Privacy Policy

Last updated: February 07, 2024

Privacy Policy of Website ‘Swoontales.com’ - swoontales.com

Riseforward Ltd., a Malta-registered company (Registration number: C110851, VAT: MT31634902) with registered office at LEVEL 1 BLUE HARBOUR BUSINESS CENTRE, IX-XATT TA’ XBIEX, TA XBIEX, XBX 1027, Malta, operates this service.

The company commits to user privacy and explains how personal information is collected, protected, and used. By accessing the website, you accept these terms. The policy covers all platforms and related services, with the company acting as data controller per GDPR Article 4(7).

Which Data Is Collected?

Personal Data includes identifying information such as name, email, phone number, birth date, and billing details.

The company collects two categories:

  • Information You Provide: Account signup details, communication content, user-generated materials, and survey responses
  • Automatically Collected Information: Usage patterns, device data, network information, and identifiers like IP addresses

Data is stored on “secure web servers, provided to us by cloud computing services of Firebase, Inc.” (Google-owned).

Minors

The services are “not directed to persons under the age of 18” and the company prohibits minor access. Parents of minors who provided data should contact [email protected] for deletion.

How Is Your Personal Data Used?

Processing relies on four legal bases:

  1. Explicit user consent
  2. Contract performance
  3. Legitimate business interests
  4. Legal compliance obligations

If You Visit or Use Our Online Products

Aggregated data monitoring and service improvement use “legitimate interests” as the legal basis under GDPR Article 6(1)(f).

If You Become a Registered User

Name, email, and billing information are required for service access. Processing bases on “the performance of the contract we have entered with you” (GDPR Article 6(1)(b)).

Sending You Service Updates

Subscription status and system announcements use contract performance as justification, per GDPR Article 6(1)(b).

Contacting Customer Service

Communication through [email protected] or postal mail relies on contractual obligations.

Subscription to Newsletters and Marketing Communications

Newsletter signup uses either “your consent” (GDPR 6(1)(a)) or legitimate interest. Users can opt-out anytime.

Using Our Social Features

Reviews and similar user interactions are processed under GDPR Article 6(1)(b) to provide the service.

Protect Security and Integrity of Our Business

The company processes data to comply with laws, investigate issues, prevent fraud, and enforce agreements.

Special Categories of Personal Data

Health information, sexual orientation, and ethnic origin are processed “only...with your prior consent” per GDPR Article 9(2)(a).

Cookies

The company uses standard cookies to understand usage trends and improve services. Cookies store preferences and avoid repeated data entry.

Users can accept or reject cookies through browser settings. Declining cookies may limit certain interactive features. Deleted cookies remove associated settings.

Users can opt-out from company tracking by contacting [email protected].

Social Plug-Ins and Third-Party Features

Third-party websites and features operate under separate privacy policies not covered here. The company assumes no responsibility for external sites.

When social network plug-ins appear on the website, direct connections occur between your device and the provider’s servers. Being logged into social networks during visits can link your activity to your accounts.

Users can avoid this by logging out before visiting. Refer to individual platform privacy policies (Facebook, Google, Twitter, Instagram, TikTok) for their practices.

Optional account connections with third-party applications share information that the user maintains an account.

How We Share and Disclose Personal Data

The company does not sell personal data and only shares information when required by law, necessary for contracts, using data processors, or with explicit consent.

Posts

Shared content becomes visible to other platform users.

Third-Party Service Providers

The company engages providers for email distribution, payment processing, fraud screening, social media management, CRM systems, and customer service. These providers are “carefully selected” and prohibited from using data beyond stated purposes. International providers are located in regions with adequate protection or safeguarded by “standard data protection clauses adopted by the European Commission.”

Law Enforcement/Legal Requests

The company may disclose data to government or law enforcement per lawful requests and legal obligations (GDPR 6(1)(c)). Information may also be shared to respond to claims, protect rights, ensure safety, prevent illegal activity, or enforce agreements (GDPR 6(1)(f)). Consent is obtained when required.

Is My Personal Data Used for Other Purposes?

Data is used only for stated purposes or as explicitly disclosed when collected.

You Have the Following Rights

  • Right of Access: Request confirmation and copies of your personal data
  • Right to Rectification: Correct inaccurate information
  • Right to Erasure: Request deletion under certain circumstances, including when data is unnecessary or consent is withdrawn
  • Right to Restriction of Processing: Limit handling if you believe it unlawful or inaccurate
  • Right to Data Portability: Receive data in structured, machine-readable format or transfer to another controller
  • Right to Object: Oppose processing based on legitimate interests or marketing
  • Right to Withdraw Consent: Revoke consent-based processing without affecting prior lawfulness
  • Right to Non-Discrimination: Protection against discrimination for exercising rights

Contact the company using details below to execute these rights. Without an account, the company may lack sufficient identifying information. Additional verification may be required.

Right to Lodge a Complaint Before the Data Protection Authority

You may file complaints with supervisory authorities in your EU Member State regarding alleged data protection violations. The company will assist in identifying the competent authority.

Data Security

The company implements “technical and organizational measures designed to secure your Personal Data from accidental loss and from unauthorized access, use, alteration, and disclosure.” However, complete security cannot be guaranteed.

Users are responsible for maintaining password confidentiality and should not share access credentials.

Data Retention

Personal data is stored as long as necessary for service provision, legal compliance, and dispute resolution. Deletion occurs when purposes are fulfilled.

Contact the company regarding specific retention periods for data types.

Automated Decision Making

The company does not use personal data for automated decisions with legal consequences.

Whom Do I Contact if I Have Any Privacy Questions?

Contact [email protected] for concerns, queries, or questions regarding this policy.

Updates to This Policy

The policy may be amended. Changes are made available through updates; users should review regularly for modifications.