Privacy & Data Processing Policy – islaymetrics
Effective Date: [current update]
Company: Islaymetrics Ltd
Contact: hello@islaymetrics.com
Data Protection Officer (DPO): Marek Matulewicz
1. Scope of Policy
- This policy covers all personal data processing activities by islaymetrics:
- As a Data Processor for business clients using analytics solutions and SaaS tools (according to Data Processing Agreements).
- As a Data Controller for data collected directly on www.islaymetrics.com, including contact forms, newsletter subscriptions, cookies, and marketing activity.
2. Role Definition
Islaymetrics acts only as a processor for data entrusted by clients, unless stated otherwise in a specific agreement. For all website and direct marketing activities, islaymetrics is the administrator.
3. Legal Basis
All activities comply with Regulation (EU) 2016/679 (GDPR), Polish law, and any relevant contractual agreements.
4. Categories and Types of Data
When acting as a processor:
- Device and technical data (browser, OS, device type, IP)
- User activity (time on site, scroll depth, previous site referrer, platform authentication status)
- No special categories of data (art. 9 GDPR)
- Data minimized, anonymized, and pseudonymized where possible
When acting as administrator (website):
- Identification data (e.g. name, email from forms/newsletter)
- Behavioral and technical (time on site, cookies, viewed pages, browser details)
- Marketing preferences and communication logs
5. Purpose and Basis of Processing
As processor:
All processing occurs only at the documented direction of the client (data controller), strictly to deliver analytics, monitoring, or optimization services outlined in the contract.
As administrator:
Data is processed for site operation, contact handling, service provision, marketing, optimization, and customization of content; marketing communications and profiling always require explicit user consent (opt-in forms, cookie banners).
6. Subprocessors and Data Sharing
- Primary subprocessors: OVH (hosting, EU), AWS (cloud infrastructure, EU), Ramcom (IT support, EU)
- Marketing and mailing automation partners (website administrator scope): [dane partnerów marketingowych]
- Any new subprocessor changes will be notified at least 7 days in advance, with the controller’s right to object.
- No cross-border data transfers outside the EEA without controller or user consent.
7. Security Measures
- Technical and organizational safeguards include pseudonymization, encryption, access controls, breach response protocols, and staff confidentiality agreements.
- Website data is secured by SSL, and access is monitored and restricted.
8. Data Retention & Deletion
- Processor data is stored only for contractual duration, deleted or returned max. 30 days after contract termination unless otherwise required by law/contract.
- Website/admin data is kept as long as the consent is valid or for the period required by law; users can request deletion or correction at any time.
9. Data Subject Rights
- As processor: Islaymetrics supports clients in complying with access, rectification, erasure, restriction and objection rights under GDPR.
- As administrator: Users of www.islaymetrics.com can request access, correction, deletion, restriction, portability, or withdrawal of consent by contacting hello@islay.tech or DPO.
- Marketing withdrawal (“unsubscribe”) is available in every communication.
10. Consent and User Information
- Website users receive clear notice at the point of data collection (privacy notice, cookie banner, opt-in forms).
- Withdrawal of consent and refusal of cookies is possible at any time.
11. Incident Notification
- All breaches or suspected breaches are notified to relevant parties within 24 hours, with full transparency and cooperation for resolution.
12. Audit & Documentation
- Clients may request audits, compliance records, or on-site inspections of processor operations.
- Full records maintained under GDPR Article 30.
13. Updates & Communication
- The policy is reviewed at least annually or in case of relevant changes. Changes are communicated via email, website updates, and direct notification to affected users/clients.
14. Contact & DPO
- All data processing, privacy, or rights queries should be addressed to the DPO at marek.matulewicz@islay.tech or hello@islay.tech.