Legal · Last updated: 26-08-2026

Privacy Policy

This Privacy Policy describes how Stuxivo collects, uses, stores, shares, and protects personal data when individuals interact with our Services.

Controller: Stuxivo

Contact Email: support@stuxivo.com

Purpose of This Policy

This Privacy Policy describes how Stuxivo ("we", "us", or "our") collects, uses, stores, shares, and protects personal data when individuals interact with our services, websites, applications, and related features (collectively, the "Services").

It also explains the rights available to individuals regarding their personal data and how those rights may be exercised.

Who This Applies To

This policy applies to any person whose personal data we process in connection with the Services, including:

  • Customers and prospective customers
  • End users of our customers’ implementations of the Services
  • Website visitors
  • Business partners, vendors, and representatives
  • Any individual who communicates with us

Scope of Processing

Depending on how the Services are used, we may process personal data for purposes such as:

  • Providing and operating the Services
  • Account management and authentication
  • Customer support and communication
  • Security, fraud prevention, and service integrity
  • Legal and contractual compliance
  • Service improvement and analytics

Data Protection Principles

We process personal data only where we have a valid legal basis to do so and limit processing to what is necessary for the relevant purpose.

We are committed to processing personal data in accordance with applicable data protection standards, including principles of:

  • Lawfulness, fairness, and transparency
  • Purpose limitation
  • Data minimization
  • Accuracy
  • Storage limitation
  • Integrity and confidentiality
  • Accountability

Individual Rights

Individuals may have rights regarding their personal data, which can include the right to request access, correction, deletion, restriction, portability, or objection to certain processing activities. Requests can be submitted using the contact information above.

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in legal requirements, operational practices, or the Services. The "Last Updated" date above indicates when this policy was most recently revised.

What Data We Collect

We collect personal data in connection with the provision and operation of the Services. The types of data collected depend on how you interact with the Services, the features you use, and the information you choose to provide.

The categories of personal data we may collect include:

  • Contact Information
  • Usage Data
  • Device & Technical Data
  • Account Credentials

Information You Provide Directly

We collect personal data that you intentionally submit to us, for example when you:

  • Create an account or profile
  • Communicate with us or request support
  • Submit forms or upload content
  • Configure or use features within the Services

Information Collected Automatically

We also collect certain information automatically when the Services are accessed or used. This may include technical, device, and usage-related information necessary to operate, secure, and improve the Services.

Service-Specific Collection

Certain features or integrations may require additional personal data to function. In such cases, the scope of collection is limited to what is relevant and necessary for that functionality.

Our Services and Features

We provide software services that may include the following features and functional modules:

  • User Accounts
  • Newsletter Subscriptions
  • Marketing Emails
  • Payment Processing
  • Subscriptions
  • File Uploads
  • Analytics & Tracking
  • Cookie Consent Banner
  • Contact Form
  • Push Notifications
  • AI-Powered Features

Relationship Between Features and Personal Data

The use of particular features may require us to process personal data in order to operate, secure, maintain, or improve the Services. The type and amount of data processed varies depending on how the feature is used and the information provided by users or customers.

For example, certain features may involve:

  • Account identification and authentication
  • User-generated content or configuration data
  • Communication and support interactions
  • Technical and usage information necessary for functionality and security

Necessary Processing

We only process personal data to the extent reasonably necessary for the relevant feature and in accordance with this Privacy Policy.

No Guaranteed Availability

Not all features are available in every region, environment, or service configuration, and features may change, be added, or be discontinued over time as part of ongoing product development.

Controller and Processor Roles

For the processing activities described in this policy, our primary role is: Data Controller.

Depending on the specific service context, we may act as a data controller, processor, or joint controller. Role allocation is determined by the purpose of processing, contractual arrangements, and applicable law.

Where we act as a processor on behalf of a customer, we process personal data only on documented instructions and under applicable data processing terms.

Third-Party Services

We rely on selected third-party providers to operate, deliver, secure, and improve the Services. These providers perform specific functions on our behalf or independently provide services that you choose to use in connection with the Services. The categories below describe typical provider roles and the types of processing involved.

We seek to engage providers that implement appropriate security and confidentiality measures and that are contractually required, where applicable, to process personal data only for authorized purposes. However, each provider maintains its own privacy practices, and you should review their privacy notices where available.

Payment Processing

When payments are required, transactions may be handled by external payment processors rather than directly by us. These providers process payment details, billing information, and related transaction data necessary to complete and record payments. We generally do not store full payment card details unless explicitly stated.

No payment processors are currently listed.

Other Service Providers

We may share limited personal data with other service providers that support infrastructure hosting, communications, analytics, security, integrations, customer support, or similar operational functions. The specific data shared depends on the functionality used and is limited to what is reasonably necessary for that purpose.

We share data with the following third-party service providers:

NamePurposeCategoryPrivacy URL
Google AnalyticsUsage analyticsAnalyticshttps://policies.google.com/privacy
Payment service providersSubscription and payment processingPayment Processing—

Changes to Providers

Our service providers may change over time as we update or improve the Services. When material changes occur, we will update this policy or associated documentation as appropriate. Where available, links to provider privacy notices can be found in the tables above or within the relevant service documentation.

Recipients and Categories of Recipients

Where the General Data Protection Regulation (GDPR) or UK GDPR applies, we disclose personal data only where there is a lawful basis and where the disclosure is necessary for the relevant processing purpose.

