personly OÜ Privacy Policy
Privacy Policy
Effective Date: October 5, 2026
Last Updated: October 5, 2026
Previous versions of this policy are available on request. Email us at contact@personly.com.
Summary of Key Points
This summary is a quick overview. The sections that follow give the full details.
- What we collect: Information you give us (such as your name, email address and payment details), plus device information, cookie data and usage analytics collected automatically when you use our services.
- Sensitive information: We don't set out to collect sensitive categories such as health data, biometrics or precise location. Payment information is handled with extra care because some laws treat financial data as sensitive.
- Third-party sources: We mainly collect information from you directly. Our payment processor also tells us whether a payment succeeded or failed.
- How we use it: To run your account, process payments, keep our services secure, improve them, communicate with you, and meet our legal obligations.
- Who we share it with: Essential service providers such as hosting and payment processing, and authorities where the law requires it. We never sell your personal data.
- Your rights: Depending on where you live, you can access, correct, delete and port your data, withdraw consent, opt out of marketing, and complain to a regulator.
- Contact: contact@personly.com
1. Introduction
personly OÜ ("personly," "we," "us" or "our") is an Estonian private limited company that provides technology and IT services to businesses through personly.com. If you register for an account, pay for our services or simply visit our website, we handle some of your personal information. This policy explains what we do with it and why.
We want you to be able to understand how your information is handled without needing a law degree. We collect only what we need, we tell you what we do with it, and we give you real control over it.
This policy applies to personal information we process through our website, your account, and our payment and communication channels. It applies to visitors and users worldwide. We have written it to meet the requirements of the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, Canada's PIPEDA, the California Consumer Privacy Act as amended by the CPRA, and other US state privacy laws. For the purposes of these laws, personly OÜ is the controller (or "business") responsible for your personal information.
If you have any privacy questions, email us at contact@personly.com.
2. What We Collect & Why
We organize this section by how the information reaches us, so you can see the reason behind each type of data.
Our approach to legal bases
Under the GDPR and UK GDPR, we need a legal basis for every kind of processing. Consent is the primary legal basis we rely on. You give it when you register, provide information, accept our cookie choices or opt in to communications. Where the law requires us to keep certain records, such as financial and tax records, we also rely on legal obligation. If we ever rely on a different legal basis for a new activity, we will update this policy first.
Information you give us directly
- Account details (name, email address and other registration details). We need these to create and manage your account and to identify you when you contact us. Basis: consent; legal obligation where records must be kept by law.
- Payment information (such as payment method details and transaction history). We need this to process payments and keep accurate financial records. Payments are handled by a payment processor, and we use the information only for that purpose. Basis: consent; legal obligation for financial and tax records.
- Communications (messages, support requests and your marketing preferences). We use these to respond to you and to respect your choices. Basis: consent.
Information collected automatically
When you use our website or services, some information is collected through your device and browser. We collect it so the services work properly, stay secure and can be improved.
- Device information (such as browser type, operating system, device identifiers and IP address). Basis: consent.
- Usage analytics (such as pages visited, features used and how you move through the service). Basis: consent.
- Cookies and similar technologies. See Section 8. Basis: consent for non-essential cookies.
Information from third parties
We don't buy personal data or build profiles from outside sources. The one exception is our payment processor, which sends us confirmation of whether your payment went through, along with related transaction details. Basis: consent; legal obligation for financial records.
3. How We Use Your Information
We use your information for specific, limited purposes, described below.
- Delivering our services. We use your information to create and maintain your account, process payments, provide the services you ask for, and give you support.
- Improving our services. Usage analytics help us see which features are useful, which are confusing, and where something is broken, so we can make the service better.
- Communicating with you. We send service messages such as account notices, payment confirmations, security alerts and changes to our terms or policies. These are part of providing the service you signed up for.
- Security and fraud prevention. We use device and usage information to detect suspicious activity, prevent abuse, and keep your account and our systems safe.
- Legal compliance. We keep financial and tax records, respond to lawful requests from authorities, and meet other legal obligations. We rely on legal obligation for this.
- Marketing. We send marketing emails only if you've opted in. You can withdraw consent at any time by using the unsubscribe link in any message or emailing contact@personly.com. Service messages will continue, because they aren't marketing.
4. When We Share Your Information
We share personal information only when there is a good reason to, and only as far as necessary.
We never sell your personal data. We also don't "share" it for cross-context behavioral advertising, as those terms are defined under California and other US state laws.
- Essential service providers. We use hosting providers to run our services and payment processors to handle transactions. They process data on our behalf and only for the purposes we specify. See Section 16.
- Legal requirements. We may disclose information when required by law, court order or a valid request from a public authority, or when needed to establish, exercise or defend legal claims.
- Business transitions. If personly OÜ is involved in a merger, acquisition, financing or sale of assets, your information may be transferred as part of that transaction. We would notify you beforehand and tell you about any meaningful change in how your information is handled.
- With your consent. For anything else, we ask you first.
