Last updated: 01.07.2026
Since your use of the Website or the Services requires processing of your personal data (or “data”), we are committed to being fully transparent with you in regard to our practices. We prepared this Privacy Policy as our appropriate measure to fulfill such commitment.
The terms in this document shall have the same meanings assigned to them in our Terms of Use.
In this document, we will explain to you the following issues:
If you are under 16, or if the laws of your country set a lower age for us to process your data based on your consent, you will need to get your parent’s or guardian’s permission before giving us any personal data. In any case, our Services are not intended for children under 16.
Scope. We collect and use the email addresses of our potential users from publicly available sources (e.g. social media, web-site contacts etc.).
Lawful basis. Since you make your email address publicly available in connection with your professional activity, we process such data on the basis of legitimate interest: offering B2B business cooperation is our legitimate business interest, and the scope and manner of processing are proportionate to this purpose. We have carried out a Legitimate Interest Assessment and are confident that this interest does not override your rights and freedoms. You have the right to object to such processing at any time — the way to do so is described in the "Your Rights" section below.
Purpose. We process these data for offering our Services (cooperation) and provide other information, relevant to our core business activities by sending you email letters. If you don’t want to receive such emails, let us know and we will never disturb you again.
Retention period. We store these data until a person opts-out from receiving our letters or object to our processing in any other way.
Access. Access to this data is granted to our employees, as well as a third-party marketing automation service located in the USA. Data transfer to this service is carried out in compliance with GDPR requirements.
Protection measures. For these data, we use the same protection measures as for the data obtained from the user account (see below).
Scope. We collect, store and use the data you provide us while completing registration on the Website, namely your full name, email address, phone number, and currency preference.
Lawful basis. We process the data because you share these data with us voluntarily. By your clear affirmative action you grant us consent to process these data.
Purpose. In general, we need these data to identify you amongst other users. Identification is required as a pre-condition for using the full range of our Services. Based on the data provided, we will create and maintain your user account. This, in turn, help other users and us to understand with whom they or we interact on the Website. The same deal with giving public feedback on the Website or commenting on our blog.
Additionally, we may use your email for our newsletters. If you don’t want to receive them, let us know and we will not disturb you until you subscribe for the newsletters again.
Retention period. Since we are obliged to maintain your account, data are stored at least for the period of your account activity, as it is required by the purpose of processing. However, we may store your data up to 12 months after account deactivation, to be able to reactivate it without delay or without new account registration, or to be able to reach you in case of any dispute arising from or in relation with the use of our Services.
After the expiration of the before-mentioned period, we shall terminate the processing of your personal data and erase such data as soon as possible, unless the law requires otherwise.
Access. We expect that you understand that our website does not operate autonomously. Our employees or contractors are involved in operations carried out on the Website and therefore have access to your data.
In addition to our employees and contractors, we transfer specific categories of your data to the following categories of service providers, who process data according to our instructions and to the extent necessary to provide the Services:
The list of specific providers belonging to the categories indicated may change. Upon request to the contacts specified below, we will provide the current list.
As you may notice, our external providers are located either within the European Union or in the USA. This means they are subject to GDPR, and for data transfers outside the EEA we use recognized protection mechanisms.
Protection measures. Despite the fact that we grant access to your data to other persons, you should not worry about a breach of confidentiality. As required by law, we provide both technical and organizational measures to protect data.
To prevent data theft when interacting with the Website, we use the HTTPS (Hypertext Transfer Protocol) protocol, applying certificates to keep your data secure and encrypt communication. We have implemented password hashing for additional security to help you avoid unauthorized use of your account.
Regarding data storage, we decided to entrust this matter to professionals. Technically, the data we collect is stored on the servers of reliable hosting service providers located within the European Union. Database backup is carried out using cloud computing platforms located in the USA, with which data processing agreements (DPA) have been concluded and Standard Contractual Clauses applied to ensure GDPR compliance.
Regarding organizational measures, we sign non-disclosure agreements with both our employees and contractors. With respect to our contractors located outside the EU, we adopt appropriate safeguards for such data transfers to ensure full GDPR compliance.
Scope. We may collect and use your payment details when you request a top-up or withdrawal of funds from the balance in your user profile. This data includes your first and last name or company name, tax identification number, registered address, and contact phone number.
If you top up or withdraw funds by cashless means, we do not collect or process your payment details ourselves — in such cases, the data is collected by third-party payment providers that you choose yourself. The processing of data by these providers is governed by their own privacy policies, which we recommend reviewing separately.
Lawful basis. We process the data to perform our contractual obligations under the terms of use. Also you share these data with us voluntarily. By your clear affirmative action you grant us consent to process these data.
