Privacy Policy
Last updated: Oct 08, 2025
Table of contents
- Introduction & scope
- Data controller & representative
- Key definitions
- What information we collect & how
- Purposes & legal bases
- Recipients & third-party sharing
- International data transfers
- Data retention
- Cookies & tracking
- Automated individual decision-making
- Your rights
- Security measures
- Changes to this policy
1. Introduction & scope
CLICKBUDDY SOFTWARE LIMITED, a Brittish company registered in United Kingdom (company number 16768835) with registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, UNITED KINGDOM, (“we,” “us,” “our”) respects your privacy and is committed to protecting your personal data. This privacy notice (“Notice”) explains what personal data we collect, how we use and protect it, and your rights regarding your data when you interact with us.
Scope
This Notice applies to the processing of personal data related to:
- All visitors to our website (clickbuddy.com).
- All registered users of our digital marketing SaaS platform (“Platform”).
- Individuals who interact with us for marketing purposes, including prospective customers and leads.
- Any other interactions where you provide personal data to us (e.g., support requests, event attendance).
2. Data controller & representative
Data controller:
The entity responsible for processing your personal data (the “Data Controller”) under the General Data Protection Regulation (GDPR) is:
CLICKBUDDY SOFTWARE LIMITED
71-75 Shelton Street
Covent Garden
London
WC2H 9JQ
UNITED KINGDOM
Data protection officer (DPO):
Under Article 37 of the GDPR, the appointment of a DPO is mandatory only under specific conditions, such as for public authorities, or if the company’s core activities involve large-scale, regular and systematic monitoring of individuals, or large-scale processing of sensitive data or criminal conviction data.
Based on our assessment of our data processing activities against the criteria set out in Article 37 of the GDPR, CLICKBUDDY SOFTWARE LIMITED is not required to appoint a formal data protection officer. For any inquiries regarding data protection, please use the contact details provided for the Data Controller above, or contact our Data Protection Lead at [email protected] for any data protection queries.
3. Key definitions
To help you understand this privacy notice, here are some key terms based on the definitions found in Article 4 of the General Data Protection Regulation (GDPR):
- Personal data: Any information relating to an identified or identifiable natural person (‘data subject’). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (like an IP address or cookie ID), or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
- Data subject: The identified or identifiable natural person to whom the personal data relates (essentially, you as a user or visitor).
- Data Controller: The natural or legal person (in this case, CLICKBUDDY SOFTWARE LIMITED) which, alone or jointly with others, determines the purposes and means of the processing of personal data.
- Data processor: A natural or legal person, public authority, agency, or other body which processes personal data (the “Data Processor”) on behalf of the Data Controller.
- Processing: Any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means. This includes collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
- Consent: Any freely given, specific, informed, and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.
- GDPR: The General Data Protection Regulation (EU) 2016/679, the primary law regulating how companies protect EU citizens’ rsonal data.
- Supervisory authority: An independent public authority established by an EU Member State responsible for monitoring the application of the GDPR. In Ireland, this is the Data Protection Commission (DPC).
- Data processing agreement (DPA): A legally binding contract entered into between a data controller and a data processor, in writing or electronic form (“DPA”). It outlines the specific rights, responsibilities, and instructions regarding the processing of personal data by the processor on behalf of the controller. A DPA is required under GDPR (and other laws) whenever a controller engages a processor to handle personal data, ensuring the data is processed lawfully and securely
4. What information we collect and how
We collect different types of personal data depending on how you interact with our website (clickbuddy.com), our Platform, and our services. The personal data we collect generally falls into the following categories based on how we obtain it:
A. Information you provide directly to us
We collect personal data that you voluntarily provide to us when you perform certain actions, such as:
- Account registration and profile: When you sign up for an account on our Platform or create a user profile, we collect Account Data, which typically includes your name, email address, password (stored securely using hashing), company name, job title, and phone number.
