Privacy Policy of Stringtale

Effective Date: August 26, 2024
Version: 1.0

Article 1: Introduction

1.1 Purpose and Scope:

This Privacy Policy explains how Stringtale collects, uses, and protects your personal data when you access or use our service. It outlines our commitment to data protection and compliance with the General Data Protection Regulation (GDPR).

1.2 Data Protection Commitment:

We are committed to safeguarding your personal data and ensuring transparency in our data processing practices. This policy details the types of data we collect, the purposes for which we collect it, and your rights regarding your data.

1.3 Applicability:

These privacy terms apply to all users of the Stringtale service, including individuals and entities using the service for personal, commercial, or professional purposes. By using Stringtale, you agree to the collection and use of information in accordance with this policy.

1.4 Updates and Changes:

We reserve the right to modify this privacy policy at any time. Any changes will be communicated through the service, and we encourage you to review the policy periodically to stay informed of any updates.

Article 2: Definitions

In this privacy policy, the following terms have the following meanings:

2.1 Service: "Service" refers to Stringtale, the Software-as-a-Service (SaaS) tool provided by Stringtale for managing static text in web projects. 2.2 User: A "User" is any individual or entity that accesses or uses Stringtale, whether for personal, commercial, or professional purposes.

2.3 Account: An "Account" is the personal or organizational account registered by a User to access and use Stringtale.

2.4 Personal Data: "Personal Data" includes all information relating to an identified or identifiable individual, such as name, email address, payment details, and IP address, processed by Stringtale.

2.5 Data Controller: "Data Controller" refers to the entity that determines the purposes and means of processing Personal Data. For Stringtale, this is Stringtale operated by De Monsters.

2.6 Data Processor: "Data Processor" refers to any third party that processes Personal Data on behalf of the Data Controller.

2.7 Processing: "Processing" refers to any operation performed on Personal Data, including collection, storage, use, transfer, and deletion.

2.8 Consent: "Consent" refers to the User's freely given, specific, informed, and unambiguous agreement to the processing of their Personal Data.

2.9 Cookies: "Cookies" are small data files stored on a User's device by the web browser, used to track and enhance User experience.

2.10 Third-Party Services: "Third-Party Services" are external services or tools integrated with Stringtale that are not provided by Stringtale.

2.11 Data Subject: "Data Subject" is the individual whose Personal Data is processed.

Article 3: Data Collection

3.1 Data We Collect: Stringtale collects the following types of personal data:

  • Account Registration Data: When you create an account, we collect your name, email address, and IP address. This is necessary to provide you with access to the service.
  • Payment Information: For subscriptions, we collect payment details, including your billing address and payment method, to process transactions.
  • Contact Information: If you contact us through our website or via email, we collect your name, email address, and any other information you choose to provide.
  • Usage Data: We collect data on how you interact with Stringtale, including IP address, browser type, and usage patterns. This data is collected to improve our service and ensure its security.

3.2 Legal Basis for Data Collection:

We collect and process your data based on the following legal grounds:

  • Contractual Necessity: To fulfill our obligations in providing the service.
  • Consent: For sending newsletters and conducting certain types of marketing.
  • Legitimate Interests: For improving the service and ensuring its security.

3.3 Data Retention:

We retain your personal data only as long as necessary to fulfill the purposes for which it was collected or as required by law. For example:

  • Account Data: Retained until account closure.
  • Payment Data: Retained as long as required by tax laws.
  • Usage Data: Retained for a period necessary to improve the service, typically anonymized after a set period.

3.4 How We Collect Data: Data is collected through:

  • Direct Interactions: When you provide information by registering, subscribing, or contacting us.
  • Automated Technologies: Such as cookies and server logs that track your use of Stringtale.

Article 4: Data Use

4.1 Purposes of Data Use:

Stringtale uses your personal data for the following purposes:

  • Providing the Service: To create and manage your account, process payments, and deliver the functionalities of Stringtale.
  • Customer Support: To respond to your inquiries and provide assistance.
  • Improving the Service: To analyze usage data and improve our offerings.
  • Marketing and Communication: To send you newsletters and promotional materials, with your consent.

4.2 Legal Basis for Processing:

  • Contractual Necessity: To fulfill our obligations in providing the service.
  • Consent: For sending newsletters and promotional communications.
  • Legitimate Interests: For improving service quality and maintaining security.

4.3 Automated Decision-Making and Profiling:

Stringtale does not use your data for automated decision-making processes that produce legal effects or similarly significant outcomes. Profiling may be used for marketing purposes, but always with your consent.

4.4 Data Minimization and Relevance:

We ensure that the data collected is relevant, adequate, and limited to what is necessary for the purposes for which it is processed.

Article 5: User Rights

5.1 Right of Access:

You have the right to request access to the personal data we hold about you. This includes information on how we use your data and the purposes for which it is processed.

5.2 Right to Rectification:

If you believe that the data we hold about you is incorrect or incomplete, you have the right to request that we correct or complete it.

