Outsaky Privacy Policy

Version: xx.xx Last Update: xxxx/xx/xx
Email

1. Overview

1.1 Integral Documents

These Privacy Policy is a legal document required by data protection laws (such as the GDPR, LGPD, CCPA/CPRA, and POPIA). It explains, in a transparent and informative manner, how this website processes the user’s personal data, including what data is collected, the purposes of the processing, the storage period, with whom it is shared, and how the user can exercise their rights, such as requesting deletion.

The Terms of use constitute a standard-form contract governing the relationship between this website and the user, establishing rules of conduct, copyright provisions, limitations of liability, and penalties for violations of applicable regulations, among other provisions.

Both are independent legal instruments, yet they are closely interrelated and complementary, establishing the governance and compliance framework for this website.

Please read this Privacy Policy and Terms of use carefully before using our Services. If you do not agree with its terms, please discontinue use of our Services.

1.2 Who We Are

Leonardo Nunes Galvão, operating under the trade name Outsaky – Digital Solutions (“we,” “us,” or “our”), is headquartered in Santos, SP, Brazil.

We operate in accordance with applicable data protection laws, including but not limited to the EU General Data Protection Regulation (GDPR), Brazil’s Lei Geral de Proteção de Dados (LGPD), the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), and other applicable national and regional privacy laws as further detailed in Section 17 (Jurisdiction-Specific Addenda).

We are committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy explains how we collect, use, share, and protect information about you when you use our website(s), products, and services (collectively, the “Services”).

Important — Consent for Data Processing: Your use of our website does not, by itself, constitute consent to the processing of your personal data. Where processing requires your consent — such as for non-essential cookies, analytics, or marketing communications — we will request it separately through an explicit, affirmative action (e.g., our Cookie Preference Center). You may withdraw any consent at any time without penalty. See Section 16 (Consent & Withdrawal).

  • Data Controller: Leonardo Nunes Galvão, operating under the trade name Outsaky – Digital Solutions, Santos, São Paulo, Brazil.
  • Privacy Contact: For any questions, requests, or concerns relating to this Privacy Policy or the processing of your personal data, please contact our Privacy Point of Contact:

As a small-scale data controller, we are not required to formally appoint a Data Protection Officer (DPO) under Art. 37 of the GDPR, the UK GDPR, or equivalent legislation, nor to designate a formal Encarregado under the LGPD (pursuant to ANPD Resolution No. 2/2022). All privacy-related requests are handled directly through the channels described in Section 19.

PLEASE NOTE THAT ALL PRODUCT PURCHASES, LICENSE MANAGEMENT, AND PAYMENT PROCESSING ON OUR WEBSITE ARE CARRIED OUT THROUGH OUR RESELLER AND MERCHANT OF RECORD, FREEMIUS, INC. FOR ALL ACTIVITIES RELATED TO CHECKOUT, PAYMENT PROCESSING, FRAUD PREVENTION, TAX CALCULATION, INVOICING, SUBSCRIPTION MANAGEMENT, CANCELLATIONS, AND REFUNDS, FREEMIUS ACTS AS OUR DATA PROCESSOR (OR “OPERADOR” UNDER THE LGPD), PROCESSING PERSONAL DATA SOLELY ON OUR BEHALF AND UNDER OUR WRITTEN INSTRUCTIONS, IN ACCORDANCE WITH OUR DATA PROCESSING ADDENDUM (DPA). OUTSAKY – DIGITAL SOLUTIONS REMAINS THE SOLE DATA CONTROLLER (OR “CONTROLADOR” UNDER THE LGPD) FOR YOUR PERSONAL DATA, ENTRUSTING FREEMIUS TO SECURELY HANDLE FINANCIAL COMPLIANCE AND TRANSACTIONAL PROCESSING. FOR COMPREHENSIVE DETAILS ON HOW DATA IS SAFEGUARDED, PLEASE ALSO REFER TO FREEMIUS’S PRIVACY POLICY (freemius.com/privacy/).


2. Definitions

For the purposes of this Privacy Policy, the following terms shall have the meanings set forth below:

“Sensitive Data” or “Special Categories of Data” means Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data processed to uniquely identify a person, health data, data concerning sex life or sexual orientation, or any other category designated as sensitive under applicable law.

“Processing” means any operation or set of operations performed on Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, restriction, erasure, or destruction.

“Data Controller” means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of Processing of Personal Data.

“Data Processor” means a natural or legal person, public authority, agency, or other body which processes Personal Data on behalf of the Data Controller.

“Consent” means any freely given, specific, informed, and unambiguous indication of the Data Subject’s agreement to the Processing of their Personal Data, expressed by a statement or by a clear affirmative action.

“Legitimate Interest” means a lawful basis for Processing where it is necessary for the genuine interests of the Data Controller or a third party, provided those interests are not overridden by the rights and freedoms of the Data Subject.

“Data Protection Officer (DPO)” or “Encarregado” means the individual designated by the Data Controller to oversee data protection compliance under applicable law.

“Third Party” means any natural or legal person other than the Data Subject, Data Controller, Data Processor, or persons authorized to process Personal Data under their direct authority.

“Cookies” means small text files placed on your device by websites you visit, used to store and retrieve information about your browsing behavior or preferences. See Section 14 (Cookie Policy) for details.

“Merchant of Record (MoR)””: A third-party financial and legal entity authorized to resell our Apps to end-users. The MoR acts as the direct seller of the software licenses, taking legal responsibility for processing financial transactions, managing global billing compliance, calculating and collecting local sales taxes (such as VAT, GST, or Sales Tax), and issuing the official invoices. While Outsaky remains the sole developer and technical provider of the Apps, the MoR manages the financial and commercial relationship with you during the checkout and billing process.


3. Data We Collect

We process Personal Data through three main channels: (i) information you provide directly to us, (ii) information collected automatically when you use our Services, and (iii) limited information received from third parties.

3.1 Information You Provide Directly

When you create an account, make a purchase, submit a form, or otherwise interact with our Services, we may collect:

  • Identifiers: Full name, username, email address, and communication preferences.
  • Account Credentials: Username, password (stored in encrypted form) and security-related authentication data.
  • Communications: Support tickets, feedback, survey responses, and any messages or attachments you voluntarily send to us.
  • User-Generated Content: Reviews, ratings, comments, or other content you voluntarily submit.

We do not collect or store your payment instrument details, full billing address, tax identification data, or other financial checkout information. All checkout, billing, tax collection, invoicing, fraud checks, subscription management, cancellations, and refunds are handled directly by Freemius, Inc., acting as our reseller and Merchant of Record, under its own Privacy Policy and Terms of Service. After a successful transaction, Freemius may transmit to us only a limited subset of data necessary to deliver and support your license (for example, your name, email address, purchase status, subscription status, and license key status), for which both Freemius and Outsaky act as independent Data Controllers within their respective scopes of processing.

3.2 Information Collected Automatically

When you interact with our Services, some technical data is generated and collected automatically. We strictly separate this collection based on the service used:

  • On our Website (outsaky.com): We collect standard internet log information and technical data when you visit our website. This may include IP address (which may be truncated or otherwise minimized where required by law), device type, operating system, browser type, language settings, and general geographic location derived from IP, as well as basic usage metrics such as pages visited, time spent, navigation paths, and error events. This data is collected via cookies and similar technologies in accordance with the cookie categories described in Section 14 (Cookie Policy) and is used only for the purposes identified in Section 5 (for example, Service Delivery, Security & Fraud Prevention, and Service Improvement & Analytics). Non‑essential cookies (including Analytics and certain Functional cookies) are activated only with your prior consent through our Cookie Preference Center.
  • Within our Apps (WordPress Plugins & Desktop Software): Our Apps do not run silent background tracking, telemetry, or behavioral analysis. The only automatic communication established by our Apps is with the Freemius API servers for the sole purpose of validating your license key, checking for available software updates, or synchronizing account status. This validation transmits basic technical parameters (such as license key, PHP version, App version, and site URL) required to perform the license check.

