Privacy Policy
How we collect, use, and share personal data when you visit itsailor.io, use our tools, or buy our products. Written plainly, GDPR-aligned, audit-ready.
Summary
ITSailor is the trading name of Michal Jatczak, a sole trader registered in Malta. We collect the minimum data needed to run our tools, fulfil paid workshops, and deliver SaaS subscriptions. Most of it stays inside the EU (Hetzner, Germany). We keep the Standard Contractual Clauses in place with every non-EEA subprocessor, including the AI providers named in section 03, give you full GDPR rights, and never run third-party ad trackers.
Who we are
ITSailor is the trading name of Michal Jatczak, a sole trader registered in Malta, operating from Level 1, Unit 60, Door No 63, Connecticlub Business Center, Triq Il-Ballut (Zona Industrijali, Mosta), MST 4001, Mosta, Malta. Malta VAT number MT32760411, DUNS number 507601021. Microsoft AI Cloud Partner Program Authorized partner, PLA ID 7113951. References to "we", "our", "ITSailor" in this Policy mean Michal Jatczak T/A ITSailor.
This Privacy Policy explains how we collect, use, and share personal data when you (a) visit itsailor.io, (b) use any of our free diagnostic tools, (c) purchase a paid workshop or eBook, (d) sign up for our SaaS products (SEAWALL FinOps Engine, HOIST autonomous IT support, DECKLOG knowledge operations - currently in sales MVP phase), or (e) contact us for consulting work.
We act as a data controller (GDPR Article 4(7)) for the data described below. This Policy is the controller-side transparency notice required by GDPR Articles 13 and 14 for the data we process as controller. Where we act as processor (see section 11), the Article 13 and 14 information for the individuals concerned is provided by you as controller.
For personal data you instruct us to process inside your own systems (for example during a paid consulting engagement), we act as a data processor (Article 4(8)) under a separate Data Processing Agreement (DPA) incorporating the Article 28(3) processor clauses, to be executed with you before any such processing begins. We do not process personal data on your behalf without it.
Data we collect
- Tool submission data. Email, optionally name and company, plus the inputs and results of any diagnostic tool you choose to submit (e.g. Microsoft 365 license CSV metadata, GitHub repo URL, deliverability scan results, automation ROI calculator inputs). Most tools work without submission - submission is opt-in for receiving a report by email.
- Workshop and eBook purchase data.Name, work email, company, selected SKU (€499 Architecture & Security Design Workshop, €149 Microsoft 365 Tenant Hardening, €99 eBooks), order timestamp, billing address (where required), and Stripe customer ID.
- SaaS account data (SEAWALL / HOIST / DECKLOG). Email, hashed password, role, subscription tier and status, Stripe customer ID, and audit logs of dashboard actions. Where the product integrates with your cloud or knowledge sources (e.g. Azure tenant, SharePoint, GitHub), we collect only the minimum metadata required for the integration to function.
- CSP licence order data. Where you buy Microsoft licences through the marketplace checkout: organisation identity and billing data, EU VAT ID (VIES verification result retained as tax evidence), Microsoft tenant ID and/or domain, company registration number, MCA signatory name and email, and the SKUs, seat counts, and terms you order. Processed as controller to place and manage licence orders; see the CSP Marketplace Terms section 07 for the full data-roles picture.
- Billing data. Stripe processes card data on our behalf; we never see or store full card numbers. We retain Stripe customer IDs, invoice metadata, and subscription state.
- Usage data. IP address, user agent, referrer, and minimal request logs of itsailor.io and the SaaS dashboards. We do not run third-party advertising trackers and we do not sell usage data.
- Contact and lead data. If you fill in the contact form or open a chat session, we retain your name, email, organisation, selected request route, message content, optional scoping details, originating page context, receipt reference, and delivery state for the time required to follow up plus retention defined in section 05. Contact-form anti-abuse checks also process the submitting IP address and reCAPTCHA risk result; these are not used for lead scoring.
- Ops Log newsletter data. If you subscribe, we process your email address, optional company name, signup source, consent version and timestamp, confirmation status, and delivery state. We use double opt-in. Confirmation and unsubscribe links use short-lived or signed tokens rather than exposing your email address in the URL.
