How Softntechnology collects, uses, and protects your data
1. Introduction
Softntechnology ("Softntechnology", "we", "us", or "our") is committed to protecting the privacy of users of our cloud-based Software-as-a-Service ("SaaS") platform and our website at https://softntechnology.com (collectively, the "Services"). This Privacy Policy explains how we collect, use, disclose, store, and safeguard personal data of visitors, registered users, customers, and authorised end users of our Services.
We operate under the laws of the Republic of Uzbekistan, including the Law of the Republic of Uzbekistan "On Personal Data" No. ZRU-547 dated 2 July 2019, and the Law "On Informatization" No. 560-II. Where applicable, we also align our practices with internationally recognised data-protection standards including the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), in order to support customers operating across borders.
By accessing or using the Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please do not use the Services.
2. Data Controller and Contact Details
The data controller responsible for your personal data is:
- Legal name: "SOFTWARE AND INFORMATION TECHNOLOGY" MCHJ (Softntechnology)
- Registered address: Maxtumkuli str. 81, Tashkent, Republic of Uzbekistan
- Email: softntechnology1@gmail.com
- Phone / Telegram: +998 97 057 7313
For any question, request, or complaint relating to this Policy or your personal data, please contact us using the details above. We will respond to verified requests within 30 days, unless a longer period is permitted by law.
3. Scope of This Policy
This Policy applies to:
- Visitors to our website at https://softntechnology.com and its subdomains;
- Prospects who request a demo, contact us, or sign up for marketing communications;
- Customers who subscribe to our SaaS modules (Project & Task Management, CRM & Sales Pipeline, Analytics & Business Intelligence, Team Collaboration Suite, Billing & Subscription Management, and Workflow Automation);
- End users authorised by our customers to access the platform.
Where our Services are used by an organisation (the "Customer"), that organisation acts as the data controller of the personal data it uploads, inputs, or otherwise processes through the platform, and Softntechnology acts as a data processor on its behalf. The terms of that processing are governed by our customer agreement and, where applicable, a separate Data Processing Agreement (DPA).
4. Personal Data We Collect
We collect the following categories of personal data:
4.1 Information you provide directly
- Account data: name, business email address, phone number, job title, company name, country, and password.
- Billing data: billing contact, billing address, tax/VAT identification number, and payment-method details processed by our payment providers.
- Demo and contact requests: any information you submit through our contact, demo, or support forms.
- Customer Content: data, files, documents, messages, contacts, tasks, deals, analytics inputs, and other content you or your authorised users submit to the platform.
- Support data: information you provide when you contact support, including tickets, chat transcripts, and screenshots.
4.2 Information collected automatically
- Device and technical data: IP address, browser type and version, operating system, device identifiers, time-zone, and language settings.
- Usage data: pages viewed, features used, clicks, session duration, timestamps, referring URLs, and error logs.
- Cookies and similar technologies: see Section 11 (Cookies).
4.3 Information from third parties
- Single sign-on and authentication providers (where you choose to log in via such providers);
- Integrations you enable (for example, email, calendar, storage, or accounting tools);
- Payment processors who confirm transaction status;
- Publicly available sources for the purposes of fraud prevention and account verification.
We do not knowingly collect special categories of personal data (such as data revealing racial or ethnic origin, political opinions, health, or biometric data) and we ask that Customers do not upload such categories of data to the platform unless expressly agreed in writing.
5. How and Why We Use Personal Data
We process personal data for the following purposes and on the following legal bases:
- Providing and operating the Services — to create and manage accounts, deliver platform features, host Customer Content, and provide technical support. Legal basis: performance of a contract; legitimate interests.
- Billing and subscription management — to invoice you, process payments, manage renewals, prevent fraud, and comply with tax and accounting obligations. Legal basis: performance of a contract; legal obligation.
- Communications — to respond to your enquiries, send service-related notices (e.g., security alerts, maintenance, policy updates), and provide customer support. Legal basis: performance of a contract; legitimate interests.
- Product improvement and analytics — to analyse aggregated and pseudonymised usage data, debug, and improve performance, reliability, and user experience. Legal basis: legitimate interests.
- Marketing — to send newsletters, product updates, and demo invitations to prospects and existing Customers. You can opt out at any time. Legal basis: consent; legitimate interests (for existing Customers, where permitted).
- Security and abuse prevention — to detect, prevent, and investigate fraud, abuse, security incidents, and unauthorised access. Legal basis: legitimate interests; legal obligation.
- Legal compliance — to comply with applicable laws, court orders, and lawful requests from public authorities. Legal basis: legal obligation.
6. How We Share Personal Data
We do not sell personal data. We share personal data only in the limited circumstances described below:
- Service providers (sub-processors): cloud hosting providers, email delivery services, payment processors, analytics providers, customer-support tools, and error-monitoring services that process data on our behalf under written contracts requiring appropriate confidentiality, security, and data-protection commitments.
- Customers and their authorised users: where you are an end user invited by a Customer, your data is visible to that Customer's administrators and authorised users in accordance with their internal policies.
- Business transfers: in connection with a merger, acquisition, restructuring, financing, or sale of assets, subject to confidentiality obligations and continuing protection of personal data.
