Cookie Policy
Official Page
1. Information Collection Scope
We collect personally identifiable information (PII) including name, email, phone, job title, company, and billing details solely for service fulfillment. Automated data collection includes IP addresses, browser fingerprints, session durations, and feature usage analytics via Google Analytics 4 and Mixpanel. We do not collect biometric data or sensitive personal data as defined in GDPR Article 9.
- Purpose limitation: Data used exclusively for account provisioning, support, and product improvement
- Data minimization: Only essential fields collected; opt-in for marketing communications required
2. Legal Basis for Processing (GDPR Art. 6)
- Consent (Art. 6(1)(a)): For direct email campaigns and non-essential cookies
- Contractual necessity (Art. 6(1)(b)): For service delivery, billing, and support
- Legitimate interests (Art. 6(1)(f)): For fraud prevention, network security, and aggregated usage trends
3. Data Retention & Erasure
Personal data retained for the duration of the contractual relationship plus 90 days post-termination for audit purposes. Anonymized training metrics retained indefinitely for benchmark development. Users may request erasure under the ‘Right to be Forgotten’ (GDPR Art. 17) by contacting [email protected]; we respond within 30 days.
4. Third-Party Data Processors
- Amazon Web Services (server hosting, SOC 2 compliant)
- Stripe (payment processing, PCI DSS Level 1)
- Mailchimp (email marketing, GDPR Shield certified)
- HubSpot (CRM, Data Processing Agreement in place)
5. International Transfers
Data stored on US-based AWS servers. For EU/EEA residents, we adhere to Standard Contractual Clauses (SCCs) and maintain Privacy Shield certification. Users from California have additional rights under CCPA (access, deletion, opt-out of sale).
6. Cookie Management
Essential cookies for session management and CSRF protection. Non-essential cookies for analytics (Google Analytics, Hotjar) and advertising (Google Ads, LinkedIn Insight) placed only after explicit opt-in via our cookie consent manager. Cookie duration: session ID cookie (24 hours), preference cookies (12 months).
7. Security Measures
Encryption at rest (AES-256) and in transit (TLS 1.3). Mandatory two-factor authentication for administrative accounts. Monthly vulnerability scans by independent assessors. Breach notification within 72 hours per GDPR Art. 33.
8. Policy Updates
This policy is reviewed quarterly. Material changes communicated via email 30 days prior to effective date. Last updated: January 15, 2024.
Elevate My Efficiency
Transform Your Productivity Today
