EazyData Logo

PRIVACY POLICY - EazyData

Last Updated: November 17, 2025

COMPANY INFORMATION: GOD OF PROMPT OÜ

Registry Code: 17108842

VAT Number: EE102805158

Address: Harju maakond, Tallinn, Lasnamäe linnaosa, Sepapaja tn 6, 15551, Estonia

Email: [email protected]

Website: https://eazydata.io

Data Protection Contact: [email protected]

1. INTRODUCTION

GOD OF PROMPT OÜ ("we," "us," "our") operates EazyData, a privacy-focused web analytics platform. This Privacy Policy explains how we collect, use, and protect data when you visit eazydata.io, use our analytics Services, or implement our tracking script. We are committed to protecting your privacy and complying with GDPR, Estonian data protection laws, and other applicable regulations.

2. DATA CONTROLLER AND PROCESSOR ROLES

2.1 When You Visit eazydata.io

  • We are the data controller.
  • We determine how your data is processed.

2.2 When You Use EazyData Services

  • YOU are the data controller for visitor data on your website.
  • WE are the data processor acting on your behalf.
  • You determine purposes and means of processing.
  • We process data according to your instructions and our Data Processing Agreement.

3. OUR PRIVACY PRINCIPLES

  • ✓No cookies - We don't use cookies or persistent identifiers
  • ✓No personal data collection - We don't track PII
  • ✓No cross-site tracking - Data isolated per website, per day
  • ✓No data selling - We never sell or share your data
  • ✓EU data hosting - All data stays in the EU
  • ✓Full data ownership - You own 100% of your data
  • ✓Easy data export - Export anytime via CSV or API
  • ✓Transparent - Open about what we collect and why

4. DATA WE COLLECT

4.1 When You Visit eazydata.io

Automatically collected: Page views and navigation paths, referral sources, device type, operating system, browser type, country (based on anonymized IP), visit duration, and interaction patterns.

Not collected: NO personally identifiable information, NO IP addresses (anonymized immediately), NO cookies or persistent identifiers, NO cross-device or cross-site tracking, NO precise geolocation, NO user IDs that persist beyond one day.

4.2 When You Create an Account

Information you provide: Email address, optional name, optional company name, password (encrypted, never stored in plain text), payment information (processed by third-party payment processor, not stored by us).

Usage data: Login timestamps, feature usage within the dashboard, account settings and preferences, support requests and communications.

4.3 When You Use EazyData on Your Website

Visitor data we process on your behalf: Page views and navigation, referral sources, device information (type, OS, browser), country (anonymized IP-based), custom events you configure, revenue data from payment integrations.

How we generate unique visitors: We use a privacy-preserving method hash(daily_salt + website_domain + anonymized_ip + user_agent). This creates a daily-changing identifier that cannot identify individuals, resets every 24 hours, cannot track users across days, and cannot track users across websites.

4.4 Payment Provider Integration Data

When you integrate payment providers (Stripe, PayPal, Shopify, Lemon Squeezy) we process transaction IDs, revenue amounts, product/service identifiers, transaction timestamps, and currency information.

NOT collected: Customer names, email addresses, credit card information, billing addresses, or any other PII from transactions.

5. LEGAL BASIS FOR PROCESSING (GDPR)

5.1 For eazydata.io Visitors: Legitimate Interest (Article 6(1)(f) GDPR).

5.2 For EazyData Customers: Contract (Article 6(1)(b) GDPR) and Legitimate Interest.

5.3 For Website Visitors (Data We Process for You): Your responsibility as data controller to establish legal basis. We recommend legitimate interest or consent depending on your use case; we provide tools to support your compliance obligations.

6. HOW WE USE DATA

6.1 Service Delivery: Provide analytics dashboards and reports, track website performance metrics, attribute revenue, process integrations.

6.2 Service Improvement: Analyze aggregated usage, develop new features, fix bugs, and enhance user experience.

6.3 Communication: Send account-related emails, respond to support, notify about service updates or security issues, send product announcements (opt-out available).

6.4 Security and Fraud Prevention: Detect and prevent abuse, monitor for threats, investigate suspicious activity, enforce Terms of Service.

6.5 Legal Compliance: Comply with legal obligations, respond to law enforcement requests, protect our legal rights, resolve disputes.

7. DATA SHARING AND DISCLOSURE

7.1 We DO NOT Sell or Share Your Data for marketing purposes.

7.2 Service Providers (Subprocessors): We use carefully vetted EU-based providers (server hosting, CDN, payment processors, email service providers, customer support tools). All subprocessors are GDPR-compliant and bound by DPAs. Full list available on request via [email protected].

