Home / Privacy Policy
Privacy Policy
Last updated: 2025.
1. Introduction
This Privacy Policy describes how RackRent Systems LTD ("Company", "we", "us") collects, uses, and protects the personal data of clients and visitors of rack.rent, in accordance with the General Data Protection Regulation (GDPR, EU Regulation 2016/679).
2. Data We Collect
When you register and use the Client Portal, we may collect:
- Full name or company name
- Email address and phone number
- Country of residence or registration
- Identity documents (as part of the KYC procedure)
- Payment and transaction data
- IP address, browser data, and cookies (technical data)
3. Purposes of Processing
Your data is processed for the following purposes:
- Performance of the service agreement (Art. 6(1)(b) GDPR)
- Compliance with legal obligations, including AML/KYC (Art. 6(1)(c) GDPR)
- Invoicing and payment management
- Technical support and communication
- Service improvement based on feedback
4. Third-Party Disclosure
We do not sell or transfer your personal data to third parties, except:
- When necessary to perform the contract (payment providers, subcontractors)
- When required by law or order of a competent authority
- When you have given explicit consent
All subcontractors are bound by confidentiality agreements and process data solely on our instructions.
5. Data Retention
Personal data is stored no longer than necessary for the purposes of collection, and in any case not less than the period required by applicable law (typically 5–7 years for financial and KYC data).
6. Your Rights (GDPR)
As a data subject, you have the right to:
- Access — obtain a copy of your data
- Rectification — request correction of inaccurate data
- Erasure — request deletion of your data ("right to be forgotten")
- Restriction — restrict processing under certain conditions
- Portability — receive data in a machine-readable format
- Objection — object to processing for marketing purposes
To exercise your rights, contact us via the contact form. We will respond within 30 days.
7. Cookies
We use only technically necessary cookies (session cookie for Client Portal login, CSRF token for form protection). No analytics or marketing cookies are used.
8. Data Security
We apply technical and organisational data protection measures: encryption of sensitive database fields, HTTPS, restricted staff access. In the event of a data breach, we will notify affected subjects and the supervisory authority within the required timeframe.
9. Contact
For questions about data processing, contact us via the contact form. You also have the right to lodge a complaint with your national data protection supervisory authority.