This Privacy Notice explains how TechComply collects, uses, discloses, and protects personal information when you visit our website, create an Account, use the Services, contact us, or otherwise interact with us.
TechComply is the data processor in regards to the provision of the EvRisko web application and the related services. Client is the data controller and decides how its personal data is used in connection to the Services.
We may collect:
Note: Client should not enter passwords, payment card details, private encryption keys, or unnecessary special category Personal Data into questionnaire fields.
Payments are processed by Stripe. We may receive limited information such as payment status, transaction identifier, card type, billing country, and the last four digits of a payment card. We do not generally receive or store full payment-card numbers.
We use information to:
Where permitted by law, we may send marketing communications. You can opt out at any time using the unsubscribe link or by contacting us.
Where GDPR or UK GDPR applies, we rely on the following legal bases:
When a business Client submits Personal Data through the Services, Client acts as data controller and TechComply acts as data processor under the GDPR. The Data Processing Addendum applies to that processing.
For information about our own website, account administration, billing, marketing, security, and support activities, we may act as an independent data controller.
We may share information with the following natural or legal entities with the sole purposes of providing you the Services:
We do not sell personal information. We do not disclose Client Data to third parties except as necessary to provide the Services, operate our business, comply with law, or as otherwise described in this Notice.
Some service providers may process information outside your country. Where required, we use appropriate transfer safeguards, such as adequacy decisions, standard contractual clauses, the UK International Data Transfer Agreement or Addendum, and supplementary security measures.
We retain information only for as long as reasonably necessary for the purposes described in this Notice, including to:
After an Account is terminated, Client Data is generally deleted or anonymized within 30 days, subject to backups, legal retention requirements, and the Data Processing Addendum.
Depending on your location, you may have the right to:
Requests may be sent by using the contact form. We may need to verify your identity before addressing your inquiry further.
Our website uses cookies and similar technologies for essential operation, authentication, security, preferences, analytics, and marketing where applicable.
For more information, see our Cookie Notice.
We use reasonable technical and organizational safeguards designed to protect Personal Data. However, no online service is completely secure. Clients are responsible for configuring their Accounts and access controls appropriately. More information on our security controls can be found in our Terms & Conditions and Security Annex.
The Services are intended for business users and are not directed to children. We do not knowingly collect Personal Data from children.
We may update this Privacy Notice from time to time. We will post the updated version and change the “Last updated” date. Where legally required, we will provide additional notice. We will not obtain your approval for the implementation of said changes.
Questions or requests should be sent to:
You may also contact the relevant data protection authority in your country of residence or operation.