- Cookie consent records. Every decision you make in the cookie banner or the preferences panel writes an audit row: the categories you chose, the consent schema version, a random consent ID, the event type (accept all, reject all, save selection, withdraw), your browser user agent, and a salted one-way hash of your IP address rather than the address itself, with a server timestamp. We keep this so we can demonstrate consent under Article 7(1). The full cookie inventory is in the Cookie Policy.
AI features: what is sent, to whom, and on what basis
We use two AI providers, both named in section 03. This is the complete per-path picture, written from the code that makes the call rather than from a product description.
- Free diagnostic report (OpenAI). When you submit the email deliverability check, the Microsoft 365 licence waste audit or the offboarding risk profiler in order to receive a report, the tool inputs and the computed results are sent to OpenAI to write it. This is not a separate opt-in: asking for the report is what starts it. Your email address is deliberately kept out of the prompt and is used only to deliver the finished report. Legal basis: Article 6(1)(f), our legitimate interest in delivering the report you asked for (see section 02, and your right to object).
- SaaS Auditor Captain's Brief and SaaS Command Brief (Anthropic). Only aggregate figures are sent: counts, money, reason buckets and third-party application names. The per-user identity list is assembled in your browser and does not form part of the payload. Legal basis: Article 6(1)(f) when you use the free tool, Article 6(1)(b) where the feature forms part of a paid subscription.
- Contract extraction in the spend register (Anthropic). If you upload a contract, order form, quote or renewal notice, the complete PDF (up to 8 MB) is transmitted as it is. It is not de-identified and not redacted: whatever the document contains, including signatory names and contact details, goes with it. We do not store the file. Nothing is sent unless you choose to upload. Legal basis: Article 6(1)(f) when you use the free tool, Article 6(1)(b) where the feature forms part of a paid subscription.
- Weekly Platform Health Briefing (OpenAI). For subscribers who enrol a repository for continuous monitoring, the scan signals and findings are sent together with your first name, or your email address where we hold no first name, so the briefing can address you. Legal basis: Article 6(1)(b), it is part of the subscription you bought.
- Ops Log article drafting (Anthropic). Internal editorial use. The input is our own session and source material; it is not a customer data path.
HOIST and DECKLOG are in sales MVP and run no AI feature over customer data today. If that changes, this section and the subprocessor list in section 03 are updated first, under the 30-day notice described there.
Where we get your data from someone else (Article 14)
One category does not come from you. When an organisation buys Microsoft licences through our marketplace checkout, that organisation gives us the name and business email address of the person who will sign the Microsoft Customer Agreement, and of any tenant administrator it names. If that is you, here is the Article 14 notice:
- Source. The organisation placing the order. We did not obtain your details from a public source, a data broker or any list.
- Categories. Name, business email address, and the role you hold in the order (MCA signatory, tenant administrator).
- Purpose and basis.Placing and provisioning the licence order. Article 6(1)(b) where you are a party to the arrangement, otherwise Article 6(1)(f): our and the purchasing organisation's legitimate interest in getting the tenant activated for the person Microsoft requires to be named.
- Recipients. Microsoft and Pax8, as described in section 03.
- Retention and rights. As set out in sections 05 and 06. You can object under Article 21 and ask for erasure under Article 17 without asking the organisation first.
We provide this notice at the latest when we first contact you (GDPR Article 14(3)). A company registration number is data about the entity, not about a person, so it is outside this notice.
Why we process it and legal basis
- Performing the contract (Art. 6(1)(b) GDPR) - account creation, billing, support, and delivery of paid workshops, eBooks, and SaaS subscriptions.
- Legitimate interests (Art. 6(1)(f) GDPR). The interests we actually pursue, named rather than summarised: keeping the service available and free of abuse; understanding in aggregate which pages and tools are useful, so we build the next thing on evidence; and replying to a business enquiry you chose to send us, including the AI-written report you asked for. Contact confirmations are transactional messages about that request, not marketing. We carry out a balancing test before relying on this basis for a purpose and record the outcome; ask for a summary of any of them at privacy@itsailor.io. You can object to any of this processing under Article 21, described separately in section 06.
- Legal obligation (Art. 6(1)(c) GDPR) - tax and accounting records under Maltese law (7-year retention); responding to lawful requests from regulators or courts.
- Demonstrating consent (Art. 6(1)(c) GDPR read with Art. 7(1)) - the cookie consent audit records described in section 01. We are required to be able to show that consent was given, which we cannot do without keeping a record of the decision.
