Last updated

Privacy Policy

1.Scope and Controller

This Privacy Policy explains how Definro (“Definro”, “we”, “us”, or “our”) collects, uses, shares, retains, and otherwise processes personal data when you:

  • visit or interact with the Definro website and related pages (the “Website”);
  • contact us or submit a form;
  • request information, a product demonstration, or a commercial discussion;
  • communicate with us in a business or professional capacity; or
  • otherwise interact with Definro in circumstances where Definro determines the purposes and means of processing your personal data.

For the processing described in this Privacy Policy, Definro is the data controller.

You can contact Definro regarding privacy matters through the contact form or other contact details made available on the Website.

This Privacy Policy is intended primarily for Website visitors, prospective and existing business contacts, partners, suppliers, and other professional users. It does not replace any privacy notice or data processing terms that may apply to a specific Definro product or contracted service.

2.When Definro Acts on Behalf of a Business Customer

Definro may provide technology, software, infrastructure, APIs, white-label solutions, or related services to business customers.

Where Definro processes personal data solely on behalf of a business customer in connection with a contracted service, that customer may act as the data controller and Definro may act as a data processor. In those circumstances, the relevant customer’s privacy notice and the applicable service agreement or data processing agreement govern that processing.

This Privacy Policy applies to processing for which Definro acts as a controller, including Website operation, business communications, relationship management, security, and Definro’s own business activities.

3.Personal Data We Collect

The personal data we process depends on how you interact with Definro.

3.1Information You Provide to Us

When you contact us, complete a Website form, request a demonstration, discuss a potential business relationship, or otherwise communicate with us, we may collect:

  • your name;
  • business email address;
  • telephone number or messaging contact;
  • job title or professional role;
  • company or organisation name;
  • country or region;
  • information about your business, intended use case, requirements, or proposed cooperation;
  • the content of messages, requests, documents, or other communications you send to us; and
  • any other information you choose to provide.

3.2Technical and Website Usage Data

When you access the Website, we or our service providers may process technical information such as:

  • IP address;
  • browser type and version;
  • device type;
  • operating system;
  • language and general device settings;
  • date and time of access;
  • referring and exit pages;
  • pages viewed and Website interactions;
  • session, diagnostic, error, and security information; and
  • similar technical data necessary to operate, protect, and understand the Website.

3.3Business Contact Data Obtained from Other Sources

In a B2B context, we may receive professional contact information from:

  • your employer or organisation;
  • colleagues, business partners, or referrals;
  • publicly available professional sources, including company websites and professional networking platforms;
  • events, conferences, or industry communities; and
  • service providers or other third parties where the disclosure and our subsequent use are lawful.

Such information may include your name, professional contact details, employer, role, and other business-related information.

Where required by applicable law, we will provide or direct you to this Privacy Policy at or before our first communication, or within the period required by law.

4.Information You Should Not Send Through the Website

The Website’s general contact forms and business communication channels are not intended for the submission of:

  • passwords;
  • private keys, seed phrases, passkeys, or authentication secrets;
  • one-time passwords or security codes;
  • full payment card credentials;
  • bank account access credentials;
  • government-issued identity documents;
  • biometric information;
  • health information;
  • special-category personal data; or
  • other highly sensitive or confidential information.

If Definro or a relevant service provider requires sensitive information for a specific service, it should be submitted only through the secure process designated for that purpose.

5.How and Why We Use Personal Data

We process personal data only where we have a lawful basis to do so.

PurposeTypical dataLegal basis
Responding to inquiries, demo requests, and commercial requestsContact details, company details, communications, requirementsLegitimate interests in responding to business inquiries and developing business relationships; steps at your request before entering into a contract where applicable
Managing business relationships with customers, prospects, partners, and suppliersProfessional contact details, company details, correspondence, relationship historyLegitimate interests in managing and developing our business relationships; performance of a contract where the individual is a party to that contract
Providing requested information and communicationsContact details, communication preferences, correspondenceLegitimate interests; consent where required by applicable law
B2B marketing and business developmentProfessional contact details, employer, role, interaction history, relevant business interestsLegitimate interests in promoting Definro’s B2B services where permitted by law; consent where required
Operating and maintaining the WebsiteTechnical data, device data, logs, Website interactionsLegitimate interests in operating a functional and reliable Website
Security, fraud prevention, abuse detection, and incident responseIP address, logs, device and security data, communicationsLegitimate interests in protecting Definro, the Website, users, systems, and business partners; legal obligations where applicable
Website analytics and improvementWebsite usage and technical dataConsent where required for non-essential analytics technologies; otherwise legitimate interests where permitted by applicable law
Establishing, exercising, or defending legal claimsRelevant contact, communication, transaction, and technical informationLegitimate interests in protecting our legal rights; legal obligations where applicable
Complying with law and lawful requestsInformation required by the relevant obligation or requestCompliance with legal obligations

Where we rely on legitimate interests, we consider whether our interests are necessary and proportionate and whether your rights and interests override those interests.

Where we rely on consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.

6.B2B Marketing and Your Right to Object

Definro may use professional contact information to communicate about products, services, integrations, partnerships, events, or other matters that we reasonably believe may be relevant to a business relationship.

Electronic marketing communications will be sent only where permitted by applicable privacy and electronic communications laws.

You may object at any time to the processing of your personal data for direct marketing. If you object, we will stop using your personal data for that purpose.

Where a marketing message includes an unsubscribe or opt-out mechanism, you may also use that mechanism to stop future marketing communications.

We may retain limited information necessary to record and respect your opt-out request.

7.Cookies and Similar Technologies

The Website may use cookies, local storage, pixels, tags, and similar technologies.

