Legal
Privacy Policy
- Version:
- 1
- Last updated:
- 9/6/2026
Privacy Policy
Effective date: 29 December 2025
Last updated: 29 December 2025
This Privacy Policy explains how WebCreationSuite s.r.l. (“WebCreationSuite,” “WCS,” “we,” “us”) collects, uses, discloses, and protects personal information when you visit webcreationsuite.com, create or use a WCS ID account, and use the WebCreationSuite ecosystem, including (currently as an MVP) PrintFlow, Parcely, and the basic features of myBusiness (business management, teams and users, calendar, chat, and project management). This Policy is designed to be valid for users in the EU/EEA, United Kingdom, United States (including California), and Canada, and it may also apply elsewhere where local laws grant similar rights.
We may release additional modules over time. This Policy is written to cover the full WCS ecosystem, including features that may be added later, and it also covers the WCS Pixel, which is currently used on our website and may later be provided to customers for installation on customer websites.
1. Who we are (Controller) and how to contact us
Data Controller: WebCreationSuite s.r.l.
Registered office: [●]
VAT/Tax ID: [●]
Certified email (PEC): [●]
Postal address: [●]
Privacy contact / DPO (where applicable): Antonio Marin
Email: privacy@webcreationsuite.com
If you have questions about this Policy, want to exercise your rights, or need to report a privacy concern, contact us at privacy@webcreationsuite.com.
EU/UK representative (where required): Antonio Marin (contact: privacy@webcreationsuite.com). If local law requires a different representative entity or address, we will update this Policy accordingly.
2. Scope and roles: when WCS is a Controller vs. a Processor
WCS acts as a Controller for personal information we process to operate our website, manage accounts and authentication (WCS ID), provide and secure the platform, handle billing and payments, communicate with you, and run our own marketing (where permitted).
WCS may act as a Processor / Service Provider when a business customer uses WCS applications to process personal information of their own end users or contacts (for example, documents sent to PrintFlow, shipping/delivery-related records in Parcely, content and attachments submitted through customer workflows, or other “Customer Content”). In those cases, the business customer typically determines the purposes and means of processing and is the Controller, while WCS processes personal information on their behalf under a data processing agreement (“DPA”) and applicable law.
3. Personal information we collect
We collect personal information in three main ways: (a) information you provide directly, (b) information collected automatically when you use our services, and (c) information received from third parties (for example, payment processors or analytics/advertising partners), subject to legal requirements.
Information you provide
When you create an account or use WCS, we may collect identifiers and contact information such as your name, surname, email address, and account identifiers (WCS ID), as well as business-related information such as your business name, team membership, user roles/permissions, and account settings. If you contact support, we collect the information you submit in your request, including any files you attach. Our proprietary support/helpdesk system stores the data needed to manage support operations, including name, surname, email, business ID, WCS ID, and IP address, plus ticket content and metadata.
Information created or processed when you use WCS apps
Depending on the modules you use, we may process operational data and Customer Content. In myBusiness (MVP) this may include calendar data (events, participants, time and reminders), chat data (messages and participants), project/task data, and related metadata. In PrintFlow this may include documents and files submitted for printing, printing options and job metadata, and status communications. In Parcely this may include delivery and operational records that can contain addresses, contact details, shipment references, and communications required to fulfill the service. The specific data types depend on how you configure and use each module.
Information collected automatically
When you visit our website or use our applications, we collect technical and usage information such as IP address, device and browser details, operating system, language, approximate location (derived from IP), session identifiers, timestamps, pages/screens viewed, interactions, error logs, security events, and performance telemetry. We use this information to provide and secure the services, prevent abuse, debug issues, and improve performance and reliability.
Cookies, pixels, and similar technologies
We use cookies, SDKs, tags, and similar technologies to operate the site and services, remember preferences, measure usage, and—where permitted—support advertising and retargeting. These technologies may collect identifiers and interaction events. Your choices may be managed through our cookie/consent controls and browser or device settings, subject to legal requirements in your jurisdiction.
4. How we use personal information (purposes)
We use personal information to provide and operate the WCS ecosystem, including creating and managing accounts, authenticating users, enabling business/team functionality, providing calendar, chat, and project features, delivering PrintFlow and Parcely services, sending transactional communications (such as confirmations and service notifications), and responding to support requests.
We use personal information for security and integrity purposes, including monitoring, access control, fraud prevention, abuse detection, audit trails, incident response, and protecting the rights and safety of users and our platform.
We use personal information to maintain and improve our services, including troubleshooting, product analytics, performance monitoring, and research and development of new features.
Where permitted by law and consistent with your choices, we use personal information for marketing and advertising, including sending newsletters or product updates, measuring campaign effectiveness, and enabling retargeting.
We may also use personal information to comply with legal obligations, respond to lawful requests, and to establish, exercise, or defend legal claims.
