Privacy Policy

Last updated: 11 November 2024

1. Introduction

This privacy notice for Another Haystack Ltd ('we', 'us', or 'our') describes how and why we collect, store, use, and/or share ('process') your information when you use our services ('Services'), such as when you:

  • Use our web application
  • Create or contribute to projects
  • Engage with us for support, sales, or marketing

2. Contact Information

3. Information We Collect

3.1 Information You Provide Directly

  • Contact Information (name, email address, phone number)
  • Account Credentials (username, password)
  • Project Content (data, images, and other contributions)
  • Payment Information
  • Company Information (for business accounts)

3.2 Information Collected Automatically

  • Log Data (IP address, device information, browser type)
  • Usage Data (how you interact with our services)
  • Technical Data (browser settings, operating system)
  • Location Data (derived from IP address)

3.3 Information from Third Parties

  • Payment processors
  • Authentication services
  • Business partners (where applicable)

4. How We Use Your Information

We process your information to:

  • Provide and maintain our Services
  • Process payments and transactions
  • Send service notifications and updates
  • Respond to support requests
  • Improve our platform and user experience
  • Protect against fraud and abuse
  • Comply with legal obligations
  • Enforce our terms of service

Under GDPR, we process your data based on:

  • Contract Performance: Processing necessary to provide our services
  • Legal Obligations: Compliance with UK law
  • Legitimate Interests: Improving our services, security, fraud prevention
  • Consent: Where specifically requested

6. Content Ownership and Rights

When you contribute content to a project:

  • The content becomes the property of the project owner
  • You grant the project owner all rights to use, modify, and distribute the content
  • This transfer of ownership is a condition of using our platform
  • Project owners are responsible for managing content rights within their projects

7. Data Sharing

7.1 Service Providers

We share data with:

  • Hosting providers
  • Payment processors
  • Analytics services
  • Customer support tools

We may share information:

  • To comply with legal obligations
  • To protect rights and safety
  • In connection with sale or merger of business assets

8. International Data Transfers

When we transfer data outside the UK:

  • We use UK-approved data transfer mechanisms
  • We implement appropriate safeguards
  • We comply with UK data protection laws
  • We use standard contractual clauses where necessary

9. Data Security

We implement:

  • Encryption in transit and at rest
  • Access controls and authentication
  • Regular security assessments
  • Employee training
  • Incident response procedures
  • Backup and recovery systems

10. Data Retention

We retain your data for:

  • Active accounts: Duration of service
  • Closed accounts: 12 months maximum
  • Financial records: 7 years (as required by UK law)
  • Project data: As specified in service agreements

11. Your Rights Under GDPR

You have the right to:

  • Access your data
  • Correct inaccuracies
  • Request deletion
  • Restrict processing
  • Data portability
  • Object to processing
  • Withdraw consent
  • Lodge complaints with the ICO

We use cookies for:

  • Essential platform functionality
  • Authentication
  • Security measures
  • Analytics and performance You can control cookie settings through your browser.

13. Children's Privacy

  • Services not intended for users under 18
  • We don't knowingly collect data from minors
  • We will delete any data if aware of collection from minors

14. Changes to This Policy

  • We will notify you of material changes
  • Changes effective 30 days after notification
  • Continued use constitutes acceptance

15. Contact Us

For privacy concerns:

You have the right to complain to the Information Commissioner's Office (ICO) if you believe we have violated your data protection rights.