PRIVACY & COOKIES
Last updated: August 22, 2025
1) Controller identity
Primary controller: Us (site operator), Georgia — azows@tuta.io.
If MoR is activated (e.g., Paddle): the MoR acts as an independent controller for checkout and invoicing (we do not store card data).
2) Data we process
Account/identity: name, email, country, any information you choose to share (e.g., bio, alias, preferences).
Technical/usage: logs, IP, device, pages viewed, events (purchase, access).
Support: messages you send to support.
Payment: order references, amount, currency, status (via MoR/PSP). We do not store card data.
3) Purposes & legal bases
Contract performance: create the account, deliver content, invoice at the time access is granted.
Legitimate interests: security, anti‑fraud/abuse, service improvement, internal statistics.
Legal obligation: accounting, tax, replies to authorities.
Consent: marketing (opt‑in), non‑essential cookies (if ever used).
4) Recipients & transfers
MoR/PSP (payments, taxes, invoicing).
Hosting/Cloud, analytics, email/support tools.
International transfers may occur; safeguards: SCCs (Standard Contractual Clauses) and technical measures.
5) Retention
Account: while the account is active, then immediate deletion upon request via support, subject to legal duties.
Billing / legal obligations: 6 years (minimum common requirement for relevant accounting/tax records in Georgia).
Technical logs: 3 months (strictly necessary for security and diagnostics).
6) Your rights
Access, rectification, erasure, restriction, objection, portability, and withdrawal of consent (where processing is based on consent). Requests: azows@tuta.io. You may lodge a complaint with the competent authority.
7) Security
We use reasonable technical and organisational measures; no system is 100% secure.
8) Minors
The service is not for users under 18. If we learn data relates to a minor, we will delete it and close the account.
9) Cookies
We use essential cookies only (e.g., authentication and security). If we ever add non‑essential cookies (analytics/marketing), we will display a consent banner and provide a preference centre.
10) Changes
Any update will be posted with a new "Last updated" date.