Data Collection and Use
Collects name, payment, usage data, and cookies for services.
🌐 drdata.ddev.site
Mentions encryption and multi-factor authentication, but lacks specifics on sensitive data handling (e.g., biometrics, location) and cookie consent granularity.
References GDPR, lists data subject rights, and mentions standard contractual clauses for transfers, but lacks explicit CCPA mention and has a future effective date (2026).
Provides user rights and opt-out for marketing, but terms are one-sided (e.g., broad legitimate interests) and lacks user recourse details beyond contacting DPO.
Uses plain language and examples, but is lengthy and includes boilerplate; cookie consent interface is present but complex.
- The privacy policy has a prospective effective date of "01 June 2026," which is in the future, making it unclear if the policy is currently in effect or if it has been backdated.
- The Data Protection Officer (DPO), Dr Joseph Bonello, is listed as a contact but the email provided is a generic Gmail address (drdata@gmail.com), which is not a professional or organizational domain, raising concerns about the legitimacy and security of data handling practices.
- The policy references a "GDPR privacy policy template" but does not provide a link or specify the source, making it difficult to verify the template's compliance or any associated terms.
- The "Data Transfer Outside the EU" section mentions using standard contractual clauses or safeguards but does not specify which countries the data is transferred to, or list any specific service providers or partners involved in these transfers.
- The policy does not specify the retention periods for different types of personal data, such as payment details or cookies, beyond a vague reference to storing order history for 7 years, leaving potential for indefinite retention of data like browsing behavior.
- The cookie consent management section includes categories like "Functional" (labeled as always active) but the purpose description is vague, and the "Statistics" purpose mentions processing "anonymous statistical purposes" but then states it can identify users, which is contradictory and unclear.
- The policy lacks a specific, detailed cookie policy link—it only says "You can access our full cookie policy [here]" with a broken or generic placeholder, meaning the user cannot actually view the full policy.
- The "Data Security" section lists general measures like encryption and multi-factor authentication but does not provide specific details about encryption standards (e.g., AES-256), authentication protocols, or how data is secured during storage and transmission.
- The policy mentions "standard contractual clauses" for data transfers but does not explain how users can access a copy of these clauses or where they are published, reducing transparency.
- The "Data Subject Rights" section outlines rights like erasure and portability but does not specify the timeframe for responding to requests (GDPR requires one month), nor does it provide a mechanism for submitting requests beyond a generic email address.
- The "Changes to this Policy" section states that users will be notified of significant changes but does not specify how notification will occur (e.g., email, website banner) or what constitutes a "significant change."
- The policy includes a copyright year of 2026 on the website footer and in the policy, but the document's effective date is also 2026, which may indicate a lack of a proper revision history or previous versions.
- The "Use of Cookies and Other Trackers" section mentions "personalized advertising" but does not state whether third-party cookies are used, or what specific advertising partners or networks are involved.
- The policy's structure mixes general informational content with specific examples, which could be confusing for users trying to understand their legal rights versus illustrative scenarios.
Collects name, payment, usage data, and cookies for services.
Processes data for services, support, legal compliance, and marketing.
You can access, rectify, erase, or port your data.
Transfers data outside EU with safeguards like standard clauses.
Uses encryption and training to protect personal data.
Install the free Termzy AI browser extension and get instant AI-powered analysis of any legal document you encounter online.
Add Termzy AI to the Browser - It's Free