Phoenix
Phoenix-App Privacy Policy

Overview

Phoenix-App ("we," "our," or "us") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, process, and safeguard your information when you use our services, in compliance with applicable data protection laws including the EU General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), Brazil's LGPD, Canada's PIPEDA, and other international privacy regulations.

Effective Date: 1/3/2026

Last Updated: 1/3/2026

Data Controller Information

Data Controller: Galattic Cyberspace Ltd.

Contact Email: info@phoenix-app.io

Data Protection Officer: info@phoenix-app.io

Contact Us About Privacy

Use this form to contact us about privacy matters.

Legal Basis for Processing (GDPR Article 6)

We process your personal data based on the following legal grounds:

  • Consent: You have given clear consent for processing your personal data for specific purposes
  • Contract: Processing is necessary for the performance of a contract with you
  • Legal Obligation: Processing is necessary for compliance with legal obligations
  • Vital Interests: Processing is necessary to protect vital interests
  • Legitimate Interests: Processing is necessary for legitimate interests pursued by us or third parties

Data Retention and Deletion

We retain personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, comply with legal obligations, resolve disputes, and enforce our agreements. Specific retention periods:

  • Account Data: Retained while your account is active and up to 3 years after account closure
  • Transaction Records: Retained for 7 years for tax and accounting purposes
  • Marketing Data: Retained until you withdraw consent or for 3 years of inactivity
  • Analytics Data: Aggregated data retained for 2 years; personal identifiers removed after 12 months
  • Legal Claims: Data may be retained longer if required for legal proceedings

Types of Personal Data We Collect

Information You Provide Directly

  • Account Information: Name, email address, phone number, company details
  • Profile Data: Profile picture, bio, preferences, settings
  • Communication Data: Messages, support tickets, feedback
  • Payment Information: Billing address, payment method details (processed by third-party providers)
  • Verification Data: Identity verification documents when required

Information We Collect Automatically

  • Device Information: IP address, device type, browser type, operating system
  • Usage Data: Pages visited, features used, time spent, click patterns
  • Location Data: General geographic location based on IP address
  • Cookies and Tracking: Session cookies, preference cookies, analytics cookies
  • Performance Data: Error logs, performance metrics, crash reports

Information from Third Parties

  • Social Media: Profile information when you connect social accounts
  • Business Partners: Contact information from authorized partners
  • Public Sources: Publicly available information to verify business details

Mode and place of processing the Data

Methods of processing

The Data Controller processes the Data of Users in a proper manner and shall take appropriate security measures to prevent unauthorized access, disclosure, modification, or unauthorized destruction of the Data.

The Data processing is carried out using computers and/or IT enabled tools, following organizational procedures and modes strictly related to the purposes indicated. In addition to the Data Controller, in some cases, the Data may be accessible to certain types of persons in charge, involved with the operation of the site (administration, sales, marketing, legal, system administration) or external parties (such as third-party technical service providers, mail carriers, hosting providers, IT companies, communications agencies) appointed, if necessary, as Data Processors by the Owner. The updated list of these parties may be requested from the Data Controller at any time.

Place

The Data is processed at the Data Controller's operating offices and in any other places where the parties involved with the processing are located. For further information, please contact the Data Controller.

Retention time

Any user's recorded data is kept for the time necessary to provide the service requested by the User or stated by the purposes outlined in the Privacy Policy but not over 12 months.

The use of the collected Data

The Data concerning the User is collected to allow the Owner to provide its services, as well as for the following purposes: Content commenting, Contacting the User, Heat mapping and session recording and Analytics. The Personal Data used for each purpose is outlined in the specific sections of this document.

Detailed information on the processing of Personal Data

Personal Data is collected for the following purposes and using the following services:

Analytics

The services contained in this section enable the Owner to monitor and analyze web traffic and can be used to keep track of User behavior.

Google Analytics (Google Inc.)

Google Analytics is a web analysis service provided by Google Inc. ("Google"). Google utilizes the Data collected to track and examine the use of this Application, to prepare reports on its activities and share them with other Google services. Google may use the Data collected to contextualize and personalize the ads of its own advertising network.

Personal Data collected: Cookies and Usage Data.

Place of processing: United States

Privacy Policy: https://policies.google.com/privacy?hl=en

Opt Out: https://tools.google.com/dlpage/gaoptout?hl=en

Contacting the User

Mailing list or newsletter Phoenix-App

By registering on the mailing list or for the newsletter, the User's email address will be added to the contact list of those who may receive email messages containing information of commercial or promotional nature concerning this Application. Your email address might also be added to this list as a result of signing up to this Application or after making a purchase.

Personal Data collected: email address and first name, comments.