5. Your Privacy Rights
Whether you live in the EU, UK, Canada, California or elsewhere, you have meaningful control over your personal information. Which rights apply depends on where you live, but we honor them as described below wherever we reasonably can.
Your rights
- Access. You can ask for a copy of the personal information we hold about you and details of how we use it.
- Correction. You can ask us to fix inaccurate or incomplete information. You can also update many details yourself in your account.
- Deletion. You can ask us to delete your personal information. We'll do so unless we need to keep certain data for legal reasons, such as financial records.
- Portability. You can ask for the information you gave us in a structured, commonly used, machine-readable format, and ask us to transmit it to another provider where technically feasible.
- Opt out of marketing. Use the unsubscribe link in any marketing email or email us.
- Withdraw consent. You can withdraw consent at any time. This won't affect the lawfulness of processing carried out before you withdrew it.
- Restrict or object to processing. Under the GDPR and UK GDPR, you can ask us to limit or stop certain processing in the circumstances the law describes.
- Additional US state rights. Depending on your state, you may also have the right to know the categories of data we collect, to opt out of sale, targeted advertising and certain profiling (which we don't do), and to not be discriminated against for exercising your rights.
- Canada (PIPEDA). You can access your information, challenge its accuracy, and withdraw consent, subject to legal and contractual restrictions.
How to make a request
Email contact@personly.com with the subject line "Privacy Request" and tell us what you'd like to do. We may need to verify your identity before acting, and we'll only ask for what's necessary. If you use an authorized agent, we may ask for proof of their authority.
How quickly we respond
We respond within one month for GDPR and UK GDPR requests, and within 45 days for California and most other US state requests. These periods can sometimes be extended where the law allows, and if so we'll tell you why.
Appeals
If you're in a US state that gives you the right to appeal and we decline your request, you can appeal by replying to our response or emailing contact@personly.com with "Appeal" in the subject line. We'll respond within the period your state's law requires.
Complaints
You can complain to a regulator at any time. See Section 18 for who to contact. We'd appreciate the chance to help first, so please feel free to contact us.
6. Data Security
We take reasonable technical and organizational measures to protect your information, including access controls that limit who can see personal data, encryption, and monitoring of our systems for suspicious activity. We also work with providers who process data on our behalf, and we expect them to protect it appropriately.
We can't promise perfect security, though. No website, app or storage system is 100% secure, and we can't guarantee that unauthorized access, loss or misuse will never happen.
You can help protect your account by:
- Using a strong, unique password that you don't reuse elsewhere
- Keeping your devices and browsers up to date
- Not sharing your login details
- Telling us promptly at contact@personly.com if you suspect unauthorized access
7. Data Retention
We keep personal information only as long as we need it for the purpose we collected it, or as long as the law requires. The periods below reflect that logic.
- Account data: Kept while your account is active. After you close it, we keep it only as long as needed to wrap up the relationship, handle disputes or legal claims, and meet our legal obligations, then delete or anonymize it.
- Financial records: Kept for up to 7 years, which is typically the period required by accounting and tax laws.
- Marketing preferences: Kept until you withdraw your consent. We keep a minimal record of your opt-out so we can honor it.
- Technical logs and usage analytics: Kept for up to 12 months. This is long enough to investigate security issues and spot trends, and short enough to avoid holding data we no longer need.
- Support communications: Kept as long as needed to resolve your request and handle any follow-up, or longer if required for legal reasons.
8. Cookies & Tracking
Cookies are small text files that a website stores on your device. We use them, and similar technologies, in a limited way.
What we use
- Strictly necessary cookies keep you logged in, protect against fraud and make the site function. These can't be switched off without breaking the service.
- Analytics cookies and similar technologies help us understand how people use our site so we can improve it. We ask for your consent before setting these where the law requires it.
Managing your preferences
You can accept or decline non-essential cookies when we ask for your consent, and you can change your mind at any time. Most browsers also let you block or delete cookies in their settings. Blocking essential cookies may stop parts of the service from working properly.
Third-party cookies
Where our analytics tools set cookies, they act on our behalf to give us usage statistics. We don't use cookies to sell your data or to show you cross-context behavioral advertising. This section serves as our cookie policy, and we don't maintain a separate one.
9. Children's Privacy
Our services are intended for business use and are not directed at children. We don't knowingly collect personal information from anyone under 16. If you believe a child has given us personal information, a parent or guardian can contact us at contact@personly.com and we'll delete it promptly. If we discover we've collected information from a child without appropriate consent, we'll delete it.
10. International Transfers
We serve people around the world, and our service providers may process data in countries other than where you live. That means your personal information may be transferred to, and processed in, countries outside the EU/EEA, the UK or your home country.
When we transfer personal data internationally, we use appropriate safeguards, such as the European Commission's Standard Contractual Clauses, or rely on an adequacy decision where one exists. These safeguards are meant to keep your information protected to the standard required by law, and your rights continue to apply wherever your data is processed. To ask about the safeguards for a specific transfer, email contact@personly.com.
