← Back to site

1 Who is responsible for your data

1.1 Netlance Limited, of Athalassis 54, Office 101, 2023 Strovolos, Nicosia, Cyprus ("Netlance", "we", "us"), is the controller of the personal data described in this Policy.

1.2 This Policy explains what we collect, why, how long we keep it, and what you can require us to do about it. It covers our website and any subscription product we operate.

1.3 We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and Cyprus data protection law. We have not appointed a Data Protection Officer, as we are not required to; privacy enquiries are handled by the contact in clause 14.

1.4 By using the Service you confirm that you have read and understood this Policy and that you are over 18. If you do not agree with it, please do not use the Service; you may contact us at any time to ask us to delete data we hold about you.

1.5 Terms used in this Policy.

"GDPR"Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
"EEA"The member states of the European Union together with those of the European Free Trade Association. For the purposes of this Policy, references to the EEA also cover the United Kingdom.
"Process"Any operation performed on personal data, including collecting it, storing it, using it and disclosing it to others.
"Service"This website and any subscription product we operate, together with the content available through them.

2 What we collect

CategoryExamplesWhere it comes from
Contact dataName, email address, company name if you give oneYou
Account dataLogin identifier, settings, subscription statusYou / generated in use
Transaction dataPurchases, renewal dates, refunds, partial card details (such as the last four digits and card type)You / our payment provider
Technical and device dataIP address, device type and model, device settings, operating system, browser type, language settings, time zone, internet service provider or mobile carrier, hardware or device identifiers, cookie identifiersCollected automatically
Approximate locationThe country or region your IP address indicates. We do not collect precise GPS location from this website.Derived from technical data
Referral and attribution dataThe website, app or link you came from, and which campaign or referring URL brought you to usCollected automatically
Usage dataPages and features viewed, session timing and duration, how often you visit, interactionsCollected automatically
CorrespondenceMessages you send us and our repliesYou

2.1 Advertising identifiers. Mobile operating systems provide advertising identifiers — Apple's Identifier for Advertising ("IDFA") and Identifier for Vendors ("IDFV"), and Google's Advertising ID ("AAID"). This website does not collect them. Where we later release a mobile product that does, we will say so in that product's own privacy notice and obtain any consent the law requires. You can reset these identifiers, or turn off personalised advertising, in your device settings; we do not control those settings.

2.2 Software development kits. Mobile applications commonly include third-party SDKs that report how the application is used and collect device and network information. This website uses none. The same commitment in clause 2.1 applies if a future product does.

2.3 What a page load involves. Opening a page on this website causes your browser to request typefaces from Google's servers, which necessarily discloses your IP address to Google. That is the only third party contacted when you view this site. See clause 5 for what this means and how to avoid it.

2.4 We do not collect special category data (such as health, biometric or political data) and we ask you not to send it to us.

2.5 We never receive your full payment card number. Card details are captured directly by our payment provider.

3 Why we use it, and our legal basis

PurposeData usedLegal basis (GDPR Art. 6)
Providing a product you have subscribed toAccount, transaction, technicalPerformance of a contract
Taking payment and handling refunds and chargebacksTransaction, contactPerformance of a contract
Replying to your enquiries and complaintsContact, correspondencePerformance of a contract; legitimate interests
Keeping the Service secure and preventing fraud and abuseTechnical, usage, transactionLegitimate interests
Measuring and improving how the Service is usedUsage, technicalConsent (where cookies require it); otherwise legitimate interests
Meeting tax, accounting and other legal dutiesTransaction, contactLegal obligation
Establishing, exercising or defending legal claimsAny of the above, as relevantLegitimate interests; legal obligation

3.1 Where we rely on legitimate interests, we have considered whether those interests are fair to you and have concluded that the processing is proportionate and that it does not override your rights. You may object — see clause 8.

3.2 We do not sell personal data, and we do not share it for cross-context behavioural advertising.

3.3 We will only send you marketing messages where you have asked us to or where the law otherwise permits it, and every message includes a one-click way to stop them.

4 Cookies and similar technologies

4.1 This clause is our cookie notice. It explains what cookies and similar tracking technologies are, which of them we use, why, and how you can control them. This website uses a deliberately small number of cookies, and we do not run advertising or cross-site tracking cookies on it.

