$ cat privacy-policy.md_

Privacy Policy

Last updated: 25 March 2026

This Privacy Policy explains how Kraft Fabrik Media Ltd. processes personal data in connection with Sally, including the website at usesally.com, contact requests, and voluntary support or sponsorship payments.

1. Controller

The controller responsible for processing personal data in connection with this website is Kraft Fabrik Media Ltd., REG-NR: HE 388979, VAT ID: CY10388979R.

Address:
Kountourioti 6, Coral Elite Residences Building 1
8560 Peyia
Cyprus

Contact for privacy questions: hello@usesally.com

2. Categories of data we may process

  • server and technical data such as IP address, browser type, operating system, referrer, timestamps, and device information
  • contact data such as name, email address, company name, and message content if you contact us
  • transaction and billing data necessary to process support payments or sponsorships
  • records of communication, requests, and support history
  • any other information you voluntarily provide to us

3. Purposes of processing

  • to provide and operate the website
  • to maintain stability, security, and abuse prevention
  • to respond to inquiries and communicate with you
  • to process support payments or sponsorships and maintain financial records
  • to comply with legal, tax, accounting, and regulatory obligations
  • to improve the website and the Sally project

4. Legal bases under the GDPR

Where the GDPR applies, we process personal data based on one or more of the following legal bases:

  • Art. 6(1)(b) GDPR — performance of a contract or steps prior to entering into a contract
  • Art. 6(1)(c) GDPR — compliance with legal obligations
  • Art. 6(1)(f) GDPR — legitimate interests, including website security, project operation, fraud prevention, and communication
  • Art. 6(1)(a) GDPR — consent, where consent is required

5. Log files and website operation

When you access the website, technical information may be processed automatically in server log files. This is necessary to deliver the website, maintain reliability, detect abuse, and protect our infrastructure.

6. Payments

If you make a support payment or sponsorship payment, payment processing is handled by third-party payment providers such as Stripe. We do not store full payment card details on our own systems.

Payment providers may process personal data such as billing details, transaction metadata, and fraud-prevention information in accordance with their own legal obligations and privacy notices.

7. Recipients and processors

We may share personal data with service providers and processors where necessary to operate the website and project, for example hosting providers, infrastructure providers, payment processors, email providers, analytics providers if used, and professional advisers where legally necessary.

We may also disclose personal data if required by law or where necessary to establish, exercise, or defend legal claims.

8. International transfers

Some service providers may process personal data outside the European Economic Area. Where required, we rely on appropriate safeguards such as adequacy decisions, standard contractual clauses, or equivalent legal mechanisms.

9. Retention periods

We retain personal data only for as long as necessary for the relevant purpose, including to meet legal, tax, accounting, security, and documentation obligations. Payment and accounting records may be retained for longer where required by applicable law.

10. Your rights

Subject to applicable law, you may have the right to request access to your personal data, rectification, erasure, restriction of processing, objection to processing, and data portability. Where processing is based on consent, you may withdraw consent at any time with effect for the future.

You may also have the right to lodge a complaint with a competent supervisory authority.

11. Cookies and similar technologies

We may use cookies or similar technologies where necessary for website operation. If non-essential analytics, marketing, or preference cookies are introduced, this Privacy Policy and any required consent mechanisms will be updated accordingly.

12. Security

We implement reasonable technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access. However, no system can be guaranteed to be completely secure.

13. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. The version published on this page is the current version.

14. Contact

For privacy-related questions or requests, contact hello@usesally.com.