Legal · Last updated: 26-08-2026
Privacy Policy
This Privacy Policy describes how Stuxivo collects, uses, stores, shares, and protects personal data when individuals interact with our Services.
Controller: Stuxivo
Contact Email: support@stuxivo.com
Purpose of This Policy
This Privacy Policy describes how Stuxivo ("we", "us", or "our") collects, uses, stores, shares, and protects personal data when individuals interact with our services, websites, applications, and related features (collectively, the "Services").
It also explains the rights available to individuals regarding their personal data and how those rights may be exercised.
Who This Applies To
This policy applies to any person whose personal data we process in connection with the Services, including:
- Customers and prospective customers
- End users of our customers’ implementations of the Services
- Website visitors
- Business partners, vendors, and representatives
- Any individual who communicates with us
Scope of Processing
Depending on how the Services are used, we may process personal data for purposes such as:
- Providing and operating the Services
- Account management and authentication
- Customer support and communication
- Security, fraud prevention, and service integrity
- Legal and contractual compliance
- Service improvement and analytics
Data Protection Principles
We process personal data only where we have a valid legal basis to do so and limit processing to what is necessary for the relevant purpose.
We are committed to processing personal data in accordance with applicable data protection standards, including principles of:
- Lawfulness, fairness, and transparency
- Purpose limitation
- Data minimization
- Accuracy
- Storage limitation
- Integrity and confidentiality
- Accountability
Individual Rights
Individuals may have rights regarding their personal data, which can include the right to request access, correction, deletion, restriction, portability, or objection to certain processing activities. Requests can be submitted using the contact information above.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements, operational practices, or the Services. The "Last Updated" date above indicates when this policy was most recently revised.
What Data We Collect
We collect personal data in connection with the provision and operation of the Services. The types of data collected depend on how you interact with the Services, the features you use, and the information you choose to provide.
The categories of personal data we may collect include:
- Contact Information
- Usage Data
- Device & Technical Data
- Account Credentials
Information You Provide Directly
We collect personal data that you intentionally submit to us, for example when you:
- Create an account or profile
- Communicate with us or request support
- Submit forms or upload content
- Configure or use features within the Services
Information Collected Automatically
We also collect certain information automatically when the Services are accessed or used. This may include technical, device, and usage-related information necessary to operate, secure, and improve the Services.
Service-Specific Collection
Certain features or integrations may require additional personal data to function. In such cases, the scope of collection is limited to what is relevant and necessary for that functionality.
Our Services and Features
We provide software services that may include the following features and functional modules:
- User Accounts
- Newsletter Subscriptions
- Marketing Emails
- Payment Processing
- Subscriptions
- File Uploads
- Analytics & Tracking
- Cookie Consent Banner
- Contact Form
- Push Notifications
- AI-Powered Features
Relationship Between Features and Personal Data
The use of particular features may require us to process personal data in order to operate, secure, maintain, or improve the Services. The type and amount of data processed varies depending on how the feature is used and the information provided by users or customers.
For example, certain features may involve:
- Account identification and authentication
- User-generated content or configuration data
- Communication and support interactions
- Technical and usage information necessary for functionality and security
Necessary Processing
We only process personal data to the extent reasonably necessary for the relevant feature and in accordance with this Privacy Policy.
No Guaranteed Availability
Not all features are available in every region, environment, or service configuration, and features may change, be added, or be discontinued over time as part of ongoing product development.
Controller and Processor Roles
For the processing activities described in this policy, our primary role is: Data Controller.
Depending on the specific service context, we may act as a data controller, processor, or joint controller. Role allocation is determined by the purpose of processing, contractual arrangements, and applicable law.
Where we act as a processor on behalf of a customer, we process personal data only on documented instructions and under applicable data processing terms.
Third-Party Services
We rely on selected third-party providers to operate, deliver, secure, and improve the Services. These providers perform specific functions on our behalf or independently provide services that you choose to use in connection with the Services. The categories below describe typical provider roles and the types of processing involved.