Content commenting

Content commenting services allow Users to make and publish their comments on the contents of this Application. Depending on the settings chosen by the Owner, Users may also leave anonymous comments. If there is an email address among the Personal Data provided by the User, it may be used to send notifications of comments on the same content. Users are responsible for the content of their own comments.

If a content commenting service provided by third parties is installed, it may still collect web traffic data for the pages where the comment service is installed, even when Users do not use the content commenting service.

Comment system managed directly Phoenix-App

This Application has its own internal content comment system.

Personal Data collected: email address and first name.

Heat mapping and session recording

Heat mapping services are used to display the areas of a page where Users most frequently move the mouse or click. This shows where the points of interest are. These services make it possible to monitor and analyze web traffic and keep track of User behavior. Some of these services may record sessions and make them available for later visual playback.

Additional information about Data collection and processing

The User's Personal Data may be used for legal purposes by the Data Controller, in Court or in the stages leading to possible legal action arising from improper use of this Application or the related services. The User declares to be aware that the Data Controller may be required to reveal personal data upon request of public authorities.

Additional information about User's Personal Data

In addition to the information contained in this privacy policy, this Application may provide the User with additional and contextual information concerning particular services or the collection and processing of Personal Data upon request.

System logs and maintenance

For operation and maintenance purposes, this Application and any third-party services may collect files that record interaction with this Application (System logs) use other Personal Data (such as the IP Address) for this purpose.

Information not contained in this policy

More details concerning the collection or processing of Personal Data may be requested from the Data Controller at any time. Please see the contact information at the beginning of this document.

Your Rights and Choices

Universal Rights (Available to All Users)

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate or incomplete data
  • Deletion: Request deletion of your personal data ("right to be forgotten")
  • Opt-out: Unsubscribe from marketing communications at any time
  • Account Control: Update, modify, or delete your account information

Additional Rights (GDPR - EU Residents)

  • Data Portability: Receive your data in a machine-readable format
  • Restriction of Processing: Limit how we process your data
  • Object to Processing: Object to processing based on legitimate interests
  • Withdraw Consent: Withdraw consent at any time where processing is based on consent
  • Complaint Rights: Lodge a complaint with your local supervisory authority

California Rights (CCPA/CPRA)

  • Know: Right to know what personal information is collected, used, shared, or sold
  • Delete: Right to delete personal information
  • Opt-out: Right to opt-out of the sale of personal information
  • Non-discrimination: Right not to receive discriminatory treatment
  • Correction: Right to correct inaccurate personal information

How to Exercise Your Rights

To exercise any of these rights, contact us using the form below:

Exercise Your Data Rights

Use this form to request access, correction, deletion, or other rights regarding your personal data.

We will respond to your request within 30 days (or as required by applicable law). We may need to verify your identity before processing your request.

International Data Transfers

We may transfer your personal data to countries outside your residence country, including countries that may not have the same level of data protection. When we do so, we implement appropriate safeguards:

  • Adequacy Decisions: Transfers to countries deemed adequate by relevant authorities
  • Standard Contractual Clauses: EU-approved contracts for data transfers
  • Binding Corporate Rules: Internal data protection rules for group companies
  • Certification Schemes: Transfers under approved certification mechanisms

For specific information about safeguards in place for your data, contact our Data Protection Officer.

Children's Privacy

Our services are not intended for individuals under 16 years of age (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal data from children under this age.

If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately. If we discover we have collected personal data from a child under the applicable age without parental consent, we will delete such information promptly.

Parental Rights: Parents have the right to review, modify, or delete their child's personal information and to refuse further collection.

Security Measures

We implement comprehensive security measures to protect your personal data:

  • Encryption: Data encrypted in transit and at rest using industry-standard protocols
  • Access Controls: Strict access controls and regular access reviews
  • Security Monitoring: Continuous monitoring for security threats and vulnerabilities
  • Employee Training: Regular security and privacy training for all staff
  • Incident Response: Established procedures for data breach response and notification
  • Third-party Security: Due diligence and contractual requirements for service providers

While we strive to protect your data, no method of transmission or storage is 100% secure. We cannot guarantee absolute security but will notify you of any material breaches as required by law.

Changes to this privacy policy

The Data Controller reserves the right to make changes to this privacy policy at any time by giving notice to its Users on this page. It is strongly recommended to check this page often, referring to the date of the last modification listed at the bottom. If a User objects to any of the changes to the Policy, the User must cease using this Application and can request that the Data Controller remove the Personal Data. Unless stated otherwise, the then-current privacy policy applies to all Personal Data the Data Controller has about Users.

What is the definition of "cookies"?

The "cookie" is a text file that can be stored in a dedicated space on the hard disk of the device used by the user (eg computer, tablet, smartphone, etc.) when the user visits the online service of Phoenix-App through their browser, and may be subject to user consent. The cookie identifies the device in which the cookie is stored for the entire period of validity or registration of the cookie.