3.3 Information Received from Third Parties

We may receive limited information about you from third parties in the circumstances described below.

3.3.1 Business Partners & Affiliates: Partners who refer you to our Services or with whom we operate joint offerings.

3.3.2 Social Media Platforms: When you connect a social media account or interact with our social content.

3.3.3 Analytics Providers: To understand how our website and Apps are used and to improve our Services, we collect usage and analytics data. This may include:

  • Pages visited, time spent, navigation paths, and referral sources;
  • App features accessed, error reports, and performance metrics;
  • Device type, operating system, and browser type (non-identifying, aggregated).

Analytics tools currently in use:

Tool
Provider
Purpose
Privacy Policy
[To be defined]
[To be defined]
Website analytics and performance monitoring
[URL — to be defined]

3.3.4 Publicly Available Sources: Business registries, public directories, or other lawfully accessible public records.

3.4 Sensitive / Special Categories of Data

We do not collect Sensitive Data as a standard practice. Where you voluntarily provide such information, or where applicable law permits or requires it in the context of a specific service (e.g., health-related features), we will process it only under explicit consent or another lawful basis, and with enhanced security protections as described in Section 9 (Security Measures).

3.5 Data We Do NOT Collect or Transmit

Consistent with our product philosophy, neither our website nor our Apps collect, store, or transmit to our servers or any third party:

  • Personal data from device sensors or camera/microphone inputs;
  • Sensitive data such as: Racial or ethnic origin, Political opinions, Religious or philosophical beliefs, Trade union membership, Genetic data, Biometric data, Health-related data, Sexual orientation;
  • Keystrokes or keyboard input;
  • Network traffic content or local network paths;
  • Operating system or system application usernames and passwords;
  • SSH keys, encryption keys, or security credentials;
  • The contents of any local files stored on your device or local database credentials.

4. Legal Basis for Processing

All Processing of your Personal Data is grounded in at least one lawful basis as required by applicable law. This section is particularly relevant to users in jurisdictions governed by the GDPR (EU/EEA/UK), LGPD (Brazil), FADP (Switzerland), POPIA (South Africa), DPDP Act (India), PDPA (Thailand/Singapore), and equivalent frameworks.

Legal Basis
Description
Typical Examples
Consent (GDPR Art. 6(1)(a); LGPD Art. 7(I))
You have provided clear, specific, and informed consent. You may withdraw consent at any time — see Section 16.
Marketing emails; non-essential cookies; Sensitive Data.
Contract Performance (GDPR Art. 6(1)(b); LGPD Art. 7(V))
Processing is necessary to fulfill a contract with you, or to take steps at your request before entering into one.
Order processing; account management; service delivery.
Legal Obligation (GDPR Art. 6(1)(c); LGPD Art. 7(II))
Processing is required by a legal or regulatory obligation applicable to us.
Tax reporting; anti-money laundering; court orders.
Vital Interests (GDPR Art. 6(1)(d); LGPD Art. 7(VIII))
Processing is necessary to protect the vital interests of you or another person.
Emergency health or safety situations.
Legitimate Interests (GDPR Art. 6(1)(f); LGPD Art. 7(IX))
Processing is necessary for our genuine interests or those of a third party, where not overridden by your rights and freedoms. We apply this basis only where the processing is necessary, proportionate, and would not reasonably be unexpected by you. You have the right to object at any time — see Section 13.
Fraud prevention; network and systems security; responding to support requests beyond contractual scope; aggregated, non-cookie-based internal analytics.
Public Task / Public Interest (GDPR Art. 6(1)(e))
Processing is necessary for a task in the public interest or in the exercise of official authority.
Applicable in regulated public-service contexts.

CCPA/CPRA Note (California): The CCPA/CPRA does not require a specific legal basis for processing but grants you distinct opt-out and deletion rights. See Section 17.

LGPD Note (Brazil): Brazil’s LGPD provides 10 legal bases (Art. 7), including credit protection and the legitimate interest basis. Our processing activities are aligned with all applicable LGPD hypotheses. See Section 17.


5. Purpose of Processing

We process your Personal Data solely for the purposes identified below, each linked to its lawful basis under Section 4. We will not use your data for purposes incompatible with those listed here without obtaining a new lawful basis or your prior consent.

Purpose
Description
Legal Basis
Service Delivery
Providing, operating, and maintaining the Services, including processing transactions and delivering products.
Contract Performance
Customer Support
Responding to inquiries, resolving disputes, and providing technical assistance.
Contract Performance (primary); Legitimate Interests – specifically, our interest in maintaining the quality and reputation of our Services by resolving issues that arise beyond the strict scope of the license contract.
Account Management
Creating, maintaining, and managing your account, including authentication and account recovery.
Contract Performance
Security & Fraud Prevention
Detecting, preventing, and responding to fraud, abuse, and unauthorized access.
Legal Obligation; Legitimate Interests — specifically, our interest in protecting our systems, our users, and the integrity of our licensing infrastructure from abuse and unauthorized use.
Legal & Regulatory Compliance
Complying with laws, regulations, judicial orders, and governmental requests.
Legal Obligation
Service Improvement & Analytics
Understanding how users interact with our Services to diagnose issues, improve usability, and optimize performance, using minimized technical and usage data.
Consent (for analytics and performance cookies — mandatory for EEA/UK users under the ePrivacy Directive and for Brazilian users under LGPD Art. 7(I)); Legitimate Interests — strictly limited to aggregated, non‑cookie‑based internal metrics (e.g., server‑side error logs and uptime data) that do not involve tracking individual behavior.
Personalization
Remembering your language, region, and display preferences to provide a consistent experience.
Legitimate Interests — specifically, our interest in reducing friction in the user experience by persisting non-sensitive preferences that you have already configured; Consent (where preferences are stored via functional cookies).
Marketing & Communications
Sending promotional offers, newsletters, and updates where you have opted in or where permitted by law.
Consent; Legitimate Interests
Business Operations
Internal purposes such as audits, financial reporting, and organizational management.
Legal Obligation (primary); Legitimate Interests — specifically, our interest in maintaining accurate internal records for operational continuity, tax compliance, and defense of legal claims.
Children’s Data Protection
Ensuring that our Services are not directed to, designed for, or knowingly intended to attract individuals below the applicable age of legal majority. See Section 15 (Children’s Data).
Legal Obligation

LGPD Note: In accordance with guidance from the ANPD (Brazil’s data protection authority), analytics processing based on cookies or similar tracking technologies directed at Brazilian users is grounded exclusively in Consent (LGPD Art. 7(I)). The “Legitimate Interests” basis does not apply to cookie-based analytics for Brazilian residents.


6. Data Sharing

We do not sell your Personal Data. We may, however, share your information with the following categories of recipients under the conditions described below.

6.1 Service Providers, Processors, and Independent Controllers

We engage trusted third parties to operate our business. These third parties fall into two distinct legal categories, which we describe transparently below.

6.1.1 Freemius, Inc. — Merchant of Record (MoR) and Data Processor

Freemius, Inc. (freemius.com) acts as our Merchant of Record (MoR) and primary Data Processor (or Operator under the LGPD) for all software license sales and subsequent licensing operations.

When you complete a purchase through our checkout, Freemius collects and processes your transaction data (such as name, email, purchase history, and subscription details) strictly on our behalf and under our written instructions, pursuant to our Data Processing Addendum (DPA). Leonardo Nunes Galvão, operating as Outsaky – Digital Solutions, remains the sole Data Controller (Controlador) for this information.

