Privacy Policy
Effective Date: January 1, 2025
Last Updated: January 1, 2025
Version: 1.0
Table of Contents
1. Introduction
IntellectAPI.io ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our B2B SaaS API platform for sports betting predictions and analytics.
This policy applies to all users of our Service, including tenant account holders, API consumers, and website visitors.
2. Data Controller Information
IntellectAPI.io is the data controller for personal data collected through our Service. Our contact information is:
- Company: IntellectAPI.io
- Email: privacy@intellectapi.io
- Support: support@intellectapi.io
- Address: [Your business address]
3. Data We Collect
3.1 Tenant Account Data
When you create a tenant account, we collect:
- Email address and password
- Company name and contact information
- Billing address and payment information (processed by Paddle)
- Subscription plan and usage preferences
- Consent timestamps for Terms and Privacy Policy
3.2 API Usage Data
When you use our APIs, we automatically collect:
- API request logs and response data
- IP addresses and user agents
- Rate limit usage and performance metrics
- Error logs and debugging information
- Webhook delivery status and retry attempts
3.3 Technical Data
We collect technical information including:
- Session cookies and authentication tokens
- Device information and browser type
- Operating system and screen resolution
- Referral sources and navigation patterns
- Server logs and system performance data
3.4 Communication Data
When you contact us, we collect:
- Support tickets and email correspondence
- Feedback and survey responses
- Marketing communication preferences
- Training and documentation usage
4. Legal Basis for Processing (GDPR)
We process personal data based on the following legal grounds:
4.1 Contract Performance
We process data necessary to provide our Service, including account management, API access, billing, and support.
4.2 Legitimate Interest
We process data for legitimate business interests including:
- Service improvement and optimization
- Security monitoring and fraud prevention
- Analytics and usage statistics
- Technical support and troubleshooting
4.3 Consent
We process data based on your explicit consent for:
- Marketing communications
- Non-essential cookies
- Data analytics beyond service delivery
4.4 Legal Obligation
We may process data to comply with legal requirements, including tax reporting, audit trails, and regulatory compliance.
5. Purpose of Processing
We use your personal data for the following purposes:
5.1 Service Delivery
- Providing API access and data feeds
- Managing subscriptions and billing
- Delivering webhook notifications
- Providing technical support
5.2 Service Improvement
- Analyzing usage patterns and performance
- Developing new features and capabilities
- Optimizing API performance and reliability
- Conducting research and analytics
5.3 Security and Compliance
- Monitoring for abuse and unauthorized access
- Maintaining audit logs and compliance records
- Preventing fraud and security threats
- Ensuring data integrity and availability
6. Data Sharing
We may share your personal data with the following third parties:
6.1 Service Providers
- Paddle: Payment processing and billing (PCI-DSS compliant)
- Resend: Email delivery and notifications
- PostgreSQL Hosting: Database storage and management
- Redis Hosting: Session and cache management
- Railway: Application hosting and infrastructure
6.2 Legal Requirements
We may disclose data when required by law, court order, or to protect our rights, property, or safety, or that of our users or the public.
6.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your data may be transferred to the new entity, subject to the same privacy protections.
6.4 Consent
We may share data with your explicit consent for specific purposes not covered above.
7. Data Retention
We retain personal data for the following periods:
7.1 Account Data
- Active Accounts: Retained while account is active
- Closed Accounts: Retained for 7 years for legal and tax purposes
- Billing Records: Retained for 7 years as required by law
7.2 API Usage Data
- Request Logs: Retained for 90 days for debugging and support
- Analytics Data: Aggregated and anonymized after 2 years
- Error Logs: Retained for 1 year for system improvement
7.3 Marketing Data
- Marketing Communications: Until consent is withdrawn
- Unsubscribed Users: Retained for 2 years to prevent re-contact
8. Data Security
We implement comprehensive security measures to protect your data:
8.1 Technical Safeguards
- End-to-end encryption for data in transit (TLS 1.3)
- Encryption at rest for sensitive data
- Secure authentication and session management
- Regular security updates and patches
- Network firewalls and intrusion detection
8.2 Administrative Safeguards
- Access controls and role-based permissions
- Employee training on data protection
- Regular security audits and assessments
- Incident response procedures
- Data protection impact assessments
8.3 Physical Safeguards
- Secure data centers with 24/7 monitoring
- Environmental controls and backup systems
- Restricted physical access to servers
9. International Transfers
Your data may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place:
9.1 Adequacy Decisions
We transfer data to countries with adequate data protection laws as recognized by the European Commission.
9.2 Standard Contractual Clauses
For transfers to countries without adequacy decisions, we use Standard Contractual Clauses approved by the European Commission.
9.3 Service Provider Safeguards
All our service providers are required to maintain appropriate data protection standards and are bound by contractual obligations.
10. Your Rights
Under GDPR and other applicable laws, you have the following rights:
10.1 Right of Access
You can request a copy of all personal data we hold about you, including how it's being used and with whom it's shared.
10.2 Right to Rectification
You can request correction of inaccurate or incomplete personal data.
10.3 Right to Erasure
You can request deletion of your personal data in certain circumstances, including when it's no longer necessary for the original purpose.
10.4 Right to Restrict Processing
You can request that we limit how we use your data in certain circumstances.
10.5 Right to Data Portability
You can request a copy of your data in a structured, machine-readable format for transfer to another service.
10.6 Right to Object
You can object to processing based on legitimate interests or for marketing purposes.
10.7 Right to Withdraw Consent
Where processing is based on consent, you can withdraw consent at any time.
Exercising Your Rights
To exercise any of these rights, contact us at privacy@intellectapi.io. We will respond within 30 days and may require identity verification.
12. Children's Privacy
Our Service is not intended for children under 18 years of age. We do not knowingly collect personal data from children under 18. If you become aware that a child has provided us with personal data, please contact us immediately.
If we discover that we have collected data from a child under 18, we will delete such information promptly.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Sending an email to your registered address
- Posting a notice on our website
- Updating the "Last Updated" date at the top of this policy
Continued use of the Service after changes constitutes acceptance of the updated Privacy Policy.
14. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
- Privacy Officer: privacy@intellectapi.io
- General Support: support@intellectapi.io
- Data Protection Officer: dpo@intellectapi.io
- Address: [Your business address]
Complaints
If you have concerns about our data practices, you can also contact your local data protection authority or the relevant supervisory authority in your jurisdiction.