- Consent (Art. 6(1)(a) GDPR) - optional newsletter; non-essential cookies (subject to your cookie banner choice); optional AI feature opt-ins. You can withdraw consent at any time from your dashboard or by emailing privacy@itsailor.io.
Whether you have to give us the data, and what happens if you do not
Article 13(2)(e) requires us to tell you which data you are obliged to provide and what follows if you withhold it. Per category:
- Free tools, the contact form and the newsletter. Entirely voluntary. There is no statutory or contractual requirement to give us anything. The only consequence of withholding is that no report, no reply and no newsletter is sent.
- Workshops, eBooks and SaaS subscriptions. Name, work email and billing details are a contractual requirement: we cannot invoice you or deliver the purchase without them, so the order cannot proceed. Billing country is additionally required as place-of-supply evidence under Article 24b of Council Implementing Regulation (EU) 282/2011, and those records are retained for 7 years under Maltese tax law.
- CSP licence orders.The MCA signatory's name and email are required by Microsoft before a tenant can be activated. A VIES-verifiable VAT ID is required by us to apply the reverse charge under Article 196 of Directive 2006/112/EC. The company registration number and the Microsoft tenant ID are required to provision the order at all. These are contractual requirements arising from the vendor terms and our tax position, not statutory obligations we impose on you. If any of them is withheld the order is not placed and any payment taken is refunded.
Subprocessors
We share personal data with the following subprocessors strictly to deliver the Services. Where data leaves the EEA we rely on the European Commission's Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) with every non-EEA subprocessor, and additionally on the EU-US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795) where the subprocessor self-certifies under it. Technical measures apply alongside both: TLS 1.2 or higher in transit, and encryption at rest. See section 04 for detail.
- Stripe Payments Europe Ltd. - payment processing and subscription billing (Ireland; EU-based, SCCs for any US data routing).
- Resend, Inc. - transactional email delivery for workshop provisioning, eBook delivery, and SaaS notifications (USA; EU-US DPF certified, SCCs as fallback).
- Upstash, Inc. - managed Redis storage for newsletter consent records, contact idempotency state, confirmation state, rate limits, and scheduled delivery jobs (USA; Data Processing Addendum and SCCs apply to transfers of customer personal data).
- Hetzner Online GmbH. - production server hosting (Falkenstein, Germany) and Storage Box backups. Houses our n8n automation, Directus backend, Postgres databases, and SaaS application data. EU jurisdiction.
- Cloudflare, Inc. - DNS, CDN, and Zero Trust Tunnel for our self-hosted services (USA; EU-US DPF certified, SCCs as fallback; EU edge nodes serve EU traffic).
- Vercel, Inc. - frontend hosting and edge logs for itsailor.io (USA; EU-US DPF certified, SCCs as fallback; EU edge regions preferred).
- Anthropic (Claude API).- generation of the SaaS Auditor Captain's Brief and SaaS Command Brief from aggregate scan figures, with no directory identity in the payload; extraction of commercial terms from a contract, order form, quote or renewal notice you choose to upload, where the complete PDF of up to 8 MB is transmitted as it is and is not de-identified; and internal drafting of Ops Log articles. Processing takes place outside the EEA and we rely on the Standard Contractual Clauses. Retention is governed by the provider's data processing agreement. The provider's terms provide that API inputs are not used to train models.
- OpenAI (API).- generation of the diagnostic report emailed to you after a free-tool submission, and of the weekly Platform Health Briefing for subscribers who enrol a repository for monitoring. Processing takes place outside the EEA and we rely on the Standard Contractual Clauses. Retention is governed by the provider's data processing agreement. We do not publish a retention figure of our own for this path: the period is set by the provider and can change without notice to us, and a number we cannot hold to is worse than no number. The provider's terms provide that API inputs are not used to train models.
- Cal.com. - scheduling for discovery calls, product demos and paid workshop sessions. When you open a booking link we send you, the name, email address, chosen slot, timezone and any notes you type are processed by the scheduling provider on our behalf. Where that processing takes place outside the EEA we rely on the Standard Contractual Clauses.
- DocRaptor.- rendering the PDF of an eBook you have purchased. The render request carries the publication HTML, which includes the single-user licence line bearing your email address. Processing takes place outside the EEA and we rely on the Standard Contractual Clauses. Retention is governed by the provider's data processing agreement.