Freemius handles the technical and administrative execution of payment processing, global tax compliance, fraud prevention, invoicing, and subscription management as our designated processor. Consequently, while Outsaky does not directly receive or store your credit card or payment instrument details, we maintain ultimate control and responsibility for your data under data protection laws. Any data subject requests (such as access, rectification, or deletion) may be submitted directly to us, and we will coordinate with Freemius to ensure your rights are fully executed. For details on how Freemius secures the data they process on our behalf, you may also consult the Freemius Privacy Policy.

6.1.2 Other Service Providers (Data Processors)

We also engage the following categories of third-party service providers who process personal data strictly on our behalf and under our instructions, bound by Data Processing Agreements (DPAs):

  • Cloud infrastructure and hosting providers: for website and server operations;
  • Email delivery platforms: for transactional emails (license confirmations, support responses, security alerts);
  • Security and monitoring providers: for uptime monitoring, vulnerability management, and access logging.

All processors are contractually required to implement appropriate security measures, process data only for the purposes we specify, and not to sub-process without our prior authorization. A list of current sub-processors is available upon request through the contact channels described in Section 19.1 (Privacy General Doubts) of this Privacy Policy.

6.2 Business Transfers and Corporate Changes

We currently operate as an individual (sole proprietor) under the trade name Outsaky – Digital Solutions, with no parent company, subsidiaries, or affiliates.

In the event of a future structural change — such as incorporation, acquisition, merger, reorganization, or sale of all or part of the business — your Personal Data may be transferred to the successor entity. In such cases:

  • We will notify you in advance through a prominent notice on our website or by direct communication prior to such transfer;
  • Your rights under applicable law will be maintained throughout and after the transition;
  • You will retain the right to exercise your choices as described in Section 13 (Your Rights).

6.3 Legal Requirements & Protection of Rights

We may disclose your Personal Data if required in good faith to:

  • Comply with a legal obligation, court order, or governmental or regulatory authority;
  • Protect and defend the rights, property, or safety of Outsaky – Digital Solutions, our users, or the public;
  • Prevent or investigate suspected fraud, abuse, or unlawful activity in connection with the Services.

6.4 With Your Explicit Consent

We may share your Personal Data with additional third parties not described above when you have provided explicit consent to such sharing, which may be withdrawn at any time — see Section 16 (Consent/Withdrawal).

6.5 Non-Sale & Non-Sharing Commitment (CCPA/CPRA)

Consistent with CCPA/CPRA principles, we do not “sell” or “share” (as defined under California law) your Personal Information for monetary or other valuable consideration, except as disclosed in Section 7 (Advertising / Targeted Ads) and Section 17 (Jurisdiction-Specific Addenda). California residents may exercise their opt-out right at: Your Privacy Choices [link].

With respect to Sensitive Personal Information, we do not use or disclose SPI for purposes other than those specified in Section 7.2. No opt-out action is currently required, as our use of SPI does not exceed the purposes necessary to provide the Services. California residents may confirm this or submit any related request at: outsaky.com/do-not-sell/ or .


7. Advertising / Targeted Ads

We do not display third-party advertisements on our website or within our Apps, and we do not share your personal data with advertising networks, demand-side platforms (DSPs), or ad-tech partners. We do not use advertising tracking technologies such as Meta Pixel, Google Ads remarketing tags, or equivalent tools.

If this practice changes in the future, this Privacy Policy will be updated accordingly and, where required by applicable law, your explicit consent will be obtained before any advertising-related processing begins.

7.1 Your Advertising Choices

Since we do not engage in interest-based advertising or behavioral profiling for advertising purposes, no opt-out action is required at this time.

For general cookie and tracking preferences — including analytics cookies — please refer to our Cookie Preference Center described in Section 14.

CCPA/CPRA — California Residents: We do not “sell” or “share” your Personal Information as defined under California law (Cal. Civ. Code § 1798.140). A formal “Do Not Sell or Share My Personal Information” link is available at: outsaky.com/do-not-sell/. We will action any request received through that channel within 15 business days and will not discriminate against you for exercising this right.

GDPR/UK GDPR — EEA, UK & Switzerland Users: We do not engage in profiling for advertising purposes. For analytics-related processing based on Consent, you may withdraw your consent at any time — see Section 16.

7.2 Sensitive Personal Information (SPI) — California Residents (CPRA)

The California Privacy Rights Act (CPRA, effective January 1, 2023) designates certain categories of personal data as Sensitive Personal Information (SPI), affording California residents the right to limit its use beyond what is necessary to provide the requested service.

SPI categories potentially applicable to our Services:

SPI Category (CPRA)
Do We Collect It?
How We Use It
Account login credentials (username + password)
Yes — password stored in encrypted form only
Solely for authentication and account security. Never shared or used for profiling.
Precise geolocation
No — we derive only general location from IP (city/region level)
Not collected at precise level.
Financial account information
No — processed exclusively by Freemius
We do not receive or store payment instrument details.

Our commitment: We use SPI exclusively for the purposes strictly necessary to provide, maintain, and secure our Services. We do not use SPI for profiling, advertising, or any purpose beyond service delivery and security.

Because we do not use SPI beyond these necessary purposes, California residents’ right to limit the use of their SPI (Cal. Civ. Code § 1798.121) is not triggered with respect to our processing. We nonetheless provide a unified privacy choices page — accessible at outsaky.com/do-not-sell/ or via the “Your Privacy Choices” link in our website footer — where you may review all applicable preferences, including any SPI-related choices, in a single location.

If our use of SPI changes in the future, this section will be updated and, where required, your prior consent will be obtained.


8. Third-Party Links / Services

8.1 External Links

Our Services may contain links to, or integrations with, websites, applications, and services operated by third parties (including social media platforms, payment processors, and partner sites). This Privacy Policy applies solely to Personal Data processed by Outsaky – Digital Solutions. We are not responsible for the privacy practices or content of any third-party website or service.

We strongly encourage you to review the privacy policy of every third-party service you access through our Services before providing any Personal Data to them.

8.2 Social Media Features & Plugins

Our Services may include social media features such as “Like,” “Share,” or “Sign in with [Platform]” buttons. These features are operated by third-party social media platforms (e.g., Meta/Facebook, X/Twitter, LinkedIn, Google). When you interact with these features, the respective platform may collect your IP address, set cookies, and receive information about your interaction. Your use of such features is governed by the privacy policy of the third-party platform, not by this Privacy Policy.

8.3 Third-Party Sign-In

If you choose to register or log in using a third-party account (e.g., “Sign in with Google” or “Sign in with Apple”), we will receive certain profile information from that provider as permitted by your settings on that platform. We will use that information only in accordance with this Privacy Policy.

8.4 Embedded Content

Certain pages of our Services may contain embedded content (e.g., videos, maps, widgets) from third-party providers. Embedded content behaves as though you visited the third-party website directly and may collect data about you accordingly.


9. Security Measures

9.1 Technical & Organizational Safeguards

Outsaky – Digital Solutions implements and maintains appropriate technical and organizational security measures designed to protect your Personal Data against unauthorized access, accidental or unlawful destruction, loss, alteration, disclosure, or misuse. These measures include:

  • Encryption: Personal Data is encrypted in transit (TLS/SSL) and at rest using industry-standard algorithms (e.g., AES-256).
  • Access Controls: Access to Personal Data is restricted to authorized personnel on a strict need-to-know basis. All access is governed by role-based permissions and regularly reviewed.
  • Authentication: We enforce strong password policies and, where available, multi-factor authentication (MFA) on internal systems handling Personal Data.
  • Pseudonymization & Anonymization: Where feasible, Personal Data is pseudonymized or anonymized to reduce the risk associated with processing.
  • Vulnerability Management: We conduct periodic security assessments, penetration testing, and vulnerability scanning of our systems.
  • Vendor Security: All third-party processors are assessed for security compliance and are contractually required to maintain appropriate safeguards (see Section 6.1).

