01
Who we are
Bucepha is a vehicle intelligence platform for professional automotive businesses. Our services include a web application, browser extension, application programming interfaces, websites, analytical tools, and related services.
The Services assist professional vehicle buyers in reviewing information associated with vehicle listings, and may generate condition assessments, repair estimates, opportunity scores, and other analytical outputs.
Bucepha is primarily a business-to-business service. It is not directed toward consumers for personal, household, or recreational use. Information processed through the Services may relate to:
- dealership employees, owners, and managers
- vehicle buyers and other authorized business users
- business contact persons and account administrators
- individuals whose information may incidentally appear within information submitted to or processed through the Services
For any privacy question, write to bucephateam@gmail.com
02
Scope of this policy
This policy applies to information processed through the Bucepha website, web application, browser extension, and API, and to account registration, authentication, customer support, subscription and billing administration, vehicle analysis, service communications, and security and fraud-prevention systems.
It does not govern third parties that operate independently of Bucepha, including vehicle auction and listing websites, sites reached through links inside listings, payment providers, authentication providers, hosting and infrastructure providers, analytics providers, email providers, and third-party AI providers. Those parties process information under their own terms and privacy policies.
03
Definitions
- Account: an account registered to access the Services.
- Authorized User: an individual authorized by a customer to access or use the Services.
- Customer: the dealership, company, or other business entity that subscribes to or uses the Services.
- Customer Data: information submitted to or processed through the Services on behalf of a Customer.
- Personal Information: information that identifies, relates to, describes, or could reasonably be linked to an identifiable individual, to the extent treated as personal information under applicable law.
- Vehicle Data: information relating to a vehicle, vehicle listing, VIN, photographs, mileage, bidding activity, auction announcements, listing descriptions, and related information.
- Analysis: an analytical output generated by the Services.
04
What we collect
We collect information necessary to provide, maintain, secure, administer, and improve the Services. What we collect depends on how you interact with Bucepha.
Account information
- name
- work email address
- dealership or company name
- business role and job title
- account identifier
- authentication information, with passwords held only in cryptographically protected form
- account status, subscription information, and account history
Third-party authentication
If you authenticate through an identity provider such as Google, that provider may share your name, email address, account identifier, and basic profile information. Bucepha never receives your third-party password.
05
Vehicle and listing data
When an Authorized User requests an Analysis, the Services may process information displayed on the applicable vehicle listing, which may include:
- VIN, make, model, model year, and trim
- title status, odometer reading, and mileage
- auction announcements and listing descriptions
- current bid, bidding information, and auction status
- listing identifiers and URLs
- vehicle photographs and photograph URLs
- damage descriptions, seller-provided information, and inspection information
The precise information processed depends on the website, the listing, the browser, and the functionality being used. Bucepha does not represent that any listing contains complete, accurate, current, or reliable information, and is not responsible for information supplied by third parties.
06
Vehicle photographs
When an Analysis is requested, photographs may be transmitted to our systems. We may receive photograph URLs, retrieve and process photographs, store copies, transmit them to designated processing providers, associate them with an Analysis, retain them as part of account history, and delete them under our retention policy.
Photographs are processed to provide the analysis functionality that was requested. We do not use vehicle photographs to build advertising profiles. Photographs taken from third-party listings may contain incidental information unrelated to the vehicle; our processing is limited to what is reasonably necessary to provide the Services.
07
Information about other individuals
Listings occasionally contain information about people other than the Authorized User: a seller or employee name, contact details, handwriting visible in a photograph, or other incidental information. We do not seek to collect unnecessary personal information about individuals appearing incidentally in listings.
If you submit information relating to another individual, you confirm that you are authorized to do so and that the submission does not violate applicable law or that individual’s rights.
08
Usage, technical and security data
We automatically collect information generated through use of the Services, including IP address, browser and operating system information, application and extension version, request timestamps, session information, referring URL, screens accessed, feature usage, error and diagnostic information, authentication and security events, API request information, response status codes, account activity, and credit usage.
