Legal · Data Protection

Privacy Policy

Last updated: [DATE]

This Privacy Policy explains how Pinpoint Maths, a sole trader based in [YOUR COUNTRY] ("we", "us", "our"), collects, uses, and protects your personal data when you use [WEBSITE/PROGRAM NAME] (the "Service"). We are committed to complying with the EU General Data Protection Regulation (GDPR).

If you have any questions about this policy or how we handle your data, contact us at [YOUR CONTACT EMAIL].

01 Who we are

[YOUR NAME], operating as a sole trader, is the data controller responsible for your personal data.

Contact: [YOUR CONTACT EMAIL]
Address: [YOUR ADDRESS — optional but recommended]

02 What data we collect

We collect the following personal data:

  • Name and email address — when you register for an account
  • Progress data — information about your activity and progress within the Service
  • Payment information — handled directly by our payment processor, Stripe. We do not store your card details ourselves; Stripe processes and stores this on our behalf. See Stripe's Privacy Policy.
  • Usage/analytics data — how you interact with the Service, used to understand and improve how the program works for users

03 Why we collect it

DataPurposeLegal basis
Name, emailCreate and manage your account, communicate with youPerformance of a contract
Progress dataDeliver and personalize the program to youPerformance of a contract
Payment data (via Stripe)Process payment for the ServicePerformance of a contract / legal obligation
Usage/analytics dataUnderstand and improve the programLegitimate interest

We do not sell your personal data to third parties.

04 Who we share data with

We share data only with service providers who help us run the Service:

  • Stripe — payment processing (Stripe Privacy Policy)
  • [HOSTING PROVIDER] — hosts our infrastructure and stores your account/progress data
  • [ANALYTICS TOOL, if any] — helps us understand usage patterns
  • [EMAIL TOOL, if any] — sends transactional emails (e.g. password resets, receipts)

We do not sell, rent, or trade your personal data to advertisers or other third parties. We may also disclose data if required by law or to protect our legal rights.

05 International data transfers

[If your providers are outside the EEA, e.g. US-based Stripe/hosting: Some of our service providers are located outside the European Economic Area (EEA), including in the United States. Where this is the case, we rely on appropriate safeguards such as Standard Contractual Clauses or the provider's participation in the EU-U.S. Data Privacy Framework to protect your data.]

06 How long we keep your data

We retain your personal data for as long as your account is active. [PLACEHOLDER — e.g. "If you delete your account, we delete your personal data within 30 days, except where we are required to retain records (e.g. payment records) for tax/accounting purposes for X years as required by law."]

07 Your rights

Under GDPR, you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Delete your data ("right to be forgotten")
  • Restrict how we process your data
  • Data portability — receive your data in a portable format
  • Object to processing based on legitimate interest
  • Withdraw consent at any time, where processing is based on consent

To exercise any of these rights, contact us at [YOUR CONTACT EMAIL]. We will respond within one month as required by GDPR.

You also have the right to lodge a complaint with your local data protection authority. If you are based in Ireland, this is the Data Protection Commission. [Adjust to your relevant supervisory authority if different]

08 Cookies

[PLACEHOLDER — describe cookies used, e.g.: "We use essential cookies to keep you logged in and, if applicable, analytics cookies to understand usage. You can control cookies through your browser settings."]

09 Security

We take reasonable technical and organizational measures to protect your personal data against unauthorized access, loss, or misuse. However, no method of transmission or storage is 100% secure.

10 Children's privacy

The Service is not directed at children under 16. We do not knowingly collect data from children under this age. If you believe a child has provided us with personal data, contact us and we will delete it.

11 Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version here with a new "Last updated" date. Significant changes will be communicated via email or a notice on the Service.

12 Contact us

If you have questions about this Privacy Policy or how we handle your data, contact us at [YOUR CONTACT EMAIL].

Fields highlighted like this still need to be filled in before publishing.