Privacy Policy
Last updated: 2026-07-07 · Data controller: HaltOps, Quito · Contact: service@haltops.com.
This policy explains how HaltOps ("we") handles personal data in HaltOps. We comply with applicable data-protection law, including the EU/Portugal General Data Protection Regulation (GDPR) for users in the European Union. HaltOps is a support tool for human decisions and does not issue fraud verdicts.
1. Data we process
- Account data: name/identifier, corporate email, organization details, role, and login/session information.
- Uploaded datasets: the files you upload for analysis. These may contain personal or financial data of third parties, controlled by your organization.
- Usage & technical data: IP address, browser, and activity logs needed for security, licensing and anti-account-sharing.
- Payment data: handled by PayPal; we do not store your card details.
2. How we use it and legal basis
We process data to: provide and secure the Service (performance of contract); manage licenses and prevent account sharing and abuse (legitimate interest); process payments (contract/legal obligation); and communicate essential account messages such as the set-password email (contract). We do not sell your data and do not use it for advertising.
3. Uploaded data — your role and ours
For the datasets you upload, your organization is the data controller and HaltOps acts as a data processor that processes the data only to provide the analytics you request, following your instructions. You are responsible for having a lawful basis to upload and analyze that data. If you require a Data Processing Agreement (DPA), contact us.
4. Sharing
We share data only with providers necessary to run the Service: PayPal (payments) and our hosting provider (Hostinger, servers located in the EU). These act under contract and applicable safeguards. We may disclose data if required by law.
5. Retention
Account data is kept while your organization is active and for a reasonable period afterwards. Uploaded datasets and analysis history are kept as your historical record until you delete them or your organization is closed. You may request deletion at any time.
6. Security
We use encryption in transit (HTTPS), access controls scoped per organization, license and session enforcement, and password hashing. No system is perfectly secure, but we take reasonable measures to protect your data.
7. Your rights (GDPR)
If you are in the EU/EEA you have the right to access, rectify, erase, restrict or object to processing, and to data portability. You may withdraw consent where processing is based on it, and lodge a complaint with your supervisory authority (in Portugal, the CNPD). To exercise your rights, contact service@haltops.com.
8. International transfers
Our infrastructure is located in the EU. If any transfer outside the EEA occurs, we apply appropriate safeguards such as Standard Contractual Clauses.
9. Cookies
We use only strictly necessary cookies: session, security (CSRF) and language preference. We do not use advertising or third-party tracking cookies.
10. Changes
We may update this policy; the "last updated" date will change and material changes will be communicated where reasonable.
11. Contact
Privacy questions or requests: service@haltops.com.