Черновик, ожидает проверки юристом. Наши правовые документы ещё не утверждены юристом. Текст в [квадратных скобках] — заполнитель, который будет заменён до запуска.
Этот документ пока доступен только на английском языке. Юридическую силу имеет английский текст ниже.
Privacy Policy
- Дата вступления в силу:
- [EFFECTIVE DATE]
- Последнее обновление:
1. Who we are and what this policy covers
[COMPANY NAME] LLC, a [STATE] limited liability company that operates IViel (“we”, “us” or “our”), is the controller of the personal data described in this Privacy Policy. Our contact details are in Section 16 (Contact).
This policy applies to our website, your Account and customer portal, and our Source Code and Managed Website services (the “Services”). It does not cover personal data that our customers collect through their own Managed Websites; for that data we act on our customers’ behalf (Section 14). Payments are processed by Polar Software, Inc., our merchant of record, under its own privacy policy. Capitalized terms have the meanings given in our Terms of Service.
2. Notice at collection
This table summarizes the categories of personal information we collect, why we collect them and whether we sell or share them. It is our notice at collection under the California Consumer Privacy Act (“CCPA”). We do not sell any category of personal information or share it for cross-context behavioral advertising. How long we keep each category is described in Section 7 (How long we keep personal data).
| Category | Examples | Purposes |
|---|---|---|
| Identifiers | Name, email address, account ID, IP address, License Keys | Accounts, Orders, Licenses, Managed Websites, security, support |
| Customer records (Cal. Civ. Code § 1798.80(e)) | Name, email address, billing details received from Polar (never full card numbers), and the messages you send to support and our replies | Processing Orders, accounting, support and record keeping |
| Commercial information | Products, Plans, amounts, Order and Subscription status and dates | Processing Orders, delivering the Services, accounting, support |
| Internet or other electronic network activity information | Sign-in sessions (IP address, browser user agent), download records, security and audit logs, error reports | Security, fraud and abuse prevention, troubleshooting |
| Sensitive personal information | Account log-in (email address with password, stored only as a hash) and two-factor authentication settings | Signing you in and protecting your Account only |
We do not collect precise geolocation, biometric information, or information about health, race, religion or similar characteristics, and we do not use personal information to make decisions with legal or similarly significant effects based solely on automated processing.
3. Personal data we collect
3.1 Information you give us
- Account data: your name, email address and password. We store only a salted hash of your password (argon2id), never the password itself. If you turn on two-factor authentication, we store its secret in encrypted form.
- Orders and Subscriptions: what you buy, the License Type or Plan, the site address and Template you choose, and your update and domain settings.
- Communications: what you write to us, for example in support emails.
3.2 Information from our merchant of record
Polar tells us limited information about your Orders and Subscriptions, such as your name and email address, the product, the amount, the payment status and renewal dates. The payment notifications it sends us may also contain billing details such as your billing address and tax country; we keep those notifications only for the period shown in Section 7 (How long we keep personal data). Your payment card details are collected and stored only by Polar.
3.3 Information collected automatically
- Sessions: when you sign in, we record the IP address and browser user agent of the session so you and we can detect unauthorized access.
- Security and audit logs: security-relevant actions on your Account, such as sign-ins, changes to security settings and the issuance of each download link (with the IP address and time).
- License checks: when a Product checks a License Key with our license validation service, the request contains the key and the product identifier.
- Error reports: technical details of errors in our own systems. Our error monitoring is configured not to collect request bodies, cookies, headers, query strings or user identifiers.
- Cookies: only the strictly necessary cookies described in our Cookie Policy.
3.4 Managed Website content
The content and data stored on your Managed Website, including its backups, are kept on our infrastructure so that we can run and back up the site. We access them only to operate and secure the Services, to provide support you ask for, or when the law requires it.