- Purchases and billing: When you subscribe to paid services, we collect billing and payment information necessary to process the transaction. This often includes your billing address and payment information. Note: Sensitive payment details like full credit card numbers are typically collected and processed directly by our secure third-party payment processor. We usually only receive confirmation of payment and necessary billing details.
- Marketing interactions: When you fill out contact forms, subscribe to newsletters, download content, or register for webinars, we collect marketing & communications data, such as your contact details (name, email, company), your communication preferences, and information about your engagement with our marketing materials (e.g., email opens/clicks).
- Support communications: When you contact us for customer support via email, chat, support tickets, or phone, we collect support data, which includes your contact information and the content of your communications with us, including any feedback you provide.
- Using the Platform: When you use our Platform, you may provide or upload data necessary for the platform’s function, such as marketing campaign details, customer lists, or content for analysis (“Client Platform Data“). Note: For this Client Platform Data, your company typically acts as the Data Controller, and we act as the Data Processor, handling this data according to your instructions and our DPA.
B. Information collected automatically
When you visit our website or use our Platform, we automatically collect certain information about your device and your interaction with our services:
- Usage Data: We collect technical information about your visits and usage patterns. This includes your IP address, device type, operating system, browser type and version, pages visited, features used, clickstream data, dates and times of access, and referring URLs. This data is typically gathered through server logs and analytics tools integrated into our website and Platform.
- Cookies and Tracking Technologies Data: We use cookies, pixel tags, web beacons, and similar technologies to collect data about your interaction with our website and Platform. This can include cookie identifiers, analytics IDs, advertising IDs assigned to your device, and preferences stored in cookies. This helps us operate our services, understand user activity, personalise experiences, and potentially deliver targeted advertising. For more details on our use of these technologies and your choices, please see Section 9 (“Cookies & tracking”).
C. Data from connected third-party platforms (e.g., Google APIs)
In some cases, we may receive personal data about you from third-party sources, such as:
- Google Search Console Data: If you connect your Google Search Console account, we access data via the Google Search Console API. This data typically includes:
- Website Performance Statistics: Such as search analytics (queries, clicks, impressions, position), sitemap information, and URL inspection data. This is used to provide you with reporting and optimisation recommendations within our Platform.
- Limited Use: We use this data solely to provide and improve these user-facing reporting and optimisation features visible within our Platform, as consented to by you when connecting the service.
- No Customer Data Transfer: We do not transfer your end-customer data through this API; the data processed is statistical information about your website’s performance in Google Search [User Request].
- Google Ads Data: If you connect your Google Ads account, we access data via the Google Ads API. This data typically includes:
- Campaign Information: Such as campaign structure, settings, performance metrics (clicks, impressions, cost), and ad copy details. This is used to facilitate campaign setup, provide reporting, and offer optimisation features for your Google Ads campaigns managed through our Platform.
- Limited Use: We use this data solely to provide and improve these user-facing campaign management, reporting, and optimisation features visible within our Platform, as consented to by you when connecting the service.
- Your Customer Data: We do not use your customer data via the Google Ads API. Our use is strictly to enable you to manage and analyse your own advertising campaigns through our Platform, in line with Google’s policies.
- Social media platforms: If you interact with us via social media or use social logins.
- Publicly available sources: Such as company websites or professional networking sites.
Human Access to Google API Data: We do not allow humans to read user data obtained via Google APIs unless:
- We have your affirmative agreement to view specific data (e.g., for support purposes).
- It is necessary for security purposes (e.g., investigating a bug or abuse).
- It is necessary to comply with applicable law.
- The data is aggregated and anonymised for internal operations in accordance with applicable privacy requirements.
Special categories of data and children’s data
We do not intentionally collect any “special categories of personal data” as defined under GDPR (e.g., data revealing racial or ethnic origin, political opinions, religious beliefs, health data, etc.). Our services are not intended for children, and we do not knowingly collect personal data from individuals under the age of 16 without appropriate parental consent where required. If we become aware that we have inadvertently collected such data, we will take steps to delete it.
