Privacy Policy
Last updated: February 07, 2024
Privacy Policy of Website ‘Swoontales.com’ - swoontales.com
Riseforward Ltd., a Malta-registered company (Registration number: C110851, VAT: MT31634902) with registered office at LEVEL 1 BLUE HARBOUR BUSINESS CENTRE, IX-XATT TA’ XBIEX, TA XBIEX, XBX 1027, Malta, operates this service.
The company commits to user privacy and explains how personal information is collected, protected, and used. By accessing the website, you accept these terms. The policy covers all platforms and related services, with the company acting as data controller per GDPR Article 4(7).
Which Data Is Collected?
Personal Data includes identifying information such as name, email, phone number, birth date, and billing details.
The company collects two categories:
- Information You Provide: Account signup details, communication content, user-generated materials, and survey responses
- Automatically Collected Information: Usage patterns, device data, network information, and identifiers like IP addresses
Data is stored on “secure web servers, provided to us by cloud computing services of Firebase, Inc.” (Google-owned).
Minors
The services are “not directed to persons under the age of 18” and the company prohibits minor access. Parents of minors who provided data should contact [email protected] for deletion.
How Is Your Personal Data Used?
Processing relies on four legal bases:
- Explicit user consent
- Contract performance
- Legitimate business interests
- Legal compliance obligations
If You Visit or Use Our Online Products
Aggregated data monitoring and service improvement use “legitimate interests” as the legal basis under GDPR Article 6(1)(f).
If You Become a Registered User
Name, email, and billing information are required for service access. Processing bases on “the performance of the contract we have entered with you” (GDPR Article 6(1)(b)).
Sending You Service Updates
Subscription status and system announcements use contract performance as justification, per GDPR Article 6(1)(b).
Contacting Customer Service
Communication through [email protected] or postal mail relies on contractual obligations.
Subscription to Newsletters and Marketing Communications
Newsletter signup uses either “your consent” (GDPR 6(1)(a)) or legitimate interest. Users can opt-out anytime.
Using Our Social Features
Reviews and similar user interactions are processed under GDPR Article 6(1)(b) to provide the service.
Protect Security and Integrity of Our Business
The company processes data to comply with laws, investigate issues, prevent fraud, and enforce agreements.
Special Categories of Personal Data
Health information, sexual orientation, and ethnic origin are processed “only...with your prior consent” per GDPR Article 9(2)(a).
Cookies
The company uses standard cookies to understand usage trends and improve services. Cookies store preferences and avoid repeated data entry.
Users can accept or reject cookies through browser settings. Declining cookies may limit certain interactive features. Deleted cookies remove associated settings.
Users can opt-out from company tracking by contacting [email protected].
Social Plug-Ins and Third-Party Features
Third-party websites and features operate under separate privacy policies not covered here. The company assumes no responsibility for external sites.
When social network plug-ins appear on the website, direct connections occur between your device and the provider’s servers. Being logged into social networks during visits can link your activity to your accounts.
Users can avoid this by logging out before visiting. Refer to individual platform privacy policies (Facebook, Google, Twitter, Instagram, TikTok) for their practices.
Optional account connections with third-party applications share information that the user maintains an account.
How We Share and Disclose Personal Data
The company does not sell personal data and only shares information when required by law, necessary for contracts, using data processors, or with explicit consent.
Posts
Shared content becomes visible to other platform users.
Third-Party Service Providers
The company engages providers for email distribution, payment processing, fraud screening, social media management, CRM systems, and customer service. These providers are “carefully selected” and prohibited from using data beyond stated purposes. International providers are located in regions with adequate protection or safeguarded by “standard data protection clauses adopted by the European Commission.”
Law Enforcement/Legal Requests
The company may disclose data to government or law enforcement per lawful requests and legal obligations (GDPR 6(1)(c)). Information may also be shared to respond to claims, protect rights, ensure safety, prevent illegal activity, or enforce agreements (GDPR 6(1)(f)). Consent is obtained when required.
Is My Personal Data Used for Other Purposes?
Data is used only for stated purposes or as explicitly disclosed when collected.
You Have the Following Rights
- Right of Access: Request confirmation and copies of your personal data
- Right to Rectification: Correct inaccurate information
- Right to Erasure: Request deletion under certain circumstances, including when data is unnecessary or consent is withdrawn
- Right to Restriction of Processing: Limit handling if you believe it unlawful or inaccurate
- Right to Data Portability: Receive data in structured, machine-readable format or transfer to another controller
- Right to Object: Oppose processing based on legitimate interests or marketing
- Right to Withdraw Consent: Revoke consent-based processing without affecting prior lawfulness
- Right to Non-Discrimination: Protection against discrimination for exercising rights
Contact the company using details below to execute these rights. Without an account, the company may lack sufficient identifying information. Additional verification may be required.
Right to Lodge a Complaint Before the Data Protection Authority
You may file complaints with supervisory authorities in your EU Member State regarding alleged data protection violations. The company will assist in identifying the competent authority.
Data Security
The company implements “technical and organizational measures designed to secure your Personal Data from accidental loss and from unauthorized access, use, alteration, and disclosure.” However, complete security cannot be guaranteed.
Users are responsible for maintaining password confidentiality and should not share access credentials.
Data Retention
Personal data is stored as long as necessary for service provision, legal compliance, and dispute resolution. Deletion occurs when purposes are fulfilled.
Contact the company regarding specific retention periods for data types.
Automated Decision Making
The company does not use personal data for automated decisions with legal consequences.
Whom Do I Contact if I Have Any Privacy Questions?
Contact [email protected] for concerns, queries, or questions regarding this policy.
Updates to This Policy
The policy may be amended. Changes are made available through updates; users should review regularly for modifications.