Privacy Policy & Data Statement
Sunllo ("the Service", "we") values the protection of your personal and business data. This statement explains how we collect, use, disclose, store, transfer across borders and protect data, and your rights under applicable data protection law. By using the Service you agree to this statement.
1. Our roles
For data you provide at registration and billing, we act as the party that collects and uses it. For "Customer Content" you create in your workspace that contains third parties' personal data (e.g. your staff, customers, suppliers), you are the data collector and we act as a data processor, processing only per your instructions and as necessary to provide the Service, and not for other purposes.
2. Data we collect
- Account & company data: company name, tax ID, contact, email, phone, country, subdomain.
- Customer Content: business data you create β customers, quotes, invoices, projects, finance, HR and employee records.
- Payment data: payments are processed by providers such as Stripe; we do not store full card numbers, only necessary transaction and subscription status.
- Usage & technical logs: sign-in records, activity logs, IP address, browser and device info, usage metrics (storage, AI tokens, audio duration).
- Cookies & local storage: sign-in sessions, language and theme preferences.
- Support communications: correspondence and support records between you and us.
3. Purposes & legal bases
- Performing the contract: providing and operating the Service, authentication and access control, billing and subscription management.
- Legitimate interests: security, anomaly detection, auditing, usage statistics and service improvement.
- Legal obligations: accounting, tax and statutory retention and cooperation.
- Consent: where consent is legally required (e.g. non-essential communications), based on your consent, which you may withdraw at any time.
4. Cookie policy
We use only essential cookies and local storage needed for sign-in and preferences β not for cross-site advertising tracking β and we do not sell your data. External services on the website (e.g. Cloudflare) may set essential cookies for security and performance. You can manage cookies in your browser, though disabling essential cookies may affect sign-in and some features.
5. Storage & location
- Cloud edition: per-tenant isolated databases; each tenant's data is logically and physically separated and can be independently backed up and exported.
- On-premise edition: all data resides on the customer's own servers and operates offline; we do not access it and it never leaves the customer's environment.
6. Retention periods
- Account and Customer Content: retained during the subscription; permanently removed after you delete the workspace (except where retention is required by law).
- Transaction and invoice records: retained for the period required by accounting and tax law.
- System and security logs: retained for a reasonable period to fulfill security and audit purposes.
7. Security
We protect data with transport-layer encryption (HTTPS), role-based (role Γ feature) access control, secrets stored encrypted in a key vault, tenant database isolation, account lockout and audit logging. No system is perfectly secure, so please safeguard your account and password and set User permissions carefully.
8. Your rights
Under applicable data protection law, you may exercise rights to inquire, review, obtain copies, supplement or correct, request cessation of collection/processing/use, and request deletion of your personal data. You may also request an export of your data. Please contact us and we will respond within a reasonable period; where third-party personal data in your workspace is involved, those individuals should exercise their rights with you (the collector), and we will assist per your instructions.
9. Children's privacy
The Service is a business tool, not designed for or offered to children; we do not knowingly collect children's personal data.
10. Data breach notification
If a personal data incident that may affect your rights occurs, we will, in accordance with applicable law, notify you and (where required) the competent authority by appropriate means within a reasonable period after ascertaining it, describing the scope of impact and remedial measures.
11. Third-party data you upload
When you create content containing personal data of staff, customers or suppliers, you must ensure you have the necessary lawful basis or consent for its collection and processing, and you are responsible for its accuracy and legality.
12. Updates
Updates will be posted on this page with a revised "Last updated" date; we will give additional notice for material changes.
13. Contact
For questions about this statement or data handling, or to exercise your rights, contact: [email protected]