4. How we use personal data and our legal bases
We use personal data for the purposes below. For people in the EEA, the UK and Switzerland, the table also shows the legal basis under the GDPR and UK GDPR. Providing your name, email address and password is necessary to create an Account; without them we cannot provide the Services.
| Purpose | Data | Legal basis |
|---|---|---|
| Create and run your Account, sign you in, keep sessions secure | Account data, credentials, sessions | Performance of our contract with you |
| Process Orders, deliver Licenses and downloads, provide Managed Websites | Account, Order, License and site data | Performance of our contract with you |
| Send service emails: verification, password resets, Order and Subscription notices, payment, suspension and deletion notices, and new releases of Products you hold a current License for | Name, email address, Order and site data | Performance of our contract; our legitimate interest in keeping you informed about products you own |
| Keep the Services secure, prevent fraud and abuse, enforce our terms | IP addresses, sessions, download records, audit logs | Our legitimate interests in security and fraud prevention |
| Diagnose errors and keep the Services reliable | Error reports with request data removed | Our legitimate interest in a working service |
| Answer your questions and requests | Support messages, Account data | Performance of our contract; legitimate interests |
| Meet legal, tax and accounting obligations, respond to lawful requests, establish or defend legal claims | Order records and other relevant data | Legal obligation; legitimate interests |
We do not send marketing emails without your consent where the law requires it, and every marketing email we send includes an unsubscribe link. We do not use personal data for targeted advertising or profiling.
6. International transfers
We are based in the United States, and we and our service providers process personal data in the United States and in other countries where they operate. When we transfer personal data from the EEA, the UK or Switzerland to countries without an adequacy decision, we rely on an adequacy mechanism where available (such as the EU-U.S. Data Privacy Framework for recipients certified under it) or on the European Commission’s Standard Contractual Clauses, with the UK International Data Transfer Addendum or the Swiss adaptations where needed, together with supplementary measures where appropriate. You can ask for a copy of the relevant safeguards at privacy@[DOMAIN].
7. How long we keep personal data
We keep personal data only for as long as we need it for the purposes described in this policy, including to meet legal, tax and accounting requirements and to resolve disputes. Then we delete or anonymize it.
| Data | How long we keep it |
|---|---|
| Account profile (name, email, password hash, two-factor settings) | While your Account is open, then deleted or anonymized within [90 days], except what we must keep as described below |
| Order, Subscription and invoice records | [seven (7) years] |
| License records and License Keys | For as long as the License exists, so that it can be validated and you can download Releases |
| Sign-in sessions (IP address, browser user agent) | Until you sign out or the session expires (at most 30 days, or 7 days without activity); expired sessions are deleted automatically |
| Email verification and password reset links | Until used or expired; expired links are deleted automatically |
| Security and audit logs, including download records | 12 months |
| Payment notifications received from Polar | 90 days |
| Error reports | [90 days] |
| Support emails | [two (2) years] |
| Managed Website data and backups | As described in the Managed Services Terms |
Записи о пополнениях и кошельке, включая криптопополнения, зачисления, корректировки и операции кошелька, являются финансовыми документами и хранятся для бухгалтерского учёта и предотвращения мошенничества. Мы не удаляем эти записи, когда вы просите удалить свой аккаунт.
Персональные данные, которые не входят в эти финансовые документы, удаляются или обезличиваются в соответствии с этой политикой.
Публичные данные блокчейна не могут быть удалены ни нами, ни кем-либо ещё.
8. How we protect personal data
We protect personal data with technical and organizational measures appropriate to the risk, including:
- encryption in transit (HTTPS) for our website and Services;
- password hashing with argon2id, and two-factor authentication available to every Account;
- application-level encryption (AES-256-GCM) of sensitive values such as License Keys, two-factor secrets, server credentials and the secrets of Managed Websites;
- restricted, logged administrative access, with two-factor authentication required for our administrators;
- isolation of each Managed Website in its own environment and network; and
- error monitoring configured to exclude request contents, cookies and user identifiers.
No system is completely secure. If a breach affects your personal data, we will notify you and the authorities as the law requires.
9. Your rights and how to use them
9.1 Your rights
Depending on where you live, you may have the right to:
- know what personal data we hold about you and get a copy of it (access);
- receive it in a portable format (portability);
- have inaccurate data corrected (correction);
- have your data deleted (deletion), subject to what we must keep by law;
- object to or restrict certain processing, and withdraw consent where we rely on it; and
- appeal our decision on your request, or complain to a regulator.
Whether or not a particular law applies to us, we will honor these requests from our customers as described here.
9.2 How to make a request
Email privacy@[DOMAIN] from the email address of your Account, or tell us which Account the request concerns. Your name and email address are shown in your Account settings; to change them, or to close your Account, contact us.
9.3 Verification and timing
To protect your data, we verify requests by confirming that they come from the email address of the Account and, where needed, by asking for additional information. We respond within the time required by applicable law (for example, one month under the GDPR, or 45 days under U.S. state laws), which may be extended where the law allows; we will tell you if we need more time. Requests are free unless they are manifestly unfounded or excessive.
