GDPR-Aligned • EU-Hosted (Germany)

Privacy Policy

Your privacy is fundamental to everything we do. Learn how we handle your data following GDPR principles, with your data hosted primarily in the EU and full transparency about your rights.

Last Updated: July 26, 2026
🇩🇪

Your data is hosted in Germany, within the EU

Your primary account and personal data is stored in data centres in Germany, within the European Union. We do not intentionally store personal data outside the EU - though some content may be cached via a global delivery network to keep storefronts fast. Need strict EU-only handling? We can arrange it in writing on request. Our practices follow the principles of the GDPR and German BDSG.

GDPR-Aligned
Built on EU 2016/679
EU Data Hosting
Primary storage in Germany
Export & Deletion
Actioned within one month
Custom Data Controls
In writing, on request

Who We Are & Scope

This Privacy Policy explains how Ecomplify ("we", "us") collects, uses, stores, and protects personal data when you use our platform, website, and related services.

For personal data we process about our own account holders, Ecomplify acts as the "data controller" under the EU General Data Protection Regulation (GDPR).

Where you use our platform to operate your own store, you are the data controller for your customers' data and we act as your "data processor" - governed by our Data Processing Agreement (see below).

This policy follows the principles of the GDPR (Regulation (EU) 2016/679) and the German Federal Data Protection Act (BDSG).

Data Controller & Contact

Ecomplify is a service operated from India under the name "Ecomplify" (business registration in progress). Where we determine the purposes and means of processing your personal data, we act as the data controller.

We provide our services to individuals in the European Union and process their personal data following the principles of the GDPR.

For any privacy or data-protection matter - including exercising your GDPR rights - you can contact us directly at privacy@ecomplify.com. We respond within one month.

As we are established outside the EU, EU/EEA individuals may contact us directly using the details above. We have not appointed a representative in the EU at this time. If we appoint one in the future under Article 27 GDPR, we will publish their contact details in this policy.

Information We Collect

Personal Information: When you sign up for an account, we collect information like your name, email address, and contact details to provide you with our services.

Payment Information: We securely collect payment details when you purchase any of our services through encrypted, PCI-DSS compliant payment processors.

Usage Data: Information about how you interact with Ecomplify, such as the pages you visit, features you use, and performance metrics to improve our platform.

Cookies and Tracking Data: We use strictly-necessary cookies to run the service and, only with your consent, optional cookies to enhance your experience.

We practise data minimisation - we only collect the data we genuinely need to provide and secure the service.

Legal Basis for Processing (Article 6 GDPR)

Performance of a contract (Art. 6(1)(b)): to create your account and deliver the services you have subscribed to.

Legitimate interests (Art. 6(1)(f)): to secure, maintain, and improve our platform, prevent fraud and abuse, and send essential service communications.

Consent (Art. 6(1)(a)): for optional marketing emails and non-essential cookies - which you can withdraw at any time without affecting the lawfulness of prior processing.

Legal obligation (Art. 6(1)(c)): to meet accounting, tax, and other statutory requirements.

How We Use Your Information

Provide and maintain our services with reliability and security.

Process payments and manage subscriptions efficiently and securely.

Improve the functionality and user experience of Ecomplify based on usage patterns.

Communicate with you about updates and important service-related information.

Comply with legal obligations and enforce our terms of service and policies.

Provide customer support and respond to your inquiries promptly.

Where Your Data Is Stored

Your primary account and personal data is stored in data centres located in Germany, within the European Union.

We do not intentionally store personal data outside the EU. However, to deliver fast and reliable storefronts, some content and data may be served through a global content-delivery and caching network and may be temporarily cached on servers outside the EU.

Likewise, if you or a store's customer accesses the service from outside the EU, some data may be processed or cached in that region as an inherent part of delivering the service - this is operational, not a deliberate export of your data.

We prefer to state this transparently rather than promise an absolute guarantee we cannot fully control at the network edge.

If you require strict EU-only data handling or specific localisation controls, contact us and we can agree these in writing and apply the appropriate restrictions to your account.

Sharing Your Information

With trusted sub-processors strictly as needed to deliver our services (e.g., payment processors, EU-based hosting, content-delivery networks). Each is engaged under appropriate confidentiality and data-protection terms.

To comply with legal obligations or in response to lawful requests from public authorities.

In the event of a business transaction such as a merger, acquisition, or sale of assets - with continued protection of your data.

With your explicit consent for specific purposes not covered in this policy.

We never sell your personal data to third parties for marketing purposes.

Data Security & Protection

We implement layered security measures including TLS/SSL encryption in transit, encryption at rest, access controls, and continuous monitoring.

All sensitive data is encrypted using industry-standard protocols, and access is restricted on a least-privilege, need-to-know basis.

We maintain internal security policies, regular reviews, and incident-response procedures aligned with GDPR requirements.

In the unlikely event of a personal data breach, we will notify the competent supervisory authority within 72 hours where required, and affected users without undue delay.

While we take extensive measures to protect your data, no internet-based service can guarantee absolute security.

Data Retention

We retain personal data only for as long as necessary to provide our services and fulfil the purposes described in this policy.

When you close your account, we delete or irreversibly anonymise your personal data within 90 days, unless a longer period is required by law (e.g., tax and accounting obligations).

Backups containing your data are kept within the EU and rotated / purged on a regular schedule.

You can request deletion at any time - see 'Your Rights Under the GDPR' below.

Your Rights Under the GDPR

Right of access (Art. 15): obtain confirmation of, and a copy of, the personal data we hold about you.

Right to rectification (Art. 16): have inaccurate or incomplete data corrected.

Right to erasure / 'right to be forgotten' (Art. 17): request deletion of your personal data.

Right to restriction (Art. 18): limit how we process your data in certain circumstances.

Right to data portability (Art. 20): receive your data in a structured, machine-readable format.

Right to object (Art. 21): object to processing based on legitimate interests or direct marketing.

Right to withdraw consent at any time, where processing is based on consent.

Right to lodge a complaint with your local data protection supervisory authority.

To exercise any of these rights, contact us at privacy@ecomplify.com. We respond within one month, as required by the GDPR.

Cookies

We use strictly-necessary cookies that are required for the platform to function, such as authentication and security.

We may also use cookies to remember your preferences and to understand how the service is used so we can improve it.

You can control, block, or delete cookies through your browser settings at any time, and you can contact us to opt out of non-essential cookies.

Where a cookie-consent banner is shown to you, the choices you make there will govern the optional cookies we set.

Children's Privacy

Our services are intended for businesses and users aged 16 and over.

We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.

Data Processing Agreement (for Merchants)

When you use Ecomplify to run a store, you are the data controller for your customers' personal data and we act as your data processor.

We can provide written data-processing terms - a Data Processing Agreement (DPA) - covering our obligations, the sub-processors we use, and the security measures in place.

To request our DPA or specific data-handling restrictions, contact privacy@ecomplify.com.

Policy Updates

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or service features.

We will notify you of any material changes by posting the new policy on our website and, where appropriate, sending email notifications.

Continued use of our services after policy updates constitutes acceptance of the revised policy.

We encourage you to review this policy periodically to stay informed about how we protect your privacy.

Questions About Your Privacy?

Our privacy team is here to help. Contact us with any questions about how we handle your data or to exercise your privacy rights.

privacy@ecomplify.com