These technologies may be used for:

  • Website operation and security;
  • remembering privacy or Website preferences;
  • preventing abuse;
  • measuring Website performance; and
  • analytics or similar non-essential purposes.

Technologies that are strictly necessary for the Website to function may be used without consent where permitted by law.

Where consent is required for analytics, advertising, or other non-essential technologies, those technologies will not be activated until the required consent has been obtained.

Where available, you can review or change your choices through the Website’s cookie or privacy settings. You may also be able to control certain technologies through your browser or device settings.

If the Website provides a separate Cookie Policy or cookie settings interface, that information forms part of the privacy information provided to you.

8.How We Share Personal Data

We do not sell or rent personal data.

We may disclose personal data where reasonably necessary to the following categories of recipients:

  • hosting, cloud infrastructure, content delivery, and Website service providers;
  • security, monitoring, logging, and fraud-prevention providers;
  • CRM, communications, email, and business productivity providers;
  • analytics providers, subject to applicable consent requirements;
  • professional advisers, including legal, accounting, tax, compliance, and insurance advisers;
  • contractors and suppliers supporting Definro’s business operations;
  • financial, payment, card, wallet, identity, compliance, or other infrastructure partners where disclosure is necessary to evaluate or provide a service you or your organisation has requested and where such disclosure is lawful;
  • prospective buyers, investors, successors, or counterparties in connection with a merger, financing, acquisition, restructuring, sale of assets, or similar corporate transaction, subject to appropriate confidentiality and data protection safeguards; and
  • courts, regulators, law-enforcement bodies, government authorities, or other parties where disclosure is required by law or reasonably necessary to protect legal rights.

Service providers processing personal data on our behalf are expected to process it only for authorised purposes and subject to appropriate contractual and security obligations.

Some third parties may process personal data as independent controllers under their own privacy notices, particularly where they independently determine the purposes and means of their processing.

9.International Data Transfers

Definro and its service providers may process personal data in countries other than the country in which you are located.

Where applicable law restricts international transfers of personal data, we will use a legally recognised transfer mechanism or other appropriate safeguard. Depending on the circumstances, this may include:

  • an adequacy decision;
  • standard contractual clauses;
  • another legally recognised transfer mechanism; or
  • a permitted derogation in limited circumstances where legally available.

Where required by law, additional technical, contractual, or organisational safeguards may also be applied.

10.Data Retention

We retain personal data only for as long as reasonably necessary for the purposes for which it was collected and as required for legitimate business, legal, security, and compliance purposes.

The retention period is determined by factors including:

  • the nature and duration of our relationship with you or your organisation;
  • whether an inquiry or commercial discussion remains active;
  • the purpose for which the data was collected;
  • whether you have objected to or withdrawn consent for a particular use;
  • applicable contractual obligations;
  • legal, accounting, regulatory, or record-keeping requirements;
  • relevant limitation periods;
  • the need to establish, exercise, or defend legal claims; and
  • security, fraud-prevention, and incident-investigation requirements.

When personal data is no longer required, we will delete or anonymise it, unless continued retention is required or permitted by law.

Backup copies may remain for a limited period as part of normal backup and disaster-recovery processes and will be protected from ordinary use until deleted or overwritten.

11.Data Security

Definro uses reasonable and appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, unauthorised access, and other unlawful processing.

Measures may include access controls, secure infrastructure, authentication controls, monitoring, logging, encryption where appropriate, and internal processes designed to limit access to personal data.

No Internet transmission, Website, or storage system can be guaranteed to be completely secure. You should therefore avoid sending sensitive credentials or highly confidential information through general Website communication channels.

12.Your Privacy Rights

Depending on your location and the applicable law, you may have rights in relation to your personal data, including the right to:

  • obtain information about how your personal data is processed;
  • request access to your personal data;
  • request correction of inaccurate or incomplete personal data;
  • request deletion of personal data in applicable circumstances;
  • request restriction of processing;
  • object to processing based on legitimate interests;
  • object at any time to processing for direct marketing;
  • request portability of certain personal data;
  • withdraw consent where processing is based on consent; and
  • lodge a complaint with a competent data protection authority.

These rights are subject to applicable legal conditions, limitations, and exceptions.

If you are in the European Economic Area, you may generally lodge a complaint with the supervisory authority in the country of your habitual residence, place of work, or place of the alleged infringement.

To exercise a privacy right, contact Definro through the contact details available on the Website. We may need to verify your identity and may request information reasonably necessary to process your request.

13.Automated Decision-Making

Definro does not use personal data collected through the Website to make decisions based solely on automated processing that produce legal effects or similarly significant effects on individuals.

If this changes, we will provide the information and safeguards required by applicable law.

14.Third-Party Websites and Services

The Website may contain links to, integrations with, or references to third-party websites, platforms, products, and services.

Definro does not control the privacy practices of independent third parties. Their collection and use of personal data are governed by their own privacy notices and terms.

You should review the applicable privacy information before providing personal data to an independent third party.

15.Children

The Website and Definro’s B2B offerings are intended for business and professional users and are not directed to children.

Definro does not knowingly use the Website to solicit personal data from children.

If you believe a child has provided personal data to Definro through the Website, contact us so that we can assess and take appropriate action.

16.Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in our Website, business activities, technologies, service providers, or legal obligations.

When we make changes, we will publish the updated version on the Website and revise the “Last updated” date.

Where required by law, we will provide additional notice of material changes or obtain consent before applying a change to processing that requires consent.

17.Contact

For questions, requests, complaints, or other matters relating to privacy or this Privacy Policy, contact Definro through the contact form or other contact details available on the Website.