Our infrastructure also generates server and security logs. We use this information to prevent unauthorized access, investigate abuse, detect attacks, troubleshoot outages, investigate security incidents, enforce account restrictions, maintain system integrity, and comply with legal obligations. We do not treat logs as a mechanism for selling or renting customer information.
09
What the browser extension can and cannot see
The extension operates on supported websites identified in its manifest and configuration. When activated on a supported listing, it may access vehicle and listing information, bid information, descriptions, image URLs, and photographs necessary to perform an Analysis, and transmits that information to our systems when the functionality is requested.
The extension is not a general-purpose browsing surveillance tool. Subject to the permissions imposed by the browser platform, we do not use it to:
- record general browsing history
- monitor unrelated websites or browser tabs
- collect passwords, payment-card numbers, or unrelated form entries
- read private communications
- build advertising profiles or track users across unrelated sites
- continuously transmit browsing activity to Bucepha
Browser extensions necessarily operate using platform permissions, and those permissions may allow more access than the extension actually uses. The technical scope of a permission does not mean we collect everything it could reach. Review the permissions shown by the extension store before installing.
10
Session information and local storage
The Services use browser storage to maintain authentication sessions and remember preferences. This may include session storage, local storage, cookies, and similar mechanisms, used to keep you signed in, preserve interface preferences, remember extension panel positioning, and retain locally configured repair-cost adjustments.
Where a session token is held in browser session storage, it is intended to last only for that browser session and is not written to persistent disk storage by Bucepha. Browser and operating-system security is outside our control.
11
The install identifier, and the one thing it does
The browser extension stores a random identifier in its own extension storage the first time it runs. It is generated on your device, it is not derived from anything about you or your machine, and it identifies a browser profile rather than a person.
What it is for. The free month is offered once. When the extension asks our API for a trial it sends this identifier, and the API refuses a second free month to an identifier that has already had one, and says plainly that the trial was already used rather than failing without explanation. It decides that and nothing else: it never decides whether an account exists, whether you can sign in, or whether you can pay.
What we store. On our side we keep the identifier, the dealership it was first seen with, and when. We do not use it to build a profile, to link your activity across sites, or for advertising, and we do not share it. It is not used for analytics.
How long. The record is kept while the dealership account exists and is deleted with it. In your browser the identifier lives in the extension's storage: it survives signing out, because signing out is the obvious way to ask for a second free month, and it does not survive uninstalling the extension or clearing its storage.
If extension storage is unavailable the identifier is simply not sent, and a trial is still granted. Nothing about the Service stops working without it.
Two more checks at sign-up, and what they keep. The free month is also withheld when a second dealership signs up from the same network address within an hour of one being granted, and when the email address is on a throwaway mail domain. For the first, we do not store the network address: we store a keyed hash of it (a one-way code computed with a secret held on our server), we read it for this one rule and nothing else, and it stops being read after an hour and is erased by a sweep that runs daily. For the second, the domain is compared against a short list and nothing is stored. When either rule applies, the account is created and works; only the free month is withheld, and the screen says which rule applied and how to continue.
The website does not set an identifier of this kind. This one belongs to the extension.
12
How we use information
Providing the Services
To perform requested analyses, generate outputs, display history, manage accounts and credit balances, authenticate users, operate APIs, and provide support.
Security
To detect unauthorized access and fraud, investigate suspicious activity, enforce security controls, and protect our infrastructure, Customers, and Authorized Users.
Administration
To administer subscriptions, process invoices, maintain billing records, and send transactional messages such as password resets and service notices.
Legal compliance
To comply with applicable law, respond to lawful requests, establish or defend legal claims, and protect persons or property.
Service improvement
We use aggregated, statistical or de-identified information to understand feature usage, system performance, analysis volume, reliability, and error patterns. We do not use Customer Data to build advertising profiles for third parties.
13
What we do not do
- We do not sell Personal Information for money.
- We do not rent Customer Data to advertisers.
- We do not sell vehicle-analysis history to other dealerships.