9.2 Incident Response & Breach Notification

In the event of a Personal Data breach that is likely to result in a risk to your rights and freedoms, we will:

  • Notify the competent supervisory authority without undue delay and in accordance with the specific timelines mandated by applicable law. For instance:
    • Under the GDPR / UK GDPR, we aim to notify the relevant supervisory authority within 72 hours of becoming aware of the breach, where feasible;
    • Under Brazil’s LGPD, we will notify the National Data Protection Authority (ANPD) within the legally prescribed timeframe (which is 3 business days from becoming aware of the incident, or 6 business days as a small-scale data processing agent under Resolução CD/ANPD nº 15/2024);
    • Under other regional frameworks, in accordance with their respective statutory deadlines.
  • Notify you directly if the breach is likely to result in a high risk to your rights and freedoms, in clear and plain language, without undue delay and in compliance with the statutory notification periods applicable to your jurisdiction.

9.3 Your Responsibility

While we take every reasonable precaution to protect your data, no method of transmission over the Internet or electronic storage is 100% secure. You are responsible for maintaining the confidentiality of your account credentials. If you discover a security vulnerability in any of our Apps or website, please report it responsibly through the contact channels described in Section 19.1 (Privacy General Doubts) of this Privacy Policy, using the subject line “Security Vulnerability Report.”

Please do not disclose the vulnerability publicly before we have had a reasonable opportunity to assess and address it. We aim to acknowledge all security reports within 2 business days and to provide a resolution timeline within 15 business days of acknowledgement.

We do not currently operate a formal bug bounty program, but we genuinely appreciate responsible disclosure and will acknowledge contributors where appropriate.


10. Automated Decision-Making and Profiling

We do not currently make decisions about you that are based solely on automated processing — including profiling — that produce legal or similarly significant effects.

Where any automated analysis is used (for example, to detect fraudulent activity, abuse of our Services, or license misuse), a human review is available upon request. You may request human intervention in any decision that has affected your access to or use of our Services through the channels described in Section 19.2 (Privacy – Data Subject Access Requests) of this Privacy Policy.

Freemius may perform certain automated risk assessments related to payment processing and fraud prevention as part of their role as Merchant of Record. For details, please refer to Freemius’s Privacy Policy.


11. Data Retention

11.1 Retention Principles

We retain your Personal Data only for as long as necessary to fulfill the purposes for which it was collected, as described in Section 5, or as required or permitted by applicable law. In determining the appropriate retention period, we consider:

  • The nature, sensitivity, and volume of the data;
  • The purposes for which we process it and whether those purposes can be achieved in a shorter period;
  • Applicable statutory or regulatory retention obligations;
  • The potential risk of harm from unauthorized use or disclosure;
  • Whether we can fulfill the same purpose with anonymized or aggregated data.

11.2 Retention Periods by Data Category

Data Category
Standard Retention Period
Legal Basis & Operational Reason
Account / Profile Data
Brazil: 5 years after account closure or permanent inactivity (Brazilian Civil Code, Art. 206, § 5º)
EU / UK / Switzerland: 3 years after account closure or last active use, sufficient to cover contractual claims under the applicable limitation periods (e.g., EU Member State civil law; UK Limitation Act 1980). Data will be deleted or anonymized promptly upon expiry of the applicable period.
Contractual defense and audit requirements; principle of storage limitation (GDPR Art. 5(1)(e); LGPD Art. 16).
Transaction & License Records
5 years from transaction date
Tax, bookkeeping, and commercial audit requirements, in sync with Freemius tax records.
Communications & Support Tickets
Up to 5 years from ticket resolution
Necessary to defend against potential licensing or contractual claims.
Behavioral & Analytics Data
14 months (then automatically deleted or aggregated)
Strictly used for service improvement; kept short to minimize storage risks.
Marketing Consent Records
Until consent is withdrawn + 1 year thereafter
Proof of compliance under GDPR and LGPD consent rules.
Security & Access Logs
1 year
To detect fraud patterns and secure systems, in line with Brazil’s Marco Civil da Internet.

Storage Limitation: Retention periods are applied per user jurisdiction where technically feasible. Where jurisdiction cannot be determined with reasonable certainty, the shorter applicable period will be applied as a conservative default. *Specific retention periods applicable to your jurisdiction may be further detailed in Section 17 (Jurisdiction-Specific Addenda).*

Note: You may request deletion of your account and associated data at any time through the channels described in Section 19.2 (Privacy – Data Subject Access Requests) of this Privacy Policy. Requests will be processed within the timeframes set out in Section 13, subject to any legal obligation to retain certain records.

11.3 Deletion & Anonymization

Upon the expiry of the applicable retention period, or upon receipt of a valid erasure request (see Section 13), we will securely delete or anonymize your Personal Data in a manner that renders it irreversibly unidentifiable. We will also direct our processors to take equivalent action within their systems.

11.4 Records of Processing Activities (RoPA)

As a small-scale data controller with fewer than 250 employees, we qualify for the partial exemption from the formal obligation to maintain Records of Processing Activities under Art. 30(5) GDPR. However, since our processing is not purely occasional and involves personal data that could pose risk to data subjects (e.g., account data and license records), we maintain an internal processing register documenting each activity’s purpose, legal basis, data categories, recipients, retention period, and applicable safeguards. This register is available to competent supervisory authorities upon request.


12. International Transfers

12.1 Cross-Border Processing

Outsaky – Digital Solutions operates from Brazil, while our Merchant of Record, Freemius, Inc., is based in the United States, utilizing global cloud servers (primarily in the United States and the European Union). This means that if you are located in the European Economic Area (EEA), the United Kingdom, or Brazil, your Personal Data (such as license key checks, purchase confirmations, and support queries) will be transferred to, stored in, and processed in the United States and Brazil.

Specifically, your data may be processed in: [// TODO: To be defined — confirm countries based on final infrastructure and hosting providers before publication (align with Terms of Use § 22.4)]

12.2 Transfer Safeguards

Whenever we transfer Personal Data internationally, we ensure that at least one of the following safeguards is in place:

Transfer Mechanism
Applicability
Adequacy Decision
Transfers to countries recognized as adequate by the European Commission or relevant authority (e.g., UK, Canada, Japan, New Zealand, South Korea).
Standard Contractual Clauses (SCCs)
EU Commission-approved SCCs (2021 version) and UK-specific IDTA are used for transfers from the EEA and UK to non-adequate countries.
Binding Corporate Rules (BCRs)
Where applicable, for intra-group transfers within our corporate group.
EU-US Data Privacy Framework (DPF)
For transfers to certified US entities under the DPF, where applicable.
Consent
In limited circumstances where you have explicitly consented to the transfer after being informed of the associated risks.
LGPD-Specific Mechanisms
For transfers from Brazil: standard contractual clauses approved by the ANPD, or demonstrable equivalent level of protection per LGPD Art. 33.

12.3 How to Obtain More Information

You may request a copy of the specific safeguards we have put in place for international transfers through the channels described in Section 19.2 (Privacy – Data Subject Access Requests) of this Privacy Policy. For EEA/UK users, this includes the right to obtain a copy of the applicable SCCs.


13. Your Rights

13.1 Overview

Depending on your jurisdiction and the legal basis applicable to the processing of your data, you may have some or all of the rights described below. We are committed to honoring these rights promptly and without discrimination.