Purpose. These data are collected and used for billing purposes, in particular for issuing the invoice, which we will send you as the payment confirmation. After the first submission of your payment requisites, we will store such data for further similar operations for your convenience so that you wouldn’t need to submit them again.
Retention period. We retain these data until you request to erase them or until your account is deactivated.
Access. Only our employees and local partners have access to these data. As we previously stated, we sign non-disclosure agreements with our employees.
Protection measures. We don’t consider that these data are less important than the data from your user account. That is why, in regard to payment requisites, we implement the same technical and organizational measures as we indicated above.
The other important thing you need to know is that we use cookies on the Website, which collect some of your personal data. For more details, please refer to our Cookie Policy.
The right to access your data
The right to rectification
The right to erasure (‘right to be forgotten’)
The right to restriction of processing
The right to withdraw your consent
The right to object to the processing
The right to data portability
How to exercise your rights
The right to access your data. You can ask us to confirm whether we process your personal data or not. If we do, you may ask us everything concerning such processing, for example, the categories of data, specific processing operations with your data, period of processing, protection measures or access to your personal data. We will provide this requested information in a structured, commonly used and machine-readable format.
The right to rectification. You can require all the inaccurate personal data concerning you being corrected. You may also complete your personal data if you consider that something is missed.
The right to erasure (‘right to be forgotten’). You can ask us to erase personal data if its processing is no longer necessary to achieve the purposes for which it was collected as well as if there are no legal grounds for the processing. In most cases, you don’t need to contact us asking for such action because we systematically examine what data we no longer need for the provision of our Services, unless otherwise required by law. Anyway, your rights are above all things, so don’t hesitate to contact us.
The right to restriction of processing. In some cases, prescribed by law you will also be able to restrict the way of processing your data. For example, if you contest the accuracy of your personal data being processed or if we are not interested in our processing of your personal data any longer, but you want us to do this for other reasons, for example, to bring some claim for somebody - then, instead of the erasure of information, its processing will be restricted.
The right to withdraw your consent. You can withdraw your consent for the processing of your personal data if it was given at any time by contacting us, without affecting the lawfulness of processing based on consent before its withdrawal. After receiving such requests, we will stop processing.
The right to object to the processing. You can object to the processing of your personal data when the processing is related to the performance of our task carried in the public interest or in the exercise of official authority vested in us; or if we process your data to pursue our or third party’s legitimate interests, and you believe that such interests are overridden by your interests or fundamental rights and freedoms.
If you make a request objecting to processing, we will no longer process the personal data unless we are able to demonstrate compelling legitimate grounds for the processing. Please note that when we process your personal data for direct marketing purposes, you have the right to object at any time to such processing without providing any justification. We will no longer process your data for such direct marketing purposes.
The right to data portability. You also have the right to transmit data we process to another controller, if the processing is based on your consent or on contract and the processing is carried out by automated means.
The right to lodge a complaint. You have the right to lodge a complaint with a supervisory authority for personal data protection, in particular with the Office of the Commissioner for Personal Data Protection (Cyprus), if you believe that the processing of your data violates GDPR.
How to exercise your rights. Your request in relation to your personal data may be submitted through the contact details specified below by any means. These requests are free of charge. We are obliged to reply to your request within one month of receipt of the request for the longest. This period may be extended by two further months if we are overwhelmed by the number of requests, or if the request at issue is complicated and requires a lot of actions. We will inform you of any such extension within one month of receipt of the request, together with the reasons.
We indicated other rights in regard to your privacy in our Cookie Policy.
If any of your personal data would be under the breach, we would inform you and the respective data protection agencies as to the accidents without undue delay, if there are high risks of violation of your rights as a data subject. We also do our best to minimize any such risks.
We may amend or update this Privacy Policy from time to time, updating “Last updated” date at the top of this Privacy Policy and adding the details to the “Key changes” section above. We will notify you about any changes 7 days before such changes come into force. Should you continue using our Website or the Services after changes in the Privacy Policy, we will consider this as the acceptance of such changes. If you don’t agree with the changes, you should stop using our Website or the Services. If the changes would be substantial to such an extent that we are required to ask for your consent again, we will do that.
We hope that this Privacy Policy has answered all the questions regarding your privacy on our Website and we expect you will trust us.
But if you still have any questions or concerns about your privacy, feel free to reach out to us:
I.M. COLLABORATOR LTD
Company registered under the laws of Cyprus,
Located at Peiraios, 30, 1st floor, Flat/Office 1, Strovolos, 2023, Nicosia, Cyprus,
Company number: ΗΕ 403087
Email for privacy issues: [email protected]
For users from Estonia, these details apply:
Collaborator OÜ, company registered under the laws of Estonia,
Located at Harju maakond, Tallinn, Kesklinna linnaosa, Vesivärava tn 50-201, 10152
Company number 16384422
Email for privacy issues: [email protected]