During the visits of the online service of Phoenix-App, the information relating to the navigation data received from the user's device could be stored in "cookies" installed on that device. At the time of the first visit, the user will be informed about the use of cookies with an information contained in a banner. With the continuation of navigation after the display of the banner, the user consents to the use of cookies.

However, you can change the settings relating to cookies at any time. Below is more information about cookies and how to manage the settings related to them.

Types of cookies used

At the time of connection to our Site, except for the user's consent, various cookies may be installed on the user's device, in order to recognize the device used by the user for the duration of the validity period of cookies. Phoenix-App uses cookies for the following purposes, except for the user's consent:

  • compiling statistics, monitoring traffic volumes and measuring the use of the various sections of the Website (eg titles and content visited, click flows), in order to improve the efficiency and usability of the Phoenix-App services;
  • compute the total number of advertisements shown in the appropriate advertising spaces, identify the same and the number of their views, identify the number of users who click on each of them, and, when possible, the subsequent actions carried out by users on these pages in order to calculate the compensation due to commercial partners (eg communication and advertising agencies, websites, etc.), for statistical analysis purposes;
  • customize the presentation of the Site to the display settings of the user's device (language, screen resolution, operating system, etc.) during the visit of the same, based on the hardware, software, video software of that device;
  • personalize advertising space to the user's device display settings (language, screen resolution, operating system, etc.), based on the hardware, software, video software of that device;
  • in the event that the user has provided personal data, including contact details, and has chosen to accept cookies at the time of registration or access to services, the navigation data acquired through cookies may be linked to the data user's personal data, for the purpose of sending advertising materials, or to show personalized advertisements on the user's device in the advertising spaces that use our cookies. These are advertising messages specifically intended for the user and which could be of interest to the user;
  • keep the information contained in the forms filled out on the Website and the information relating to certain products or services selected through the Site (eg services to which the user has registered, contents of the cart, etc.);
  • allow access to reserved and personalized areas, e.g. the account, based on username, password and other data to which the user has previously given access to Phoenix-App;
  • implement security measures (for example, which allow the registered user to be recognized during subsequent visits after a certain period of time, by requesting to login again).

Cookies related to the integration of third-party applications

Phoenix-App may include third-party software applications on the Site, which allow the user to share the content of the Site with other users or to inform other users about the visit or opinion related to that content. This is the case, in particular, of the "Share" and "Like" buttons on social networks (like Facebook, Twitter, etc.).

The social networks that provide these buttons may use them to identify the user, even if the user has not clicked them while visiting the site. In fact, this kind of buttons could allow the social network to track the navigation on the site, simply because the user has logged in to their account on the social network from their device (so-called open session) during the visit to the Site.

Phoenix-App has no control over the processes used by social networks to collect information about the site visit by the user or other related personal data. Please consult the personal data protection policies of these social networks in order to understand the purposes for which the collection of browsing data takes place through the aforementioned buttons, especially with regard to advertising purposes. Social network policies must allow you to exercise your personal choices through account settings.

Definitions and legal references

Personal Data (or Data)

Any information regarding a natural person, a legal person, an institution or an association, which is, or can be, identified, even indirectly, by reference to any other information, including a personal identification number.

Usage Data

Information collected automatically through this Application (or third-party services employed in this Application), which can include: the IP addresses or domain names of the computers utilized by the Users who use this Application, the URI addresses (Uniform Resource Identifier), the time of the request, the method utilized to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the server's answer (successful outcome, error, etc.), the country of origin, the features of the browser and the operating system utilized by the User, the various time details per visit (e.g., the time spent on each page within the Application) and the details about the path followed within the Application with special reference to the sequence of pages visited, and other parameters about the device operating system and/or the User's IT environment.

User

The individual using this Application, which must coincide with or be authorized by the Data Subject, to whom the Personal Data refers.

Data Subject

The legal or natural person to whom the Personal Data refers.

Data Processor (or Data Supervisor)

The natural person, legal person, public administration or any other body, association or organization authorized by the Data Controller to process the Personal Data in compliance with this privacy policy.

Data Controller (or Owner)

The natural person, legal person, public administration or any other body, association or organization with the right, also jointly with another Data Controller, to make decisions regarding the purposes, and the methods of processing of Personal Data and the means used, including the security measures concerning the operation and use of this Application. The Data Controller, unless otherwise specified, is the Owner of this Application.

This Application

The means by which the Personal Data of the User is collected and processed.

Cookies

Small sets of data stored in the User's device.

Legal information

Notice to European Users: this privacy statement has been prepared in fulfillment of the obligations under Art. 10 of EC Directive n. 95/46/EC, and under the provisions of Directive 2002/58/EC, as revised by Directive 2009/136/EC, on the subject of Cookies. This privacy policy relates solely to this Application.