Last updated
Privacy Policy
1.Scope and Controller
This Privacy Policy explains how Definro (“Definro”, “we”, “us”, or “our”) collects, uses, shares, retains, and otherwise processes personal data when you:
- visit or interact with the Definro website and related pages (the “Website”);
- contact us or submit a form;
- request information, a product demonstration, or a commercial discussion;
- communicate with us in a business or professional capacity; or
- otherwise interact with Definro in circumstances where Definro determines the purposes and means of processing your personal data.
For the processing described in this Privacy Policy, Definro is the data controller.
You can contact Definro regarding privacy matters through the contact form or other contact details made available on the Website.
This Privacy Policy is intended primarily for Website visitors, prospective and existing business contacts, partners, suppliers, and other professional users. It does not replace any privacy notice or data processing terms that may apply to a specific Definro product or contracted service.
2.When Definro Acts on Behalf of a Business Customer
Definro may provide technology, software, infrastructure, APIs, white-label solutions, or related services to business customers.
Where Definro processes personal data solely on behalf of a business customer in connection with a contracted service, that customer may act as the data controller and Definro may act as a data processor. In those circumstances, the relevant customer’s privacy notice and the applicable service agreement or data processing agreement govern that processing.
This Privacy Policy applies to processing for which Definro acts as a controller, including Website operation, business communications, relationship management, security, and Definro’s own business activities.
3.Personal Data We Collect
The personal data we process depends on how you interact with Definro.
3.1Information You Provide to Us
When you contact us, complete a Website form, request a demonstration, discuss a potential business relationship, or otherwise communicate with us, we may collect:
- your name;
- business email address;
- telephone number or messaging contact;
- job title or professional role;
- company or organisation name;
- country or region;
- information about your business, intended use case, requirements, or proposed cooperation;
- the content of messages, requests, documents, or other communications you send to us; and
- any other information you choose to provide.
3.2Technical and Website Usage Data
When you access the Website, we or our service providers may process technical information such as:
- IP address;
- browser type and version;
- device type;
- operating system;
- language and general device settings;
- date and time of access;
- referring and exit pages;
- pages viewed and Website interactions;
- session, diagnostic, error, and security information; and
- similar technical data necessary to operate, protect, and understand the Website.
3.3Business Contact Data Obtained from Other Sources
In a B2B context, we may receive professional contact information from:
- your employer or organisation;
- colleagues, business partners, or referrals;
- publicly available professional sources, including company websites and professional networking platforms;
- events, conferences, or industry communities; and
- service providers or other third parties where the disclosure and our subsequent use are lawful.
Such information may include your name, professional contact details, employer, role, and other business-related information.
Where required by applicable law, we will provide or direct you to this Privacy Policy at or before our first communication, or within the period required by law.
4.Information You Should Not Send Through the Website
The Website’s general contact forms and business communication channels are not intended for the submission of:
- passwords;
- private keys, seed phrases, passkeys, or authentication secrets;
- one-time passwords or security codes;
- full payment card credentials;
- bank account access credentials;
- government-issued identity documents;
- biometric information;
- health information;
- special-category personal data; or
- other highly sensitive or confidential information.
If Definro or a relevant service provider requires sensitive information for a specific service, it should be submitted only through the secure process designated for that purpose.
5.How and Why We Use Personal Data
We process personal data only where we have a lawful basis to do so.
| Purpose | Typical data | Legal basis |
|---|---|---|
| Responding to inquiries, demo requests, and commercial requests | Contact details, company details, communications, requirements | Legitimate interests in responding to business inquiries and developing business relationships; steps at your request before entering into a contract where applicable |
| Managing business relationships with customers, prospects, partners, and suppliers | Professional contact details, company details, correspondence, relationship history | Legitimate interests in managing and developing our business relationships; performance of a contract where the individual is a party to that contract |
| Providing requested information and communications | Contact details, communication preferences, correspondence | Legitimate interests; consent where required by applicable law |
| B2B marketing and business development | Professional contact details, employer, role, interaction history, relevant business interests | Legitimate interests in promoting Definro’s B2B services where permitted by law; consent where required |
| Operating and maintaining the Website | Technical data, device data, logs, Website interactions | Legitimate interests in operating a functional and reliable Website |
| Security, fraud prevention, abuse detection, and incident response | IP address, logs, device and security data, communications | Legitimate interests in protecting Definro, the Website, users, systems, and business partners; legal obligations where applicable |
| Website analytics and improvement | Website usage and technical data | Consent where required for non-essential analytics technologies; otherwise legitimate interests where permitted by applicable law |
| Establishing, exercising, or defending legal claims | Relevant contact, communication, transaction, and technical information | Legitimate interests in protecting our legal rights; legal obligations where applicable |
| Complying with law and lawful requests | Information required by the relevant obligation or request | Compliance with legal obligations |
Where we rely on legitimate interests, we consider whether our interests are necessary and proportionate and whether your rights and interests override those interests.