- Legal and regulatory: where required by law, regulation, court order, or to protect the rights, property, or safety of Softntechnology, our customers, or others.
- With your consent: where you explicitly direct us to share specific data with a third party.
7. Sub-processors
We engage carefully selected sub-processors to help us deliver the Services. Categories include:
- Cloud infrastructure and hosting providers;
- Database and storage providers;
- Email and transactional messaging providers;
- Payment-processing providers;
- Analytics, monitoring, and logging providers;
- Customer-support and ticketing tools.
A current list of sub-processors is available on request by contacting softntechnology1@gmail.com. We require all sub-processors to maintain appropriate technical and organisational measures and to process personal data only in accordance with our written instructions.
8. International Data Transfers
Softntechnology is established in the Republic of Uzbekistan. To deliver a global SaaS service, personal data may be transferred to, stored in, or processed in countries outside of Uzbekistan, the European Economic Area, the United Kingdom, or your country of residence.
Where such transfers occur, we rely on appropriate safeguards, including:
- Compliance with localization and cross-border transfer requirements of the Uzbekistan Law on Personal Data;
- Standard Contractual Clauses (SCCs) approved by the European Commission, where personal data of EU/EEA data subjects is transferred outside the EEA;
- Equivalent contractual or regulatory safeguards in other jurisdictions.
You may request a copy of the safeguards in place by contacting us.
9. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, tax, or reporting requirements, and to resolve disputes or enforce our agreements.
Typical retention periods:
- Account data: for the duration of the subscription, and up to 24 months after termination, unless deletion is requested earlier.
- Customer Content: for the duration of the subscription, and for a grace period of up to 60 days after termination, after which content is securely deleted or anonymised, unless legally required to be retained longer.
- Billing and tax records: as required by applicable tax and accounting laws (typically 5–10 years).
- Marketing data: until you withdraw consent or object, plus a short residual period to honour your opt-out.
- Security and system logs: typically up to 12 months.
10. Security
We implement appropriate technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, or destruction. Measures include:
- Encryption in transit using TLS and, where applicable, encryption at rest;
- Role-based access controls and the principle of least privilege;
- Network segregation, firewalls, and intrusion detection;
- Regular backups, disaster-recovery testing, and a stated 99.9% uptime target;
- Employee training on confidentiality and data protection;
- Vendor due-diligence and contractual data-protection obligations.
No method of transmission or storage is 100% secure. In the event of a personal data breach affecting your data, we will notify you and, where required, the competent authorities, without undue delay and in accordance with applicable law.
11. Cookies and Similar Technologies
We use cookies and similar technologies (such as local storage, pixels, and SDKs) to operate, secure, and improve our website and Services.
Categories of cookies we use:
- Strictly necessary cookies — required for authentication, security, and core platform functionality.
- Functional cookies — remember your preferences (e.g., language, layout).
- Analytics cookies — help us understand how visitors and users interact with the Services so we can improve them.
- Marketing cookies — used (with consent) to measure campaign performance and present relevant content.
You can control non-essential cookies through our cookie banner (where available) and through your browser settings. Disabling certain cookies may affect functionality.
12. Your Rights
Subject to applicable law, you have the following rights in relation to your personal data:
- Right of access — request a copy of the personal data we hold about you.
- Right to rectification — request correction of inaccurate or incomplete data.
- Right to erasure ("right to be forgotten") — request deletion of your personal data, subject to legal exceptions.
- Right to restriction of processing — request that we limit how we process your data in certain circumstances.
- Right to data portability — request transfer of your data to another controller in a structured, commonly used, machine-readable format.
- Right to object — object to processing based on our legitimate interests or for direct marketing.
- Right to withdraw consent — where processing is based on consent, you may withdraw it at any time.
- Right not to be subject to solely automated decisions producing legal or similarly significant effects.
- Right to lodge a complaint with a competent supervisory authority, including the Personalization Agency under the Cabinet of Ministers of the Republic of Uzbekistan, or your local data-protection authority.
To exercise any of these rights, contact us at softntechnology1@gmail.com. We may need to verify your identity before fulfilling your request. If you are an end user invited to the platform by a Customer, please contact that Customer first; we will support them in responding to your request.
13. Children
The Services are intended for business use by adults. We do not knowingly collect personal data from children under the age of 16 (or the higher age set by your local law). If you believe a child has provided us with personal data, please contact us so we can take appropriate action.
14. Third-Party Links and Integrations
The Services may contain links to, or integrations with, third-party websites and services that are not operated by us. This Policy does not apply to those third parties. We encourage you to review the privacy policies of any third-party services you use.
15. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. Material changes will be notified by email, in-product notice, or a prominent posting on our website at least 14 days before they take effect. The "Last Updated" date above indicates when this Policy was last revised. Your continued use of the Services after the effective date constitutes acceptance of the updated Policy.
16. How to Contact Us
Questions, requests, or complaints relating to this Privacy Policy may be addressed to:
Softntechnology ("SOFTWARE AND INFORMATION TECHNOLOGY" MCHJ)
Maxtumkuli str. 81, Tashkent, Republic of Uzbekistan
Email: softntechnology1@gmail.com
Phone / Telegram: +998 97 057 7313
— End of Privacy Policy —