01Information we collect
Contact information you provide voluntarily: name, email address, phone number, company, message content, and any files you attach to a request.
Account information when you register: email, hashed password, profile preferences and role.
Usage data automatically collected: IP address, browser type, device identifiers, pages viewed, referring URLs and approximate location derived from IP.
Cookie and similar technology data — see our Cookie Notice for details.
02How we use information
Deliver requested services and respond to inquiries.
Authenticate access to client portals and admin systems.
Improve product quality, security, accessibility and performance through anonymized analytics.
Comply with legal obligations, prevent fraud and enforce our terms.
We do not sell personal information. We do not share it with advertisers.
03Legal bases (GDPR)
For EU/UK individuals, we process personal data under one of these bases: (a) consent, (b) performance of a contract you've entered into with us, (c) compliance with a legal obligation, or (d) our legitimate interests in operating, securing and improving our business — balanced against your rights.
04Data sharing & subprocessors
We share personal data only with vetted subprocessors who help us operate (cloud hosting, email delivery, analytics, error monitoring). Each is bound by a written data-processing agreement and may not use your data for their own purposes.
We may disclose information when required by law, valid legal process, or to protect rights, property and safety.
05Your rights
You may request access to, correction of, or deletion of your personal data. EU/UK and California residents have additional rights including data portability and objection to certain processing.
To exercise any right, email [email protected]. We respond within 30 days.
06Retention
We retain personal data only as long as necessary to provide our services and meet legal obligations. Inactive accounts are purged after 24 months. Backups roll off after 90 days.
07Security
We apply industry-standard administrative, technical and physical safeguards: encryption in transit and at rest, MFA on administrative accounts, role-based access, audit logging and periodic security review. No system is impenetrable — we do our best, and tell you promptly if something goes wrong.
08Contact
Privacy questions: [email protected]. Postal: Bitdo Studio, San Salvador, El Salvador.