1. Who we are
SOBORRO LTD is the controller of the personal data described in this policy. We are a private limited company registered in England and Wales under company number 13305893. Our registered office is 13 Carlyle Road, Edgbaston, Birmingham B16 9BH, England.
For privacy questions or requests, contact support@soborro.com or +32 467 66 3575 .
This policy covers the Soborro website, Portfolio Risk Profiler, demonstration requests, enquiries and related communications. It does not govern a separate service supplied under terms that include their own privacy provisions.
2. Information we collect
Depending on how you use Soborro, we collect:
- Identity and contact information: your name, email address, telephone number, organisation and role.
- Account information: account identifiers, authentication and security records.
- Subscription information: your selected plan, subscription status, allowances, billing references and records of payments or cancellations. Stripe processes payment-card details and does not provide us with your complete card number.
- Service information: analysis names, portfolio inputs, model settings, saved configurations, run status, results and exports.
- Communications: messages, demo requests, support requests and feedback.
- Technical and usage information: IP address, browser and device information, timestamps, requested pages, diagnostic events and security logs.
- Cookie and session information: information needed to authenticate users, protect forms, maintain sessions and operate the website.
Do not include personal data about portfolio beneficiaries, employees, clients or other individuals where aggregate or anonymised information is sufficient. If you submit another person's personal data, you must have a lawful basis and provide any information required by law.
3. How we obtain information
We receive information directly from you when you create an account, subscribe, configure or run an analysis, request a demonstration, contact us or use the website. We also receive subscription and transaction information from Stripe and technical information automatically from the systems used to deliver and secure the service.
An organisation may provide your business contact details so that you can use its Soborro account. If we need additional information from another source, we will provide any further notice required by law.
4. Why we use information
Contract
We use account, subscription, portfolio and support information to provide the service, administer access, process subscriptions, preserve requested analyses, respond to support requests and enforce the Terms of Service.
Legitimate interests
We use appropriate technical, usage and security information to authenticate users, prevent abuse, diagnose faults, protect accounts and maintain the service. Where you act for an organisation, this basis also supports administering its agreement.
Legal obligations
We use transaction, contract and communication records to meet accounting, tax, consumer-protection, data-protection and other legal obligations, and where necessary for legal claims.
Consent and permitted communications
We use contact details for marketing only with consent or where applicable law otherwise permits it. You can opt out at any time without affecting service or legally required messages.
If we ask for consent for another purpose, we will explain that purpose when asking. You may withdraw consent at any time, without affecting processing that was lawful before withdrawal.
5. Portfolio information and automated processing
Portfolio inputs and account-specific outputs are treated as confidential service information. We use them to provide, maintain and support the requested analysis and for closely related security and fault diagnosis. We do not use them for unrelated marketing.
Risk Profiler uses automated calculations to produce scenario-based portfolio outputs from the inputs and settings selected by the user. Those calculations do not make decisions about a person that produce legal or similarly significant effects. Soborro does not use solely automated decision-making of that kind unless we first provide the information and safeguards required by law.
6. When we share information
We share personal data only as needed with:
- Stripe, for subscription and payment processing;
- Google Cloud Platform, which provides the virtual server and supporting infrastructure used to host the application, database, operational logs and Soborro-operated email service in the
us-east1-czone in Moncks Corner, South Carolina, United States; - backup and security providers, where used to operate and protect the service;
- professional advisers, including accountants, auditors, insurers and legal advisers;
- an organisation responsible for an account through which you use Soborro; and
- courts, regulators, law-enforcement bodies or other parties where disclosure is legally required or necessary to protect legal rights.
These recipients receive only the information needed for their function. Providers processing personal data for us are required to protect it and act on our instructions. We do not sell personal data.
7. International transfers
Soborro operates across Belgium and the United Kingdom. Its production application, database, operational logs and self-hosted email service run on Google Cloud infrastructure in Moncks Corner, South Carolina, United States. This means that personal data supplied to or generated by the service is processed in the United States.
Transfers between the European Economic Area and the United Kingdom may rely on applicable adequacy decisions. For transfers to the United States and other restricted transfers, we use an approved transfer mechanism where required, such as standard contractual clauses, the UK International Data Transfer Agreement or an applicable adequacy framework, together with additional safeguards where appropriate.
Contact us if you want information about the safeguard used for a particular transfer.
8. How long we keep information
We retain personal data only for as long as needed for the purpose for which it was collected, including service delivery, security, accounting, legal claims and compliance obligations.
Analyses and results remain available subject to the plan limits while the subscription is active. After the paid period ends, the account has the 14-calendar-day export period described in the Terms of Service . Available analyses and results may be deleted or anonymised after that period, except where retention is legally required.
We retain transaction, tax and contract records for the period required by applicable law and for legal claims. We keep enquiries and support records for as long as needed to resolve and follow up the matter. Security and diagnostic records are kept for a proportionate period based on their purpose and risk.
Encrypted backups are retained for up to 30 days and are used only for disaster recovery and security restoration. Information deleted from the live service may remain in protected backups until those backups expire, after which it is deleted through the ordinary backup cycle. We do not restore an individual's deleted information except where legally required or where it forms part of a necessary security or disaster-recovery restoration.
We review retention when an account closes or a valid deletion request is received. We may retain a minimal suppression record where needed to respect an opt-out or establish that a request was completed.
9. Cookies
Soborro uses cookies and similar storage that are necessary to authenticate users, maintain sessions, protect forms, preserve security and provide requested functionality. These technologies do not require consent where they are strictly necessary, but we still explain their use.
If we introduce analytics, advertising or other non-essential cookies, we will identify them and request consent where required before placing them. Browser controls can remove or block cookies, but blocking necessary cookies may prevent account and workspace functions from operating.
10. Your rights
Depending on the circumstances and applicable law, you may have the right to:
- obtain information about our processing and a copy of your personal data;
- correct inaccurate or incomplete personal data;
- request deletion of personal data;
- restrict processing;
- receive personal data you provided in a portable format and transmit it to another controller;
- withdraw consent at any time where processing relies on consent; and
- complain to a data-protection supervisory authority.
You may object to processing based on our legitimate interests, including related profiling, on grounds arising from your situation. You may object to direct marketing at any time.
These rights are not absolute and depend on the purpose and legal basis for processing. We may ask for information needed to verify your identity and protect the account. There is normally no charge. Send requests to support@soborro.com . We will respond within the period required by applicable law.
You may complain to the Belgian Data Protection Authority, Rue de la Presse 35, 1000 Brussels, Belgium, contact@apd-gba.be , at www.dataprotectionauthority.be . If UK data-protection law applies, you may also complain to the UK Information Commissioner's Office at www.ico.org.uk . You may instead complain to the competent authority where you live or work or where an alleged infringement occurred. We would appreciate the opportunity to address your concern first, but contacting us is not a condition of complaining to an authority.
11. Security
We use technical and organisational measures designed to protect personal data against accidental or unlawful loss, alteration, disclosure or access. Access is limited according to operational need. No online service can guarantee absolute security. Please use a secure authentication link or credentials, protect access to your email account and contact us promptly if you suspect unauthorised access.
12. Children
Soborro is intended for people aged 18 and over. We do not knowingly offer accounts to children. Contact us if you believe a child has supplied personal data so that we can investigate and take appropriate action.
13. Changes to this policy
We may update this policy to reflect changes in the service, providers or legal requirements. We will publish the revised policy with a new effective date and give appropriate notice before a material change takes effect. We will seek consent where a change requires it.