5. Purposes & legal bases
| Processing activity / data category | Purpose(s) of processing | Legal basis (GDPR Article 6) |
|---|---|---|
| Providing Platform access & managing accounts (using account data, some usage data) | To register you as a user, create and manage your account, authenticate logins, provide access to the Platform features, and communicate essential service-related information (e.g., updates, security alerts). | Contract: Processing is necessary for the performance of the contract (our Terms of Service) we have with you or your organisation to provide the SaaS Platform. |
| Processing payments & subscriptions (using account data, payment information | To process subscription payments, manage billing cycles, issue invoices, prevent fraudulent transactions, and maintain financial records. | Contract: Necessary to fulfill our contractual obligation to provide paid services. Legal obligation: Necessary to comply with financial and tax law requirements for record-keeping. |
| Operating & maintaining the service (using Usage Data, some Cookies & Tracking Data) | To monitor the performance and availability of our website and Platform, ensure network and information security, detect and prevent technical issues or security incidents, perform backups, and analyse usage for technical improvement. | Legitimate interests: Necessary for our legitimate interests in ensuring the security, stability, and technical functionality of our services, provided these interests are not overridden by your data protection rights. |
| Improving our services & analytics (using usage data, cookies & tracking data, support data insights) | To understand how users interact with our website and Platform, identify areas for improvement, develop new features, analyse trends (often using aggregated or anonymised data), and enhance user experience. | Legitimate interests: Necessary for our legitimate interests in improving and developing our products and services. Consent: For certain analytics activities, especially those involving non-essential cookies or extensive tracking (see Section 9). |
| Providing customer support (using account data, support data) | To respond to your inquiries, troubleshoot problems, provide technical assistance, gather feedback, and manage our customer relationships. | Contract: Necessary to fulfill our contractual obligations to provide support as part of our service agreement. Legitimate interests: Necessary for our legitimate interests in providing effective customer service and improving user satisfaction. |
| Marketing & communications (using account data, marketing & communications data, some cookies & tracking data) | To send you newsletters, product updates, promotional offers, event invitations, and other marketing communications (where permitted), personalise marketing content, and manage communication preferences. | Consent: Where required by law (e.g., for email newsletters to prospects or based on cookie consent for tracking), we rely on your freely given, specific, informed, and unambiguous consent. Legitimate interests: In limited cases (e.g., communicating with existing customers about similar products/services, subject to opt-out rights), we may rely on legitimate interests. You always have the right to object to direct marketing. |
| Using cookies & similar technologies (using cookies & tracking data) | To enable essential website/platform functions, remember preferences, analyse performance, and potentially deliver targeted advertising. | Consent (for non-essential cookies like analytics and advertising) Legitimate interest (for strictly necessary functional cookies). This is detailed further in Section 9 (“Cookies & tracking”). |
| Legal compliance & disputes (using any relevant data category as needed | To comply with applicable laws, regulations, court orders, or legal processes; to establish, exercise, or defend legal claims. | Legal obligation: Necessary to comply with a legal requirement we are subject to. Legitimate interests: Necessary for our legitimate interests in defending our rights or complying with lawful requests from authorities. |
| Processing client platform data (acting as processor) | To provide the Platform’s functionalities to our clients, allowing them to process their data according to their instructions as documented in our DPA. | Contract (DPA): We process this data based on the contractual agreement (DPA) with our client (the Data Controller). The client is responsible for establishing the legal basis for their processing of this data. |
| Providing Google Search Console Integration Features (using Google Search Console API Data) | To enable you to view website performance reports (search analytics, sitemap status) and receive optimisation recommendations for your website within our Platform. | Contract: Processing is necessary to provide the integrated features of our Platform that you have chosen to connect and use. Consent: Your explicit action to consent for this specific data access and use for the stated features. |
| Providing Google Ads Integration Features (using Google Ads API Data) | To enable you to manage your Google Ads campaigns (setup, reporting, optimisation) directly through our Platform. | Contract: Processing is necessary to provide the integrated features of our Platform that you have chosen to connect and use. Consent: Your explicit action to consent for this specific data access and use for the stated features. |
We only collect and process your personal data when we have a legitimate reason and a valid legal basis under the General Data Protection Regulation (GDPR) and other applicable data protection laws. We process the personal data categories described in Section 4 for the following purposes and rely on the following legal bases as defined in Article 6 of the GDPR:
Explanation of Legal Bases:
- Contract: Processing is necessary to fulfill the terms of a contract we have with you (e.g., providing the service you signed up for).
