Privacy Policy

Last updated: December 2025

Introduction

Escalet ("we," "our," or "us") is committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website, services, and applications (collectively, the "Services").

This Privacy Policy complies with the EU General Data Protection Regulation (GDPR), the ePrivacy Directive, and other applicable data protection laws. We are the data controller responsible for your personal data.

Please read this Privacy Policy carefully. By using our Services, you consent to the data practices described in this policy.

1. Information We Collect

1.1 Personal Data You Provide

We collect personal data that you voluntarily provide when you:

  • Register an Account: Name, email address, password, company name, phone number
  • Use Our Services: Profile information, venue details, payment information, uploaded content
  • Contact Us: Name, email address, subject, message content
  • Subscribe to Newsletter: Email address, preferences
  • Participate in Surveys: Responses and feedback

1.2 Automatically Collected Data

When you access our Services, we automatically collect certain information:

  • Device Information: IP address, browser type, operating system, device identifiers
  • Usage Data: Pages visited, time spent, clicks, features used, access times
  • Location Data: Approximate location based on IP address
  • Cookies and Tracking Technologies: See Section 8 for details

1.3 Data from Third Parties

We may receive information about you from third-party sources:

  • Social Media Login: Profile information when you sign in with Google, Facebook, etc.
  • Payment Processors: Transaction confirmation and payment status
  • Analytics Providers: Aggregated usage statistics

2. Legal Basis for Processing (GDPR)

Under GDPR, we process your personal data based on the following legal grounds:

  • Contract Performance: Processing necessary to provide our Services to you (Art. 6(1)(b) GDPR)
  • Legitimate Interests: For improving our Services, fraud prevention, and security (Art. 6(1)(f) GDPR)
  • Consent: For marketing communications and non-essential cookies (Art. 6(1)(a) GDPR)
  • Legal Obligation: To comply with legal requirements and regulations (Art. 6(1)(c) GDPR)

3. How We Use Your Information

We use your personal data for the following purposes:

3.1 Service Delivery

  • Create and manage your account
  • Provide access to our Services and features
  • Process payments and transactions
  • Send service-related communications (account verification, updates, technical notices)
  • Provide customer support

3.2 Service Improvement

  • Analyze usage patterns and trends
  • Conduct research and development
  • Test new features and improvements
  • Monitor and improve performance

3.3 Marketing and Communications

  • Send promotional emails and newsletters (with your consent)
  • Provide personalized recommendations
  • Conduct surveys and gather feedback

3.4 Security and Compliance

  • Detect and prevent fraud, abuse, and security incidents
  • Comply with legal obligations and regulations
  • Enforce our Terms of Service
  • Protect our rights and property

4. Data Sharing and Disclosure

We do not sell your personal data. We may share your information in the following circumstances:

4.1 Service Providers

We share data with third-party service providers who perform services on our behalf:

  • Cloud Hosting: Third-party cloud infrastructure providers for data storage and authentication
  • Payment Processing: Stripe
  • Email Services: Resend
  • Analytics: Google Analytics (with anonymization)

All service providers are bound by data processing agreements and are required to protect your data in accordance with GDPR standards.

4.2 Legal Requirements

We may disclose your information if required by law or in response to:

  • Legal process (subpoenas, court orders)
  • Government or regulatory requests
  • Protection of our rights or safety
  • Investigation of potential violations

4.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity. You will be notified via email and/or prominent notice on our Services of any such change in ownership.

5. International Data Transfers

Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA), including the United States. These countries may have different data protection laws than your country of residence.

When we transfer data internationally, we ensure appropriate safeguards are in place:

  • Standard Contractual Clauses (SCCs): Approved by the European Commission
  • Adequacy Decisions: Transfers to countries with adequate data protection
  • Data Processing Agreements: With all service providers handling EU data

You have the right to obtain a copy of the safeguards we use for international transfers by contacting us.

6. Your Rights Under GDPR

If you are located in the European Economic Area (EEA), you have the following rights regarding your personal data:

Right of Access (Art. 15)

You can request a copy of your personal data we hold about you.

