Privacy Policy (GDPR)
How the Adetio operating entity (to be published before launch) handles personal data for our own website and account holders, in line with the EU General Data Protection Regulation (GDPR). For end users of products built on Adetio, our customer is the controller and we act as processor under our DPA.
1. Who we are
The controller for this policy is the Adetio operating entity (to be published before launch). You can reach our data protection contact at privacy@adetio.eu for any question about your personal data or this policy.
2. The waitlist — the only data we collect today
Adetio is in closed pre-launch, so there are no accounts and no product data yet. The single piece of personal data this site processes is the email address you give us on the waitlist form, stored together with your consent and the date you gave it. We do not record your IP address, your browser, or where you came from. The lawful basis is your consent (Art. 6(1)(a)). The purpose is one message telling you when early access opens — no newsletter, no profiling, and your address is never shared or sold. We keep it until launch or until you ask us to delete it, whichever comes first; email privacy@adetio.eu and it is removed. Withdrawing consent is as easy as giving it.
3. What we will collect once accounts open
When the product opens: name, work email, organisation, authentication metadata (sign-in events, IP, device), and billing details. For website visitors: only the strictly necessary information described in our Cookie Policy. We do not buy personal data or use advertising trackers.
4. Lawful basis
We process account and platform data to perform our contract with you (Art. 6(1)(b)), security and fraud-prevention data under our legitimate interests (Art. 6(1)(f)), and billing records to meet legal obligations (Art. 6(1)(c)). Where we rely on consent, you may withdraw it at any time.
5. Where your data is stored
All personal data is stored and processed within the European Union, in the EU region you choose at setup. We do not transfer personal data outside the EU/EEA in the ordinary course of providing the service.
6. Retention
We keep account data for the life of your account and delete it within 90 days of closure, except records we must retain for legal or tax purposes. Authentication logs follow the retention window of your plan; you can export or erase them sooner.
7. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict, and port your data, and to object to processing based on legitimate interests. Email privacy@adetio.eu and we will respond within one month. You may also lodge a complaint with the competent EU data-protection supervisory authority, or with the supervisory authority of your own member state.
8. Security
We protect personal data with encryption in transit and at rest, least-privilege access, and environment isolation. See our Security page for details and our responsible-disclosure process.