We are a one person business. We collect as little personal data as we can and we do not sell it to anyone.
1. Our software does not collect anything
Our plugins run on your own machine. They do not report back to us. We receive no usage data, no telemetry and no content from your files.
Where a plugin sends data somewhere, it sends it to a destination you configure, and it sends it directly from your machine to that destination. It does not pass through us. You choose what is sent and where it goes.
2. What we collect and why
| Data | Why | Lawful basis |
|---|---|---|
| Name, work email, company, billing address, VAT number | To take your order, invoice you and keep tax records | Contract, and legal obligation for the tax records |
| Your Browzwear account name | To request licence assignment from Browzwear for you | Contract |
| Order and licence history, including renewal dates | To administer your licence and support you | Contract |
| Reports from Browzwear on how many people at your organisation use our software | To check licence use matches what was bought and to talk to you about it | Legitimate interest in enforcing our licence terms |
| Emails you send us and our replies | To answer you and keep a record of what was agreed | Contract, and legitimate interest in keeping records |
The reports described above are provided to us at organisation and user count level. They do not name individuals.
We do not use cookies, analytics or tracking on this website. There is nothing to consent to and no banner to dismiss.
3. Card details
We never see your card details. Card payments are processed by Stripe, who collect the card data directly and act as their own controller for it. Stripe tells us only that a payment succeeded, along with the billing information you gave them.
4. Who we share it with
We share personal data only where we need to, and only with these:
- Browzwear receives your Browzwear account name, your company name and the number of licences, so it can assign entitlement. Browzwear is a separate controller for what it does with that information.
- Stripe processes payments and issues invoices.
- Airtable holds our order and licence records.
- Cloudflare hosts the service that records orders.
- Our email and accounting providers hold correspondence and invoices.
- Our accountant and, if we ever need one, our lawyer.
We will also disclose data where the law requires it.
We do not sell personal data and we do not share it for anyone else's marketing.
5. Transfers outside the European Economic Area
Some of the providers above are based in the United States or store data there. Where that happens the transfer is covered by the European Commission's Standard Contractual Clauses, or by the provider's certification under the EU-US Data Privacy Framework, under the terms of our agreement with each of them.
6. How long we keep it
- Invoices and the records behind them: seven years, because Dutch tax law requires it.
- Order and licence records: for as long as your licence is active and seven years after the final invoice.
- Correspondence: three years after the conversation ends, unless it relates to an invoice.
- Enquiries that do not become orders: twelve months.
After that we delete it.
7. Your rights
You can ask us to give you a copy of the personal data we hold about you, correct it if it is wrong, delete it, restrict what we do with it, or send it to you in a portable form. You can object to processing we carry out on the basis of legitimate interest.
Email [email protected] and we will respond within one month. There is no charge.
Some data we cannot delete on request. Invoices and the records behind them have to be kept for seven years under Dutch tax law, and a deletion request does not override that.
If you are unhappy with how we have handled your data you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens. We would rather you told us first so we can put it right.
8. Security
Access to our records is protected by two factor authentication. Data in transit is encrypted. Only Sam Ruane has access, because there is nobody else.
If a breach happens that is likely to put your rights at risk we will tell the Autoriteit Persoonsgegevens within seventy two hours and tell you without undue delay.
9. Changes
If we change this policy we update the version and date at the top. If a change materially affects you we will tell you by email.