- Legal obligation: Processing is necessary for us to comply with the law (e.g., tax laws requiring financial record keeping).
- Legitimate interests: Processing is necessary for our legitimate business interests (e.g., improving our service, security, marketing in specific contexts), provided these interests do not override your fundamental rights and freedoms. We conduct balancing tests where we rely on this basis.
- Consent: You have given us clear, specific, and freely given permission to process your data for a particular purpose (e.g., subscribing to a newsletter). You can withdraw consent at any time.
We determine the appropriate legal basis for each processing activity before starting the processing. Where we rely on legitimate interests, we have considered the balance between our interests and your rights. Where we rely on consent, you have the right to withdraw it at any time (see Section 11).
6. Recipients & third-party sharing
We respect your privacy and do not sell your personal data to third parties. However, we may share your personal data with certain categories of trusted third parties under specific circumstances to operate our business, provide and improve our Platform and services, and comply with legal obligations. We take steps to ensure that any third party with whom we share personal data provides adequate protection for that data and uses it only for the purposes for which it was disclosed.
We may share personal data with the following categories of recipients:
- Service providers (data processors): We engage third-party companies and individuals to perform essential services on our behalf, acting as data processors under our instructions. These providers only have access to the personal data necessary to perform their specific tasks and are typically bound by DPAs obliging them to protect your data. Examples include providers for:
- Cloud hosting, storage, and infrastructure
- Payment processing (*Note: We generally do not store full credit card details; these are handled directly by the payment processor*)
- Email delivery and communication platforms (for transactional emails, newsletters, etc.)
- Customer relationship management (CRM) and support tools
- Security monitoring and fraud prevention services
- Third-party integrations (as directed by you): If you choose to connect third-party applications or services to your account on our Platform (e.g., connecting your advertising platforms like Google Ads, Microsoft Advertising, Meta Ads Manager, LinkedIn Ads, or other marketing tools), we will share data with those services as necessary to facilitate the integration, based on your instruction or configuration. The use of your data by these third-party services is governed by their own privacy policies and your agreements with them.
- Legal and regulatory authorities: We may disclose your personal data if required to do so by law, regulation, court order, or other legal process. This includes responding to lawful requests from public authorities (e.g., law enforcement, tax authorities, regulators) to meet national security or legal compliance requirements, subject to applicable legal frameworks (like those discussed regarding Article 48 GDPR for third-country authorities).
- Professional advisors: We may share necessary personal data with our professional advisors, such as lawyers, accountants, auditors, and insurers, when required in the course of the professional services they render to us (e.g., legal advice, financial audits).
- Business transfers: In the event of a merger, acquisition, reorganisation, bankruptcy, sale of assets, or other similar transaction involving our company, your personal data may be transferred as part of the deal. We will notify affected users of such a transfer and any changes to how their data is processed, as required by law.
- Connected Third-Party Platforms (as directed by you): If you choose to connect your accounts from third-party platforms like Google Search Console or Google Ads to our Platform, we will exchange data with these services via their APIs as necessary to provide the requested functionality.
