Draft — pending review. This document is a minimal pilot draft. Fields shown as [PLACEHOLDER] must be completed, and the text should be reviewed by a lawyer before any paying customer.

Privacy Policy

Last updated: [EFFECTIVE DATE]

This Privacy Policy explains how [LEGAL ENTITY NAME] ("ChurnWarn", "we") handles personal data in connection with the ChurnWarn service. We can be reached at [CONTACT EMAIL], [REGISTERED ADDRESS].

1. Data we handle

  • Account data — the details of your staff who use ChurnWarn (name, email, authentication data). We are the controller of this data.
  • Customer event data — the product, billing and support events you send us about your end customers, and any attributes you attach. For this data we act as a processor on your behalf; you are the controller and are responsible for having a lawful basis to send it.

2. Why we process it

We process account data to provide, secure and bill the Service (contract and legitimate interest). We process customer event data solely to provide the Service to you under your instructions.

3. Sub-processors

We use a small number of vendors to run the Service (for example: hosting, payment processing, email, and error monitoring). Our current sub-processors are:

  • [SUB-PROCESSOR LIST — e.g. hosting provider, Stripe, Zarinpal, email/SMTP provider, error monitoring]

Some sub-processors may process data outside your country; where they do, we rely on appropriate safeguards. [LAWYER TO REVIEW: cross-border transfer mechanism.]

4. Retention

We keep customer event data for as long as your account is active and for [RETENTION PERIOD] after your account closes, after which it is deleted or anonymized. Account data is kept for as long as needed for the purposes above and legal obligations.

5. Security

We protect data with encryption in transit, access controls, and tenant isolation so that one customer's data is not accessible to another. No system is perfectly secure, but we work to protect your data and will notify you of material breaches as required by law.

6. Your rights

Depending on your location, you (or, for end-customer data, your customers via you) may have rights to access, correct, export or delete personal data. To make a request, contact [CONTACT EMAIL]. For customer event data, we will assist you as processor in fulfilling such requests.

7. Cookies

The application uses only essential cookies/local storage for authentication, theme and language preferences. We do not use them for third-party advertising.

8. Children

The Service is not intended for children, and you must not send us end-customer data about individuals under 16 unless you have a lawful basis to do so.

9. Changes and contact

We may update this Policy; material changes will be notified via the Service or email. Questions or requests: [CONTACT EMAIL]. [LAWYER TO REVIEW: a standalone Data Processing Addendum (DPA) is recommended before paid customers.]