Legal / draft

Privacy Policy

Draft for legal review. The controller identity, privacy contact, processors, retention schedule and transfer assessment must be completed before live sales.

Controller and contact

The controller is [LEGAL ENTITY NAME], [REGISTERED OFFICE ADDRESS]. Privacy requests should be sent to [PRIVACY CONTACT EMAIL]. If a data protection officer or UK/EU representative is required, identify them here: [DPO OR REPRESENTATIVE DETAILS].

Information we use

We collect information you provide, information created by your orders and account, security/session identifiers, and limited device or request information needed to operate and protect the service. Do not submit social-media passwords or unnecessary sensitive personal data.

DataPurposeBasis
Account and contact detailsCreate and secure an account, verify email, provide supportContract; legal obligation where applicable
Order target and delivery informationProcess an order, troubleshoot delivery, prevent misuseContract; legitimate interests
Payment and tax metadataConfirm payment, issue records, prevent fraud and meet accounting dutiesContract; legal obligation; legitimate interests
Security and session dataProtect accounts, rate-limit abuse, investigate incidentsLegitimate interests; legal obligation
Optional support-chat dataAnswer a support conversation after optional consent or when necessary for an active support requestConsent or contract, depending on the final provider setup

Recipients and international transfers

We use selected providers for hosting, email delivery, authentication, payment processing and optional support. Name each provider and its role in the final processor list. If information is transferred outside the UK or EEA, document the applicable adequacy decision or safeguard, such as the UK IDTA or UK Addendum, and the required transfer risk assessment.

Retention

We retain account information while the account is active and for as long as needed for security, disputes and legal obligations. Order, payment and invoice records should follow the accountant-approved tax retention schedule. Expired sessions and one-time auth tokens should be removed or anonymised. Insert the final retention schedule here; do not publish estimates as confirmed periods.

Your rights

Depending on where you live, you may have rights to access, correct, erase, restrict, object to or port personal information, and to withdraw consent. We may verify identity before fulfilling a request. You may complain to the UK ICO or your local supervisory authority. We do not use solely automated decisions to determine access to purchased services.

Cookies

Necessary session and security storage is described in the Cookie Policy. Optional support technology is gated by consent in the current first-release implementation.