We seek to engage providers that implement appropriate security and confidentiality measures and that are contractually required, where applicable, to process personal data only for authorized purposes. However, each provider maintains its own privacy practices, and you should review their privacy notices where available.
Payment Processing
When payments are required, transactions may be handled by external payment processors rather than directly by us. These providers process payment details, billing information, and related transaction data necessary to complete and record payments. We generally do not store full payment card details unless explicitly stated.
No payment processors are currently listed.
Other Service Providers
We may share limited personal data with other service providers that support infrastructure hosting, communications, analytics, security, integrations, customer support, or similar operational functions. The specific data shared depends on the functionality used and is limited to what is reasonably necessary for that purpose.
We share data with the following third-party service providers:
| Name | Purpose | Category | Privacy URL |
|---|---|---|---|
| Google Analytics | Usage analytics | Analytics | https://policies.google.com/privacy |
| Payment service providers | Subscription and payment processing | Payment Processing | — |
Changes to Providers
Our service providers may change over time as we update or improve the Services. When material changes occur, we will update this policy or associated documentation as appropriate. Where available, links to provider privacy notices can be found in the tables above or within the relevant service documentation.
Recipients and Categories of Recipients
Where the General Data Protection Regulation (GDPR) or UK GDPR applies, we disclose personal data only where there is a lawful basis and where the disclosure is necessary for the relevant processing purpose.
The recipients or categories of recipients of personal data may include:
| Recipient Category | Recipient Role | Personal Data Categories Disclosed | Purpose of Disclosure | Notes |
|---|---|---|---|---|
| Service providers and processors | Data Processor | Account data, contact information, usage data, technical data, and support information | Operating, securing, supporting, and improving the Services | Disclosed only as reasonably necessary for the provider's service function |
| Payment processors | Independent controller | Billing details, payment method information, transaction records, and fraud-prevention information | Processing payments, refunds, chargebacks, tax records, and fraud prevention | Full payment card details are normally handled by the payment processor |
Recipient Roles and Safeguards
These recipients may process personal data as processors acting on our instructions, as independent controllers for their own lawful purposes, as joint controllers where applicable, or as public authorities where disclosure is required or permitted by law. We limit disclosures to what is reasonably necessary for the relevant purpose and use contractual, technical, organizational, or legal safeguards where appropriate.
Data Security
We implement reasonable technical and organizational safeguards designed to protect personal data against unauthorized access, loss, alteration, or disclosure. These safeguards are selected based on the nature of the data, the processing activities involved, and the risks associated with the Services.
The measures we apply may include:
- Encryption at rest
- Encryption in transit (TLS/SSL)
- Access controls & authentication
- Regular security audits
No Absolute Security
While we strive to protect personal data using appropriate safeguards, no system or transmission method can be guaranteed to be completely secure. Accordingly, we cannot ensure or warrant absolute security, and there remains a residual risk inherent in any online service.
We continuously review and update our security practices as appropriate to address evolving risks and operational requirements.
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes described in this policy, including providing the Services, maintaining operational records, complying with legal obligations, resolving disputes, and enforcing agreements.
The typical retention periods applicable to different categories of data are summarized below:
| Period | Category | Criteria |
|---|---|---|
| Until account deletion + 30 days | Account data | Service provision |
Retention Principles
We determine retention periods based on factors such as:
- The duration of the customer relationship or account activity
- Technical and operational requirements of the Services
- Applicable legal, accounting, or reporting obligations
- The need to investigate incidents, resolve disputes, or enforce agreements
Deletion and Anonymization
When personal data is no longer required for the purposes for which it was collected, we take reasonable steps to delete, anonymize, or securely isolate the data. In certain cases, we may retain information for a longer period where necessary to comply with legal obligations, establish or defend legal claims, perform audits, or maintain security and integrity of our systems.
Backup systems and archives may retain residual copies for a limited time until overwritten in accordance with normal lifecycle processes.
Children's Data
Our services are not directed to children unless explicitly stated otherwise, and we do not knowingly collect children's personal data in contexts where parental authorization is required under applicable law.