Right to Rectification (Art. 16)

You can request correction of inaccurate or incomplete personal data.

Right to Erasure / "Right to be Forgotten" (Art. 17)

You can request deletion of your personal data in certain circumstances.

Right to Restriction of Processing (Art. 18)

You can request limitation on how we use your personal data.

Right to Data Portability (Art. 20)

You can request a copy of your data in a structured, machine-readable format.

Right to Object (Art. 21)

You can object to processing based on legitimate interests or for direct marketing.

Right to Withdraw Consent (Art. 7)

You can withdraw consent at any time where we rely on consent for processing.

Right to Lodge a Complaint (Art. 77)

You can file a complaint with your local data protection authority.

How to Exercise Your Rights:
To exercise any of these rights, please contact us at: privacy@escalet.io
We will respond to your request within 30 days as required by GDPR.

7. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:

  • Account Data: For the duration of your account plus 30 days after deletion
  • Transaction Records: 7 years for tax and accounting purposes (legal requirement)
  • Marketing Data: Until you unsubscribe or withdraw consent
  • Analytics Data: Anonymized after 26 months
  • Legal Claims: For the duration of any legal proceedings plus applicable limitation periods

After the retention period, we securely delete or anonymize your personal data.

8. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to collect and store information. Cookies are small text files placed on your device to help us provide and improve our Services.

8.1 Types of Cookies We Use

Essential Cookies (Strictly Necessary)

Required for the Services to function. Cannot be disabled.

  • Authentication and session management
  • Security and fraud prevention

Functional Cookies

Enhance functionality and personalization. Require consent.

  • Remember your preferences and settings
  • Language selection

Analytics Cookies

Help us understand how visitors use our Services. Require consent.

  • Google Analytics (with IP anonymization)
  • Usage statistics and performance monitoring

Marketing Cookies

Used to deliver relevant advertisements. Require consent.

  • Track campaigns and conversions
  • Retargeting and personalized ads

8.2 Managing Cookies

You can control cookies through:

  • Cookie Banner: Manage your preferences when you first visit our site
  • Cookie Settings: Update preferences in your account settings
  • Browser Settings: Most browsers allow you to refuse or delete cookies

Note: Disabling essential cookies may affect the functionality of our Services.

9. Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction:

  • Encryption: Data in transit (TLS/SSL) and at rest (AES-256)
  • Access Controls: Role-based access and authentication
  • Security Monitoring: Continuous monitoring and logging
  • Regular Audits: Security assessments and vulnerability testing
  • Employee Training: Data protection and security awareness
  • Incident Response: Procedures for data breach notification

While we strive to protect your personal data, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security.

10. Children's Privacy

Our Services are not intended for children under the age of 16 (or the applicable age of digital consent in your country). We do not knowingly collect personal data from children under 16.

If we become aware that we have collected personal data from a child under 16 without parental consent, we will take steps to delete that information as soon as possible.

If you are a parent or guardian and believe your child has provided us with personal data, please contact us at privacy@escalet.io.

11. Third-Party Links

Our Services may contain links to third-party websites, services, or applications that are not operated by us. We are not responsible for the privacy practices of these third parties.

We encourage you to review the privacy policies of any third-party sites you visit. This Privacy Policy applies only to information collected by our Services.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by:

  • Posting the updated policy on our website with a new "Last Updated" date
  • Sending you an email notification (for material changes)
  • Displaying a prominent notice on our Services

Your continued use of the Services after any changes constitutes your acceptance of the updated Privacy Policy.

13. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Data Controller: Escalet

Email: privacy@escalet.io

Data Protection Officer: dpo@escalet.io

Address: Islandshøjparken 33, Nivå 2990, Denmark

Supervisory Authority (EU):
You have the right to lodge a complaint with your local data protection authority. For a list of EU data protection authorities, visit: https://edpb.europa.eu/about-edpb/about-edpb/members_en

Your Consent

By using our Services, you acknowledge that you have read and understood this Privacy Policy and consent to the collection, use, and disclosure of your personal data as described herein.