The recipients or categories of recipients of personal data may include:

Recipient CategoryRecipient RolePersonal Data Categories DisclosedPurpose of DisclosureNotes
Service providers and processorsData ProcessorAccount data, contact information, usage data, technical data, and support informationOperating, securing, supporting, and improving the ServicesDisclosed only as reasonably necessary for the provider's service function
Payment processorsIndependent controllerBilling details, payment method information, transaction records, and fraud-prevention informationProcessing payments, refunds, chargebacks, tax records, and fraud preventionFull payment card details are normally handled by the payment processor

Recipient Roles and Safeguards

These recipients may process personal data as processors acting on our instructions, as independent controllers for their own lawful purposes, as joint controllers where applicable, or as public authorities where disclosure is required or permitted by law. We limit disclosures to what is reasonably necessary for the relevant purpose and use contractual, technical, organizational, or legal safeguards where appropriate.

Cookies

We use cookies and similar tracking technologies (such as local storage, pixels, and identifiers) to operate and support the website and related Services. These technologies store or access information on a device in order to recognize a browser or device, remember preferences, enable functionality, measure usage, and support security.

Data Security

We implement reasonable technical and organizational safeguards designed to protect personal data against unauthorized access, loss, alteration, or disclosure. These safeguards are selected based on the nature of the data, the processing activities involved, and the risks associated with the Services.

The measures we apply may include:

  • Encryption at rest
  • Encryption in transit (TLS/SSL)
  • Access controls & authentication
  • Regular security audits

Shared Responsibility

You also play an important role in protecting personal data. You should maintain the confidentiality of your credentials, use strong passwords, restrict device access, and promptly notify us of any suspected unauthorized use of your account.

No Absolute Security

While we strive to protect personal data using appropriate safeguards, no system or transmission method can be guaranteed to be completely secure. Accordingly, we cannot ensure or warrant absolute security, and there remains a residual risk inherent in any online service.

We continuously review and update our security practices as appropriate to address evolving risks and operational requirements.

Data Retention

We retain personal data only for as long as necessary to fulfill the purposes described in this policy, including providing the Services, maintaining operational records, complying with legal obligations, resolving disputes, and enforcing agreements.

The typical retention periods applicable to different categories of data are summarized below:

PeriodCategoryCriteria
Until account deletion + 30 daysAccount dataService provision

Retention Principles

We determine retention periods based on factors such as:

  • The duration of the customer relationship or account activity
  • Technical and operational requirements of the Services
  • Applicable legal, accounting, or reporting obligations
  • The need to investigate incidents, resolve disputes, or enforce agreements

Deletion and Anonymization

When personal data is no longer required for the purposes for which it was collected, we take reasonable steps to delete, anonymize, or securely isolate the data. In certain cases, we may retain information for a longer period where necessary to comply with legal obligations, establish or defend legal claims, perform audits, or maintain security and integrity of our systems.

Backup systems and archives may retain residual copies for a limited time until overwritten in accordance with normal lifecycle processes.

Children's Data

Our services are not directed to children unless explicitly stated otherwise, and we do not knowingly collect children's personal data in contexts where parental authorization is required under applicable law.

Automated Decision-Making and Profiling

We do not carry out solely automated decision-making or profiling that produces legal effects or similarly significant effects on individuals unless explicitly disclosed.

Data Protection Officer

We have not appointed a Data Protection Officer unless this policy states otherwise. Privacy questions and data protection requests may be submitted using the contact channels described in this policy.

International Data Transfers

We do not perform direct transfers of personal data outside the EEA or the United Kingdom as part of our own processing.

Certain third-party providers we use may process personal data, or make personal data accessible, outside the EEA or the United Kingdom depending on their infrastructure, support operations, and configuration.

Transfer Basis and Safeguards

Where personal data is transferred outside the EEA or the United Kingdom, we rely on the applicable transfer basis or safeguards required by GDPR or UK GDPR. These may include the safeguards listed below, together with appropriate contractual, technical, and organizational measures for the transfer context.

We rely on the following transfer mechanisms where applicable:

  • User Consent

Changes Over Time

Our service providers, infrastructure locations, and operational processes may evolve. As a result, transfer destinations and safeguards may change periodically, and this policy may be updated where appropriate to reflect material updates.

Data Protection Impact Assessment

Where the General Data Protection Regulation (GDPR) or UK GDPR applies, we follow a risk-based approach to assessing the impact of certain processing activities on individuals’ rights and freedoms.

We perform a Data Protection Impact Assessment (DPIA) when processing is likely to result in a high risk, taking into account factors such as the nature, scope, context, and purposes of the processing. This may include, for example, large-scale processing of sensitive data, systematic monitoring, or the use of new or innovative technologies.

A DPIA typically evaluates the necessity and proportionality of the processing, identifies potential risks to individuals, and considers appropriate measures to mitigate those risks. Where relevant, we review and update assessments as processing activities or associated risks evolve.

Not all processing activities require a DPIA, and assessments are conducted only where applicable under relevant data protection law or regulatory guidance.

Your Rights

Depending on your location and applicable data protection laws, you may have certain rights regarding your personal data. These rights may include:

These rights are not absolute and may be subject to legal limitations, verification requirements, and exceptions permitted by applicable law.

  • Right to access your data
  • Right to rectification
  • Right to erasure
  • Right to restrict processing
  • Right to data portability
  • Right to object to processing

How to Exercise Your Rights

You can submit a request using one of the following methods:

Email

Rights Request Email

support@stuxivo.com

Verification and Handling of Requests

We may need to verify your identity before responding to your request in order to protect personal data and prevent unauthorized disclosures. The verification method may vary depending on the nature and sensitivity of the request.

We will evaluate and respond to requests within the timeframe required by applicable law.

Response Timeframe: Within 30 days

Where permitted by law, we may decline or limit a request if an exemption applies, if the request is manifestly unfounded or excessive, or if fulfilling it would adversely affect the rights and freedoms of others.