Privacy Policy
Effective Date: November 1, 2025
Last Updated: November 1, 2025
Version: 1.0.0
This policy is originally written in English. In case of discrepancies in translations, the English version shall prevail.
PAACS Software Ltd is committed to protecting your privacy and complying with applicable data protection laws including the UK GDPR, EU GDPR, and international privacy regulations. This Privacy Policy forms a binding agreement regarding our data practices.
1. DATA CONTROLLER INFORMATION
Company: PAACS Software Ltd
Registered Address: [To be provided]
Company Number: [To be provided]
Data Protection Officer: privacy@paacs.pro
ICO Registration: [To be provided]
2. SCOPE AND APPLICATION
This Privacy Policy applies to all personal data processed by PAACS Software Ltd through:
- Our website (https://paacs.pro and all subdomains)
- Our desktop software applications (Windows, macOS, Linux)
- Our mobile applications (when available)
- Our APIs and web services
- Customer support and communications
- Marketing and sales activities
3. DATA WE COLLECT
3.1 Information You Provide Directly
- Account Information: Name, email address, username, password (hashed), profile picture, organization name, job title
- Contact Information: Mailing address, phone number (optional)
- Payment Information: Billing address, payment method details (processed via secure payment processors)
- Academic Verification: Educational institution, student/faculty ID, academic email address
- Communications: Support tickets, feedback, survey responses, forum posts
- User Content: Files, simulations, projects created within our software
3.2 Information Collected Automatically
- Device Information: Operating system, hardware specifications, device identifiers, screen resolution
- Usage Data: Features used, frequency of use, performance metrics, error logs, crash reports
- Network Information: IP address, ISP, geographic location (country/region), browser type and version
- Cookies and Tracking: See our Cookie Policy for details
- License Validation: License key usage, activation data, machine fingerprint
3.3 Information from Third Parties
- OAuth Providers: Basic profile information from Google, GitHub when you use social login
- Payment Processors: Transaction confirmations, subscription status
- Analytics Services: Aggregated usage statistics
- Public Sources: Company information for B2B customers
4. HOW WE USE YOUR DATA
4.1 Primary Purposes
| Purpose | Legal Basis (GDPR) |
|---|
| Provide and maintain services | Contract performance |
| Process payments | Contract performance |
| Verify license compliance | Legitimate interests |
| Send service updates | Contract performance |
| Marketing communications | Consent / Legitimate interests |
| Improve products | Legitimate interests |
| Security and fraud prevention | Legitimate interests |
| Legal compliance | Legal obligation |
4.2 Detailed Processing Activities
Service Delivery:
- Creating and managing user accounts
- Authenticating users and maintaining sessions
- Providing software functionality and features
- Saving user preferences and settings
- Syncing data across devices
Customer Support:
- Responding to inquiries and support requests
- Troubleshooting technical issues
- Providing documentation and guidance
- Following up on reported problems
Product Improvement:
- Analyzing usage patterns and trends
- Identifying and fixing bugs
- Developing new features based on user needs
- Conducting A/B testing and experiments
- Performance optimization
Security Purposes:
- Detecting and preventing fraud
- Identifying unauthorized access attempts
- Protecting against malware and abuse
- Maintaining system integrity
- Investigating security incidents
5. DATA SHARING AND DISCLOSURE
5.1 We DO NOT Sell Your Data
PAACS Software Ltd does not sell, rent, or trade your personal data to third parties for their marketing purposes.