- Google API Services: For data obtained through Google APIs (e.g., Google Search Console, Google Ads), we adhere to the Google API Services User Data Policy. This means we do not transfer or sell this user data to other third parties like advertising platforms or data brokers. Its use is strictly limited to providing or improving the user-facing features you have enabled within our application, for security purposes, or to comply with applicable laws. We do not use data obtained via these APIs for serving unrelated ads, including retargeting or personalised advertising, nor for determining credit-worthiness.
We strive to share only the minimum amount of personal data necessary for the specific purpose.
Note: Details regarding the transfer of personal data to recipients located outside the European Economic Area (EEA) are provided in Section 7 (“International data transfers”).
7. International data transfers
As part of providing our Platform and services, your personal data may be processed in or transferred to countries outside the European Economic Area (EEA), such as the United States, where some of our service providers (as mentioned in Section 6) may be located. Data protection laws in these countries may differ from those within the EEA.
We are committed to ensuring that any transfer of personal data outside the EEA is conducted in compliance with the GDPR and that your data remains protected to a standard essentially equivalent to that within the EEA. We rely on the following legal mechanisms for such transfers:
- Adequacy decisions: We may transfer personal data to countries, territories, or specific sectors within countries that the European Commission has determined provide an adequate level of data protection. This includes countries like the United Kingdom, Switzerland, Canada (commercial organisations), Japan, South Korea, Argentina, and others recognised by the Commission. It also includes transfers to US companies certified under the EU-U.S. Data Privacy Framework (DPF).
- Standard contractual clauses (SCCs): For transfers to countries not covered by an adequacy decision (including transfers to US companies not certified under the DPF), we typically rely on the standard contractual clauses adopted by the European Commission. These are contractual commitments between us and the data recipient outside the EEA, requiring them to protect the personal data according to EU standards. Where necessary, particularly following the Schrems II judgment, we assess the laws of the destination country and implement supplementary technical, organisational, and contractual measures alongside the SCCs to ensure adequate protection.
- Other legal grounds: In specific situations, we may rely on derogations permitted under Article 49 of the GDPR (e.g., explicit consent for a specific transfer, necessity for the performance of a contract with you), although these are used exceptionally.
You have the right to obtain more information about the safeguards we use for international data transfers. You can request details, including potentially a copy of the relevant SCCs (subject to confidentiality redactions where necessary), by contacting us at [email protected].
8. Data retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including to comply with legal, regulatory, tax, accounting, or reporting requirements. Once your personal data is no longer needed, we securely delete or anonymise it.
The retention periods for different categories of personal data we process are generally as follows:
| Data category | Retention period | Retention criteria |
|---|---|---|
| Account data | As long as account is active plus 6 years | To manage your account and comply with contractual and legal obligations |
| Usage data & logs | 6 months | For operational troubleshooting, security, and service improvement |
| Cookies & analytics | 12 months | As described in our Cookie Policy (see Section 9) |
| Support correspondence | 2 years after issue resolved/account closed | To provide customer support and handle any legal claims |
| Payment data | 6 years | To comply with financial and tax record-keeping laws |
General retention principle
In accordance with GDPR Article 5(1)(e), we apply the principle of storage limitation, meaning personal data is kept no longer than necessary for the purposes of processing. We regularly review the data we hold and securely delete or anonymise data that is no longer required.
Your rights regarding data retention
You have the right to request the erasure of your personal data where applicable, subject to any overriding legal obligations or legitimate interests that require us to retain certain information. For example, we may need to retain data to comply with tax laws or to defend legal claims.
If you wish to request deletion or have questions about our data retention practices, please contact us at [email protected].
9. Cookies & tracking
What are cookies?
Like most websites and online services, our website (clickbuddy.com) and Platform use cookies and similar tracking technologies (such as pixels, web beacons, and local storage). Cookies are small text files placed on your device (computer, tablet, smartphone) when you visit our site or use our Platform. They help us recognise your device, store preferences, understand how you interact with our services, and enable certain functionalities.
