1. Data Controller
Subiq is the data controller responsible for your personal data. For questions or requests regarding your data, contact us at hello@subiq.io.
2. Information We Collect
Information you provide directly:
- Name and email address (at registration)
- Subscription and payment data you enter into the platform
- Communications you send to us (e.g. support requests)
Information collected automatically:
- Device and browser information (e.g. browser type, operating system)
- IP address
- Usage data (e.g. pages visited, features used, timestamps)
- Cookies and similar technologies (see Section 8)
3. How We Use Your Information
We use your personal data to:
- Provide, operate, and maintain the Service
- Manage your account and authenticate your identity
- Send important notifications (e.g. subscription renewals, security alerts, Terms updates)
- Analyze usage patterns to improve the platform
- Respond to your questions and support requests
- Comply with legal obligations
We do not use your data for advertising or profiling purposes.
4. Legal Basis for Processing (GDPR)
We process your data based on the following legal grounds:
| Legal basis | When it applies |
|---|---|
| Contract | Processing necessary to provide the Service to you (Art. 6(1)(b) GDPR) |
| Legitimate interest | Analytics and service improvement, fraud prevention (Art. 6(1)(f) GDPR) |
| Legal obligation | When required by law, e.g. tax or accounting rules (Art. 6(1)(c) GDPR) |
| Consent | Optional cookies and marketing emails, where applicable (Art. 6(1)(a) GDPR) |
5. Data Sharing and Third-Party Services
We do not sell, rent, or trade your personal data.
We use trusted third-party services strictly to operate the platform:
| Provider | Purpose |
|---|---|
| Supabase | Database and authentication |
| Resend | Transactional email delivery |
We may also disclose data if required by law or to protect our legal rights.
6. Data Storage and Transfers
- Your data is stored on servers operated by our infrastructure providers (see Section 5).
- If data is transferred outside the EU/EEA, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission.
7. Data Retention
- We retain your personal data for as long as your account is active and as needed to provide the Service.
- If you delete your account, your data will be permanently removed within 30 days, except where retention is required by law (e.g. accounting records).
- Anonymized and aggregated data may be retained indefinitely for analytics purposes.
8. Cookies
We may use cookies and similar technologies to keep you logged in, remember your preferences, and understand how the Service is used.
| Type | Purpose | Required? |
|---|---|---|
| Essential | Authentication, security, core functionality | Yes |
| Analytics | Usage statistics and service improvement | No (consent-based) |
You can manage cookie preferences through your browser settings. Disabling essential cookies may affect the functionality of the Service.
9. Your Rights
Under the GDPR, you have the right to:
- Access — request a copy of the personal data we hold about you
- Rectification — request correction of inaccurate data
- Erasure — request deletion of your data (“right to be forgotten”)
- Restriction — request that we limit processing of your data
- Data portability — receive your data in a structured, machine-readable format
- Object — object to processing based on legitimate interest
- Withdraw consent — where processing is based on consent, withdraw it at any time
To exercise any of these rights, contact us at hello@subiq.io. We will respond within 30 days.
If you are unsatisfied with our response, you have the right to lodge a complaint with a supervisory authority. In Sweden, this is the Swedish Authority for Privacy Protection (IMY).
10. Security
We take reasonable technical and organizational measures to protect your data, including encryption in transit (TLS) and at rest. However, no system is completely secure, and we cannot guarantee absolute security.
11. Children
The Service is not intended for users under the age of 16. We do not knowingly collect data from children. If we become aware that we have collected data from a child under 16, we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you via email or through the Service. The "Last updated" date at the top reflects the most recent revision.
13. Contact
For privacy-related questions or data requests, contact us at hello@subiq.io.