Privacy Policy

Privacy Policy

This privacy policy (“Policy”) describes how the personally identifiable information (“Personal Information”) you may provide on the isofy.tech website (“Website”), the “isofy” web application (“Web Application”), and any related products and services (collectively, the “Services”) is collected, protected, and used. It also describes the choices available to you regarding our use of your Personal Information and how you can access and update this information.

This Policy is a legally binding agreement between you (“User”, “you” or “your”) and ISOFY LLC (“isofy”, “we”, “us” or “our”). By accessing and using the Services, you acknowledge that you have read, understood, and agree to be bound by the terms of this Policy. This Policy does not apply to the practices of companies that we do not own or control, or to individuals that we do not employ or manage.

Automatic collection of information

When you open the Website or use the Web Application, our servers automatically record information that your browser or device sends. This data may include information such as your device IP address and approximate location, browser and device name and version, operating system type and version, language preferences, the webpage you were visiting before you came to the Services, pages of the Services that you visit, the time spent on those pages, search terms or actions within the Services, access times and dates, and other statistics.

Information collected automatically is used primarily to identify potential cases of abuse and to generate statistical information regarding usage and traffic of the Services. This statistical information is not otherwise aggregated in such a way that would identify any particular user of the system.

Collection of personal information

You can access and use the Services without telling us who you are or revealing any information that would identify you as a specific, identifiable individual. If, however, you wish to use some of the features on the Services, you may be asked to provide certain Personal Information. We receive and store any information you knowingly provide to us when you create an account, make a purchase, or fill out a form on the Services.

When required, this information may include for example:

  • Personal details such as name, country of residence, company, and role.
  • Contact information such as email address, phone number, and mailing address.
  • Account details such as username, unique user ID, and password.
  • Payment information such as credit card details or billing details (processed via third party payment providers).

Some of the information we collect is provided directly by you via the Services. We may also receive Personal Information about you from other sources such as public databases, social media platforms, third party data providers, and joint marketing partners. Personal Information we collect from other sources may include demographic information, approximate location, device information such as IP addresses, and online behavioral data such as your use of social media websites or page view information.

You can choose not to provide us with certain Personal Information, but this may limit your ability to use some features of the Services. Users who are uncertain about what information is mandatory are welcome to contact us.

Use and processing of collected information

In order to make the Services available to you, or to meet a legal obligation, we may need to collect and use certain Personal Information. If you do not provide the information that we request, we may not be able to provide you with the requested products or services.

Any of the information we collect from you may be used for the following purposes:

  • Create and manage user accounts.
  • Provide, operate, and maintain the Services.
  • Improve products and services.
  • Send administrative information such as service, billing, or security notices.
  • Send marketing and promotional communications (where permitted by law).
  • Respond to inquiries and offer support.
  • Request user feedback.
  • Run and operate the Services and related business operations.

The processing of your Personal Information depends on how you interact with the Services, where you are located, and whether one of the following applies:

  1. You have given your consent for one or more specific purposes.
  2. Provision of information is necessary for the performance of an agreement with you and or any pre-contractual obligations.
  3. Processing is necessary for compliance with a legal obligation to which we are subject.
  4. Processing is necessary for the purposes of the legitimate interests pursued by us or by a third party, provided those interests are not overridden by your rights and interests.

In any case, we will be happy to clarify the specific legal basis that applies to a particular processing activity and whether the provision of Personal Information is a statutory or contractual requirement or a requirement necessary to enter into a contract.

Billing and payments

We use third party payment processors to assist us in processing your payment information securely. Such third party processors use your Personal Information in accordance with their own privacy policies, which may differ from this Policy. We encourage you to review their privacy policies directly:

We do not store full payment card numbers on our own systems. Limited billing metadata may be stored to manage your subscription, invoicing, or account.

Managing information

You are able to delete certain Personal Information we hold about you. The Personal Information you can delete may change as the Services evolve. When you delete Personal Information, we may maintain a copy of the unrevised information in our records for the period necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.

If you would like to delete your Personal Information or permanently delete your account, you can do so by contacting us at support@isofy.tech

Disclosure of information

Depending on the requested Services or as necessary to complete a transaction or provide a service you have requested, we may share your information with:

  • Trusted third parties that work with us such as hosting providers, analytics providers, and support tools.
  • Affiliates and subsidiaries that assist in the operation of the Services.

We do not sell your Personal Information to unaffiliated third parties. Service providers are not authorized to use or disclose your information except as necessary to perform services on our behalf or comply with legal requirements. They receive only the Personal Information they need to perform their designated functions.

We may also disclose any Personal Information we collect, use, or receive if required or permitted by law, such as to comply with a subpoena or similar legal process, or when we believe in good faith that disclosure is necessary to protect our rights, your safety or the safety of others, investigate fraud, or respond to a government request.