- We do not disclose one Customer’s analysis history to another Customer.
- We do not use purchasing activity to advertise to other dealerships.
- We do not use the extension to build a general browsing-history profile.
- We do not knowingly use passwords, payment-card numbers, or unrelated private communications for vehicle analysis.
None of this prevents us from processing information as necessary to provide the Services, through service providers, as required by law, to protect rights or security, in connection with a corporate transaction, in aggregated or de-identified form, or with your consent.
14
AI processing
We use automated technologies, including machine-learning systems, to analyze vehicle photographs and listing information. Photographs may be processed using third-party vision-model infrastructure, currently including the OpenAI API.
Information sent for AI processing may include photographs, listing context, VIN or other identifiers, mileage, and other information reasonably necessary to generate the Analysis. Credentials, passwords, payment-card numbers, and unrelated account information are not intended to be transmitted for vehicle analysis.
Third-party AI providers process information under the agreements, security controls, and configuration applicable to our use of their services, and may process it in jurisdictions other than your own. We may change providers, models, or processing architecture over time, and will update this policy where a material change requires it.
15
AI outputs are estimates, not facts
The Services generate damage assessments, repair estimates, condition assessments, opportunity scores, risk indicators and classifications. AI systems make mistakes. An Analysis may be incomplete or incorrect, affected by photograph quality, lighting, camera angle or compression, unable to identify hidden damage or mechanical problems, or based on incomplete listing information.
An Analysis is decision-support information. It is not a mechanical or physical inspection, a professional appraisal, a safety certification, a warranty, or a guarantee of condition, repair cost, resale value, profitability, or auction outcome. It is not a substitute for professional inspection or independent diligence.
Repair estimates
Actual repair costs vary with location, labor rates, parts availability, OEM versus aftermarket parts, hidden damage, mechanical condition, damage discovered during repair, the repair facility, market conditions, vehicle configuration and history, and manufacturer requirements. We do not guarantee that an estimate will match the amount ultimately required.
Opportunity scores
An opportunity score is not investment or financial advice, a purchase recommendation, an appraisal, a valuation, or a prediction of profit. A high score does not guarantee a vehicle will be profitable, and a low score does not guarantee it will not be. Purchasing decisions remain yours.
16
Third-party listing data and your responsibility
We rely on information made available by third-party websites, which may change without notice. A site may modify or remove a listing, change photographs or bids, restrict access, change its architecture or terms, experience an outage, or provide incomplete information. We do not guarantee the continued availability of any third-party listing or data source.
You are responsible for complying with the terms and rules of the websites and platforms you access through the Services. Bucepha does not grant permission to violate any third-party website’s terms, and is not responsible for changes to those terms, suspension or termination of your third-party account, restrictions imposed by an auction platform, or third-party enforcement actions.
17
Customer data and business customers
Customers are responsible for the information they submit. By submitting information you confirm you have the rights, permissions, authority, and lawful basis to do so. Customers should not submit passwords, payment-card numbers, government identification numbers, highly sensitive personal information, or other information unnecessary for the Services.
Depending on applicable law and the contractual relationship, Bucepha may act as a service provider, processor, contractor, or independent controller with respect to particular categories of information.
Where an account belongs to a dealership or other organization, administrators may manage users and access, view account activity, administer subscriptions and credits, and access analyses associated with that organization. If you use Bucepha through an employer, your organization may have access to information associated with your use of the Services. Bucepha is not responsible for a Customer’s internal privacy practices or access-control decisions.
19
Payment information
Payments are processed by Stripe or another processor we designate. Bucepha does not intentionally receive or store complete payment-card numbers. We may receive customer, subscription and invoice identifiers, payment and billing status, and transaction references. Payment processors independently collect and process payment information under their own policies.
20
Legal disclosures and business transfers
We may disclose information where we reasonably believe it is necessary to comply with law, a subpoena, a court order or a lawful governmental request; to enforce our agreements; to investigate fraud or a security incident; to protect the rights or safety of Bucepha, our Customers, our users or third parties; or to defend legal claims. We may preserve information where reasonably necessary for those purposes. Where legally permitted, we may attempt to notify the affected Customer.