5.3 Right to Erasure (Right to be Forgotten):

You can request the deletion of your personal data where it is no longer necessary for the purposes for which it was collected, or if you withdraw your consent (where consent is the legal basis for processing).

5.4 Right to Restriction of Processing:

You can request that we restrict the processing of your personal data under certain conditions, such as if you contest the accuracy of the data or if the processing is unlawful but you oppose erasure.

5.5 Right to Data Portability:

You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to have that data transmitted to another controller, where technically feasible.

5.6 Right to Object:

You have the right to object to the processing of your personal data for certain purposes, such as direct marketing or profiling.

5.7 Right to Withdraw Consent:

Where the processing of your personal data is based on your consent, you have the right to withdraw that consent at any time. This will not affect the lawfulness of processing based on consent before its withdrawal.

5.8 How to Exercise Your Rights:

To exercise any of the rights mentioned above, you can contact us through the details provided in this privacy policy. We will respond to your request within one month, and this period may be extended by a further two months where necessary, taking into account the complexity and number of requests.

Article 6: Data Sharing

6.1 Sharing with Third-Party Service Providers:

Stringtale may share your personal data with trusted third-party service providers to perform functions essential to our service, such as payment processing (e.g., Stripe), email delivery, and hosting services. These providers are bound by strict data protection agreements to ensure the security and confidentiality of your data.

6.2 Legal Compliance:

We may disclose your personal data to comply with legal obligations, such as responding to lawful requests by public authorities, including to meet national security or law enforcement requirements.

6.3 Data Transfers Outside the EEA:

If we transfer your personal data to a third country outside the European Economic Area (EEA), we ensure that appropriate safeguards are in place, such as Standard Contractual Clauses or equivalent legal mechanisms.

6.4 No Sale of Personal Data:

Stringtale does not sell or rent your personal data to third parties for any purpose.

6.5 User Rights in Data Sharing:

You have the right to know which third parties receive your data and for what purposes. You can contact us for more details or to request that your data not be shared with certain parties, subject to legal and contractual limitations.

6.6 List of Third-Party Services:

  • TransIP (Hosting):
    • Purpose: To provide secure hosting for the Stringtale platform.
    • Data Shared: Server logs, IP addresses, and related hosting data.
    • Location: Data is processed within the EEA.
  • Cloudflare (Network Traffic Management and Security):
    • Purpose: To manage network traffic and enhance security.
    • Data Shared: IP addresses, security-related data.
    • Location: Data may be processed outside the EEA, with appropriate safeguards in place.
  • Stripe (Payment Processing):
    • Purpose: To process payments securely for subscriptions and other transactions.
    • Data Shared: Name, billing address, payment method, transaction details.
    • Location: Data may be processed outside the EEA, with appropriate safeguards in place.
  • SendGrid (Email Delivery):
    • Purpose: To send transactional and promotional emails to users.
    • Data Shared: Email address, name, and email content.
    • Location: Data may be processed outside the EEA, with appropriate safeguards in place.
  • Mailchimp (Newsletter Management):
    • Purpose: To manage and distribute newsletters.
    • Data Shared: Email address, name, and subscription preferences.
    • Location: Data may be processed outside the EEA, with appropriate safeguards in place.
  • Google Analytics (Analytics):
    • Purpose: To collect and analyze usage data to improve the service.
    • Data Shared: IP address, usage data, device information.
    • Location: Data may be processed outside the EEA, with appropriate safeguards in place.
  • Hotjar (User Experience Analytics):
    • Purpose: To analyze user behavior and improve the user experience.
    • Data Shared: IP address, device information, usage patterns.
    • Location: Data may be processed outside the EEA, with appropriate safeguards in place.
  • Bugsnag (Error Monitoring):
    • Purpose: To monitor and report errors in the application.
    • Data Shared: Error reports, user sessions, device information.
    • Location: Data may be processed outside the EEA, with appropriate safeguards in place.
  • Cookiebot (Cookie Consent Management):
    • Purpose: To manage and display cookie consent banners and handle user preferences for cookie usage.
    • Data Shared: Consent status, IP address, user interaction data.
    • Location: Data may be processed outside the EEA, with appropriate safeguards in place.

Article 7: Data Retention and Deletion

7.1 Retention Periods:

Stringtale retains your personal data only as long as necessary to fulfill the purposes for which it was collected or as required by applicable law. Specific retention periods include:

  • Account Data: Retained until account closure.
  • Payment Data: Retained as long as required by tax laws.
  • Newsletter Subscription Data: Retained until you unsubscribe.
  • Contact Form Data: Retained until the inquiry is resolved.

7.2 Data Deletion:

Upon request or account closure, your data will be securely deleted, except where retention is required by law. For example, payment data may be retained for tax compliance, and anonymized data may be retained for statistical purposes.

7.3 Anonymization:

In cases where data cannot be deleted immediately (e.g., for legal reasons), it will be anonymized to prevent identification of individuals.