11. Changes to This Policy
We may update this policy from time to time, for example when our services change or the law changes. The "Last Updated" date at the top always shows the current version's date.
If we make material changes, we'll notify you by email or through a prominent notice on our website before they take effect. Where the law requires your consent for a new use of your data, we'll ask for it. Existing data stays protected under the version of the policy it was collected under unless you agree otherwise. You can find the current version at personly.com, and previous versions are available on request.
12. Contact Us
Questions, concerns or requests about your privacy? Contact us:
- Email: contact@personly.com (we don't have a separate privacy mailbox, so this address handles all privacy matters)
- Website: personly.com
13. California Privacy Disclosures (CCPA/CPRA)
If you're a California resident, this section gives the detail the CCPA/CPRA requires. The table covers the categories of personal information we collected in the last 12 months.
| Category | Sources | Business purpose | Categories of third parties disclosed to | Retention period |
|---|---|---|---|---|
| Identifiers and account information (name, email, account details) | You | Creating and managing your account; service delivery; communications; security | Hosting providers | Duration of your account, then only as long as needed for closure, disputes and legal obligations |
| Payment and financial information (payment method details, transaction history) | You; our payment processor | Processing payments; financial record-keeping; fraud prevention | Payment processors; hosting providers | Up to 7 years, as required for financial records |
| Commercial information (purchase and subscription history) | You; our systems | Service delivery; billing; legal compliance | Payment processors; hosting providers | Up to 7 years |
| Internet and network activity (usage analytics, pages viewed, cookie data) | Automatically from your browser or device | Improving our services; security | Hosting providers | Up to 12 months |
| Device information (IP address, browser type, device identifiers, technical logs) | Automatically from your device | Security; fraud prevention; troubleshooting; service operation | Hosting providers | Up to 12 months |
| Communications and preferences (support messages, marketing choices) | You | Responding to you; honoring your preferences; marketing (with consent) | Hosting providers | Support: as long as needed to resolve your request. Marketing preferences: until withdrawn |
Sale and sharing: We do not sell personal information or share it for cross-context behavioral advertising, and we haven't done so in the past 12 months.
Sensitive personal information: We don't collect categories such as health data, biometrics, precise geolocation, or racial or ethnic origin. Some laws classify certain financial account information as sensitive. We use payment information only to process payments and for the related legal and security purposes, not to infer characteristics about you. Because of this, we don't offer a "limit the use of my sensitive personal information" option. If this changes, we'll tell you and give you the right to limit.
Your California rights: You have the right to know, access, correct and delete your personal information, to opt out of sale and sharing, to limit the use of sensitive personal information, and to be free from discrimination for exercising these rights. To exercise them, see Section 5.
14. Automated Decision-Making
We do not use automated decision-making or profiling that produces legal or similarly significant effects on you, as described in Article 22 of the GDPR. Decisions about your account, payments and access to our services involve human oversight. If this changes, we'll update this policy and give you the rights the law requires, including the right to request human review.
15. Privacy Signals
We honor Global Privacy Control (GPC) signals. If your browser sends a GPC signal, we treat it as a valid request to opt out of the sale or sharing of your personal information, as required in California, Colorado, Connecticut, Montana, Texas and other states. Since we don't sell or share personal information, there is currently nothing to opt out of, but we'll continue to respect the signal if our practices ever change.
16. Sub-Processors
We use a small number of service providers (sub-processors) to help us run our services. They process personal information only on our instructions and for the purposes described in this policy. They currently fall into these categories:
- Hosting providers, which store and serve our website, application and account data
- Payment processors, which handle payment transactions on our behalf
Keeping the list current: A list of our sub-processors is maintained and available on request. Email contact@personly.com and we'll send you the current list. If you're a customer and want to know before we add or replace a sub-processor, email us to be added to our notification list, and we'll tell you before the change takes effect.
17. EU/UK Representative
GDPR Article 27 and the UK GDPR require some businesses established outside the EU or UK to appoint a local representative. personly OÜ is established in Estonia, so we're not required to appoint an EU representative. We have not yet appointed a UK representative. People in the EU or UK can contact us directly at contact@personly.com about anything covered by this policy, and we'll respond to them directly.
18. Supervisory Authority
If you're unhappy with how we've handled your personal information, you have the right to complain to a data protection authority. Here are the main ones:
- Estonia (our lead EU supervisory authority): Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), aki.ee
- Elsewhere in the EU/EEA: You can complain to the data protection authority in your own country of residence, work, or where you believe a violation occurred.
- United Kingdom: Information Commissioner's Office (ICO), ico.org.uk
- Canada: Office of the Privacy Commissioner of Canada, priv.gc.ca
- California: California Privacy Protection Agency, cppa.ca.gov, or the California Attorney General
- Other US states: Your state Attorney General's office
Thank you for trusting personly OÜ with your information. If anything in this policy is unclear, please ask us.
Consent Required
By clicking "I Agree", you acknowledge that you have read and understood this policy.