DATA PROTECTION
Data protection
Our controller and processor roles, privacy safeguards and individual rights.
Last updated 31 August 2026
1. Our data-protection roles
PrimoDevStudio is controller for TradePocket account administration, service security, support, website and subscription-status data. When a business customer instructs TradePocket to store or use customer, job, review, campaign or managed-website personal data, that customer is normally the controller and TradePocket acts as its processor.
Customers are responsible for their own privacy notices, lawful basis, communication permissions, uploaded content and instructions to TradePocket.
2. Data-protection principles
We process personal data lawfully, fairly and transparently; use it for specified purposes; limit collection to what is needed; support accuracy; retain it only for justified periods; and apply safeguards appropriate to the risk.
3. Processors and independent controllers
Core providers may include Supabase for authentication and database services, Vercel for application delivery, Bunny for file storage and delivery, and Northflank for application services and background processing. Google measurement tools are used only after the relevant consent when configured.
FastSpring acts as Merchant of Record and an independent controller for buyer, payment, tax, fraud, refund and transaction-compliance data when it is identified as the seller or authorized reseller. Its handling is described in the FastSpring Privacy Notice.
4. International transfers
Service providers may process data in multiple countries. Where data-protection law requires a transfer safeguard, we use an adequacy decision, approved standard contractual clauses or another legally recognized mechanism and apply supplementary safeguards where appropriate.
5. Security and incidents
Measures include least-privilege access, encryption in transit, managed authentication, separation of public and private credentials, monitoring, backups, dependency maintenance and incident response. We investigate suspected personal-data breaches and notify affected controllers, individuals or authorities within legally required periods where notification is required.
6. Individual requests
Requests for access, correction, erasure, restriction, portability, objection or consent withdrawal can be sent to hello@tradepocket.pro. We ordinarily respond within one month where GDPR applies, subject to identity verification, lawful extensions and permitted exceptions.
If the request concerns data controlled by a TradePocket customer, we will direct it to that customer or assist the customer with its response.
7. Complaints and business enquiries
You may complain to the data-protection authority where you live or work, or where an alleged infringement occurred. Business customers can contact hello@tradepocket.pro for processor terms, security information or assistance with a data-protection assessment.