy decision or safeguard, such as the UK IDTA or UK Addendum, and the required transfer risk assessment.
Retention
We retain account information while the account is active and for as long as needed for security, disputes and legal obligations. Order, payment and invoice records should follow the accountant-approved tax retention schedule. Expired sessions and one-time auth tokens should be removed or anonymised. Insert the final retention schedule here; do not publish estimates as confirmed periods.
Your rights
Depending on where you live, you may have rights to access, correct, erase, restrict, object to or port personal information, and to withdraw consent. We may verify identity before fulfilling a request. You may complain to the UK ICO or your local supervisory authority. We do not use solely automated decisions to determine access to purchased services.
Cookies
Necessary session and security storage is described in the Cookie Policy. Optional support technology is gated by consent in the current first-release implementation.