2. Privacy Policy
2.1 Who We Are
This Privacy Policy explains how THYNKR SYSTEMS LTD, company number 15306717, processes personal information in connection with PalletPOS, Pallet Back Office and related services.
Registered office:
Office 2, 1st Floor, 73 Station Passage, London, England, E18 1JL
Privacy enquiries: [email protected]
In this Policy, “PalletPOS”, “Pallet Back Office”, “we”, “us” and “our” refer to THYNKR where it acts as controller.
2.2 When This Policy Applies
This Policy applies where THYNKR determines why and how personal data is processed, including data relating to:
- visitors to our websites;
- prospective customers;
- business owners and business contacts;
- account administrators;
- billing and subscription contacts;
- support users;
- partners and suppliers; and
- individuals whose data we independently process for security, fraud prevention, service analytics or legal compliance.
Where THYNKR processes personal data strictly on behalf of a Customer, that Customer is normally the controller and THYNKR is the processor. That processing is governed by the DPA and the Customer’s own privacy information.
2.3 Information We May Collect
Depending on use of the Services, we may process:
Identity and contact information
Name, business name, job title, address, email address, telephone number and account identifiers.
Business and verification information
Company details, ownership information, outlet information, regulatory details and information needed to assess eligibility for particular Services.
Account and authentication information
Login identifiers, password hashes, security settings, permissions, device identifiers and authentication logs.
Billing and payment information
Subscription plan, billing address, invoice records, payment status, transaction references and limited payment metadata.
Full card data may be handled directly by a PSP rather than stored by THYNKR.
Technical information
IP address, device type, browser, operating system, application version, logs, crash information, cookie identifiers and security events.
Usage information
Features used, interactions, configuration, audit events and operational activity.
Communications
Emails, support requests, chat messages and other communications with us.
Business operational data
Where relevant to our own controller purposes, information concerning locations, devices, service usage, integration status and platform configuration.
2.4 Customer Data Processed on Behalf of Businesses
Customers may use the Services to process information relating to their own customers, staff, suppliers or business contacts.
Depending on the Customer’s configuration, this may include:
- names;
- telephone numbers;
- email addresses;
- addresses;
- customer account details;
- transaction and purchase history;
- account balances;
- invoice and statement data;
- credit limits and payment terms;
- loyalty or membership data;
- communications; and
- other data entered by the Customer.
The Customer determines the purpose of this processing and is normally responsible for providing appropriate privacy information to those individuals.
THYNKR may separately process limited information as controller where necessary for security, fraud prevention, legal compliance, platform integrity or establishment and defence of legal claims.
2.5 Sensitive Information
Customers should not use general free-text fields to submit unnecessary sensitive or special-category personal data.
PalletPOS is not intended to operate as a medical-record, criminal-record or highly sensitive-data repository.
2.6 Why We Use Personal Information
Where we act as controller, we may use personal data to:
- create and administer accounts;
- provide requested services;
- manage subscriptions and billing;
- verify businesses or authorised users;
- enable or administer payment-related features;
- communicate with customers;
- provide support;
- secure systems and prevent fraud;
- investigate misuse;
- maintain logs and auditability;
- improve product reliability and user experience;
- understand service performance;
- comply with legal and regulatory obligations;
- establish, exercise or defend legal claims;
- manage suppliers and partners;
- market our business where permitted; and
- develop and improve products using appropriately governed data.
2.7 Lawful Bases
Depending on the activity, we may rely on:
- contract;
- legitimate interests;
- legal obligation;
- consent; or
- another lawful basis available under applicable data-protection law.
Where special-category data is processed, an additional lawful condition will be identified where required.
2.8 Marketing
We may send business communications about PalletPOS where permitted by law.
Recipients may opt out of non-essential electronic marketing using the unsubscribe mechanism or by contacting us.
Transactional, security, billing and service communications are not marketing and may continue where necessary to provide or administer the Services.
2.9 Automated Processing
The Services may use automated systems to assist with activities such as fraud or risk signals, operational recommendations, support routing, product analytics or other service functionality.
We do not intend to make solely automated decisions producing legal or similarly significant effects about individuals unless an appropriate legal basis, safeguards and notice are in place.
2.10 Who We Share Information With
We may share personal information with:
- cloud-hosting and infrastructure providers;
- payment service providers;
- email and communications providers;
- telecommunications or messaging providers where enabled;
- monitoring, logging and security providers;
- analytics providers;
- professional advisers;
- government, regulators, courts or law-enforcement authorities where lawfully required;
- prospective purchasers or investors in a corporate transaction, subject to appropriate safeguards; and
- other processors or subprocessors necessary to operate the Services.
Where THYNKR acts as processor, subprocessor use is governed by the DPA.
2.11 International Transfers
Our providers and infrastructure may process personal information in more than one country.
Where data-protection law restricts an international transfer, we use an appropriate lawful transfer mechanism, which may include:
- UK adequacy regulations;
- the UK International Data Transfer Agreement;
- the UK Addendum to approved EU Standard Contractual Clauses;
- applicable Standard Contractual Clauses;
- another legally recognised safeguard; or
- a permitted exception where appropriate.
Where required, we also undertake appropriate transfer-risk or data-protection assessments.
2.12 Data Retention
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including contractual, operational, security, tax, accounting, dispute and legal requirements.
Retention periods vary by category of data and applicable requirements.
When we process data solely as processor, deletion and return are governed by the Customer’s instructions and the DPA, subject to legal retention requirements and secure backup cycles.
2.13 Security
We use technical and organisational measures designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
Controls are selected according to risk and may include access controls, authentication, encryption, secure transport, network hardening, monitoring, backups, vulnerability management, least privilege and incident-response procedures.
No system can be guaranteed completely secure.
2.14 Your Rights
Depending on the law applicable to you, you may have rights to:
- access personal data;
- correct inaccurate data;
- request deletion;
- restrict processing;
- object to processing;
- receive portable data;
- withdraw consent where processing is based on consent;
- object to certain direct marketing; and
- obtain safeguards relating to certain automated decisions.
Rights are subject to legal conditions and exemptions.
Where THYNKR processes your information solely on behalf of a Customer, we may direct your request to that Customer.
2.15 Complaints
You may contact us first so we can try to resolve your concern.
Individuals in the United Kingdom may also have the right to complain to the Information Commissioner’s Office (ICO).
2.16 Children
PalletPOS is a business platform and is not intended to permit children to create merchant or business-operator accounts.
Customers remain responsible for complying with applicable laws when they process information relating to minors as their own customers.
2.17 Cookies
Our websites and applications may use cookies, local storage and similar technologies for authentication, security, preferences, analytics and other purposes.
Further information is provided in the Cookie Policy.
2.18 Changes to This Policy
We may update this Policy to reflect changes in law, providers, products or processing.
The “Last updated” date indicates the current version.
2.19 Contact
THYNKR SYSTEMS LTD
Office 2, 1st Floor
73 Station Passage
London, England
E18 1JL
Email: [email protected]
Telephone: +44 (0)333 011 8207