What cookies are

4.2 A cookie is a small text file placed on your device — computer, phone or other device — when you visit a website, storing information such as a language preference or the fact that you have set an option. Cookies we set ourselves are first-party cookies; cookies set from a domain other than ours are third-party cookies, which are typically used for advertising and marketing. Session cookies are deleted when you close your browser and let a site connect your actions within one visit. Persistent cookies remain until they expire or you clear them, and let a site remember your preferences between visits.

Similar technologies

4.3 Several other techniques can perform a comparable function. For completeness, these are what they are and whether we use them:

TechnologyWhat it doesUsed here?
Web beacons / pixel tagsA small transparent image embedded in a page or email containing a unique identifier. When your browser loads it, it reports information such as device specification, operating system and settings, activity during a session, and — in email — that a message was opened, from which IP address and device.No
Software development kits (SDKs)Third-party code included in a mobile application that reports how the application is used and collects device and network information.No — this is a website
Local shared objects ("Flash cookies")Data stored by sites using Adobe Flash to support Flash features; can track parameters similar to cookies and also report use of the specific feature, such as how much of a video was watched.No
HTML5 local storageBrowser functionality that stores information locally in the browser's data files. It works much like a cookie but can hold more information and does not need to exchange data with the server.No
FingerprintingCombining information elements — device configuration, CSS and JavaScript properties, installed fonts and plug-ins, API use, HTTP headers, clock data — to identify a particular device uniquely.No
Device identifiersIdentifiers unique to a device, such as Apple's IDFA and Google's AAID, stored on the device and used to recognise you across apps and devices for marketing purposes. You can reset them or opt out of personalised advertising in your device settings.No — see clause 2.1

Categories of cookie, and what we actually set

4.4 Cookies are conventionally grouped into four categories:

4.5 On this website we set exactly one cookie, in the first category:

CookiePurposeTypeDuration
netlance_ckRemembers your cookie choice so we do not ask againStrictly necessary / preference12 months

4.6 We set no analytical, functionality or targeting cookies at present. If we introduce any, we will add them to the table above and obtain your consent before setting them.

Managing cookies and opting out

4.7 Our consent banner. Non-essential cookies are only ever set with your consent, which you give or decline through the banner shown on your first visit. You can change or withdraw that choice at any time by clearing this site's cookies in your browser, after which the banner appears again. Strictly necessary cookies cannot be switched off, and the banner cannot control cookies set by third-party websites you reach through links from ours.

4.8 Browser and device settings. Most browsers let you refuse and delete cookies. The method differs between browsers and versions — Chrome, Firefox, Safari, Edge and Opera each publish current instructions in their own help pages, and consolidated guidance is available at aboutcookies.org. Note that blocking all cookies degrades the usability of most websites, including parts of ours.

4.9 Analytics and device identifiers. Google publishes an opt-out for Google Analytics at tools.google.com/dlpage/gaoptout. Advertising identifiers can be reset, and personalised advertising turned off, in your device settings — Apple and Google each document the steps for their own operating systems. Neither is currently relevant to this website, since we run no analytics and collect no advertising identifiers.

4.10 Interest-based advertising. Where a business works with advertising partners that belong to the industry self-regulatory programmes, those programmes offer collective opt-outs: the Network Advertising Initiative (optout.networkadvertising.org), the Digital Advertising Alliance (optout.aboutads.info), the DAA of Canada (youradchoices.ca/choices), the European Interactive Digital Advertising Alliance (youronlinechoices.com) and the DAA AppChoices tool (aboutads.info/appchoices). We do not currently work with such partners on this website; these links are provided so the position is clear if that changes.

4.11 "Do Not Track" signals. Some browsers can send a "Do Not Track" signal. There is no common industry standard for interpreting it, and this website does not respond to it — which makes no practical difference here, because we do not track you across sites in any event. If we later add third-party services, you would need to check their own policies to see whether they honour the signal.

4.12 Changes to this cookie notice are published as part of this Policy, and the "Last updated" date at the top of the page changes when they are.

5 Who we share it with

5.1 We share personal data only with the following categories of recipient, and only as far as necessary:

5.2 Providers acting on our behalf are processors bound by a written contract under GDPR Article 28. They may use the data only on our instructions and must apply appropriate technical and organisational security measures.