In the event we go through a business transition such as a merger, acquisition, or sale of all or a portion of our assets, your user account and Personal Information may be among the transferred assets.

Data hosting and international transfers

isofy provides services to customers in multiple countries. This means Personal Information may be stored and processed outside your country of residence, including in the United States.

We store limited Personal Information required to deliver our software platform and network-management services. This typically includes:

  • First and last names.
  • Email addresses and usernames.
  • Phone numbers.
  • Account and usage metadata needed to operate the Services.

These data elements reside in the following systems:

  • An AWS Aurora PostgreSQL database, hosted and managed by Amazon Web Services (AWS).
  • A Tiger Data / Tiger Cloud (TimescaleDB) database, independently hosted on AWS by our reporting and analytics vendor.

Both environments use industry-standard encryption and access control mechanisms.

Because our infrastructure uses cloud services hosted in the United States, Personal Information may be transferred from the United Kingdom (UK) and European Economic Area (EEA) to the United States. Such transfers are permitted under the UK General Data Protection Regulation (UK GDPR) and the EU General Data Protection Regulation (EU GDPR) when appropriate safeguards are in place.

To protect Personal Information when it is transferred internationally, isofy relies on one or more of the following mechanisms, as applicable:

  • The EU–US Data Privacy Framework (DPF).
  • The UK–US Data Bridge (UK extension to the DPF).
  • The EU Standard Contractual Clauses (SCCs) together with the UK International Data Transfer Addendum (IDTA).

Amazon Web Services participates in the relevant Data Privacy Framework programs. You can learn more about AWS privacy and compliance here:

Our analytics vendor, Tiger Data (Tiger Cloud), publishes information about its security practices and GDPR-related commitments here:

All sub-processors that handle Personal Information on our behalf must:

  • Enter into a written data processing agreement with isofy.
  • Maintain appropriate security, confidentiality, and privacy controls.
  • Notify us of security incidents that could affect Personal Information.

A current list of key sub-processors is available from us upon request.

Retention of information

We retain and use your Personal Information for as long as necessary to provide the Services, comply with our legal obligations, resolve disputes, and enforce our agreements, unless a longer retention period is required or permitted by law.

We may use aggregated or de-identified data derived from your Personal Information after you update or delete it, but not in a manner that would identify you personally. Once the retention period for a given category of data expires, Personal Information is deleted or irreversibly anonymized.

After deletion or anonymization, some rights such as access, rectification, and data portability may no longer be enforceable, because we no longer hold identifiable data.

Transfer of information (general notice)

Depending on your location, data transfers may involve transferring and storing your information in a country other than your own. You are entitled to learn more about the legal basis of information transfers to a country outside the European Union, the EEA, or the UK, and the security measures taken to safeguard your information. You can request additional information by contacting us at support@isofy.tech

The rights of users

You may exercise certain rights regarding your information processed by us. In particular, and subject to applicable law, you may have the right to:

  • Withdraw consent where you have previously given your consent to the processing of your information.
  • Object to the processing of your information if the processing is carried out on a legal basis other than consent.
  • Learn whether information is being processed by us, obtain disclosure regarding certain aspects of the processing, and obtain a copy of the information undergoing processing.
  • Verify the accuracy of your information and ask for it to be updated or corrected.
  • Restrict the processing of your information under certain circumstances, in which case we will not process your information for any purpose other than storing it.
  • Obtain the erasure of your Personal Information under certain circumstances.
  • Receive your information in a structured, commonly used, and machine-readable format and, if technically feasible, have it transmitted to another controller without hindrance.

These rights may be limited in some situations, for example when we need to retain certain data for legal or contractual reasons.

The right to object to processing

Where Personal Information is processed for the public interest or for the purposes of the legitimate interests pursued by us or a third party, you may object to such processing by providing a ground related to your particular situation to justify the objection.

If your Personal Information is processed for direct marketing purposes, you can object to that processing at any time without providing any justification. To find out whether we process Personal Information for direct marketing purposes, you can refer to the relevant sections of this Policy or contact us at support@isofy.tech

Data protection rights under GDPR and UK GDPR

If you are a resident of the European Economic Area (EEA) or the United Kingdom (UK), you have certain data protection rights under the EU GDPR and UK GDPR. isofy aims to take reasonable steps to allow you to correct, amend, delete, or limit the use of your Personal Information.

If you wish to be informed about what Personal Information we hold about you or if you want it to be removed from our systems, please contact us at support@isofy.tech

In certain circumstances, you have the following data protection rights:

  • The right to request access to your Personal Information that we store.
  • The right to request that we correct any Personal Information you believe is inaccurate and to request completion of incomplete information.
  • The right to request the erasure of your Personal Information under the conditions set out in applicable law.
  • The right to object to our processing of your Personal Information.
  • The right to seek restrictions on the processing of your Personal Information.
  • The right to receive a copy of the information we have on you in a structured, machine-readable, and commonly used format.
  • The right to withdraw your consent at any time where isofy relies on your consent to process your Personal Information.