13.2 Rights Available to You

Right
Description
Key Jurisdictions
Right of Access
Obtain confirmation of whether we process your Personal Data and receive a copy of it.
GDPR Art. 15; LGPD Art. 18(I-II); CCPA/CPRA; POPIA; PDPA; APPs; DPDP
Right to Rectification
Request correction of inaccurate or incomplete Personal Data.
GDPR Art. 16; LGPD Art. 18(III); POPIA; PDPA; DPDP
Right to Erasure (“Right to be Forgotten”)
Request deletion of your Personal Data, subject to legal retention obligations.
GDPR Art. 17; LGPD Art. 18(VI); CCPA/CPRA; PDPA; DPDP
Right to Restriction
Request that we limit the processing of your data while a dispute is pending.
GDPR Art. 18; LGPD Art. 18(IV)
Right to Data Portability
Receive your Personal Data in a structured, machine-readable format and transmit it to another controller.
GDPR Art. 20; LGPD Art. 18(V); CCPA/CPRA
Right to Object
Object to processing based on Legitimate Interests or for direct marketing purposes.
GDPR Art. 21; LGPD Art. 18(IX)
Right to Opt-Out of Sale/Sharing
Opt out of the sale or sharing of your Personal Information for cross-context behavioral advertising.
CCPA/CPRA; LGPD
Right to Non-Discrimination
We will not discriminate against you for exercising any of your privacy rights.
CCPA/CPRA; LGPD Art. 18
Right to Withdraw Consent
Withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal. See Section 16.
GDPR Art. 7(3); LGPD Art. 8(5); All jurisdictions
Right Not to Be Subject to Automated Decisions
Request human review of solely automated decisions. See Section 10.
GDPR Art. 22; LGPD Art. 20; PDPA; DPDP
Right to Lodge a Complaint
Lodge a complaint with the competent supervisory authority in your jurisdiction (see list below).
GDPR Art. 77; LGPD Art. 18(VIII); All applicable frameworks

13.3 How to Exercise Your Rights

We will verify your identity before processing your request to prevent unauthorized disclosure. We will respond within the timeframes required by applicable law:

Jurisdiction / Law
Response Deadline
Extension Permitted
GDPR / UK GDPR / FADP (Switzerland)
30 days
Up to 2 additional months with prior notice
LGPD (Brazil)
15 days
Not specified; we target resolution within 15 days
CCPA / CPRA (California)
45 days
Additional 45 days with notice
PIPEDA (Canada — federal)
30 days
Up to 30 additional days with notice
Law 25 (Québec, Canada)
30 days
Not permitted without justification
Privacy Act / APPs (Australia)
30 days
Reasonable extension with written notice
Ley 1581/2012 (Colombia)
Consultas: 10 business days; Reclamações: 15 business days
Not permitted
Ley 21.719 (Chile)
30 days
Up to 15 additional days with notice
APPI (Japan)
Prompt response; target 30 days
Reasonable extension with notice
PIPA (South Korea)
10 days
Up to 10 additional days with notice
Privacy Act 2020 (New Zealand)
20 working days
Up to 20 additional working days with notice
Ley 25.326 (Argentina)
5 business days (access); 30 days (correction/deletion)
Not specified
PDPA (Thailand / Singapore)
30 days
Reasonable extension with notice
POPIA (South Africa)
30 days
Not specified
DPDP Act 2023 (India)
As notified by the Data Protection Board
All other jurisdictions (Addendum H)
30 days (our default standard)
Up to 15 additional days with notice

For jurisdictions not individually listed above, we apply a 30-day default as a conservative standard consistent with the broadest international practice. If applicable law in your jurisdiction mandates a shorter period, that shorter period shall prevail.

See all support channels in this Privacy Policy, section 19.

13.4 Supervisory Authorities

If you believe your rights have been violated and we have not adequately resolved your concern, you have the right to contact the relevant supervisory authority in your jurisdiction, including:

Jurisdiction
Supervisory Authority
EU / EEA
Your local Data Protection Authority (DPA) — full list at edpb.europa.eu
UK
Information Commissioner’s Office (ICO) — ico.org.uk
Brazil
Autoridade Nacional de Proteção de Dados (ANPD) — gov.br/anpd
Switzerland
Federal Data Protection and Information Commissioner (FDPIC) — edoeb.admin.ch
South Africa
Information Regulator — inforegulator.org.za
India
Data Protection Board of India (DPBI) — (as established under the DPDP Act 2023)
California (USA)
California Privacy Protection Agency (CPPA) — cppa.ca.gov

A complete list of supervisory authorities mapped to your 18 jurisdictions is provided in Section 17 (Jurisdiction-Specific Addenda).


14. Cookie Policy

14.1 What Are Cookies?

Cookies are small text files placed on your device when you access our Services. They allow us to recognize your device on subsequent visits, remember your preferences, and understand how you interact with our Services. In addition to cookies, we may use similar technologies such as web beacons, pixel tags, local storage objects (LSOs), and software development kits (SDKs), all of which are collectively referred to as “cookies” throughout this section.

14.2 Categories of Cookies We Use

Category
Purpose
Legal Basis
Can Be Disabled?
Strictly Necessary
Enable core functions such as secure login, session management, security, and payment processing. This includes cookies set by Freemius when you open our checkout widget. These are essential for the Services to function.
Contract Performance; Legal Obligation
No
Functional
Remember your settings, language, and region preferences to provide a consistent and personalized experience on our website.
Consent
Yes
Analytics
Collect anonymized or pseudonymized data on website traffic, pages visited, and navigation paths to help us diagnose issues and improve usability. Data is aggregated and not used for advertising purposes.
Consent
Yes
Performance
Monitor technical performance indicators such as page load times, Core Web Vitals (LCP, FID, CLS), server response times, uptime status, and error rates. Data is collected in aggregated form and used exclusively for technical optimization — not for behavioral analysis or advertising. [Tool name and link to be added prior to launch.]
Consent
Yes
Marketing
We do not currently use marketing or advertising cookies. This category is listed for transparency and will be activated only if our advertising practices change, with prior notice and renewed consent as required by applicable law.
N/A — not in use
N/A

Note: Our downloadable Apps (WordPress plugins and Desktop software) do not use cookies or tracking technologies of any kind. Cookies are strictly confined to our website (outsaky.com).

14.3 Cookie Lifespan

  • Session Cookies: Exist only during your active browser session and are automatically deleted when you close your browser.
  • Persistent Cookies: Remain on your device for a set duration (ranging from [X days] to [X months]) or until you manually delete them, even after your session ends.

14.4 Managing Your Cookie Preferences

IMPORTANT NOTICE: We implement rigorous technical measures using our proprietary CMP to ensure that non-essential cookies (including Analytics and Performance cookies) are strictly blocked until you provide your explicit consent. However, please be aware that certain client-side variables (such as aggressive ad-blockers, custom browser shields, or private browsing modes) and server-side delivery factors (such as CDN caching) may occasionally interfere with these script-blocking mechanisms. If you detect any technical anomaly where a non-essential cookie has loaded prior to your authorization, we encourage you to notify our Privacy Team immediately so we can investigate and optimize our configurations.

You may manage your cookie preferences at any time through the following means:

  • Cookie Preference Center: Click Manage Cookie Preferences — URL/Floating Button to review and update your consent choices at any time. Withdrawing consent will not affect the lawfulness of any processing already performed.
  • Browser Settings: Most browsers allow you to block or delete cookies via their settings. Note that disabling Strictly Necessary Cookies may impair the functionality of our Services.
  • Mobile Device Settings: You may limit ad tracking via your device’s operating system settings (e.g., “Limit Ad Tracking” on iOS or “Opt out of Ads Personalization” on Android).
  • Industry Opt-Out Tools: Since we do not currently engage in advertising or interest-based tracking, no advertising-specific opt-out is required at this time. Should this practice change in the future, explicit prior consent will be obtained and this section will be updated accordingly. For general cookie and tracking preferences, please use our Cookie Preference Center described in Section 14.1, or refer to Section 7.1 (Your Advertising Choices).

ePrivacy Directive & GDPR (EEA/UK): We obtain prior, freely given, specific, informed, and unambiguous consent before placing any non-strictly-necessary cookies on your device, in compliance with the ePrivacy Directive (2002/58/EC) and GDPR. Your consent is recorded with a timestamp and version reference and may be withdrawn at any time without penalty.