5.3 We will name the specific providers in use on request.

6 International transfers

6.1 Some of our providers are located outside the European Economic Area, including in the United States — currently Amazon Web Services for hosting and Google for typeface delivery and, for product data, BigQuery. Where personal data leaves the EEA, we rely on one of the following:

6.2 You may ask us for a copy of the safeguards we rely on for a given transfer, using the contact in clause 14.

7 How long we keep it

DataRetention
Account dataFor as long as your account is active, then up to 12 months after closure to handle reactivation and disputes
Transaction and invoicing recordsRetained for the period required by Cyprus tax and accounting law, currently at least 6 years from the end of the relevant tax year
Enquiry and complaint correspondenceUp to 24 months from the last message, or longer where a dispute is unresolved
Technical and usage dataUp to 14 months, then deleted or aggregated so it no longer identifies you
Cookie preference12 months
Records needed for a legal claimUntil the claim and any appeal period is concluded

7.1 When a retention period ends, we delete the data or irreversibly anonymise it.

8 Your rights, and how to use them

8.1 Subject to the conditions in the GDPR, you have the right to: be informed; access a copy of your data; have inaccurate data corrected; have data erased; restrict processing; object to processing based on legitimate interests or to direct marketing; receive your data in a portable form; and withdraw consent at any time where consent is the basis we rely on.

8.2 How to exercise them. Write to us using the contact in clause 14. We will respond within one month. If your request is complex or you have made several, we may extend that by up to two further months and will tell you why within the first month.

8.3 Exercising these rights is free. We may charge a reasonable fee, or decline, only where a request is manifestly unfounded or excessive — and we will explain our reasoning if so.

8.4 We may need to verify your identity before acting, so that we do not disclose your data to someone else.

8.5 Withdrawing consent or objecting does not affect processing already carried out lawfully, and it may mean we can no longer provide part of the Service.

9 Automated decision-making

9.1 We do not make decisions about you that have legal or similarly significant effects using automated processing alone, and we do not carry out profiling for that purpose.

9.2 Our payment providers may apply automated fraud screening to a transaction. If a payment is declined on that basis, you can contact us and a person will look at it.

10 Children

10.1 The Service is intended for adults. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. This is consistent with the minimum age for holding an account in our Terms of Use.

10.2 If you believe a child has given us personal data, contact us and we will delete it.

11 Security

11.1 We apply technical and organisational measures appropriate to the risk, including encryption of data in transit, access controls on a need-to-know basis, and separation of payment handling into specialist providers so that card data never reaches our systems.

11.2 No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

11.3 Where a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the Office of the Commissioner for Personal Data Protection within 72 hours of becoming aware of it, and we will tell you directly where the risk to you is high.

12 Additional information for US residents

12.1 Where US state privacy laws apply to you — including in California, Colorado, Connecticut, Texas and Virginia — the following applies in addition to the rest of this Policy.

12.2 The categories of personal information we collect, our purposes, and the categories of recipient are set out in clauses 2, 3 and 5. We collect this information from you and from your use of the Service.

12.3 We do not sell personal information, and we do not share it for cross-context behavioural advertising. We do not use or disclose sensitive personal information for purposes beyond those permitted without a right to limit.

12.4 Depending on your state, you may have the right to know, access, correct, delete and obtain a portable copy of your personal information, and to appeal a refusal. To exercise any of these, use the contact in clause 14; you may use an authorised agent, and we will verify their authority.

12.5 California "Shine the Light". California law entitles California residents to ask once a year what personal information a business disclosed to third parties for those third parties' own direct marketing purposes. We make no such disclosures. To confirm this in writing, email us with "Request for California Privacy Information" in the subject line, stating your state of residence and the email address we should reply to.

12.6 We will not discriminate against you for exercising these rights.

13 Changes to this Policy

13.1 We may update this Policy. The "Last updated" date at the top will change, and where a change materially affects how we use your data we will notify you by available means — such as email — before it takes effect, so that you have an opportunity to review it. Continuing to use the Service after that point means the revised Policy applies to you.

13.2 We keep earlier versions of this Policy and will provide one on request.

14 Contact and complaints

ControllerNetlance Limited
Registered officeAthalassis 54, Office 101, 2023 Strovolos, Nicosia, Cyprus
Privacy enquirieshq@netlancelimited.com
Response timeWithin one month of a rights request

14.1 If you are not satisfied with how we have handled your data, you may complain to the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus, or to the supervisory authority in your own country of residence or place of work.