9.4 Appeals
If we decline your request, you may appeal by replying to our decision or by writing to privacy@[DOMAIN] with the subject “Privacy appeal”. We will respond within the time required by law. If your appeal is denied, you may contact your state Attorney General or your data protection authority.
10. Additional information for U.S. residents
10.1 California
If you are a California resident, the CCPA, as amended by the California Privacy Rights Act, gives you the right to know the categories and specific pieces of personal information we collected about you, the categories of sources, the purposes, and the categories of recipients; to delete and correct personal information; to opt out of the sale or sharing of personal information; to limit the use of sensitive personal information; and not to be discriminated against for using these rights.
- Categories and sources. In the past 12 months we collected the categories listed in Section 2 (Notice at collection), from you, automatically from your use of the Services, and from our merchant of record.
- Disclosures for a business purpose. In the past 12 months we disclosed identifiers, customer records, commercial information and internet or other electronic network activity information to our service providers, and identifiers, customer records and commercial information to our merchant of record at your direction when you check out, for the purposes described in Section 5 (How we share personal data).
- No sale or sharing. We do not sell personal information or share it for cross-context behavioral advertising, and we have no actual knowledge of selling or sharing personal information of consumers under 16.
- Sensitive personal information. We use your account log-in only to sign you in and protect your Account, which the CCPA permits without offering a right to limit, and we do not use it to infer characteristics about you.
- Authorized agents. You may use an authorized agent. We will ask for your signed permission (or a power of attorney) and may ask you to verify your identity directly with us.
- No financial incentives. We do not offer financial incentives in exchange for personal information.
- Shine the Light. We do not disclose personal information to third parties for their own direct marketing purposes.
10.2 Other U.S. states
Residents of other states with comprehensive privacy laws, including Virginia, Colorado, Connecticut, Utah, Texas and Oregon, may have similar rights to access, correct, delete and obtain a copy of their personal data, to opt out of targeted advertising, the sale of personal data and certain profiling, and to appeal our decision. We do not sell personal data, process it for targeted advertising, or use it for profiling that produces legal or similarly significant effects. Use the process in Section 9 (Your rights and how to use them) to exercise these rights.
11. Additional information for the EEA, the UK and Switzerland
- Controller. [COMPANY NAME] LLC (see Section 16). Representative in the EU: [EU REPRESENTATIVE NAME AND ADDRESS, OR "NOT APPOINTED"]. Representative in the UK: [UK REPRESENTATIVE NAME AND ADDRESS, OR "NOT APPOINTED"].
- Legal bases are listed in Section 4 (How we use personal data and our legal bases). Where we rely on legitimate interests, you may object, and we will stop unless we have compelling legitimate grounds.
- Your rights include access, rectification, erasure, restriction, portability, objection and the withdrawal of consent, as described in Section 9 (Your rights and how to use them).
- Complaints. You may complain to the data protection authority where you live or work or where you believe an infringement occurred. In the EU, see the list of EU data protection authorities; in the UK, the Information Commissioner’s Office. We would appreciate the chance to address your concern first.
12. Children
The Services are not directed to children. You must be at least 18 to create an Account, and we do not knowingly collect personal information from children under 16 (or under 13 within the meaning of the U.S. Children’s Online Privacy Protection Act). If you believe a child has given us personal information, contact privacy@[DOMAIN] and we will delete it.
13. Do Not Track and Global Privacy Control
We do not track you across other websites and do not use advertising or analytics trackers, so Do Not Track signals do not change how the Services work. We treat a Global Privacy Control (GPC) signal as a valid request to opt out of the sale or sharing of personal information for that browser, as the law requires; because we do not sell or share personal information, no further change is needed.
14. Data on our customers’ Managed Websites
Our customers decide what personal data their Managed Websites collect about their visitors and customers, and they are the controllers of that data. We process it on their behalf as a processor or service provider, under our Terms of Service and a data processing agreement where one is agreed. If you are a visitor of a site we host and want to exercise your rights, please contact the owner of that site; we will help our customer respond.
15. Changes to this policy
We will update this policy when our Services or the law change. The “Last updated” date at the top shows when it last changed. If a change is material, we will tell you by email or in your Account before it takes effect.
16. Contact
Questions and requests about privacy:
[COMPANY NAME] LLC[STREET ADDRESS]
[CITY], [STATE] [ZIP CODE]
United States
Email: privacy@[DOMAIN]