Draft — under legal review
Privacy Policy
Draft. This document is a draft prepared by the Solispec development team and is under review by a lawyer. It is not yet in force. Translations are provided for convenience; if a translation differs from the English version, the English version prevails.
1. Who is responsible
The controller of the personal data described here is the operator of Solispec, a Ukrainian sole proprietor: [OPERATOR: full name, tax ID and address — to be provided by the owner]. Contact: [email protected].
[LAWYER: confirm whether an EU representative under Article 27 GDPR must be appointed and add their details.]
This policy explains how we process personal data under the EU General Data Protection Regulation (GDPR) when you visit solispec.com or use the Solispec service.
2. Controller or processor
- We are the controller for data about our visitors and users: accounts, organizations, billing, support and website use.
- We are a processor for personal data that our customers store about their own clients (the clients address book and client details in projects). The customer is the controller of that data and our Data Processing Agreement applies. If you are one of our customer's clients, please contact that customer first.
3. What we process and why
Guest mode
In guest mode your project stays only in your browser's local storage. We do not receive it until you move it into an account.
Account and organization data
Email address, password (stored only as a cryptographic hash), email verification status, organization membership and role, and the settings of your account. Purpose: to create and run your account. Legal basis: performance of a contract (Article 6(1)(b) GDPR).
Project data
Project inputs, installation locations or addresses, calculation results, versions and, once available, reports. Purpose: to provide the Service. Legal basis: performance of a contract.
Payment data
Card payments are handled by Stripe and cryptocurrency payments by Heleket. We do not receive or store full card details. We receive the payment and subscription status and invoice records. Purpose: billing. Legal basis: performance of a contract, and legal obligation for accounting and tax records (Article 6(1)(c)).
Communications
When you email us, we process your message and contact details to answer you. Legal basis: performance of a contract or our legitimate interest in answering enquiries (Article 6(1)(f)).
Security and technical data
Our servers may process technical data such as IP address, browser type and request times to deliver the Service and protect it against abuse. Legal basis: legitimate interest in a secure service. [verify: exact contents and retention of server logs]
Analytics
We use Google Analytics only if you consent to analytics cookies. Legal basis: consent (Article 6(1)(a)). See the Cookie Policy.
We do not sell personal data, and we do not use it for automated decisions that have legal or similarly significant effects on you.
4. Maps and address search
When you use address search or maps, your browser sends requests directly to OpenStreetMap/Nominatim and to map tile providers. These providers receive your IP address and the search text or map area, under their own privacy policies. If you enter your own Mapbox token, maps are loaded from Mapbox; the token is stored only in your browser.
5. Recipients
We share personal data only with providers that help us run the Service:
- OVH — hosting and backups (EU);
- Stripe — card payments;
- Heleket — cryptocurrency payments;
- Google — Google Analytics, only with your consent;
- an email delivery provider (SMTP) for account and service emails [to be named];
- OpenStreetMap/Nominatim and map tile providers, and Mapbox if you use your own token, as described in section 4.
We may also disclose data where required by law.
6. Where data is stored
Our servers and backups are located in the EU (OVH). Stripe, Heleket and Google may process data outside the EU; such transfers rely on their own safeguards, such as adequacy decisions or standard contractual clauses. [LAWYER: confirm Heleket's location and transfer basis.]
[LAWYER: the operator is established in Ukraine and administers the Service remotely; assess whether this access requires safeguards under Chapter V GDPR.]
7. How long we keep data
- Account data: as long as the account exists. After deletion, copies may remain in backups for up to 30 days of rotation [verify].
- Deleted projects: soft-deleted first and permanently purged later [period to be set].
- Billing records: as long as required by accounting and tax law [period to be confirmed].
- Analytics data: according to the retention set in Google Analytics [period to be confirmed].
8. Your rights
Under the GDPR you have the right to:
- access your personal data;
- have inaccurate data corrected (rectification);
- have your data erased;
- restrict processing;
- receive your data in a portable format (export);
- object to processing based on our legitimate interests;
- withdraw consent at any time, without affecting earlier processing — for cookies, use "Cookie settings" in the footer;
- lodge a complaint with a supervisory authority, in particular in the EU country where you live, work or where the alleged infringement took place.
Until self-service export is available, send requests to [email protected]. We reply within one month; this may be extended in complex cases as allowed by the GDPR, and we will tell you if so. We may ask you to confirm your identity.
9. Security
We use encryption in transit (TLS), access control, separation of data between organizations, password hashing and regular backups. No system is perfectly secure; if a breach affects your data, we will inform you and the authorities as required by law.
10. Children
The Service is meant for professionals and is not directed at children. Accounts are for people aged 18 or over.
11. Changes
We will publish updates to this policy here and tell users about material changes by email or in the Service.
12. Contact
Privacy questions and requests: [email protected].