Privacy Policy
Last updated
This policy explains what personal data LOFISTACK collects, why we collect it, who we share it with and what you can ask us to do with it. We have tried to write it in plain language; where a term has a specific legal meaning we have said so.
Who we are
LofiStack Ltd. ("LOFISTACK", "we", "us") builds software products (LofiBook, LofiCRM, LofiConnect and Restaurant) and delivers client engineering and design engagements. We are the data controller for personal data collected through this website and through those products, unless we are processing it on a client's behalf under a written agreement, in which case that client is the controller and their policy governs.
Our registered address is Agrabad, Chittagong, Bangladesh. You can reach us about anything in this policy at privacy@lofistack.com.
What we collect
We collect three kinds of information, and we try to collect as little of each as the thing you are doing requires.
- Information you give us. Your name, email address, company and whatever you write when you contact us, book a call, or sign up for a product. If you become a customer, this extends to billing details, which are handled by our payment processor; we do not store full card numbers.
- Information we collect automatically. IP address, browser and device type, pages visited, referring page and approximate location derived from IP. This arrives through server logs and, where you have consented, analytics cookies.
- Information from our products. Content you create in a LOFISTACK product, account settings, and diagnostic logs recording errors and performance. We access this only to run the service, to support you when you ask, or where we are legally required to.
Why we use it, and on what basis
Under the GDPR and comparable laws we need a lawful basis for each use. Ours are:
- To provide the service you asked for: performance of a contract. Running your account, delivering an engagement, answering a support request.
- To operate and improve the site and products: legitimate interests. Keeping things fast and secure, understanding which pages are useful, diagnosing faults. We balance this against your interests and use aggregate data where we can.
- To send you marketing: consent. Only if you opted in, and every message carries an unsubscribe link that works.
- To meet legal and accounting obligations: legal obligation. Tax records, statutory retention, responding to lawful requests.
International transfers
Our providers may process data outside the country you are in, including outside the EEA and UK. Where that happens we rely on an adequacy decision where one exists, and otherwise on Standard Contractual Clauses together with a transfer risk assessment. You can ask us for details of the safeguards applied to a specific transfer.
How long we keep it
We keep personal data only as long as we need it for the purpose we collected it for, and then delete or anonymise it. In practice that means: enquiry and contact records for 24 months after our last exchange; customer account data for the life of the account and 90 days after closure, except where tax or accounting law requires longer; server and diagnostic logs for 30 days; and marketing consents until you withdraw them.
Your rights
Depending on where you live, you have some or all of the following rights over your personal data. We will not charge you for exercising them and we will respond within one month.
- Access: get a copy of the personal data we hold about you.
- Rectification: have inaccurate or incomplete data corrected.
- Erasure: have data deleted where we no longer have grounds to keep it.
- Restriction and objection: limit or object to processing based on our legitimate interests, including profiling.
- Portability: receive data you gave us in a structured, machine-readable format.
- Withdraw consent: at any time, without affecting processing already carried out.
- Complain: to your local supervisory authority. We would rather you came to us first, but it is your right either way.
Security
We use encryption in transit, access controls scoped to what each person needs, audit logging on administrative actions, and regular dependency and infrastructure patching. No system is perfectly secure, and we will not claim otherwise. If a breach affects your personal data and is likely to result in a risk to your rights, we will notify you and the relevant authority within the statutory deadline.
Children
Our site and products are not directed at children under 16 and we do not knowingly collect their personal data. If you believe a child has given us personal data, contact us and we will delete it.
Changes to this policy
We update this policy when what we do changes. The date at the top of the page is the date of the current version. Where a change materially affects your rights we will tell you directly rather than relying on you noticing the date.
Contact
Questions, requests and complaints all go to privacy@lofistack.com, or by post to LofiStack Ltd., Agrabad, Chittagong, Bangladesh.