LGPD (Brazil): Cookie consent is treated as a form of data processing consent under LGPD Art. 7(I), and you may revoke it at any time per Art. 8(5).

Marco Civil da Internet (Brazil — Law No. 12.965/2014): In addition to the LGPD, Brazilian law requires express and highlighted consent for the collection, use, and sharing of connection data and application access data generated during your browsing (Art. 7, VII and VIII). This consent is obtained through our Cookie Preference Center prior to any non-essential data collection. You may revoke this consent at any time, and revocation will not affect the lawfulness of any collection performed prior to withdrawal.


15. Children’s Data

15.1 Age Thresholds by Jurisdiction

Our Services — including our website, WordPress plugins, and desktop software — are strictly designed for professional use, including use by freelancers, self‑employed individuals, agencies, developers and other business users, as reflected in the age thresholds set out in our Terms of use (Section 2.1) .

We do not direct, design, or knowingly intend our Services to attract children or any person who would require parental or guardian consent to enter into a binding agreement. We provide our Services exclusively to adults and professional users (such as freelancers, self‑employed individuals, agencies, and developers) and do not offer a supervised or parental‑consent pathway for minors.

By using our Services, you confirm that you meet this requirement.

For clarity, the minimum age thresholds for access to our Services are aligned with the concept of “legal majority” under applicable law, including:

Jurisdiction / Law
Minimum Age for Our Services
Brazil (LGPD / ECA)
18 years
EU / EEA (GDPR)
18 years
UK (UK GDPR)
18 years
United States (COPPA + general)
18 years
India (DPDP Act 2023)
18 years
PDPA (Thailand)
20 years (legal minor)
POPIA (South Africa)
18 years
All other jurisdictions
Age of legal majority as defined by local law

We do not knowingly collect or process Personal Data from individuals below these thresholds. If you do not meet the applicable age requirement, you must not use our Services under any circumstances.

15.2 Age Verification Mechanism (Age Gate)

To support our commitment to excluding minors from our Services, we implement a combined age‑gate and cookie‑consent mechanism through our Cookie Preference Center:

Stage 1 — Visitor-Level Declaration (Consent Banner)
On first visit, the Cookie Preference Center displays a mandatory age-declaration checkbox with a neutral, multi-jurisdiction statement confirming that you are at least 18 or 20 years old, or the age of legal majority in your jurisdiction, as applicable. No separate age declaration is collected by Outsaky during ordinary account login, account registration, or use of free services.

Non‑essential cookies (including analytics and certain functional cookies) and non‑essential features are activated only after you have both provided any required cookie consent and confirmed that you meet the applicable age threshold.

Stage 2 — Paid Checkout
Where age-related or legally required customer information is requested as part of a paid transaction, that information is collected directly by Freemius, Inc. in its capacity as Merchant of Record and independent Data Controller for checkout and financial processing. Outsaky does not collect or receive that data as part of its ordinary operations.

Audit Trail:
The declaration is recorded in an immutable consent audit trail using HMAC + SHA256 + wp_salt, capturing the following data points:

  • Timestamp of the declaration;
  • Version identifiers of the active Consent Banner, Terms of Use, and Privacy Policy at the time of acceptance;
  • Anonymized access data (hashed session reference, general geographic location);
  • The specific age threshold applied based on the visitor’s detected jurisdiction.

This audit record is maintained for the duration of the applicable retention period defined in Section 11 (Data Retention), and constitutes the primary evidence record for compliance purposes under GDPR Art. 8, LGPD Art. 14, COPPA, DPDP Act 2023 (India), and equivalent applicable frameworks.

While this mechanism constitutes a good-faith technical and organizational measure to discourage access by minors, we are unable to verify age with absolute certainty. If we become aware by any means that a minor has accessed or registered for our Services, we will immediately suspend the associated account and securely delete any Personal Data under our control, without undue delay, as described in this Section.

15.3 Discovery of Minor’s Data

If we discover or are informed that we have inadvertently collected Personal Data from a person below the applicable age threshold, we will:

  • Immediately suspend the associated account and block access to our Services;
  • Delete the personal data under our control without undue delay, subject only to any mandatory legal retention obligation;
  • Notify the affected individual or, where appropriate, their guardian of the action taken.

If you believe a minor has registered on our Services, please notify us immediately through the contact channels described in Section 19.1 (Privacy General Doubts) of this Privacy Policy.

15.4 No Parental Consent Flow

We do not offer a parental consent mechanism or a supervised minor registration pathway. Persons who do not meet the applicable age requirement for our Services must not use them under any circumstances, even with parental or guardian consent.


16. Consent / Withdrawal

16.1 How We Obtain Consent

Where consent is our legal basis for processing (see Section 4), we ensure that consent is:

  • Freely given: Not bundled as a condition of access to our core Services where processing is not necessary for service delivery;
  • Specific: Obtained separately for each distinct processing purpose;
  • Informed: Accompanied by a clear description of what you are consenting to, referencing the applicable section of this Privacy Policy;
  • Unambiguous: Obtained through a clear affirmative action (e.g., ticking an opt-in checkbox, clicking a confirm button) — never via pre-ticked boxes, silence, or inactivity;
  • Documented: Recorded with timestamp, version of the policy presented, and the mechanism used, to demonstrate compliance.

16.2 How to Withdraw Consent

You may withdraw your consent for any consent-based processing at any time, without penalty and without affecting the lawfulness of processing carried out prior to withdrawal. To withdraw consent:

Method
Use For
Cookie Preference Center <a href="#" class="wlw-revision-trigger">Review Consent</a>
Non-essential cookies, functional, analytics and performance
Account Settings → Privacy
Support emails, personalization
Email to
Any other consent-based processing not covered above
Online Privacy Rights Form (outsaky.com/data-subject-access-request/)
All consent types, including Sensitive Data processing
Support channels
Any other consent-based processing not covered above – described in Section 19.2 (Privacy – Data Subject Access Requests)

16.3 Consequences of Withdrawal

Withdrawal of consent will result in the cessation of the relevant processing activity. Where you have validly requested restriction of processing under applicable law (e.g., Art. 18 GDPR, LGPD Art. 18(III)), we will cease active processing of the relevant data within 5 (five) business days of receiving and verifying your request.

Withdrawal will not affect:

  • Processing already performed prior to the withdrawal;
  • Processing carried out on a legal basis other than consent (e.g., contract performance, legal obligation);
  • The continued provision of Services that do not depend on that processing.

GDPR Art. 7(3): Withdrawal is a fundamental right and must be as easy to exercise as giving consent. We honor this principle across all consent-based processing activities.

LGPD Art. 8(5): Consent may be revoked at any time by explicit manifestation of the Data Subject, and data collected on the basis of revoked consent must be deleted unless another legal basis exists.

During the restriction period, we will continue to store the data but will not use it for any purpose other than those permitted by law (e.g., establishing, exercising, or defending legal claims, or protecting the rights of another person).

We will notify you before lifting any restriction on processing.


17. Jurisdiction-Specific Addenda

This section provides supplemental notices required by specific laws and jurisdictions. Users in the regions identified below should read the applicable addendum in addition to the main body of this Privacy Policy.

Governing Law and Jurisdiction (contractual context): The contractual relationship for the use of our Apps and Services — including software licensing, support, warranties, and intellectual property matters — is governed by the laws of the Federative Republic of Brazil, as described in Section 22 (Governing Law and Jurisdiction) of our Terms of Use. As a general rule, disputes relating to these contractual aspects are subject to the jurisdiction of the courts of Santos, State of São Paulo, Brazil, except where mandatory law in your country of residence grants you the right to bring proceedings before your local courts (for example, as a consumer in the EU or UK). Nothing in this Privacy Policy limits such mandatory rights or any protections afforded to you under applicable data protection laws (such as GDPR/UK GDPR or LGPD).