- Google LLC (reCAPTCHA). - automated abuse and fraud risk analysis on our public contact and scan-request forms. reCAPTCHA may process device, network and interaction data and set the necessary
_GRECAPTCHAcookie (USA; Google's applicable data-transfer safeguards and terms apply). The cookie itself is itemised under third-party cookies in the Cookie Policy. - Plausible Insights OÜ. - opt-in, cookie-free website and conversion analytics hosted in the EU. We suppress private routes, form contents, arbitrary query parameters, and dynamic report identifiers before an event is sent. Plausible is not used for advertising or cross-site profiling.
- GitHub, Inc. - private repository hosting for client deliverables (Terraform modules, Intune baselines, SOPs), and authentication for the DevEx Maturity Scan tool (USA; EU-US DPF certified under the Microsoft umbrella, SCCs as fallback).
- Microsoft Ireland Operations Limited. - Microsoft 365 services where you choose to purchase through us via the Pax8 marketplace.
- Pax8 Inc. - Microsoft 365 licensing marketplace (EU operations from the Netherlands). Only billing metadata flows to Pax8 when you purchase Microsoft licences through us; your Microsoft tenant data does not.
Four rows above (Anthropic, OpenAI, Cal.com, DocRaptor) name the service rather than a corporate entity. That is deliberate: we do not print a contracting entity or a certification we have not verified against the provider's own data processing agreement. Write to privacy@itsailor.io and we will tell you which entity we contract with and on what transfer basis.
International transfers
Most personal data is stored and processed inside the EU/EEA (Malta, Germany, Ireland, Netherlands). Some personal data is transferred to US-headquartered subprocessors that operate EU regions or EU edge nodes. For each such transfer we rely on a Chapter V GDPR mechanism:
- The Standard Contractual Clauses (Implementing Decision (EU) 2021/914, Modules Two and Three as applicable), which we keep in place with every non-EEA subprocessor regardless of its Framework status. If the Data Privacy Framework adequacy decision were suspended or annulled, these clauses continue to govern the transfer without interruption.
- The EU-US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795 of 10 July 2023), in addition, where the subprocessor self-certifies under it. Stripe, Resend, Cloudflare, Vercel, Microsoft and GitHub self-certify, and we check each listing on the public Data Privacy Framework List when we revise this Policy. The four subprocessors added in August 2026 (Anthropic, OpenAI, Cal.com, DocRaptor) are deliberately absent from that group: we do not publish a certification we have not verified, so those transfers rest on the clauses above alone.
Getting a copy of the clauses. Where a transfer relies on the Standard Contractual Clauses, you can obtain a copy of the clauses we have concluded, with commercially confidential terms redacted, by writing to privacy@itsailor.io. You do not have to be a customer to ask (GDPR Article 13(1)(f)).
Consistent with the CJEU's judgment in Schrems II (C-311/18), we apply supplementary technical measures alongside the SCCs: encryption in transit (TLS 1.2 minimum), encryption at rest where supported, and minimisation of the personal data flowing to non-EEA endpoints. A transfer impact assessment (TIA) summary is available to active customers on written request under NDA.
The Framework adequacy decision remains in force. The General Court dismissed the action against it on 3 September 2025 (Case T-553/23, Latombe v Commission), an appeal was lodged on 31 October 2025, and that appeal is pending before the Court of Justice as Case C-703/25 P. Because we keep Standard Contractual Clauses in place with every US subprocessor regardless, a change to the Framework would not interrupt any transfer.
Retention
- Tool and campaign lead data - up to 24 months from last interaction, then deleted or anonymised. Public contact briefs use the shorter period below.
- Customer account data - for the duration of the subscription or engagement, and 12 months after termination, then deleted unless legally required.
- Billing records - 7 years (Maltese tax law).
- Security and HTTP request logs - 90 days rolling.
- Dashboard audit logs (who did what inside your account) - for the duration of the subscription and 12 months after termination, so that we can answer an access request or settle a dispute about an action taken in the account.
- Cookie consent records - 24 months from the decision, then deleted. Each new decision writes its own row, so a withdrawal is retained on the same footing as the consent it withdraws.
- Contact form and chat messages - 12 months from last interaction. Short-lived contact idempotency records expire after 24 hours; rate-limit state expires with its configured window.
- Newsletter subscribers - until you unsubscribe; we honour unsubscribe requests immediately and purge from active lists within 30 days.
