[PLACEHOLDER] must be completed, and the text should be reviewed by a lawyer before any paying customer.Privacy Policy
Last updated: [EFFECTIVE DATE]
This Privacy Policy explains how [LEGAL ENTITY NAME] ("ChurnWarn", "we") handles personal data in connection with the ChurnWarn service. We can be reached at [CONTACT EMAIL], [REGISTERED ADDRESS].
1. Data we handle
- Account data — the details of your staff who use ChurnWarn (name, email, authentication data). We are the controller of this data.
- Customer event data — the product, billing and support events you send us about your end customers, and any attributes you attach. For this data we act as a processor on your behalf; you are the controller and are responsible for having a lawful basis to send it.
2. Why we process it
We process account data to provide, secure and bill the Service (contract and legitimate interest). We process customer event data solely to provide the Service to you under your instructions.
3. Sub-processors
We use a small number of vendors to run the Service (for example: hosting, payment processing, email, and error monitoring). Our current sub-processors are:
- [SUB-PROCESSOR LIST — e.g. hosting provider, Stripe, Zarinpal, email/SMTP provider, error monitoring]
Some sub-processors may process data outside your country; where they do, we rely on appropriate safeguards. [LAWYER TO REVIEW: cross-border transfer mechanism.]
4. Retention
We keep customer event data for as long as your account is active and for [RETENTION PERIOD] after your account closes, after which it is deleted or anonymized. Account data is kept for as long as needed for the purposes above and legal obligations.
5. Security
We protect data with encryption in transit, access controls, and tenant isolation so that one customer's data is not accessible to another. No system is perfectly secure, but we work to protect your data and will notify you of material breaches as required by law.
6. Your rights
Depending on your location, you (or, for end-customer data, your customers via you) may have rights to access, correct, export or delete personal data. To make a request, contact [CONTACT EMAIL]. For customer event data, we will assist you as processor in fulfilling such requests.
7. Cookies
The application uses only essential cookies/local storage for authentication, theme and language preferences. We do not use them for third-party advertising.
8. Children
The Service is not intended for children, and you must not send us end-customer data about individuals under 16 unless you have a lawful basis to do so.
9. Changes and contact
We may update this Policy; material changes will be notified via the Service or email. Questions or requests: [CONTACT EMAIL]. [LAWYER TO REVIEW: a standalone Data Processing Addendum (DPA) is recommended before paid customers.]