5.2 Authorized Sharing
We may share your data with:
Service Providers:
- Supabase: Database and authentication services (US-based)
- Stripe/PayPal: Payment processing
- SendGrid: Email delivery
- AWS/Google Cloud: Cloud infrastructure
- Cloudflare: CDN and DDoS protection
Legal Requirements:
- Law enforcement agencies with valid legal requests
- Courts or tribunals with proper jurisdiction
- Regulatory authorities for compliance
- To protect our legal rights or prevent harm
Business Transfers:
- In case of merger, acquisition, or sale of assets
- During due diligence (under confidentiality agreements)
- To successor entities
With Your Consent:
- When you explicitly agree to sharing
- For testimonials or case studies
- In community forums (public posts)
6. DATA RETENTION
6.1 Retention Periods
| Data Category | Retention Period |
|---|
| Account information | Duration of account + 30 days |
| Payment records | 7 years (legal requirement) |
| Support tickets | 2 years after resolution |
| Usage analytics | 26 months |
| Security logs | 6 months |
| Marketing preferences | Until withdrawn + 3 years |
| User content | 90 days after deletion request |
6.2 Deletion Process
- Automated deletion after retention period expires
- Secure overwriting of deleted data
- Removal from backups within 90 days
- Anonymization where deletion not possible
7. INTERNATIONAL DATA TRANSFERS
7.1 Transfer Mechanisms
When we transfer data outside the UK/EEA, we ensure protection through:
- EU-approved Standard Contractual Clauses (SCCs)
- UK International Data Transfer Agreement (IDTA)
- Adequacy decisions (e.g., EU-US Data Privacy Framework)
- Your explicit consent for specific transfers
7.2 Primary Data Locations
- United Kingdom: Primary servers and backups
- European Union: CDN and edge servers
- United States: Supabase database, payment processing
8. DATA SECURITY
8.1 Technical Measures
- AES-256 encryption for data at rest
- TLS 1.3 for data in transit
- Bcrypt hashing for passwords
- Multi-factor authentication (MFA) available
- Regular security audits and penetration testing
- Intrusion detection and prevention systems
- DDoS protection via Cloudflare
8.2 Organizational Measures
- Access control on need-to-know basis
- Employee confidentiality agreements
- Regular security training
- Incident response procedures
- Vendor security assessments
- Data processing agreements with sub-processors
8.3 Breach Notification
In the event of a personal data breach, we will:
- Notify the ICO within 72 hours (if required)
- Inform affected users without undue delay
- Document the breach and our response
- Take measures to mitigate harm
- Review and improve security measures
9. YOUR RIGHTS
9.1 Rights Under GDPR
You have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion (“right to be forgotten”)
- Restriction: Limit processing of your data
- Portability: Receive your data in machine-readable format
- Object: Oppose certain processing activities
- Automated Decisions: Not be subject to solely automated decisions
- Withdraw Consent: Where processing is based on consent
9.2 Exercising Your Rights
To exercise your rights:
- Email privacy@paacs.pro with your request
- Provide proof of identity
- Specify which right(s) you wish to exercise
- We will respond within 30 days
- Complex requests may take up to 90 days
9.3 California Privacy Rights (CCPA/CPRA)
California residents have additional rights to:
- Know what personal information is collected
- Know if information is sold or disclosed (we do not sell)
- Opt-out of sale (not applicable as we don't sell)
- Non-discrimination for exercising rights
- Limit use of sensitive personal information
10. COOKIES AND TRACKING
We use cookies and similar technologies for functionality, analytics, and security. For detailed information, please see our Cookie Policy.
10.1 Managing Preferences
- Cookie banner on first visit
- Granular consent options
- Browser settings for cookie control
- Do Not Track signal respect (optional)
11. CHILDREN'S PRIVACY
Our services are not intended for children under 13 (or 16 in certain jurisdictions). We do not knowingly collect data from children. If we discover such collection, we will:
- Delete the data immediately
- Terminate any associated account
- Notify parents/guardians if possible
Educational institutions using our software for students must:
- Obtain parental consent where required
- Act as data controller for student data
- Ensure compliance with COPPA/FERPA (US) or equivalent
12. AUTOMATED DECISION-MAKING
We use limited automated processing for:
- Fraud detection and prevention
- License compliance verification
- Service recommendations
- Content moderation in forums
You have the right to request human review of automated decisions that significantly affect you.
13. THIRD-PARTY LINKS
Our services may contain links to third-party websites. We are not responsible for their privacy practices. We encourage you to read their privacy policies before providing any data.
14. CHANGES TO THIS POLICY
14.1 Update Process
We may update this policy to reflect:
- Changes in our practices
- New legal requirements
- New features or services
- User feedback
14.2 Notification
For material changes, we will:
- Email registered users
- Display prominent website notice
- Request renewed consent where required
- Provide 30-day notice before changes take effect
15. LEGAL COMPLIANCE
This policy is designed to comply with:
- UK General Data Protection Regulation (UK GDPR)
- EU General Data Protection Regulation (EU GDPR)
- Data Protection Act 2018 (UK)
- Privacy and Electronic Communications Regulations (PECR)
- California Consumer Privacy Act (CCPA/CPRA)
- Other applicable privacy laws
16. CONTACT INFORMATION
16.1 Data Protection Officer
16.2 Supervisory Authority
You have the right to lodge a complaint with:
UK Information Commissioner's Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Phone: 0303 123 1113
Website: ico.org.uk
16.3 EU Representative
[To be appointed if required]
17. ACCESSIBILITY
If you need this Privacy Policy in an alternative format due to disability, please contact us at accessibility@paacs.pro.
Your Privacy Matters
We are committed to protecting your privacy and handling your data responsibly. If you have any questions or concerns about our privacy practices, please don't hesitate to contact our Data Protection Officer.