5. Legal bases (EU/EEA & UK) and comparable grounds elsewhere
If you are in the EU/EEA or the UK, we process personal data under the GDPR/UK GDPR legal bases. Processing may be necessary to perform a contract (to provide WCS services), comply with legal obligations (for example, accounting/tax requirements), pursue legitimate interests (such as securing the platform and improving services) balanced against your rights, or based on your consent (for example, certain cookies or marketing in jurisdictions that require opt-in).
If you are in the United States or Canada, we process personal information consistent with applicable privacy principles and legal requirements, including transparency, purpose limitation, data minimization, and providing required rights and choices (for example, opt-out of targeted advertising where required).
6. Sharing and disclosures (third parties)
We disclose personal information only as necessary to provide and operate WCS, meet legal requirements, protect our users and services, and run our business.
Service providers and infrastructure partners
We use vendors who process personal information on our behalf to host and deliver our services, provide communications, process payments, and support security and reliability. Based on current operations, these providers include:
- Contabo (cloud hosting; servers located in Europe)
- Cloudflare and bunny.net (CDN and delivery/optimization services)
- Qbox Mail and Amazon SES (transactional and marketing email delivery)
- Stripe (payment processing)
- Sentry (error tracking)
- Prometheus, Grafana, and Loki (observability/monitoring/logging tooling)
- Microsoft services for telemetry/monitoring (service name may vary and will be specified in our sub-processor disclosures as it is finalized)
We require service providers to protect personal information and restrict their use to the services they provide to us, consistent with applicable contracts and law.
Analytics, advertising partners, and pixels
We use analytics and advertising technologies such as Google Analytics, Meta Pixel, TikTok Pixel, Plausible, and our WCS Pixel. These tools may collect information about your interactions and device identifiers via cookies or similar technologies. Where required, we provide consent controls and allow you to adjust preferences. In some configurations, certain partners may act as independent controllers for their own purposes; in other configurations they may act as processors/service providers. We aim to configure these tools to respect consent signals and applicable legal requirements.
Legal and safety disclosures
We may disclose personal information to comply with law, regulation, legal process, or lawful governmental requests; to enforce our terms; to detect or prevent fraud or security issues; or to protect the rights, property, and safety of WCS, our users, or the public.
Business transfers
If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, personal information may be transferred as part of that transaction, subject to appropriate safeguards and notices where required by law.
7. WCS Pixel (present and future customer use)
The WCS Pixel is currently integrated on webcreationsuite.com and may later be offered to customers to install on their own websites. When a customer installs and configures the WCS Pixel on their website, the customer typically determines the purposes (for example, conversion tracking, analytics, or retargeting). In such cases, the customer may be the Controller and WCS may act as a Processor/Service Provider for certain processing activities, depending on configuration and contractual setup.
If the WCS Pixel is used for retargeting or targeted advertising, the customer and/or WCS must ensure that end users receive appropriate notice and that required consent/opt-out mechanisms are provided under applicable law.
8. Targeted advertising, “sale/share” (California) and opt-outs (USA)
We may use pixels and advertising technologies to measure performance and, where enabled, support retargeting or other forms of targeted advertising. Under certain U.S. state privacy laws—especially California (CCPA/CPRA)—sharing identifiers and interaction data with advertising partners for cross-context behavioral advertising may be considered a “share” of personal information, and in some cases could be interpreted as a “sale” under statutory definitions, even if no money is exchanged.
Where required, we provide mechanisms to opt out of the sale and/or sharing of personal information and to opt out of targeted advertising. Typically, this is done through our cookie/consent controls and any “Do Not Sell or Share My Personal Information” mechanism we provide on the site. If you submit an opt-out request via privacy@webcreationsuite.com, we will also process it in accordance with applicable law.
Where legally required, we will process opt-out preference signals (such as browser-based signals) when they are recognized and verifiable in our environment. The specific availability of such signals may depend on your browser, device, and technical feasibility.
We do not knowingly discriminate against you for exercising privacy rights.
9. International data transfers (EU/UK/Canada/USA)
Our primary servers are located in the European Union. However, some of our vendors (including analytics, advertising, email, or global infrastructure providers) may process or access personal information from countries outside the EEA/UK, including the United States and Canada.
When we transfer personal data from the EEA or UK to countries without an adequacy decision, we use appropriate safeguards such as the European Commission Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum (where applicable), and we may conduct transfer impact assessments and implement supplementary measures such as encryption and strict access controls.
For Canada (PIPEDA), we take steps to ensure cross-border processing is handled with appropriate contractual and security protections, and we remain accountable for personal information transferred to third parties for processing.
10. Data retention and deletion
We retain personal information only as long as necessary for the purposes described in this Policy, unless a longer retention period is required or permitted by law (for example, tax/accounting rules) or needed for security, dispute resolution, or enforcement of agreements.
