Privacy Policy
Last updated: March 29, 2026
1. Introduction
CFTR ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Cloud service or On-Premise software (collectively, the "Service"). This policy is compliant with the General Data Protection Regulation (GDPR) (EU) 2016/679.
2. Data Controller
The data controller responsible for your personal data is:
CFTR
Contact: yi@yioannou.com
3. Information We Collect
3.1 Information You Provide
- Account registration data: name, email address, company name, password (hashed)
- Billing information: processed through third-party payment providers; we do not store credit card details
- Support communications: emails, messages, and feedback you send us
3.2 Information Collected Automatically (Cloud Only)
- Usage data: features used, test execution counts, session duration
- Technical data: browser type, IP address, operating system
- Agent connection data: agent identifiers, connection timestamps
3.3 On-Premise Installations
On-Premise installations store all data on your own infrastructure. We do not have access to your On-Premise data. The only data transmitted to us is license validation requests (account ID and license key).
4. Legal Basis for Processing (GDPR Article 6)
- Contract performance (Art. 6(1)(b)): Processing necessary to provide the Service you subscribed to
- Legitimate interest (Art. 6(1)(f)): Usage analytics to improve the Service, fraud prevention, security
- Consent (Art. 6(1)(a)): Marketing communications (opt-in only)
- Legal obligation (Art. 6(1)(c)): Tax records, regulatory compliance
5. How We Use Your Information
- To provide, maintain, and improve the Service
- To process your registration and manage your account
- To process payments and send billing-related communications
- To send you technical notices, updates, and security alerts
- To respond to your support requests
- To monitor and analyze usage patterns to improve user experience
- To detect, prevent, and address technical issues and fraud
6. Data Sharing and Disclosure
We do not sell your personal data. We may share data with:
- Service providers: hosting, payment processing, email delivery — bound by data processing agreements
- Legal requirements: when required by law, court order, or governmental authority
- Business transfers: in connection with a merger, acquisition, or sale of assets (you will be notified)
7. International Data Transfers
If your data is transferred outside the European Economic Area (EEA), we ensure adequate protection through Standard Contractual Clauses (SCCs) approved by the European Commission, or other lawful transfer mechanisms under GDPR Chapter V.
8. Data Retention
We retain your personal data for as long as your account is active or as needed to provide you the Service. After account deletion, we retain data for up to 30 days for backup purposes, after which it is permanently deleted. Billing records are retained for up to 7 years as required by tax law.
9. Your Rights Under GDPR
As a data subject, you have the right to:
- Access (Art. 15): Request a copy of your personal data
- Rectification (Art. 16): Correct inaccurate or incomplete data
- Erasure (Art. 17): Request deletion of your data ("right to be forgotten")
- Restriction (Art. 18): Request limitation of processing
- Data portability (Art. 20): Receive your data in a structured, machine-readable format
- Object (Art. 21): Object to processing based on legitimate interest
- Withdraw consent (Art. 7(3)): Withdraw consent at any time where processing is based on consent
To exercise any of these rights, contact us at yi@yioannou.com. We will respond within 30 days.
10. Data Security
We implement appropriate technical and organizational measures to protect your data, including encryption in transit (TLS), encrypted storage, access controls, and regular security assessments. However, no method of transmission or storage is 100% secure.
11. Cookies
Our Cloud service uses essential cookies for session management and authentication. We do not use third-party tracking cookies. The website may use analytics cookies only with your explicit consent.
12. Children's Privacy
The Service is not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 16, we will take steps to delete it promptly.
13. Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority in the EU Member State of your habitual residence, place of work, or place of the alleged infringement.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the Service. Continued use of the Service after changes constitutes acceptance.
15. Contact Us
For any questions about this Privacy Policy or our data practices, contact us at:
yi@yioannou.com