1. Who we are (Data Controller)
The data controller responsible for your personal data is:
- MAO Tech OÜ
- Estonian registry code: [PLACEHOLDER: Estonian registry code]
- [PLACEHOLDER: street address], [PLACEHOLDER: postal code] Tallinn, Estonia
- Privacy contact: team@maotechnology.com
2. Scope
This policy covers this corporate website (maotechnology.com) and our products, including WakeApp (a mobile application) and WWID (a SaaS web platform), except where a product presents its own product-specific privacy notice, which then takes precedence for that product.
3. Personal data we process
Depending on how you interact with us, we may process the following categories of data:
- Contact data: name and email address you provide via our contact form or by emailing us.
- Account data: where a product offers accounts, identifiers such as email, authentication data, and profile information you choose to provide.
- Product usage and content: data you create or generate while using a product (for example, alarms and habits in WakeApp, or pages and links in WWID).
- Device and technical data: IP address, device/browser type, operating system, and similar diagnostic information collected automatically.
- Analytics data: aggregated and pseudonymous usage statistics (see Section 7).
- Transaction metadata: limited records relating to purchases (see Section 5); we do not store full payment card details.
4. Why we process data and our legal bases
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing and operating our products and accounts | Performance of a contract (Art. 6(1)(b)) |
| Responding to enquiries and support requests | Legitimate interests / pre-contractual steps (Art. 6(1)(f)/(b)) |
| Security, fraud prevention, and service integrity | Legitimate interests (Art. 6(1)(f)) |
| Analytics and product improvement | Consent or legitimate interests (Art. 6(1)(a)/(f)) |
| Complying with legal, tax, and accounting obligations | Legal obligation (Art. 6(1)(c)) |
5. Payments and Merchants of Record
We do not sell directly to consumers from this website. Purchases of our products are processed by third-party Merchants of Record (MoR), who act as the seller of record and handle payment processing, billing, and related taxes:
- Apple (App Store) for iOS in-app purchases and subscriptions;
- Google (Google Play) for Android in-app purchases and subscriptions;
- Paddle for web/SaaS purchases.
These providers process your payment information as independent controllers under their own privacy policies. We receive only limited transaction metadata (for example, that a purchase occurred, the product, and a transaction identifier) needed to provide the service and meet our accounting obligations. Please review the privacy policies of Apple, Google, and Paddle for details of their processing.
6. Sharing and processors
We share personal data only as necessary, including with: cloud hosting and infrastructure providers; the Merchants of Record described above; analytics providers; communication/email providers; and professional advisers or authorities where legally required. Where a third party processes data on our behalf, we put in place a data processing agreement under GDPR Article 28.
7. Analytics
We use analytics to understand how our websites and products are used so we can improve them. Where required by law, analytics that rely on cookies or similar technologies are used only with your consent. We aim to use privacy-respecting, aggregated analytics and to minimise the personal data involved. See our Cookie Policy for details.
8. International transfers
Some of our providers may process data outside the European Economic Area (EEA). Where this occurs, we rely on appropriate safeguards such as European Commission adequacy decisions or Standard Contractual Clauses to protect your data.
9. Data retention
We keep personal data only for as long as necessary for the purposes described above. In general:
- Account and product content: for the life of the account, then deleted or anonymised within a reasonable period after closure;
- Contact/enquiry messages: typically up to 24 months;
- Accounting and transaction records: for the period required by Estonian law (generally 7 years);
- Analytics data: retained in aggregated/pseudonymous form for limited periods.
10. Your rights
Under the GDPR, you have the right to:
- access the personal data we hold about you;
- request rectification of inaccurate or incomplete data;
- request erasure ("right to be forgotten") where applicable;
- restrict or object to certain processing;
- data portability for data you provided to us;
- withdraw consent at any time, without affecting prior processing; and
- lodge a complaint with a supervisory authority. In Estonia this is the Data Protection Inspectorate (Andmekaitse Inspektsioon).
To exercise any of these rights, contact us at team@maotechnology.com. We will respond within the time limits set by the GDPR.
11. Children
Our products are not directed at children under the age required by applicable law (and not under 13 in any case). We do not knowingly collect personal data from children. If you believe a child has provided us personal data, please contact us so we can delete it.
12. Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or misuse. No method of transmission or storage is completely secure, but we work to protect your data and to notify you and the relevant authority of breaches where required by law.
13. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version here and revise the effective date above. Material changes will be communicated where appropriate.
14. Contact
For any privacy question or request, contact us at team@maotechnology.com or by post at the address in Section 1.
This document is a starting template for MAO Tech OÜ and should be reviewed by qualified counsel before relying on it. Placeholder values must be completed after company formation.