Based on current retention targets, WCS applies the following standard periods, subject to legal requirements and legitimate operational needs:
Account and profile data may be retained for up to 10 years. Billing and accounting-related information may be retained for up to 10 years. Security and audit logs may be retained for up to 10 years. Marketing-related records may be retained for up to 10 years where lawful and relevant. Certain operational content and Customer Content (for example, files and data processed for PrintFlow/Parcely or certain project-related content) may be retained for up to 1 year, unless deleted earlier by the customer or required longer for contractual or legal reasons.
If you request deletion or close your account, we apply a 90-day grace period during which data may remain in active systems to support restoration or to address errors, fraud prevention, or disputes. After the grace period, data is removed from active systems and may remain only in backups until the last backup containing that data expires, which may be up to 1 additional year. Backup data is protected and is not used for routine operations; access is restricted and typically occurs only to restore systems after serious incidents.
11. Security measures (encryption and protections)
We implement technical and organizational measures designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. We generally use encryption in transit via secure protocols (such as TLS 1.2+ / TLS 1.3) to protect communications between your devices and our services. Where applicable, we use encryption at rest (such as AES-256 or equivalent) to protect stored data and backups, together with secure key management practices.
We employ access controls based on least privilege, authentication safeguards, role-based permissions, logging and monitoring of relevant security events, and operational security practices such as vulnerability management and patching. We also maintain monitoring and alerting through observability systems and may apply network and application protections (including CDN/WAF capabilities where used).
If a personal data breach occurs, we follow an incident response process to contain and remediate the issue. Where required by law, we will notify competent authorities and affected individuals within legally mandated timeframes and provide information about recommended protective steps.
12. Children and age restrictions
WCS services are primarily intended for professional and business use and are not directed to children. We do not knowingly collect personal information from children where prohibited by applicable law. Because age thresholds vary by jurisdiction, we apply protections consistent with the local laws of the end user, including the EU/UK rules on children’s consent for information society services and U.S. requirements such as COPPA where applicable.
If you believe a child has provided us with personal information without appropriate authorization, please contact privacy@webcreationsuite.com so we can investigate and take appropriate action, including deletion where required.
13. Your rights and how to exercise them
EU/EEA and UK (GDPR / UK GDPR)
If you are located in the EU/EEA or UK, you may have the right to request access to your personal data, rectification, erasure, restriction of processing, data portability, and to object to processing (including objection to direct marketing). Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of processing before withdrawal. You also have the right to lodge a complaint with your local supervisory authority (for example, in Italy the Garante per la protezione dei dati personali; in the UK the Information Commissioner’s Office).
United States (including California CCPA/CPRA and other state laws)
Depending on your state of residence, you may have rights to know/access, delete, correct, obtain a copy of your information, and to opt out of targeted advertising and certain disclosures sometimes described as “sale” or “sharing.” You may also have the right not to be discriminated against for exercising privacy rights. California residents may have additional rights regarding “Sensitive Personal Information” where applicable, including limiting certain uses, and rights to use an authorized agent to submit requests on their behalf, subject to verification requirements.
Canada (PIPEDA)
If you are in Canada, you generally have rights to access your personal information, request corrections, and obtain information about how we use and disclose personal information, subject to limited exceptions permitted by law.
How to submit a request and verification
To exercise rights, contact us at privacy@webcreationsuite.com and include the email associated with your account and a clear description of your request. To protect you, we may need to verify your identity before fulfilling certain requests. If we cannot fulfill a request in full (for example, because retention is required by law or because the information is necessary to complete a transaction), we will explain the reason and, where available, provide alternatives.
14. Automated decision-making and profiling
We may use automated tools to support security monitoring, fraud prevention, and service performance (for example, detecting suspicious login activity or abnormal usage). These systems are designed to protect the service and users and generally do not produce legal or similarly significant effects without human review, unless explicitly stated and permitted by applicable law.
15. AI and large language models (planned)
WCS may in the future integrate AI features using providers such as Google Gemini and OpenAI. At the time of this writing, these features are not currently planned for active processing in the MVP. If and when AI features are introduced, we will update this Policy and provide appropriate notices explaining what data is processed, for what purposes, and what choices and controls are available, including any contractual and transfer safeguards required by law.
16. Changes to this Policy
We may update this Privacy Policy to reflect changes to our services, technologies, legal requirements, or business practices. We will post the updated version on /privacy and update the “Last updated” date. If changes are material, we may provide additional notice (for example, via email or in-product notification) where required.
17. Related notices
This Privacy Policy should be read together with our Cookie Policy at /cookies and our Terms of Service at /terms. If you are a business customer and WCS acts as a Processor on your behalf, additional terms may be provided in a Data Processing Agreement (DPA): [●].