How we use cookies
We use cookies and similar technologies for various purposes, including:
- Essential operations: To operate our website and Platform securely and enable core features, such as user authentication, session management, and security functions.
- Performance and analytics: To collect information about how visitors use our website and Platform, such as which pages are visited most often, how users navigate the site, loading times, and error messages. This helps us understand usage patterns, monitor performance, and improve our services. We may use third-party analytics tools for this purpose.
- Functionality and preferences: To remember choices you make (like language preference or region) and provide enhanced, more personalised features.
- Marketing and targeting: To track your browsing activity across our site and potentially other websites, allowing us (or our third-party advertising partners) to build a profile of your interests and show you more relevant marketing communications or advertisements.
Types of cookies we use
We categorise the cookies we use as follows:
- Strictly necessary cookies: These are essential for the website and Platform to function correctly and securely. They are typically set in response to actions made by you which amount to a request for services, such as logging in or filling in forms. You cannot opt out of these cookies as our services cannot be provided without them.
- Performance and analytics cookies: These cookies allow us to count visits and traffic sources so we can measure and improve the performance of our site and Platform. They help us know which pages are the most and least popular and see how visitors move around the site. All information these cookies collect is aggregated and therefore anonymous (or pseudonymised).
- Functionality cookies: These cookies enable the website to provide enhanced functionality and personalisation based on your interactions. They may be set by us or by third-party providers whose services we have added to our pages.
- Targeting and marketing cookies: These cookies may be set through our site by us or our advertising partners. They may be used to build a profile of your interests and show you relevant adverts on other sites. They store uniquely identifying information about your browser and internet device.
Your consent and choices
We respect your right to privacy. For any cookies that are not “Strictly Necessary,” we will only place them on your device if we have obtained your prior, informed consent.
- Cookie consent tool: When you first visit our website, you will be presented with a cookie banner providing information about the cookies we use and asking for your consent. You can manage your preferences and choose which categories of non-essential cookies to accept or reject through our cookie consent management tool. You can change your settings or withdraw your consent at any time via [Link to Cookie Settings / Preference Centre – e.g., a link in the website footer]. Consent choices are typically stored for a period (e.g., up to 6 months) before we may ask you to reaffirm them.
- Browser settings: Most web browsers allow some control of most cookies through the browser settings. You can configure your browser to block cookies or alert you when cookies are being sent, but blocking Strictly Necessary cookies may affect the site’s functionality.
Third-party cookies
Some cookies may be set by third-party services integrated into our website or Platform (e.g., advertising networks). The use of these cookies is subject to the privacy policies of these third parties.
10. Automated individual decision-making
CLICKBUDDY SOFTWARE LIMITED does not carry out the processing under Article 22(1) of the GDPR: You will not be subject to a decision adopted by CLICKBUDDY SOFWARE LIMITED based solely on automated processing of your personal data, including profiling, which produces legal effects concerning you or similarly significantly affects you.
11. Your rights
Under the General Data Protection Regulation (GDPR) and other applicable data protection laws, you have specific rights regarding your personal data. We are committed to facilitating the exercise of these rights. Subject to legal conditions and potential exceptions, you have the following rights:
- Right to be informed: To receive clear, transparent, and easily understandable information about how we process your personal data (which is the purpose of this privacy notice).
- Right of access: To obtain confirmation as to whether or not personal data concerning you is being processed, and, where that is the case, access to that personal data and related information (often referred to as a ‘subject access request’).
- Right to rectification: To request the correction of inaccurate personal data concerning you and to have incomplete personal data completed.
- Right to erasure (‘right to be forgotten’): To request the deletion or removal of your personal data where there is no compelling reason for us to keep using it (e.g., the data is no longer necessary for the purpose it was collected, you withdraw consent where consent was the basis, you object and there are no overriding legitimate grounds).
- Right to restrict processing: To ‘block’ or suppress further use of your personal data in certain circumstances (e.g., while we verify the accuracy of data you contest, or if you have objected to processing based on legitimate interests pending verification).
