Data Protection Notice

General information about personal data processing and privacy rights

1. Purpose of This Notice

This notice explains, in general terms, how personal data may be collected, used, stored, shared, and protected when you visit or interact with a website, digital product, application, or online service. It is intended to provide clear information about common privacy practices and the rights that individuals may have under applicable data protection laws.

2. Data Controller

The data controller is generally the person, company, institution, or organization that determines why and how personal data is processed. The identity and contact information of the relevant data controller should be provided by the website or service owner in its privacy policy, cookie policy, contact page, or other legal notice.

3. Categories of Personal Data

Depending on how a website or service is used, the following categories of personal data may be processed:

  • Identity information such as name and surname
  • Contact information such as email address, phone number, or address
  • Account information such as username, preferences, and settings
  • Transaction or request information submitted through forms
  • Technical information such as IP address, browser type, device information, operating system, and log records
  • Usage information such as pages visited, actions taken, referring URLs, and interaction history
  • Cookie and similar technology data, where applicable

4. Purposes of Processing

Personal data may be processed for purposes such as:

  • Providing, operating, and improving a website, application, or service
  • Responding to contact forms, support requests, or demo requests
  • Creating and managing user accounts
  • Communicating important service, security, or administrative information
  • Personalizing user experience and remembering preferences
  • Analyzing website usage, performance, and reliability
  • Preventing fraud, abuse, unauthorized access, and security incidents
  • Complying with legal obligations and responding to lawful requests

5. Legal Bases for Processing

Personal data should be processed only where there is an appropriate legal basis under applicable privacy laws. Common legal bases include:

  • Consent: The individual has given permission for a specific processing activity.
  • Contract: Processing is necessary to provide a requested service or take steps before entering into a contract.
  • Legal obligation: Processing is necessary to comply with applicable laws or regulatory requirements.
  • Legitimate interests: Processing is necessary for a legitimate business or operational interest, provided that the individual’s rights and freedoms do not override that interest.
  • Vital or public interest: Processing is necessary in limited situations recognized by law.

6. Cookies and Similar Technologies

Websites may use cookies, pixels, local storage, and similar technologies to remember preferences, keep sessions active, analyze traffic, measure performance, and support security. Where required by law, non-essential cookies should be used only after appropriate notice and consent. Users may usually manage cookie preferences through browser settings or a cookie preference tool provided by the website.

7. Sharing Personal Data

Personal data may be shared with third parties where necessary and lawful, including:

  • Hosting, infrastructure, analytics, communication, payment, or support providers
  • Professional advisers such as legal, accounting, or security consultants
  • Public authorities, courts, or regulators when required by law
  • Business partners or service providers acting under appropriate contractual safeguards

8. International Transfers

Personal data may be transferred to countries other than the country where the individual is located. Where required by law, such transfers should be protected through appropriate safeguards, such as adequacy decisions, standard contractual clauses, binding corporate rules, explicit consent, or other legally recognized transfer mechanisms.

9. Retention Periods

Personal data should be retained only for as long as necessary for the purposes for which it was collected, unless a longer retention period is required or permitted by law. Retention periods may vary based on the type of data, legal obligations, limitation periods, security needs, accounting requirements, and the nature of the relationship with the individual.

10. Security Measures

Appropriate technical and organizational measures should be used to protect personal data against unauthorized access, accidental loss, misuse, alteration, or disclosure. These measures may include:

  • Access controls and authentication mechanisms
  • Encryption or secure transmission methods
  • Logging, monitoring, and security reviews
  • Data minimization and retention controls
  • Incident response and breach management procedures
  • Confidentiality obligations for personnel and service providers

11. Individual Rights

Depending on the applicable law and the location of the individual, privacy rights may include:

  • The right to know whether personal data is processed
  • The right to access personal data
  • The right to request correction of inaccurate or incomplete data
  • The right to request deletion or erasure in certain circumstances
  • The right to restrict or object to processing
  • The right to data portability, where applicable
  • The right to withdraw consent where processing is based on consent
  • The right not to be subject to certain solely automated decisions, where applicable
  • The right to lodge a complaint with a competent supervisory authority

12. How to Exercise Rights

To exercise privacy rights, individuals should contact the relevant website or service owner using the contact details provided in that website’s privacy policy or legal notice. A request may need to include sufficient information to verify identity and understand the scope of the request. Requests should be answered within the timeframe required by applicable law.

13. Children’s Data

Websites and online services should not knowingly collect personal data from children unless permitted by applicable law and, where required, appropriate parental or guardian consent has been obtained. If personal data of a child is collected unintentionally, reasonable steps should be taken to delete or restrict that data.

14. Updates to This Notice

This notice may be updated from time to time to reflect changes in legal requirements, technology, services, or privacy practices. The latest version should be made available on the relevant website or service.

This page provides general information and does not replace a website-specific privacy policy, cookie policy, or legal advice. Each website or service should publish privacy information that reflects its own data processing activities, contact details, legal bases, retention periods, and third-party providers.