Where we rely on consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
6.B2B Marketing and Your Right to Object
Definro may use professional contact information to communicate about products, services, integrations, partnerships, events, or other matters that we reasonably believe may be relevant to a business relationship.
Electronic marketing communications will be sent only where permitted by applicable privacy and electronic communications laws.
You may object at any time to the processing of your personal data for direct marketing. If you object, we will stop using your personal data for that purpose.
Where a marketing message includes an unsubscribe or opt-out mechanism, you may also use that mechanism to stop future marketing communications.
We may retain limited information necessary to record and respect your opt-out request.
9.International Data Transfers
Definro and its service providers may process personal data in countries other than the country in which you are located.
Where applicable law restricts international transfers of personal data, we will use a legally recognised transfer mechanism or other appropriate safeguard. Depending on the circumstances, this may include:
- an adequacy decision;
- standard contractual clauses;
- another legally recognised transfer mechanism; or
- a permitted derogation in limited circumstances where legally available.
Where required by law, additional technical, contractual, or organisational safeguards may also be applied.
10.Data Retention
We retain personal data only for as long as reasonably necessary for the purposes for which it was collected and as required for legitimate business, legal, security, and compliance purposes.
The retention period is determined by factors including:
- the nature and duration of our relationship with you or your organisation;
- whether an inquiry or commercial discussion remains active;
- the purpose for which the data was collected;
- whether you have objected to or withdrawn consent for a particular use;
- applicable contractual obligations;
- legal, accounting, regulatory, or record-keeping requirements;
- relevant limitation periods;
- the need to establish, exercise, or defend legal claims; and
- security, fraud-prevention, and incident-investigation requirements.
When personal data is no longer required, we will delete or anonymise it, unless continued retention is required or permitted by law.
Backup copies may remain for a limited period as part of normal backup and disaster-recovery processes and will be protected from ordinary use until deleted or overwritten.
11.Data Security
Definro uses reasonable and appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, unauthorised access, and other unlawful processing.
Measures may include access controls, secure infrastructure, authentication controls, monitoring, logging, encryption where appropriate, and internal processes designed to limit access to personal data.
No Internet transmission, Website, or storage system can be guaranteed to be completely secure. You should therefore avoid sending sensitive credentials or highly confidential information through general Website communication channels.
12.Your Privacy Rights
Depending on your location and the applicable law, you may have rights in relation to your personal data, including the right to:
- obtain information about how your personal data is processed;
- request access to your personal data;
- request correction of inaccurate or incomplete personal data;
- request deletion of personal data in applicable circumstances;
- request restriction of processing;
- object to processing based on legitimate interests;
- object at any time to processing for direct marketing;
- request portability of certain personal data;
- withdraw consent where processing is based on consent; and
- lodge a complaint with a competent data protection authority.
These rights are subject to applicable legal conditions, limitations, and exceptions.
If you are in the European Economic Area, you may generally lodge a complaint with the supervisory authority in the country of your habitual residence, place of work, or place of the alleged infringement.
To exercise a privacy right, contact Definro through the contact details available on the Website. We may need to verify your identity and may request information reasonably necessary to process your request.
13.Automated Decision-Making
Definro does not use personal data collected through the Website to make decisions based solely on automated processing that produce legal effects or similarly significant effects on individuals.
If this changes, we will provide the information and safeguards required by applicable law.
14.Third-Party Websites and Services
The Website may contain links to, integrations with, or references to third-party websites, platforms, products, and services.
Definro does not control the privacy practices of independent third parties. Their collection and use of personal data are governed by their own privacy notices and terms.
You should review the applicable privacy information before providing personal data to an independent third party.
15.Children
The Website and Definro’s B2B offerings are intended for business and professional users and are not directed to children.
Definro does not knowingly use the Website to solicit personal data from children.
If you believe a child has provided personal data to Definro through the Website, contact us so that we can assess and take appropriate action.
16.Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our Website, business activities, technologies, service providers, or legal obligations.
When we make changes, we will publish the updated version on the Website and revise the “Last updated” date.
Where required by law, we will provide additional notice of material changes or obtain consent before applying a change to processing that requires consent.
17.Contact
For questions, requests, complaints, or other matters relating to privacy or this Privacy Policy, contact Definro through the contact form or other contact details available on the Website.