7.3 Legal Requirements: We may disclose data if required by law, court order, government authority, or to protect rights, property, or safety.

7.4 Business Transfers: In a merger, acquisition, or sale of assets, your data may be transferred; you will be notified and can delete your account.

8. DATA SECURITY

8.1 Technical Measures: Encryption in transit (TLS/HTTPS), encryption at rest, hashing with rotating salts, access controls, regular updates.

8.2 Organizational Measures: Employee training, limited access on a need-to-know basis, confidentiality agreements, regular security audits, incident response procedures.

8.3 Data Center Security: EU hosting providers maintain ISO 27001 certification, physical and environmental controls, redundancy, and backups.

9. DATA RETENTION

9.1 Account Data: Retained while active; retained up to 30 days after deletion for recovery; permanently deleted after 30 days.

9.2 Analytics Data: Retained while account is active; you control retention period; deleted within 30 days of account deletion.

9.3 Aggregated Data: Anonymized, aggregated data may be retained indefinitely; cannot be linked back to individuals or accounts.

9.4 Legal Obligations: We may retain data longer if required to resolve disputes, enforce agreements, or comply with laws.

10. YOUR RIGHTS (GDPR)

  • Right of Access
  • Right to Rectification
  • Right to Erasure ("Right to be Forgotten")
  • Right to Restriction
  • Right to Data Portability
  • Right to Object
  • Right to Withdraw Consent
  • Right to Lodge a Complaint

How to Exercise Your Rights: Contact us at [email protected] with your request. We'll respond within 30 days.

11. COOKIES AND TRACKING

11.1 Our Website (eazydata.io): NO cookies, NO consent banners needed for EazyData tracking, NO persistent identifiers. 11.2 Your Website (Using EazyData): EazyData script doesn't use cookies. Your responsibility: ensure compliance for other services you use.

12. INTERNATIONAL DATA TRANSFERS

12.1 EU Data Hosting: All data is hosted on servers within the European Union and never transferred outside EU/EEA. 12.2 Compliance with Schrems II: No US-based hosting or subprocessors with access to your data. Standard Contractual Clauses and safeguards apply.

13. DATA PROTECTION OFFICER

For GDPR-related inquiries, contact [email protected] with the subject line "Data Protection Inquiry".

14. CHILDREN'S PRIVACY

EazyData is not intended for children under 18. We don't knowingly collect data from children. If you believe we've inadvertently collected such data, contact us immediately.

15. YOUR RESPONSIBILITIES AS DATA CONTROLLER

When you use EazyData on your website, you are responsible for providing privacy notices, obtaining necessary consents, establishing legal basis, responding to data subject requests, complying with GDPR/CCPA/PECR and other laws, not processing sensitive personal data, and implementing appropriate security measures. We offer tools to assist, but responsibility rests with you.

16. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy to reflect changes in practices, comply with legal requirements, or improve clarity. We'll notify you via email, website notice, or in-app notification. Continued use after changes constitutes acceptance.

17. SUPERVISORY AUTHORITY

Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) — https://www.aki.ee/en — Tatari 39, 10134 Tallinn, Estonia — Email [email protected] — Phone: +372 627 4135.

18. CONTACT US

GOD OF PROMPT OÜ — Harju maakond, Tallinn, Lasnamäe linnaosa, Sepapaja tn 6, 15551, Estonia — Registry Code 17108842 — VAT EE102805158 — Email [email protected] — Response Time: within 48 business hours.

19. DATA PROCESSING AGREEMENT (DPA)

By using EazyData Services, you automatically accept our Data Processing Agreement, which includes Standard Contractual Clauses as required by GDPR. You are the data controller; we are the data processor; we process data only on your documented instructions, maintain appropriate security measures, assist with data subject requests, notify you of data breaches, and delete or return data upon termination. Full DPA available upon request.

20. SPECIFIC COMPLIANCE NOTES

20.1 GDPR Compliance: Data minimization by design, privacy by default, no unnecessary data collection, EU-only storage, full data portability, easy deletion.

20.2 ePrivacy Directive Compliance: No cookies, no access to device storage, no persistent identifiers, minimal data collection.

20.3 CCPA Compliance (California): Right to know, delete, opt-out of data sales (we don't sell data), and right to non-discrimination.

20.4 Estonian Personal Data Protection Act: We comply with all Estonian national provisions supplementing GDPR.

BY USING EAZYDATA, YOU ACKNOWLEDGE YOU HAVE READ AND UNDERSTOOD THIS PRIVACY POLICY. END OF PRIVACY POLICY