- Right to data portability: To receive the personal data concerning you, which you have provided to us, in a structured, commonly used, and machine-readable format and the right to transmit that data to another controller.
- Right to object: To object to certain types of processing, including:
- Processing based on our legitimate interests, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms.
- Processing for direct marketing purposes; if you object, we will stop processing your data for these purposes.
- Right to withdraw consent: Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawing consent will not affect the lawfulness of processing based on consent before its withdrawal.
- Right to lodge complaint: You have the right to lodge a complaint with a respective supervisory authority pursuant to Art. 77 GDPR (in particular in the country of your residence, place of work or of an alleged infringement of the GDPR).
Exercising your rights
To exercise your rights, email [email protected] or write to:
CLICKBUDDY SOFTWARE LIMITED
Attn: Privacy Request
71-75 Shelton Street
Covent Garden
London
WC2H 9JQ
UNITED KINGDOM
Verification: To protect your privacy and security, we will need to verify your identity before processing your request. We may ask you to provide sufficient information to identify yourself (e.g., account details or specific transaction information).
Response time: We will respond to your request without undue delay and in any event within one month of receipt. This period may be extended by two further mohths where necessary, taking into account the complexity and number of requests. We will inform you of any such extension within one month of receipt of the request, together with the reasons for the delay.
Right to lodge a complaint
You also have the right to lodge a complaint with a data protection supervisory authority if you believe that our processing of your personal data infringes applicable data protection laws. The lead supervisory authority for CLICKBUDDY SOFTWARE LIMITED is the Brittish Information Commissioner’s Office (ICO).
Information Commissioner’s Office (ICO), UNITED KINGDOM
Website: ico.org.uk
Contact details available on their website.
We would, however, appreciate the chance to deal with your concerns before you approach the ico, so please contact us in the first instance.
12. Security measures
We take the security of your personal data seriously and implement appropriate technical and organisational measures designed to protect it against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. We consider the risks involved in the processing and the nature of the personal data when determining appropriate security levels.
Examples of the security measures we implement include:
- Data encryption: Using encryption technologies, such as Transport Layer Security (TLS), to protect data during transmission over the internet. We also employ encryption for sensitive data at rest where appropriate.
- Access controls: Implementing strict access controls, including role-based access permissions and strong authentication mechanisms (e.g., multi-factor authentication where feasible), to ensure that only authorised personnel have access to personal data on a need-to-know basis.
- Network security: Utilising firewalls, intrusion detection systems, and other network security tools to protect our systems from unauthorised access.
- Regular monitoring & audits: Conducting regular security monitoring, vulnerability scanning, and periodic security audits or assessments to identify and address potential threats.
- Data minimisation: Designing our systems and processes to collect and retain only the personal data necessary for the purposes outlined in this notice.
- Secure development practices: Integrating security considerations into our software development lifecycle.
- Incident response: Maintaining procedures to respond to potential data security incidents effectively.
- Staff training: Providing regular data protection and security awareness training to our employees.
- API Security Practices: When accessing data via third-party APIs, we implement security practices consistent with the requirements of those API providers. This may include adhering to specific secure data handling standards and, where applicable for sensitive or restricted scopes, undergoing security assessments as required by the provider (e.g., Google’s requirements for certain API scopes).
Disclaimer: While we strive to use commercially acceptable means to protect your personal data, please remember that no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee its absolute security. Maintaining the confidentiality of your account credentials is also your responsibility.
13. Changes to this policy
We may update this privacy notice from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. We encourage you to review this notice periodically to stay informed about how we collect, use, and protect your personal data.
If we make significant changes, we will provide a more prominent notice. This may include notifying registered account holders directly via email or posting a clear notice on our website prior to the change becoming effective.
The date this privacy notice was last revised is indicated at the top of this page. Your continued use of our website or Platform after any changes or revisions to this privacy notice indicates your agreement with the terms of the revised notice.