Privacy Policy
Who we are
[Company] ([legal entity], [address], [jurisdiction]) is the data controller for the personal data described in this policy. Contact us at [privacy@your-saas.com] with any privacy question or to exercise your rights.
What we collect
We collect only what we need to run the service:
- Account data — your name, email, and (if you sign in with a provider) your provider profile and avatar.
- Authentication data — a password hash and/or OAuth identifiers, plus session records (token, browser/user-agent, and a coarse network location used to flag new-device sign-ins).
- Organization data — your workspace membership and role, where applicable.
- Billing data — your billing contact and subscription status. Payments are handled by our payment processor; we never see or store raw card numbers.
- Product usage — pseudonymous analytics (see below).
- Content you create — feedback, form submissions, and anything you store in the product.
Information we receive from others
Some data reaches us from third parties you choose to involve: identity providers (if you sign in with Google/GitHub/etc. we receive the profile you authorize), and our payment processor (your subscription and payment status — never raw card details). We don't buy personal data or enrich your profile from data brokers.
Why we're allowed to (legal bases)
We process your data on these GDPR bases: performance of our contract with you (running your account), our legitimate interests (security, preventing abuse, understanding product usage), legal obligations (tax, accounting), and your consent where required (e.g. optional analytics for guests, and session replays/heatmaps, which run only with your opt-in).
No automated decisions
We do not use your data to make solely automated decisions that produce legal or similarly significant effects about you, and we do not profile you for advertising. Abuse/anti-bot checks may flag activity for a human to review — they never decide anything important about you on their own.
Children
The service is not directed to children. You must be at least [16] (or the digital-consent age in your country; [13] in the United States) to use it. We don't knowingly collect data from children under that age — if you believe a child has given us data, contact us at [privacy@your-saas.com] and we'll delete it.
Marketing and communications
We send service emails you can't opt out of while you have an account (security alerts, billing, policy updates) — these are required to run your account. Any marketing or product-update emails are separate: we only send them with your consent and every one has a one-click unsubscribe. Unsubscribing from marketing never affects service emails.
How long we keep it
We keep account data for the life of your account and delete or anonymize it when you delete your account. Sessions expire automatically. Billing records are retained as required by tax law. Backups roll off on their own schedule.
Deletion is real
When you delete your account we remove or anonymize your personal data across the platform. Where crypto-shredding is enabled for the deployment, per-account keys are destroyed so the underlying data becomes permanently unreadable — even in backups — not merely flagged as deleted.
Your rights
Under the GDPR (and similar laws) you can:
- Access and export your data — available as a self-service export in your settings.
- Correct inaccurate data — edit it in your profile or ask us.
- Delete your account and data — self-service in settings.
- Object to or restrict certain processing, and withdraw consent.
- Lodge a complaint with your supervisory authority ([authority for your jurisdiction]).
Exercising your rights
Most rights are self-service in your settings; for anything else, email [privacy@your-saas.com]. We respond within one month (extendable by two for complex requests) and never charge except where the law allows.
Our data-protection contact is [DPO or privacy contact, email]. [If [Company] is NOT established in the EU/UK but offers the service there, also name your Article 27 representative here — an EU-established company does not need one.]
Security
Data is encrypted in transit (TLS 1.3) and at rest (AES-256). We keep a real, append-only audit log, and the slice relevant to you is visible in your own settings. See /security for the full picture.
International transfers
We host in the [region] region where available. Where data is processed outside your region by a subprocessor, it is covered by appropriate safeguards (e.g. Standard Contractual Clauses) — see each subprocessor's DPA at /legal/subprocessors.
California residents
If you're a California resident, the CCPA/CPRA gives you the rights to know, access, correct, and delete the personal information we collect, and to not be discriminated against for exercising them. The categories we collect and why are described above (identifiers, commercial/billing info, internet activity, and the content you create).
We do NOT sell or share your personal information as those terms are defined by the CCPA, and we have not in the preceding 12 months — so there is no "Do Not Sell or Share" action to take. We also do not use or disclose sensitive personal information beyond what's needed to provide the service. Exercise any of these rights the same way as above; you may use an authorized agent.
Do Not Track & Global Privacy Control
Because our analytics are cookieless and we set no advertising trackers, there is very little to "track" in the first place. Browsers send no universal Do Not Track standard, so we don't act on the legacy DNT header; where required we honor the Global Privacy Control (GPC) signal as an opt-out of any sale/sharing — which we don't do anyway.
Changes to this policy
We version this policy and keep a change summary for each update. For material changes we'll ask you to review and re-accept before you continue using the service.
Privacy questions?
Email our privacy contact or send us a message.