Addendum A — EU/EEA and UK: GDPR Representative

Applicability of Art. 27 GDPR — Representative in the EU/EEA

As an independent developer based in Brazil — that is, outside the European Union and without a physical presence in the European Union or the United Kingdom — we have conducted a proportionate impact assessment of our data processing activities.

Under Art. 3(2) of the GDPR, we may be subject to the Regulation to the extent that we offer services to individuals in the EU/EEA or monitor their behavior. However, pursuant to Art. 27(2)(a) of the GDPR, the obligation to designate a representative in the EU may not apply to us because our data processing:

  • Is occasional in nature — we do not engage in large-scale, systematic, or continuous monitoring of EU data subjects;
  • Does not involve, on a large scale, the processing of special categories of data (Art. 9) or personal data relating to criminal convictions (Art. 10); and
  • Is unlikely to result in a risk to the rights and freedoms of natural persons, given the nature and scale of our operations as a small, individual-run software business.

This assessment is made in good faith based on our current operational profile. We periodically reassess our obligations under Art. 27 GDPR and Art. 37 GDPR (DPO appointment) in light of changes to our processing activities.

Internal Reassessment Thresholds

Trigger
Threshold
Active registered users under GDPR/UK GDPR
Exceeds 50,000 data subjects
Processing of special categories of data (Art. 9 GDPR)
Any large-scale or systematic processing begins
Behavioral monitoring of EU/UK data subjects
Any systematic, continuous tracking is introduced
Structural change
Incorporation, acquisition, or establishment of EU/UK presence

Until any of these thresholds is reached, we maintain that:

  • Our processing of EU/UK data subjects’ personal data is occasional and limited in nature (license validation, support, purchase confirmation);
  • We do not engage in large-scale systematic monitoring;
  • We do not process special categories of data on a large scale;
  • The risk to data subjects’ rights and freedoms remains low, given the nature and sensitivity of the data we process.

We will update this Policy and notify affected users promptly upon any material change to our obligations under Art. 27 or Art. 37 GDPR.

Privacy Contact for EU/EEA and UK Users

All requests, complaints, or inquiries from EU/EEA and UK residents may be directed to the contact information provided in this Privacy Policy, Section 19.

You also have the right to lodge a complaint with your local supervisory authority. A list of EU supervisory authorities is available at: edpb.europa.eu/about-edpb/about-edpb/members_en.

Right of Withdrawal — Digital Content (EU Consumer Rights Directive / UK Consumer Rights Act)

If you are a consumer resident in the European Union or the United Kingdom and you purchase digital content (such as a software license) through our website, you have the right to withdraw from the contract within 14 days of purchase, without giving any reason, in accordance with EU Directive 2011/83/EU (Art. 16(m)) and the UK Consumer Rights Act 2015.

Important limitation: If you have explicitly consented — prior to download or first use — to the immediate performance of the contract and acknowledged that your right of withdrawal will thereby be lost, this right may no longer apply to that specific digital content, to the extent permitted by applicable law.

Our commercial refund policy (Terms of Use, Section 13) provides a 14-day no-questions-asked refund guarantee that operates independently of and in addition to this statutory right, and is not conditioned on the above limitation.

For withdrawal or refund requests, please consult the contact information provided in this Privacy Policy, Section 19.


Addendum B — Brazil: Lei Geral de Proteção de Dados (LGPD)

Consumer vs. Professional Users (CDC x LGPD):
Our Terms of Use distinguish between Business/Professional Users and Consumer Users for purposes of Brazilian consumer contract law (CDC). This contractual classification does not limit or reduce your rights under the LGPD as a Data Subject: all individuals whose Personal Data we process — including business contacts and professional users — benefit from the LGPD rights described in Section 13 (Your Rights) of this Privacy Policy, regardless of whether their use of the Services is classified as consumer or professional under the CDC.

Small-Scale Operator Exemption (Agente de Tratamento de Pequeno Porte):
Pursuant to ANPD Resolution No. 2/2022, we qualify as a small-scale data processing agent (agente de tratamento de pequeno porte) and are therefore:

  • Exempt from the mandatory formal appointment of an Encarregado (Data Protection Officer);
  • Exempt from maintaining formal records of processing activities (as per the simplified regime);
  • Subject to all substantive obligations of the LGPD, including lawful basis for processing, data subject rights, security measures, and breach notification.

Data Controller — Brazilian Law:
Leonardo Nunes Galvão
Operating under the trade name: Outsaky – Digital Solutions
Individual taxpayer (pessoa física), domiciled in Santos, State of São Paulo, Brazil.

Contact:
To ensure that you can fully exercise your rights under Article 18 of the LGPD in a straightforward and hassle-free manner, we have made our official, streamlined data subject support channel available:

Support Channel: please consult the contact information provided in this Privacy Policy, Section 19. Any request or inquiry submitted through this channel will be received, reviewed, and responded to directly by our privacy team within the legally prescribed timeframe.

Statutory Right of Withdrawal — Brazilian Consumers (CDC Art. 49)

If you are an individual consumer (consumidor) as defined under Article 2 of the Brazilian Consumer Defense Code (Law No. 8.078/1990, “CDC”), you are entitled to withdraw from any purchase made outside a physical establishment (e.g., online) within 7 (seven) calendar days from the date of the transaction or receipt of the product, whichever is later, in accordance with CDC Art. 49.

This statutory right of withdrawal is separate from and in addition to our 14-day voluntary refund policy described in the Terms of Use (Section 13). The 7-day right cannot be contractually waived or limited.

To exercise this right, please consult the contact information provided in this Privacy Policy, Section 19. Refund processing is coordinated with our Merchant of Record, Freemius, Inc., as described in the Terms of Use (Section 13).

Privacy Contact for Brazilian Users (Canal de Atendimento ao Titular):
Please consult the contact information provided in this Privacy Policy, Section 19.

Response times and data subject rights are described in Section 13 of this Privacy Policy.


Addendum C — United States: California (CCPA / CPRA)

1. Statutory Applicability & Voluntary Commitment

Leonardo Nunes Galvão, operating as Outsaky – Digital Solutions, is an individual developer and small-scale business. Under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), a “business” is subject to statutory obligations only if it meets specific thresholds defined in Cal. Civ. Code § 1798.140(d)(1) (such as having annual gross revenues in excess of $25,000,000 [as adjusted under Cal. Civ. Code § 1798.199.95(d)], or annually buying, selling, or sharing the personal information of 100,000 or more California consumers or households).

Because our operational scale falls substantially below these statutory criteria, Outsaky is legally exempt from the CCPA/CPRA. However, out of a strong commitment to transparency, trust, and global data protection best practices, we voluntarily extend the privacy rights and protections set forth in the CCPA/CPRA to California residents on a goodwill basis.

2. Your California Rights (Voluntary Provision)

If you are a California resident, we honor your rights to submit requests regarding your personal information, including:

  • Right to Know / Access: Request details about the categories and specific pieces of personal data we have collected about you.
  • Right to Delete: Request the deletion of personal data collected from you, subject to standard legal retention exceptions.
  • Right to Correct: Request the rectification of inaccurate personal information we maintain.
  • Right to Opt-Out: Request that we do not “sell” or “share” your personal information. As described below, we do not engage in these practices.
  • Right to Limit the Use of Sensitive Personal Information: As detailed in Section 7.2, our limited use of SPI (e.g., encrypted account credentials strictly for security) does not trigger limitation obligations, but we respect your inquiry.
  • Right to Non-Discriminrimination: We will never discriminate against you or deny Services if you choose to exercise these privacy choices.

