Your data is yours. We handle all information with the highest standards of privacy and GDPR compliance.
1 Information We Collect
Account Information
Name, email address, phone number, and password when you create an account.
Appeal Data
Information related to your appeals, including platform names, account identifiers, content descriptions, appeal reasons, and supporting documentation.
Technical Data
- Device Information: Browser type, operating system, device identifiers, and screen resolution
- Usage Data: Pages visited, features used, time spent on pages, and interaction patterns
- Information stored through cookies and similar technologies
Communications
Messages you send to our support team or through our contact forms.
Payment Information
Billing address and payment method details (processed securely by our third-party payment provider).
2 How We Use Your Information
- To create and maintain your account, authenticate your identity, and process payments
- To process and manage your appeals, communicate with platforms on your behalf, and provide case updates
- To send you service-related notifications, respond to your inquiries, and provide customer support
- To analyse usage patterns, identify issues, and improve the functionality and user experience of our platform
- To detect, prevent, and address fraud, abuse, security risks, and technical issues
- With your explicit consent, to send you information about new features, services, or promotional offers. You can opt out at any time
3 Legal Basis for Processing (GDPR)
- Contractual Necessity (Art. 6(1)(b)): Processing necessary for the performance of our contract with you, including managing your account, processing appeals, and delivering our services
- Legal Obligation (Art. 6(1)(c)): Processing necessary to comply with EU and member state legal obligations, including tax regulations and anti-money laundering requirements
- Legitimate Interests (Art. 6(1)(f)): Processing necessary for fraud prevention, platform security, service improvement, and analytics, provided these interests do not override your fundamental rights
- Consent (Art. 6(1)(a)): Where you have given explicit consent, such as for marketing communications, non-essential cookies, and optional data collection. You may withdraw your consent at any time
4 Data Sharing & Disclosure
We may share your data with:
- Trusted third-party providers who assist in operating our platform (e.g., cloud hosting, payment processing, email delivery), bound by data processing agreements
- When processing your appeal, we share relevant information with the target platform as necessary to pursue your case
- When escalating appeals to out-of-court dispute settlement bodies certified under the DSA
- When necessary to protect the rights, safety, or property of myAct, our users, or the public
All third-party service providers are required to process your data in accordance with GDPR and our data processing agreements.
5 International Data Transfers
Your personal data is primarily processed and stored within the European Economic Area (EEA). In cases where data must be transferred outside the EEA, we ensure adequate protection through:
- EU adequacy decisions (Art. 45 GDPR) for countries deemed to have adequate data protection
- Supplementary measures as recommended by the European Data Protection Board (EDPB)
6 Data Retention
- Support communications are retained for 2 years for quality assurance and dispute resolution
- Appeal data is retained for 3 years after case resolution to support potential follow-up actions and legal requirements
After the retention period expires, data is securely deleted or anonymised. You may request early deletion of your data at any time, subject to legal obligations that may require continued retention.
7 Your Rights Under GDPR
Under the GDPR, you have the following rights regarding your personal data:
- Right of Access: Obtain confirmation of whether your data is being processed and access a copy of your personal data
- Right to Rectification: Have inaccurate personal data corrected and incomplete data completed
- Right to Restriction: Request restriction of processing under certain conditions
- Right to Portability: Receive your data in a structured, commonly used, machine-readable format and transmit it to another controller
- Right to Object: Object to processing based on legitimate interests, including profiling
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time
- Right to Lodge a Complaint: Lodge a complaint with your local Data Protection Authority (DPA)
To exercise any of these rights, please contact our Data Protection Officer at dpo@arbbio.com. We will respond to your request within 30 days, as required by the GDPR.
8 Cookies & Tracking Technologies
- Strictly Necessary Cookies: Essential for the platform to function properly, including session management and security features. These cannot be disabled
- Analytics Cookies: Help us understand how users interact with our platform to improve performance and usability. Used only with your consent
- Marketing Cookies: Used to deliver relevant communications. Only activated with your explicit consent
9 Children's Privacy
Our Service is not directed to individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that a child under 18 has provided us with personal data, we will take steps to delete such data promptly.
If you are a parent or guardian and believe that your child has provided personal data to myAct, please contact our Data Protection Officer immediately at dpo@arbbio.com.
10 Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will notify you in advance.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your data.
11 Contact & Data Protection Officer
For any questions, concerns, or requests related to this Privacy Policy or the processing of your personal data, please contact: