Privacy Policy

v1.0 Last updated: 30 April 2026
In short: we take privacy seriously. We collect what we need to run the Service (account info, calculation inputs, technical telemetry) and nothing more. We don't sell your data, we don't use it to train external AI models, and we delete it when you ask. This page explains the detail — what we collect, why, who else handles it, and the rights you have under UK GDPR.

1. Who we are

PromoWave Ltd is the data controller for personal data processed in connection with PromoTrace.

54 Quicksilver Street, Worthing, BN13 1FN, United Kingdom
Company No. 11303443 · VAT GB293075488
Email: [email protected]

This policy explains how we handle personal data under the UK GDPR and the UK Data Protection Act 2018, with reference to the EU GDPR for EU data subjects.

2. What data we collect

2.1 Account data

2.2 Calculation data

We treat calculation data as your Customer Data, not as our own asset. We do not use your calculations to train external AI models or to sell aggregated insights to third parties.

2.3 Technical data

2.4 Payment data

2.5 Communications

3. Why we process it (lawful basis)

PurposeLawful basis
Provide the Service to youPerformance of contract (Art. 6(1)(b))
Authenticate users, prevent fraud and abuseLegitimate interest (Art. 6(1)(f))
Send transactional emails (invoices, password resets)Performance of contract
Improve product reliability and performanceLegitimate interest
Comply with tax, accounting, and legal obligationsLegal obligation (Art. 6(1)(c))
Respond to your support requestsPerformance of contract / legitimate interest
Send marketing emails (where applicable)Consent (Art. 6(1)(a)), opt-in only

4. Who we share it with (sub-processors)

We use a small number of trusted vendors to operate the Service. Each is bound by a data-processing agreement that requires them to handle your data only as instructed by us and to maintain appropriate security.

ProviderRoleLocation
Vistoweb E.E. Develops and operates the Platform on PromoWave's behalf (engineering, hosting management, monitoring, support). Athens, Greece (EU)
Hetzner Online GmbH Provides the underlying server infrastructure and storage. Falkenstein, Germany (EU)
Cloudflare, Inc. Provides DDoS protection, CDN, and edge security in front of the application. Global edge network with EU data residency where available
Stripe Payments Europe Ltd Processes card payments (when Stripe is enabled). PCI-DSS Level 1. Dublin, Ireland (EU)
Vistochat (Vistoweb E.E.) Powers the live-chat assistant on our public pages. Stores chat transcripts on Vistoweb's infrastructure. Athens, Greece (EU)

The current list above is up-to-date as of the "Last updated" date at the top of this page. We will update this list when we add or change a sub-processor; material changes are announced with at least 30 days' notice.

5. International transfers

All current sub-processors are based in the UK or EU/EEA. Where data is transferred outside the UK or EEA (for example, when Cloudflare routes through a global edge node), we rely on:

You can request a copy of the transfer mechanism by emailing [email protected].

6. How long we keep it

Data typeRetention
Active account dataFor the lifetime of the subscription
Calculation dataFor the lifetime of the subscription, plus 90 days post-cancellation for export
Invoices and payment records6 years (UK HMRC requirement for VAT-registered companies)
Server access logs30 days rolling
Application audit logs (admin actions)12 months rolling
Support emails24 months from last interaction
Marketing emails (if opted in)Until you unsubscribe, plus 30 days
Vistochat transcripts90 days, or until you ask us to delete sooner

7. Your rights

Under UK GDPR you have the right to:

To exercise any of these rights, email [email protected]. We respond within 30 days, with the option to extend by 60 days for complex requests, in line with UK GDPR. We don't charge a fee for reasonable requests.

8. Security

We use industry-standard technical and organisational measures appropriate to the risk:

If we discover a personal-data breach that risks your rights and freedoms, we will notify the UK Information Commissioner's Office within 72 hours and you without undue delay, with the information required by UK GDPR Articles 33–34.

9. Cookies and similar technologies

See our Cookie Policy for details of the cookies and local-storage items we use.

10. Children

PromoTrace is a B2B service. It is not intended for use by individuals under 18, and we do not knowingly collect personal data from children.

11. Changes to this policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the most recent version. For material changes, we will email account holders and require explicit re-acceptance via a login banner.

12. Contact and complaints

For privacy questions, requests, or to exercise your rights:

PromoWave Ltd (Data Controller)
54 Quicksilver Street, Worthing, BN13 1FN, United Kingdom
Email: [email protected]

If you're not satisfied with our response, you have the right to lodge a complaint with:

Questions about this policy? Contact [email protected] or write to PromoWave Ltd, 54 Quicksilver Street, Worthing, BN13 1FN, United Kingdom.