Legal · Data Protection
Privacy Policy
Last updated: [DATE]
This Privacy Policy explains how Pinpoint Maths, a sole trader based in [YOUR COUNTRY] ("we", "us", "our"), collects, uses, and protects your personal data when you use [WEBSITE/PROGRAM NAME] (the "Service"). We are committed to complying with the EU General Data Protection Regulation (GDPR).
If you have any questions about this policy or how we handle your data, contact us at [YOUR CONTACT EMAIL].
01 Who we are
[YOUR NAME], operating as a sole trader, is the data controller responsible for your personal data.
Contact: [YOUR CONTACT EMAIL]
Address: [YOUR ADDRESS — optional but recommended]
02 What data we collect
We collect the following personal data:
- Name and email address — when you register for an account
- Progress data — information about your activity and progress within the Service
- Payment information — handled directly by our payment processor, Stripe. We do not store your card details ourselves; Stripe processes and stores this on our behalf. See Stripe's Privacy Policy.
- Usage/analytics data — how you interact with the Service, used to understand and improve how the program works for users
03 Why we collect it
| Data | Purpose | Legal basis |
|---|---|---|
| Name, email | Create and manage your account, communicate with you | Performance of a contract |
| Progress data | Deliver and personalize the program to you | Performance of a contract |
| Payment data (via Stripe) | Process payment for the Service | Performance of a contract / legal obligation |
| Usage/analytics data | Understand and improve the program | Legitimate interest |
We do not sell your personal data to third parties.
05 International data transfers
[If your providers are outside the EEA, e.g. US-based Stripe/hosting: Some of our service providers are located outside the European Economic Area (EEA), including in the United States. Where this is the case, we rely on appropriate safeguards such as Standard Contractual Clauses or the provider's participation in the EU-U.S. Data Privacy Framework to protect your data.]
06 How long we keep your data
We retain your personal data for as long as your account is active. [PLACEHOLDER — e.g. "If you delete your account, we delete your personal data within 30 days, except where we are required to retain records (e.g. payment records) for tax/accounting purposes for X years as required by law."]
07 Your rights
Under GDPR, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete your data ("right to be forgotten")
- Restrict how we process your data
- Data portability — receive your data in a portable format
- Object to processing based on legitimate interest
- Withdraw consent at any time, where processing is based on consent
To exercise any of these rights, contact us at [YOUR CONTACT EMAIL]. We will respond within one month as required by GDPR.
You also have the right to lodge a complaint with your local data protection authority. If you are based in Ireland, this is the Data Protection Commission. [Adjust to your relevant supervisory authority if different]
09 Security
We take reasonable technical and organizational measures to protect your personal data against unauthorized access, loss, or misuse. However, no method of transmission or storage is 100% secure.
10 Children's privacy
The Service is not directed at children under 16. We do not knowingly collect data from children under this age. If you believe a child has provided us with personal data, contact us and we will delete it.
11 Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version here with a new "Last updated" date. Significant changes will be communicated via email or a notice on the Service.
12 Contact us
If you have questions about this Privacy Policy or how we handle your data, contact us at [YOUR CONTACT EMAIL].