Unlocking Joy: 50% Off On o11 Pro unlocked panels! Get It Now >

GDPR Policy

GDPR Compliance Policy

Effective Date: January 28, 2026
Last Updated: January 28, 2026

Introduction

This GDPR (General Data Protection Regulation) Compliance Policy supplements our Privacy Policy and applies specifically to users located in the European Economic Area (EEA), United Kingdom, and Switzerland.

Data Controller

o11scripts.com is the data controller responsible for your personal data. Contact details:

Please use our contact page.

Legal Basis for Processing

We process your personal data under the following legal bases:

Contractual Necessity

  • Account creation and management
  • Processing purchases and delivering digital products
  • Providing customer support

Legitimate Interests

  • Fraud prevention and security
  • Website analytics and improvements
  • Marketing to existing customers (with opt-out option)

Legal Obligation

  • Compliance with tax and financial regulations
  • Responding to legal requests

Consent

  • Optional marketing communications
  • Non-essential cookies and tracking

Your GDPR Rights

As an EEA resident, you have the following rights:

Right to Access

Request a copy of all personal data we hold about you in a structured, commonly used format.

Right to Rectification

Request correction of inaccurate or incomplete personal data.

Right to Erasure ("Right to be Forgotten")

Request deletion of your personal data, subject to legal retention requirements.

Right to Restrict Processing

Request limitation of how we process your data in certain circumstances.

Right to Data Portability

Receive your data in a machine-readable format and transfer it to another service.

Right to Object

Object to processing based on legitimate interests or for direct marketing purposes.

Right to Withdraw Consent

Withdraw consent at any time where processing is based on consent.

Right to Lodge a Complaint

File a complaint with your local data protection authority.

How to Exercise Your Rights

To exercise any GDPR rights, contact us using our contact page. with:

  • Subject line: "GDPR Rights Request"
  • Your full name and email address
  • Specific right(s) you wish to exercise
  • Verification of identity (for security purposes)

We will respond within 30 days of receiving your request.

Data We Collect

Personal Data

  • Email address, username, password (encrypted in our database)
  • Cryptocurrency wallet addresses (for transactions) (encrypted in our database)
  • IP address, browser type, device information (encrypted in our database)
  • Purchase history and transaction records (encrypted in our database)
  • PGP keys (encrypted in our database)

Special Category Data

We do not knowingly collect sensitive personal data (racial/ethnic origin, health data, etc.).

Purpose and Retention

Data Type

Purpose

Retention Period

Account information

Service provision

Until account deletion + 30 days

Transaction records

Legal compliance, tax

7 years

Support communications

Customer service

3 years

Analytics data

Website improvement

26 months (anonymized)

Marketing data

Communications

Until opt-out or 2 years inactive

Data Sharing and Transfers

Third-Party Services

We may share data with:

  • Cryptocurrency payment processors
  • Email service providers
  • Analytics platforms
  • Hosting providers

All third parties are contractually required to comply with GDPR.

International Transfers

Data may be transferred outside the EEA. We ensure adequate safeguards through:

  • Standard Contractual Clauses (SCCs)
  • Adequacy decisions by the European Commission
  • Other approved transfer mechanisms

Cookies and Tracking

Essential Cookies

Required for website functionality (cannot be disabled).

Analytics Cookies

Track website usage and performance (can be disabled).

Marketing Cookies

Used for advertising and remarketing (requires consent).

You can manage cookie preferences through our cookie consent banner or browser settings.

Children's Data

We do not knowingly process data of individuals under 16 years of age without parental consent.

Data Security

We implement appropriate technical and organizational measures including:

  • Encryption of data in transit and at rest
  • Regular security assessments
  • Access controls and authentication
  • Employee data protection training

Data Breach Notification

In the event of a data breach affecting your rights, we will:

  • Notify the relevant supervisory authority within 72 hours
  • Notify affected individuals without undue delay if high risk
  • Document the breach and response measures

Automated Decision-Making

We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects you.

Updates to This Policy

We will notify you of material changes via email or prominent website notice at least 30 days before changes take effect.

Supervisory Authority

You have the right to lodge a complaint with your local data protection authority. Find your authority at: https://edpb.europa.eu/about-edpb/board/members_en

Contact

For GDPR-related inquiries: use our contact page to connect with us.

We use cookies to personalize your experience. By continuing to visit this website you agree to our use of cookies

More