If Bucepha is involved in a merger, acquisition, financing, reorganization, sale of assets, bankruptcy or similar transaction, information may be transferred as part of that transaction. Any successor may be required to honor applicable privacy obligations, and we will give notice where required by law.
21
Aggregated and de-identified information
We may create aggregated, anonymized or de-identified information, such as usage statistics, average analysis volumes, average photographs per listing, system performance statistics, and generalized analysis statistics. To the extent permitted by law we may use and disclose such information without restriction, maintaining de-identification safeguards where the law requires them.
23
Security
We use reasonable administrative, technical and organizational safeguards designed to protect information against unauthorized access, destruction, alteration, disclosure or loss.
- Encryption in transit. Connections use modern transport-layer encryption; plain HTTP is not accepted for normal application traffic.
- Encryption at rest, where supported by our infrastructure providers.
- Password protection. Passwords are never stored in readable plaintext and are processed using salted cryptographic hashing. Our personnel have no ordinary access to your password in readable form, and account recovery replaces a lost password rather than revealing it.
- Access control. Production access is limited according to operational requirement.
- Credential protection. Sensitive infrastructure credentials remain on server-side systems and are not exposed through the browser or extension.
- Tenant isolation. Customer data is logically isolated so requests are scoped to the authenticated account or organization.
- Monitoring. We monitor infrastructure and application activity for security events, abuse and operational problems.
We may use automated systems to identify unusual login activity, detect abnormal API behaviour and suspicious requests, enforce rate limits, block malicious traffic, and suspend suspicious sessions. Automated controls occasionally produce false positives, which we will investigate and correct where appropriate.
No security guarantee
No method of transmission over the internet and no method of electronic storage is completely secure. We cannot guarantee that information will never be accessed without authorization, that systems will never be compromised, or that third-party infrastructure will never experience an incident. You are responsible for keeping your credentials confidential and for notifying us promptly of suspected unauthorized access.
You are responsible for the security of your own devices, browser, email account and network, and for activity under your Account that results from a credential you disclosed or failed to protect. To the maximum extent permitted by law, we are not responsible for unauthorized access to information that results from your acts or omissions, from a compromise of a third-party service outside our control, or from circumvention of our controls by criminal acts, and our liability for any security incident is subject to the limitations in our terms of service.
Payment card data
We never receive, see or store your full card number or security code. Card details are entered on pages operated by our payment processor, Stripe, and held by it. What we do receive is described in the payment information section below.
Security incidents
If we determine that a security incident has occurred involving information for which notification is legally required, we will provide the notices required by law, by email, through the application or website, or through a Customer where the Customer is responsible for notifying affected individuals.
24
Data retention
We retain information only as long as reasonably necessary for the purposes described here, unless a longer period is required or permitted by law.
- Account information is generally retained while the account is active. After closure we may retain certain account information for up to 90 days to allow restoration, resolve disputes and complete administrative processes.
- Vehicle analyses and photographs are retained while an account is active so that users can access their history. Users may be able to delete individual analyses through the Services.
- Server and security logs are generally retained for up to 90 days, subject to operational, security, legal or investigative requirements.
- Billing and financial records are retained for the period required by tax, accounting and financial-recordkeeping requirements, which may be approximately seven years.
- Information may be retained beyond these periods where necessary to comply with law, establish or defend legal claims, respond to litigation or governmental requests, investigate security incidents, prevent fraud, or enforce agreements.
Deleted information may remain temporarily in encrypted backup and disaster-recovery systems, which are deleted or overwritten on their own lifecycle rather than immediately on request. We will not ordinarily restore deleted information to production except for disaster recovery, security, legal compliance or another legitimate operational purpose.
