Privacy policy
We take our users' privacy seriously and are committed to protecting it. This privacy policy explains how we collect, use, disclose, and protect personal information gathered through our website.
Last updated: 12 September 2026
Information provided by the user
When you use our website, you may be asked to provide certain personally identifiable information, which may include, among others:
- Name and surname
- Email address
- Contact information
- Demographic information
Automatically collected information
We automatically collect certain information about your device and browsing behavior using technologies such as cookies, server logs, and web analytics. This information may include:
- IP address
- Browser type
- Pages visited on our website
- Time spent on our website
Use of information
We use the collected information for various purposes, including:
- Personalizing your experience on our website
- Providing relevant content and advertisements
- Improving our products and services
- Communicating with you, responding to your inquiries, and providing information about our services
Information disclosure
We do not sell or share your personal information with third parties except as permitted by law or as necessary to provide the requested services. We may disclose your information in the following circumstances:
- When required by law or in response to legal processes
- To protect and defend our rights and property
- In emergencies to protect personal safety
Account Manager and reserved area
When a user creates or uses a Business Apps / Account Manager account, the Controller processes the data required for registration, authentication and access management: name, email, email-verification status, technical account and session identifiers, organization membership, role, permissions, application-access requests and service notifications.
To document registration, the reference organization, the accepted Privacy Policy and Terms of Use versions, the language and the time of acknowledgement are also stored. Any marketing consent is recorded separately, including grant and withdrawal timestamps.
This processing is necessary to create and manage the account, authenticate the user, provide the reserved area and manage requested services (Art. 6(1)(b) GDPR). Technical security and anti-abuse data are processed to protect systems, users and the Controller's rights (Art. 6(1)(f) GDPR and, where applicable, Art. 6(1)(c) GDPR).
Account data and the related evidence are retained while the account and service relationship remain active and afterwards only for as long as necessary to comply with legal obligations, handle data-subject requests, or establish, exercise or defend legal claims. Technical data with shorter operational windows are deleted according to the system's security rules.
Service communications and marketing
Communications required for the account and services — including authentication, invitations, password recovery, registration notifications and access changes — are transactional communications and do not depend on marketing consent.
Transactional emails may be sent through Resend. Open and click tracking is disabled for authentication, invitation and service communications.
Marketing consent is optional, separate and not preselected. It may be withdrawn at any time without affecting the account or access to services; promotional communications are sent only when consent is valid and the relevant feature is active.
Cloudflare services may be used for application infrastructure, security and database services; Resend may be used for email delivery. These providers and their subprocessors may process data outside the European Economic Area. Where required, transfers rely on adequacy decisions, Standard Contractual Clauses or other safeguards provided by the GDPR.
