PrivacyPolicy

Last updated: January 2025

At Pallasite, we are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, and safeguard your data in compliance with GDPR and other applicable regulations.

Information We Collect

  • Account Information: When you create an account, we collect your name, email address, company name, and contact details.
  • Usage Data: We collect information about how you use our services, including access times, pages viewed, and the routes by which you access our service.
  • Technical Data: IP addresses, browser type and version, time zone settings, browser plug-in types and versions, operating system and platform.
  • Communication Data: Records of your communications with us, including email correspondence and support tickets.

How We Use Your Information

  • Service Delivery: To provide, maintain, and improve our cloud infrastructure, security, and analytics services.
  • Account Management: To manage your account, process payments, and provide customer support.
  • Communication: To send you technical notices, updates, security alerts, and support messages.
  • Analytics: To understand how our services are used and to improve our offerings.
  • Compliance: To comply with legal obligations and protect our rights and the security of our services.

Data Security

  • We implement industry-standard security measures including ISO 27001 certified security frameworks.
  • All data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption.
  • Access to personal data is restricted to authorized personnel only on a need-to-know basis.
  • We conduct regular security audits and penetration testing to ensure the integrity of our systems.
  • All data is stored in EU-based data centers to ensure compliance with GDPR and eIDAS regulations.

Data Sharing and Disclosure

  • Service Providers: We may share data with trusted third-party service providers who assist in operating our services, subject to strict confidentiality agreements.
  • Legal Requirements: We may disclose information if required by law or in response to valid legal processes.
  • Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred subject to the same privacy protections.
  • We do not sell your personal data to third parties.

Your Rights Under GDPR

  • Right to Access: Request copies of your personal data.
  • Right to Rectification: Request correction of inaccurate or incomplete data.
  • Right to Erasure: Request deletion of your personal data under certain conditions.
  • Right to Restriction: Request restriction of processing your personal data.
  • Right to Data Portability: Request transfer of your data to another service provider.
  • Right to Object: Object to processing of your personal data for certain purposes.
  • Right to Withdraw Consent: Withdraw consent for data processing at any time.

Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. When data is no longer needed, we securely delete or anonymize it.

Account data is retained for the duration of your active subscription plus 90 days. Backup data is retained for 30 days. Logs and analytics data are retained for 12 months.

Cookies and Tracking Technologies

We use cookies and similar tracking technologies to improve your experience on our website. Essential cookies are necessary for the website to function properly. Analytics cookies help us understand how visitors interact with our site. You can control cookie preferences through your browser settings.

For more information, please see our Cookie Policy.

International Data Transfers

All data is processed and stored within the European Union to ensure compliance with GDPR. We do not transfer personal data outside the EU/EEA except where necessary for service delivery and only with appropriate safeguards in place, such as Standard Contractual Clauses approved by the European Commission.

Children's Privacy

Our services are not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately so we can delete it.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date. We encourage you to review this Privacy Policy periodically.

Contact Us

If you have any questions about this Privacy Policy or wish to exercise your rights under GDPR, please contact us:

Pallasite

Email: privacy@pallasite.net

General Inquiries: info@pallasite.net

Phone: +90 531 509 2954

We will respond to your request within 30 days as required by GDPR.