Privacy Policy
Last updated: 29 July 2026
This Privacy Policy explains how Olfigton Technologies Ltd (“Olfigton”, “we”) handles personal data in connection with the Olventa website and service. We act as a data controller for our own website and account data, and as a data processor for the business data our customers manage in the app (see our DPA).
This document is an informational template and does not constitute legal advice. We recommend having it reviewed by qualified legal counsel before you rely on it.
1. Data we collect
- Account data: name, email, organization details you provide.
- Usage data: pages viewed, device and approximate location, via analytics.
- Cookies: set only after you accept, for analytics (Google Analytics 4) and product insights (Microsoft Clarity).
- Payment data: handled by our processor Stripe; we do not store full card details.
- Customer Data: business records you enter in the app, processed on your behalf (see DPA).
2. How we use data and legal bases
We use data to provide and secure the Service, process payments, respond to enquiries, and improve the product. Under UK GDPR our legal bases are: performance of a contract, legitimate interests (product improvement, security), consent (analytics cookies, marketing), and legal obligation.
3. Cookies and analytics
Our site loads analytics only after you accept via the cookie banner; you can decline. Google Consent Mode governs analytics storage. You can withdraw consent by clearing the choice in your browser.
4. Sharing and sub-processors
We share personal data with service providers who help us operate, including: Supabase (hosting/database), Stripe (payments), Google (Analytics), Microsoft (Clarity), and PostHog (product analytics). We do not sell personal data.
5. International transfers
Some providers process data outside the UK/EEA. Where they do, we rely on appropriate safeguards such as the UK IDTA / EU Standard Contractual Clauses.
6. Retention
We keep personal data only as long as needed for the purposes above or as required by law. Customer Data retention is controlled by the customer.
7. Your rights
Under UK GDPR (and, where applicable, Türkiye’s KVKK) you may request access, rectification, erasure, restriction, portability, and object to processing. Contact contact@olfigtontech.com. You may also complain to the UK ICO or your local authority.
8. Security
We use technical and organisational measures including encryption in transit, access controls, and tenant isolation (row-level security) to protect data.
9. Children
The Service is for businesses and is not directed at children under 16.
10. Changes and contact
We may update this policy; material changes will be notified. Controller: Olfigton Technologies Ltd, United Kingdom — contact@olfigtontech.com.