25
Your privacy rights
Depending on your jurisdiction you may have the right to know whether we process Personal Information; to access it; to obtain information about our processing; to correct inaccuracies; to request deletion; to obtain a copy; to restrict or object to certain processing; to withdraw consent where processing relies on it; and to lodge a complaint with a supervisory authority.
These rights are subject to legal limits. We may decline to delete information where retention is required by law or is reasonably necessary to establish, exercise or defend legal claims, where a request cannot be verified, where fulfilling it would adversely affect another person’s rights, or where it is manifestly unfounded or excessive. Where the law provides an appeal right, we will explain the appeal process.
California
California residents may have rights to know or access categories of Personal Information collected, to learn the purposes of collection, to request deletion or correction, to obtain information about disclosures, to opt out of certain activities, and to receive equal treatment for exercising those rights. Bucepha does not sell Personal Information for monetary consideration and does not use vehicle-analysis activity for cross-context behavioral advertising.
Other US states
Several US states provide rights of access, correction, deletion, portability, opting out of certain processing, limiting certain uses, and appealing a privacy decision. We respond to valid requests under the law applicable to the requester.
EEA and UK
If you are in the European Economic Area or the United Kingdom you may have rights of access, rectification, erasure, restriction, portability, objection and withdrawal of consent, and the right to complain to your supervisory authority. Where the GDPR or UK GDPR applies we process personal data on the basis of contract, legitimate interests, legal obligation, or consent, as applicable.
International transfers
Bucepha is operated from the United States, and our providers may process information in the United States and elsewhere, so information may be transferred across borders. Where the law requires safeguards, we rely on legally recognized transfer mechanisms such as standard contractual clauses or adequacy decisions.
26
Making a privacy request
To exercise a privacy right, or to request deletion of Personal Information, write to bucephateam@gmail.com
Please include enough information for us to understand who you are, what you are asking for, and how to respond. We may need to verify your identity or authority, and we may require evidence that you are authorized to act on another person’s behalf. We will never ask for your password or payment-card number to verify a request.
We generally aim to respond within 30 days, subject to applicable law and any permitted extension. Where the law sets a different period, that period controls.
You may close your account through the account interface where available, or by contacting us. Closing an account does not immediately delete all information: it may remain for the retention periods described above, and certain records may be kept longer where legally required.
27
Children and third-party links
The Services are intended for professional business use and are not directed toward children under 18. We do not knowingly collect Personal Information from children under 18. If you believe a child has provided us information, contact us and we will investigate as required by law.
The Services may link to third-party websites. A link is not an endorsement, and we are not responsible for third-party privacy practices, security, content, terms, or data collection. Review the privacy policy of any third-party service you use, including any authentication provider.
Some browsers transmit Do Not Track signals. There is no universally accepted standard governing responses to them, so we may not respond to all such signals. We do not use the Services to build advertising profiles from your general browsing activity.
28
Data accuracy and professional judgment
We try to keep account information accurate, but information originating from third-party sources may not be. We do not independently verify every item displayed on a vehicle listing, and we do not guarantee that vehicle information, VIN, mileage, announcements, photographs or listing details are accurate, complete, current or unmodified.
The Services assist professional buyers; they do not replace professional judgment. Where appropriate, consider physical and mechanical inspections, vehicle-history reports, title records, manufacturer information, repair professionals, auction documentation, independent appraisals, and photographs not processed by Bucepha.
Bucepha is not a party to any vehicle transaction. We do not sell, buy, own, or guarantee vehicles, sellers, auctions, bids, title, condition, or profitability. Any purchase, sale, bid, financing arrangement or repair decision is solely between the relevant parties, and you remain responsible for evaluating vehicles, verifying information, and making all final decisions.
29
Reporting a security vulnerability
If you believe you have found a security vulnerability affecting Bucepha, write to bucephateam@gmail.com
We encourage responsible disclosure. Please provide enough information for us to reproduce and investigate the issue, and please do not publicly disclose an unremediated vulnerability where doing so could expose Bucepha, our Customers or our users to unnecessary risk. We will make reasonable efforts to acknowledge and investigate legitimate reports.