Automated Decision-Making and Profiling
We do not carry out solely automated decision-making or profiling that produces legal effects or similarly significant effects on individuals unless explicitly disclosed.
Legal Basis for Processing
Where the General Data Protection Regulation (GDPR) or UK GDPR applies, we process personal data only where a valid legal basis exists. The applicable legal basis depends on the specific processing activity, the context in which personal data is collected, and the relationship between the parties.
The table below links each processing purpose to the legal basis we rely on for that purpose. Where legitimate interests are used, the table identifies the specific legitimate interest pursued by us or by a third party:
| Processing Purpose | Legal Basis | Personal Data Categories |
|---|---|---|
| Providing, operating, and securing the Services | Contract Fulfillment | Account data, contact information, usage data |
How Legal Bases Apply
For context, the legal bases reflected in the processing table are:
Different processing activities rely on different legal bases. For example, certain processing may be necessary to provide the Services, while other processing may occur to comply with legal obligations, protect legitimate interests, or where consent has been provided. Not every legal basis applies to every type of processing.
Where consent is used as a legal basis, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal. Where legitimate interests are relied upon, we consider and balance any potential impact on individuals before processing the data.
Further details about specific processing activities and purposes are described in the relevant sections of this policy.
- Contract Fulfillment
Data Protection Officer
We have not appointed a Data Protection Officer unless this policy states otherwise. Privacy questions and data protection requests may be submitted using the contact channels described in this policy.
International Data Transfers
We do not perform direct transfers of personal data outside the EEA or the United Kingdom as part of our own processing.
Certain third-party providers we use may process personal data, or make personal data accessible, outside the EEA or the United Kingdom depending on their infrastructure, support operations, and configuration.
Transfer Basis and Safeguards
Where personal data is transferred outside the EEA or the United Kingdom, we rely on the applicable transfer basis or safeguards required by GDPR or UK GDPR. These may include the safeguards listed below, together with appropriate contractual, technical, and organizational measures for the transfer context.
We rely on the following transfer mechanisms where applicable:
- User Consent
Changes Over Time
Our service providers, infrastructure locations, and operational processes may evolve. As a result, transfer destinations and safeguards may change periodically, and this policy may be updated where appropriate to reflect material updates.
Data Protection Impact Assessment
Where the General Data Protection Regulation (GDPR) or UK GDPR applies, we follow a risk-based approach to assessing the impact of certain processing activities on individuals’ rights and freedoms.
We perform a Data Protection Impact Assessment (DPIA) when processing is likely to result in a high risk, taking into account factors such as the nature, scope, context, and purposes of the processing. This may include, for example, large-scale processing of sensitive data, systematic monitoring, or the use of new or innovative technologies.
A DPIA typically evaluates the necessity and proportionality of the processing, identifies potential risks to individuals, and considers appropriate measures to mitigate those risks. Where relevant, we review and update assessments as processing activities or associated risks evolve.
Not all processing activities require a DPIA, and assessments are conducted only where applicable under relevant data protection law or regulatory guidance.
Your Rights
Depending on your location and applicable data protection laws, you may have certain rights regarding your personal data. These rights may include:
These rights are not absolute and may be subject to legal limitations, verification requirements, and exceptions permitted by applicable law.
- Right to access your data
- Right to rectification
- Right to erasure
- Right to restrict processing
- Right to data portability
- Right to object to processing
How to Exercise Your Rights
You can submit a request using one of the following methods:
Rights Request Email
Verification and Handling of Requests
We may need to verify your identity before responding to your request in order to protect personal data and prevent unauthorized disclosures. The verification method may vary depending on the nature and sensitivity of the request.
We will evaluate and respond to requests within the timeframe required by applicable law.
Response Timeframe: Within 30 days
Where permitted by law, we may decline or limit a request if an exemption applies, if the request is manifestly unfounded or excessive, or if fulfilling it would adversely affect the rights and freedoms of others.