Your rights (GDPR)
If your personal data is subject to the GDPR (Regulation 2016/679) you hold the following rights, exercisable free of charge in the first instance (Article 12(5)):
- Access (Article 15) - request a copy of personal data we hold about you and the processing context.
- Rectification (Article 16) - correct inaccurate or incomplete data.
- Erasure (Article 17) - request deletion (subject to the retention rules in section 05 and to any legal-obligation exemptions in Article 17(3)).
- Restriction (Article 18) - limit how we process your data while a dispute or correction is pending.
- Portability (Article 20) - receive your data in a structured, commonly-used, machine-readable format and transmit it to another controller.
- Object (Article 21) - set out separately immediately below, as Article 21(4) requires.
- Withdraw consent (Article 7(3)) - where processing relies on consent under Article 6(1)(a) or 9(2)(a); withdrawal does not affect prior lawful processing.
- Not be subject to solely automated decisions (Article 22) - see section 10. We do not run such decisions today.
- Lodge a complaint (Article 77) with the Information and Data Protection Commissioner of Malta (IDPC) - our lead supervisory authority - or with the supervisory authority of your EU/EEA Member State of residence.
Security
Per GDPR Article 32, we implement technical and organisational measures appropriate to the risk of the personal data we process. These include TLS 1.2+ in transit, encryption at rest for databases that support it, principle-of-least-privilege access, dependency scanning, server hardening (UFW, fail2ban, unattended security patches), automated daily backups to off-site Storage Box, and secret rotation procedures. We use the same baseline we deliver to our clients - see our public Architecture Workshop materials for the technical specifics.
We notify the IDPC of personal data breaches within 72 hours of becoming aware where the breach is likely to result in a risk to the rights and freedoms of natural persons (Article 33). Where the risk is high, we also notify affected individuals without undue delay (Article 34).
Children
None of the Services is directed to children. Most Services are sold business-to-business; where a Service is sold to consumers, the rights described in our Terms of Service and Refund Policyapply. We do not knowingly collect personal data from anyone under 16, and we do not rely on a child's consent as a legal basis for any processing. If you believe a child has provided us with personal data, contact privacy@itsailor.io and we will delete it.
Automated decision-making
Per GDPR Article 22, you have the right not to be subject to a decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you. Where AI features make recommendations on our platform (e.g. HOIST suggesting a ticket resolution path, DECKLOG returning ranked documents, AI Readiness Scan scoring), these are advisory only - a human (your team, or ours during a consulting engagement) makes the final decision, so Article 22 does not apply.
Our current AI features are limited-risk at most. Where the EU AI Act (Regulation 2024/1689) applies a transparency obligation to a feature we operate (for example, making clear when you are interacting with an AI system or viewing AI-generated content), we provide that disclosure at the point of use (Article 50). If we ever add a function that would be classified as high-risk under Annex III, we will complete the applicable conformity and transparency steps before that function goes live, in line with the AI Act's phased application dates.
SaaS Auditor: Google Workspace and Microsoft 365 data
Our SaaS Auditor tool reads your cloud-directory data to produce a posture, licensing, and security report, and, for customers on the paid continuous-monitoring tier, to keep that report current. This section explains exactly what it reads, on what basis, and what we do and do not do with it. Where this section and the rest of this Policy differ, this section controls for SaaS Auditor processing.
Our role: data processor, you are the controller
For the directory data the SaaS Auditor reads from your Google Workspace or Microsoft 365 tenant, you are the data controller and we act as your data processor (GDPR Article 4(8)). We process this data only on your documented instruction, which you give by connecting your tenant and authorising the read-only permissions below. That processing is governed by the controller-to-processor terms required by GDPR Article 28, which we provide and execute before enrolment. Access is strictly read-only: we do not create, modify, or delete anything in your tenant.
What we read, and the exact permissions
Google Workspace. Your Workspace administrator authorises a single ITSailor OAuth client. We request read-only Admin SDK Directory scopes only:
admin.directory.user.readonly- the user list and per-user status, last login, and administrator flag.admin.directory.domain.readonly- domain and customer account information.admin.directory.user.security- per-user third-party OAuth token grants (for Shadow IT discovery) and two-step verification state.