30
Changes to this policy
We may update this policy as the Services, technology, vendors, legal requirements, AI systems or extension functionality change. When we do, we will update the date shown at the top. Where a material change legally requires notice, we may notify you by email, in the application, on the website, or by another permitted method.
This policy should be read together with our Terms of Service and any applicable customer agreement. Where a separate written agreement governs the processing of Customer Data, that agreement controls to the extent permitted by law. Nothing here waives a right that cannot lawfully be waived, and where applicable law provides greater rights, that law controls. If any provision is held unenforceable, the remainder continues in effect.
31
Our approach, in plain terms
We process information because it is necessary to make the product work, not because your data is the product. The information required to analyze a vehicle is used to provide that analysis. Account information operates the account. Billing information administers payment. Technical information operates and secures the platform.
We do not sell Customer analysis history to competing dealerships, we do not turn your vehicle-buying activity into an advertising profile, and we do not use the browser extension as a general-purpose browsing tracker. At the same time, we are a technology platform that depends on hosting, AI, payment, storage and communications providers, and those providers necessarily process information on our behalf.
Bucepha is a software and information service. It is not a vehicle inspection company, repair facility, auction house, dealership, appraisal company, insurer, or mechanical certification provider.
Questions about this policy: bucephateam@gmail.com
32
Categories of information, at a glance
This table summarises what we process, why, and who it reaches. The sections above and below give the detail.
| Category | Why we process it | Who it reaches | How long |
|---|---|---|---|
| Account and contact details | To create and operate your account, authenticate you and provide support | Hosting, database and email providers | While the account is active, then up to 90 days |
| Authentication data | To sign you in and keep a session valid | Hosting and identity providers | Passwords as hashes while active; sessions expire |
| Vehicle listing data | To perform the analysis you requested | Hosting, database and model providers | While the account is active |
| Vehicle photographs | To detect visible damage and price the repair | Hosting, storage and model providers | While the account is active, or until deleted |
| Analyses and estimates | To return results and keep your history | Hosting and database providers | While the account is active, or until deleted |
| Billing records | To take payment, grant credits, apply referral rewards and meet accounting obligations | Payment processor, accounting advisors | As tax and accounting law requires |
| Sign-up network address, as a keyed hash | To refuse a second free month from one network within an hour | Hosting and database providers | Read for an hour, erased by a daily sweep |
| Install identifier | To offer the free month once per browser, and to say when it was already used | Hosting and database providers | While the dealership account exists |
| Technical and security logs | To operate the service, prevent abuse and investigate incidents | Hosting and monitoring providers | About 90 days, longer if under investigation |
| Support correspondence | To answer your question and keep a record of it | Email provider | While needed, then on a routine cycle |
We do not process special categories of personal data, government identification numbers, biometric identifiers or payment card numbers. The Service is not designed for them and they must not be submitted to it.
33
Legal bases, by purpose
Where the GDPR or UK GDPR applies, we rely on the following bases. Where another law applies, we process on the basis that law provides.
| Purpose | Legal basis |
|---|---|
| Creating and operating your account | Performance of a contract |
| Performing a requested analysis | Performance of a contract |
| Taking payment and issuing invoices | Performance of a contract, and legal obligation |
| Refusing a repeated free month from one network or a throwaway mail domain | Legitimate interests in offering a free trial once without it being taken repeatedly |
| Offering the free month once per browser | Legitimate interests in offering a free trial once without it being taken repeatedly |
| Securing the service and preventing fraud | Legitimate interests in protecting our users and infrastructure |
| Improving reliability using aggregated data | Legitimate interests in operating a functioning service |
| Responding to lawful requests | Legal obligation |
| Optional marketing communications | Consent, withdrawable at any time |
Where we rely on legitimate interests, we have considered whether those interests are overridden by the rights of the individuals concerned, and we will provide further information about that assessment on request.
34
Our role, and yours
Where a dealership uses the Service, the dealership decides what to submit and why. In the language of data protection law, the dealership is generally the controller of the Customer Data it submits, and we act as a processor or service provider acting on its documented instructions.