You also have the right to lodge a complaint with a supervisory authority. For EEA residents, this is your local data protection authority. For UK residents, this is the Information Commissioner’s Office (ICO).

California privacy rights

In addition to the rights explained in this Policy, California residents who provide Personal Information to obtain products or services for personal, family, or household use may be entitled to request information about Personal Information we shared, if any, with other businesses for their direct marketing uses. If applicable, this information would include the categories of Personal Information and the names and addresses of those businesses with which we shared such Personal Information for the prior calendar year.

We may update this section as California privacy law evolves. To obtain this information, please contact us at support@isofy.tech

How to exercise these rights

Any requests to exercise your rights can be directed to isofy through the contact details provided in this Policy. We may ask you to verify your identity before responding to such requests.

Your request must provide sufficient information to allow us to verify that you are the person you claim to be (or that you are an authorized representative) and include enough detail to allow us to properly understand and respond to it. We cannot respond to your request or provide you with Personal Information unless we can verify your identity or authority and confirm that the Personal Information relates to you.

Privacy of children

We do not knowingly collect any Personal Information from children under the age of 18. If you are under the age of 18, please do not submit any Personal Information through the Services.

We encourage parents and legal guardians to monitor their children’s Internet usage and to help enforce this Policy by instructing their children never to provide Personal Information through the Services without parental permission. If you have reason to believe that a child under the age of 18 has provided Personal Information to us through the Services, please contact us and we will take appropriate steps to delete that information.

Cookies

The Services use cookies to help personalize your online experience. A cookie is a text file that is placed on your device by a web page server. Cookies cannot be used to run programs or deliver viruses to your computer.

We may use cookies to collect, store, and track information for statistical purposes to operate the Services. You can choose to accept or decline cookies. Most web browsers automatically accept cookies, but you can usually modify your browser setting to decline cookies. If you choose to decline cookies, some parts of the Services may not function properly.

Do Not Track signals

Some browsers incorporate a Do Not Track feature that signals to websites that you do not want to have your online activity tracked. For these purposes, tracking refers to collecting personally identifiable information about consumers as they move across different websites over time.

The Services do not track visitors over time and across third party websites to provide targeted advertising. However, some third party sites may track your browsing activities when they serve you content, which enables them to tailor what they present to you.

Advertisements

We may permit certain third party companies to help us tailor advertising that we think may be of interest to users and to collect and use other data about user activities on the Services. These companies may deliver ads that place cookies or other tracking technologies and may otherwise track user behavior, in accordance with their own privacy policies.

Links to other resources

The Services may contain links to other websites or resources that are not owned or controlled by us. We are not responsible for the privacy practices of such other resources or third parties. We encourage you to be aware when you leave the Services and to read the privacy statements of each website that may collect Personal Information.

Information security

We secure information you provide on computer servers in a controlled, secure environment protected from unauthorized access, use, or disclosure. We maintain reasonable administrative, technical, and physical safeguards to protect against unauthorized access, use, modification, and disclosure of Personal Information in our control and custody.

However, no data transmission over the Internet or wireless network can be guaranteed as completely secure. While we strive to protect your Personal Information, you acknowledge that there are security and privacy limitations of the Internet that are beyond our control and that any information and data may be viewed or tampered with in transit by a third party, despite our best efforts.

Data breach

If we become aware that the security of the Services has been compromised or users Personal Information has been disclosed to unrelated third parties as a result of external activity, including security attacks or fraud, we reserve the right to take reasonably appropriate measures, including investigation and reporting, as well as notification to and cooperation with law enforcement authorities.

When required by law, we will notify affected individuals if we believe there is a reasonable risk of harm as a result of the breach. When we do, we will post a notice on the Services and or contact you using the contact details you have provided.

Changes and amendments

We reserve the right to modify this Policy or its terms relating to the Services from time to time at our discretion. When we do, we will revise the updated date at the bottom of this page. We may also provide notice to you in other ways, such as through the contact information you have provided or within the Services.

Any updated version of this Policy will be effective immediately upon posting unless otherwise specified. Your continued use of the Services after the effective date of the revised Policy will constitute your consent to those changes. We will not, without your consent, use your Personal Information in a manner materially different than what was stated at the time your Personal Information was collected.

Acceptance of this Policy

You acknowledge that you have read this Policy and agree to all its terms and conditions. By accessing and using the Services, you agree to be bound by this Policy. If you do not agree to abide by the terms of this Policy, you are not authorized to access or use the Services.

Contacting us

If you would like to contact us to understand more about this Policy or wish to exercise any of your rights relating to your Personal Information, you may send an email to support@isofy.tech