Microsoft 365 (Microsoft Graph). A tenant administrator authorises read-only access. The SaaS Auditor live scan requests exactly these permissions:
User.Read.AllandDirectory.Read.All- directory and user data.AuditLog.Read.All- sign-in and audit activity.Organization.Read.All- tenant and licensing information.SecurityEvents.Read.All- Microsoft Secure Score and security findings.Policy.Read.All- Conditional Access posture.IdentityRiskEvent.Read.All- identity risk signals.Application.Read.All- registered and enterprise applications.RoleManagement.Read.Directory- directory role assignments, so the report can show which accounts hold administrative roles.Reports.Read.All- service usage and activity reports.offline_access- a refresh token, so a scheduled re-scan can run for customers on the paid continuous-monitoring tier. It grants no access to data of its own; it only lets the connector renew its own access token.
We request the minimum permissions needed for the audit and nothing more, and every scope requested is read-only (GDPR Article 5(1)(c), data minimisation). The complete, always-current list of permissions each connector requests, across the SaaS Auditor, the Microsoft 365 Security Scorecard, and the offboarding risk scan, together with the reason for each one and what is stored, is published at itsailor.io/trust/scopes and generated from the code that makes the request, so it stays in sync.
How we handle it
- Pseudonymisation before logging. Before any directory identity is written to our logs, we replace it with a short SHA-256 digest of the form
acct_<hex>. Raw identifiers (email addresses, user principal names, display names) are not written to our logs. The digest is computed without a secret key, so it is a pseudonym and not anonymisation: an identifier you already hold can be tested against it. Pseudonymised log data therefore remains personal data in our hands (GDPR Article 4(5) and Article 32(1)(a); Court of Justice, Case C-413/23 P EDPS v SRB, 4 September 2025; EDPB Guidelines 01/2025). - AI sub-processor.Where you ask for a Captain's Brief or a Command Brief, the aggregate figures behind it are sent to Anthropic to write the narrative; no directory identity is in that payload. Where you upload a contract to the spend register, the complete PDF is sent to Anthropic for extraction. Anthropic is engaged as a sub-processor under GDPR Article 28(2) and 28(4), and the transfer rests on the Standard Contractual Clauses. This addition is announced under the 30-day notice in section 03.
- No model training.Your directory data is not used to train, fine-tune, or improve any AI or machine-learning model, ours or a third party's.
- Retention.For a one-off scan, processing is ephemeral: we hold the data only for as long as it takes to generate your report, then discard it. We store an OAuth refresh token, encrypted, only for customers who enrol in the paid continuous-monitoring (“Tenant Monitor”) tier, and only so the scan can repeat on schedule (GDPR Article 5(1)(e), Article 32(1)(a)).
- You can revoke at any time. Your administrator can revoke our access immediately and independently of us. For Google, remove the grant at admin.google.com or myaccount.google.com; for Microsoft, remove the application under Enterprise applications in Microsoft Entra. Revoking access stops all further reads at once.
- Security. Data is encrypted in transit (TLS 1.2 or higher) and refresh tokens are encrypted at rest, under least-privilege access controls (GDPR Article 32).
Google API Services User Data Policy: Limited Use
ITSailor's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google Workspace data only to provide and improve the SaaS Auditor features you have authorised. We do not transfer it except as necessary to provide those features or as required by law, we do not use it for advertising, and we do not allow humans to read it except with your consent, for security or to comply with applicable law, or where the data has been aggregated and de-identified.
Deletion and complaints
As the controller, you or your administrator may ask us to delete any SaaS Auditor data we hold for your tenant by emailing dsr@itsailor.io; we action verified deletion requests within the timelines in section 06. Our lead supervisory authority for this processing is the Information and Data Protection Commissioner of Malta (IDPC), and you may also lodge a complaint with the supervisory authority in your own EU/EEA Member State (GDPR Article 77).
Changes
Material changes to this Policy will be announced by email at least 30 days before they take effect to all active customers, and posted on this page with a revised effective date. Older versions are available on request.
Contact
- Data Subject Rights requests (access, rectification, erasure, portability, objection, restriction, withdraw consent): dsr@itsailor.io
- General privacy questions: privacy@itsailor.io
- Legal: legal@itsailor.io
- General contact: hello@itsailor.io
We have not appointed a formal Data Protection Officer under Article 37 - our scale and processing categories do not require one. If a DPO is appointed in the future, contact details will be added to this section.
Postal: Michal Jatczak T/A ITSailor, Level 1, Unit 60, Door No 63, Connecticlub Business Center, Triq Il-Ballut (Zona Industrijali, Mosta), MST 4001, Mosta, Malta.