We act as a controller in our own right for a narrower set of processing: operating and securing the platform, administering accounts and billing, meeting our own legal obligations, and improving the Service using aggregated or de-identified data.
The dealership is responsible for the lawfulness of the data it submits, for providing any notice its own staff require, and for its internal access decisions. Where a data processing agreement is required, we will enter into one.
35
Processor commitments
When we act as a processor for Customer Data, we commit to the following, subject to any separate written agreement between us:
- We process Customer Data only on documented instructions, including for international transfers, unless legally required otherwise, in which case we will inform you unless the law forbids it.
- Personnel authorised to process Customer Data are bound by confidentiality obligations.
- We implement appropriate technical and organisational measures, and will describe them on request.
- We will not engage a new subprocessor for Customer Data without making information about it available, and where the law requires, giving you an opportunity to object.
- We assist you, so far as reasonably possible, with responding to individual rights requests and with your own security and impact assessment obligations.
- We notify you without undue delay after becoming aware of a personal data breach affecting Customer Data.
- On termination we delete or return Customer Data in accordance with the retention section, except where storage is required by law.
36
International transfers, in detail
We operate from the United States, and our providers process data in the United States and other jurisdictions. Where personal data is transferred out of the European Economic Area, the United Kingdom or Switzerland, we rely on a lawful transfer mechanism.
- Standard contractual clauses approved by the European Commission, with the UK addendum where the UK GDPR applies.
- An adequacy decision, where one covers the destination.
- Another mechanism permitted by applicable law.
We take account of the circumstances of each transfer, including the legal regime of the destination and the technical measures protecting the data in transit and at rest. You may request further information about the mechanism applicable to a specific provider.
37
Automated processing and human involvement
The Service uses automated systems to produce condition findings, repair estimates and opportunity scores about vehicles. Those outputs are about vehicles, not about people, and they are decision support for a professional buyer rather than an automated decision producing a legal or similarly significant effect on an individual.
No purchasing decision is taken automatically. A person reviews the analysis and decides. Where an automated control affects an account, such as a rate limit or a security suspension, a person reviews the case on request.
38
If something goes wrong
If we determine that a personal data breach has occurred, we will act on the timelines applicable law sets.
- Where we act as a processor, we notify the affected customer without undue delay after becoming aware, with the information available to us, and we supplement it as the investigation progresses.
- Where we act as a controller and the breach is likely to result in a risk to individuals, we notify the relevant supervisory authority within the period the law requires, generally 72 hours where the GDPR applies.
- Where a breach is likely to result in a high risk to individuals, we notify those individuals as the law requires.
A notice will describe, so far as we know it, what happened, the categories and approximate number of records affected, the likely consequences, and the measures taken or proposed. We will not delay a notice in order to make it complete.
39
How we decide retention periods
Where this policy gives a specific period, that period applies. Where it does not, we decide by reference to:
- how long the data is needed to provide the Service you asked for
- whether a law requires us to keep it, and for how long
- whether it is needed to establish, exercise or defend a legal claim
- whether it is needed to investigate or prevent fraud or a security incident
- the sensitivity of the data and the risk of keeping it longer than necessary
When none of those apply, the data is deleted or de-identified on its ordinary cycle.
40
Precedence and interpretation
This policy should be read with our terms of service and any separate written agreement. Where a negotiated data processing agreement conflicts with this policy in respect of Customer Data, that agreement controls to the extent permitted by law.
This policy is a statement of our practices. It is not a contract, and it does not create rights enforceable by any third party except where applicable law provides them. Disputes about it are resolved under the dispute resolution terms in our terms of service.
Nothing in this policy is intended to waive a right that cannot lawfully be waived, or to limit a protection applicable law gives you. Where applicable law provides greater rights than this policy describes, that law controls. If any provision is held unenforceable, the remainder continues in effect.
Questions, or a request to exercise a right: bucephateam@gmail.com