3. Online-Only Business Exemption

Pursuant to Cal. Civ. Code § 1798.130(a)(1)(A), as an online-only business that maintains direct relationships with its consumers, we handle all requests, inquiries, and complaints electronically. A toll-free telephone number is not required. You may submit any request to the channels provided in Section 19 of this Privacy Policy.

4. Sale and Sharing of Personal Information

  • Do Not Sell or Share My Personal Information: Our website does not sell or share your Personal Information for monetary or other valuable consideration, nor for cross-context behavioral advertising (pursuant to Cal. Civ. Code § 1798.140(ad) and (ah)). To manage general cookie preferences, please use our Cookie Preference Center.
  • Categories Sold/Shared (past 12 months): None.
  • Response Times: We aim to respond to verified requests within 45 days (which may be extended by an additional 45 days with prior notice when reasonably necessary), consistent with the timelines of Cal. Civ. Code § 1798.130.

Addendum D — United States: Other State Laws

We honor privacy rights afforded by additional US state laws, including but not limited to:

State
Law
Key Right(s)
Virginia
VCDPA
Opt-out of targeted ads, deletion, portability
Colorado
CPA
Opt-out of profiling, correction, portability
Connecticut
CTDPA
Opt-out of targeted ads, right to appeal
Texas
TDPSA
Deletion, correction, opt-out
Florida
FDBR
Access, deletion, opt-out (for covered controllers)

Residents of these states may submit rights requests using the same channels in Section 13.3.


Addendum E — South Africa (POPIA — Protection of Personal Information Act 4 of 2013)

  • Information Officer: Leonardo Nunes Galvão/ Email:
  • Lawful Processing: All processing is grounded in a condition for lawful processing under POPIA Chapter 3.
  • Rights: Access, correction, deletion, and the right to object to processing.
  • Supervisory Authority: Information Regulator of South Africa — inforegulator.org.za.
  • Exclusive Support Channel: To exercise any of your rights, all requests, complaints, inquiries or privacy requests may be directed to the contact information provided in this Privacy Policy, Section 19. A toll-free phone number is not required.

Note: As a foreign operator without a physical establishment in South Africa, we are currently assessing our registration obligations with the Information Regulator of South Africa under POPIA §55. If registration is confirmed as required based on our processing activities, we will complete it accordingly. In the meantime, all data subject requests from South African residents will be handled through the contact above and in accordance with the rights set out in Section 13 of this Policy.

Your rights under POPIA include:

  • The right to access your personal information;
  • The right to request correction or deletion of your information;
  • The right to object to the processing of your information;
  • The right to lodge a complaint with the Information Regulator of South Africa:
    Website: inforegulator.org.za
    Email:

Addendum F — India (DPDP Act — Digital Personal Data Protection Act, 2023)

  • Data Fiduciary: Leonardo Nunes Galvão, operating under the trade name Outsaky – Digital Solutions, Santos, São Paulo, Brazil/ .
  • Consent Manager: Where applicable, consent obtained via a registered Consent Manager under the DPDP Act.
  • Rights of Data Principals: Access, correction, erasure, grievance redressal, right to nominate.
  • Children’s Data: No processing of Personal Data of children under 18 years without verifiable parental consent.
  • Supervisory Authority: Data Protection Board of India (DPBI).
  • Exclusive Support Channel: To exercise any of your rights, all requests, complaints, inquiries or privacy requests may be directed to the contact information provided in this Privacy Policy, Section 19. A toll-free phone number is not required.

As a non-Significant Data Fiduciary under the DPDP Act 2023, we are not required to appoint a Data Protection Officer based in India or designate a local representative. All data protection inquiries from Indian residents are handled directly through the contact above. We will reassess this position if our processing volume or data categories meet the threshold criteria for Significant Data Fiduciary classification as notified by the Indian government.


Addendum G — Thailand / Singapore (PDPA)

  • Privacy Contact: Leonardo Nunes Galvão/ Email:
  • Rights: Access, rectification, erasure, portability, objection, and right to withdraw consent.
  • Thailand Supervisory Authority: Office of the Personal Data Protection Committee (PDPC Thailand).
  • Singapore Supervisory Authority: Personal Data Protection Commission (PDPC Singapore) — pdpc.gov.sg.
  • Exclusive Support Channel: To exercise any of your rights, all requests, complaints, inquiries or privacy requests may be directed to the contact information provided in this Privacy Policy, Section 19. A toll-free phone number is not required.

As a small-scale foreign operator, we are not required to appoint a formal Data Protection Officer under the PDPA. All privacy-related requests from Thai residents are handled directly through the contact above.

Your rights under the PDPA include:

  • Right to be informed;
  • Right of access;
  • Right to data portability;
  • Right to objection;
  • Right to erasure;
  • Right to restriction of processing;
  • Right to rectification.

Addendum H — Additional Jurisdictions

The following jurisdictions and their applicable laws are also covered by this Privacy Policy. Supplemental notices are available upon request or will be provided contextually within the Services when accessed from these regions:

  • Exclusive Support Channel: To exercise any of your rights, all requests, complaints, inquiries or privacy requests may be directed to the contact information provided in this Privacy Policy, Section 19. A toll-free phone number is not required.
Jurisdiction
Applicable Law
Argentina
Ley 25.326 (PDPA Argentina)
Australia
Privacy Act 1988 (APPs)
Canada
PIPEDA / Law 25 (Québec)
Chile
Ley 21.719
Colombia
Ley 1581/2012
Costa Rica
Ley 8968/2011
Dominican Republic
Ley 172-13
Ecuador
Ley Org. PDP 2021
Israel
Privacy Protection Law
Japan
APPI (Act on Protection of Personal Information)
Mexico
LFPDPPP
New Zealand
Privacy Act 2020
South Korea
PIPA (Personal Information Protection Act)
UAE / Saudi Arabia
PDPL / applicable national law

18. Changes to This Policy

18.1 How We Update This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Services we offer, applicable legal requirements, or regulatory guidance. The updated version will always be accessible at [URL to Privacy Policy] and will indicate the “Last Updated” date at the top of the document.

18.2 How We Notify You

The method and timing of notification will be proportionate to the significance of the updates:

  • Minor Changes (e.g., typos, formatting corrections, clarify wording): We will update the “Last Updated” date at the top of this page. We encourage you to review this policy periodically.
  • Significant Changes (e.g., changes to retention times, new third-party integrations, or modifications to our data processing activities): We will provide at least 30 days’ prior notice before the changes take effect by:
    • Sending an email notification to the address associated with your account; and/or
    • Placing a prominent notice on our website at outsaky.com.
  • Changes Requiring Re-Consent: If a change introduces a new processing activity that relies on your consent, we will request your explicit approval before that specific activity takes effect.

18.3 Policy Archive

Previous versions of this Privacy Policy are archived and available upon request through the contact channels described in Section 19.1 (Privacy General Doubts) of this Privacy Policy.


19. Contact Us

19.1 Privacy — General Doubts

For any questions, concerns or complaints regarding this Privacy Policy, please contact our Team using the details below:

Outsaky – Digital Solutions
Attn: Privacy Team / Leonardo Nunes Galvão
Santos, State of São Paulo, Brazil
Email:
Online Form: outsaky.com/contact/

19.2 Privacy – Data Subject Access Requests

For any requests about processing of your Personal Data, please use the exclusive form:

Exclusive Form: outsaky.com/data-subject-access-request/

19.3 Technical Support

For technical product support, licensing assistance, or general commercial inquiries, please use our support channel:

Email:
Online Form: outsaky.com/contact/

19.4 Response Commitment

We will acknowledge receipt of your request within 2 business days and respond substantively within the timeframe required by applicable law, as specified in Section 13.3. If your request requires additional time, we will notify you with the reason and expected resolution date.


This Privacy Policy was last reviewed and approved by Outsaky – Digital Solutions’s Privacy Team on [xxxx/xx/xx].
Version: [xx.xx]