Cookie Policy
Information We Collect & Legal Basis
We collect personal data strictly necessary for service provision: name, email, billing info (via PCI-compliant processor), and usage analytics. This processing is based on contract performance (Art. 6(1)(b) GDPR) and legitimate interest (Art. 6(1)(f)) for improving our offerings. We do not collect sensitive categories like ethnicity or health data.
- Account creation: email, hashed password, timezone
- Consultation forms: productivity challenges, goals, current tools
- Cookies: essential session cookies; optional analytics via anonymized IP
Data Sharing & Third-Party Processors
Trusted sub-processors include: Stripe (payment), G Suite (email), and Cloudflare (CDN). Each is vetted for GDPR compliance via Data Processing Agreements (DPA). No data sold or used for advertising. We may disclose if required by law (e.g., court order) or to protect our rights.
- Stripe – payment processing (PCI DSS Level 1)
- Zapier – workflow automation (no raw data stored)
- Google Analytics – anonymized site traffic (IP masking enabled)
Your Rights & Data Retention
Under GDPR, you have right to access, rectification, erasure, data portability, and objection. Retain data for the duration of your account plus 12 months for billing records (legal obligation). To exercise rights, email [email protected] with subject ‘Data Request’. We respond within 30 days.