7.4 User Control:

You can request deletion or anonymization of your data at any time by contacting Stringtale. We will process such requests in accordance with applicable laws and within a reasonable timeframe.

Article 8: International Data Transfers

8.1 Data Transfers Outside the EEA:

Stringtale may transfer your personal data to countries outside the European Economic Area (EEA) for processing by third-party service providers. When such transfers occur, we ensure that adequate safeguards are in place, such as Standard Contractual Clauses, to protect your data in compliance with GDPR.

8.2 Adequate Protection:

We will only transfer your data to countries deemed by the European Commission to provide an adequate level of data protection or where we have implemented appropriate safeguards to ensure the security of your data.

8.3 User Rights and Information:

You have the right to request more information about the safeguards in place for any transfers of your data outside the EEA. If you wish to exercise this right, please contact us as provided in this privacy policy.

Article 9: Data Security

9.1 Security Measures:

Stringtale takes the security of your personal data seriously. We implement a range of technical and organizational measures to protect your data from unauthorized access, loss, or misuse. These measures include encryption, secure access controls, regular security audits, and data anonymization where applicable.

9.2 Access Control:

Access to personal data is restricted to authorized personnel only, and is granted on a need-to-know basis. All employees and partners are required to follow strict confidentiality agreements.

9.3 Data Breach Notification:

In the unlikely event of a data breach that compromises your personal data, we will notify you and the relevant authorities without undue delay, as required by GDPR.

9.4 Third-Party Security:

We work with third-party service providers who are required to implement security measures that meet or exceed our standards. These providers are regularly audited to ensure compliance with our security policies.

9.5 User Responsibilities:

While we take extensive measures to protect your data, you are also responsible for keeping your account credentials secure. We recommend using strong, unique passwords and updating them regularly.

Article 10: Cookies and Tracking Technologies

10.1 Use of Cookies:

Stringtale uses cookies and similar tracking technologies to enhance your experience on our platform. Cookies help us understand how you use our service, personalize content, and improve our offerings.

10.2 Types of Cookies:

  • Essential Cookies: Necessary for the operation of the service, enabling basic functions like page navigation and access to secure areas.
  • Analytical Cookies: Used to collect information on how users interact with the service, helping us to improve performance and user experience.
  • Functional Cookies: Allow the service to remember your preferences and settings, providing a more personalized experience.
  • Marketing Cookies: Used to track your online activity to help us deliver more relevant advertisements and measure the effectiveness of our campaigns.

10.3 Managing Cookies:

Upon your first visit, you will be prompted to consent to the use of non-essential cookies. You can manage your cookie preferences at any time through your browser settings or our cookie consent tool. Note that disabling certain cookies may affect the functionality of the service.

10.4 Third-Party Cookies:

We may also allow third-party service providers, such as Google Analytics and Hotjar, to place cookies on your device to track and analyze usage data. These third parties are responsible for their own cookie policies, and we recommend reviewing them.

10.5 Data Collected via Cookies:

Cookies may collect data such as your IP address, browser type, device information, and interactions with the service. This data is used to analyze trends, administer the service, track users' movements, and gather demographic information.

10.6 Consent and Withdrawal of Consent:

You can withdraw your consent to our use of cookies at any time by adjusting your browser settings or using our cookie management tool.

Article 11: Complaints and Dispute Resolution

11.1 Filing Complaints:

If you believe that Stringtale is not processing your personal data in accordance with this privacy policy or applicable data protection laws, you have the right to file a complaint with Stringtale directly. Please contact us using the details provided in this document.

11.2 Contacting Data Protection Authorities:

You also have the right to lodge a complaint with a data protection authority in your country of residence. For users in the Netherlands, you can contact the Autoriteit Persoonsgegevens.

11.3 Dispute Resolution:

We are committed to resolving any complaints or disputes regarding the collection, use, or processing of your personal data. If you have a concern, please contact us, and we will work with you to resolve the issue promptly.

Article 12: Updates to this Privacy Policy

12.1 Right to Modify:

Stringtale reserves the right to update or modify this Privacy Policy at any time. Any changes will be posted on this page, and we will notify you through the service or via email if the changes are significant.

12.2 Review of Changes:

We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your personal data. Your continued use of the service after any modifications signifies your acceptance of the updated terms.

12.3 Historical Versions:

Previous versions of this Privacy Policy will be archived and available upon request, so you can see how our practices have evolved over time.

12.4 Effective Date:

Any changes to this Privacy Policy will become effective immediately upon posting, unless otherwise specified.

Article 13: Miscellaneous Provisions

13.1 Governing Law:

This privacy policy is governed by the laws of the Netherlands. Any disputes arising out of or related to this policy shall be resolved in the courts of Amsterdam, Netherlands.

13.2 Severability:

If any provision of this policy is found to be unenforceable or invalid, the remaining provisions will remain in full force and effect.

13.3 Entire Agreement:

This privacy policy constitutes the entire agreement between you and Stringtale regarding the use of your personal data.