Key information
This Privacy Notice applies to superbasic.net, the shared Super Basic account system, and every Super Basic app or service that links to it, including QR8.to, Linkads.to, Bookin.to, Entry.to, Justinvoice.to and Payup.to.
A shorter, layered notice should also appear at the point where information is collected, such as on account sign-up, booking, event registration, invoice and payment pages. Where a layered notice conflicts with this Privacy Notice, this Privacy Notice applies unless the layered notice gives a more specific lawful explanation for that particular feature.
Plain-English summary
- We aim to collect only the personal information reasonably needed to operate, secure and improve lightweight online tools.
- We do not sell or rent personal information, and we do not provide customer or End User information to data brokers.
- We do not use Customer Content or End User Content to train general-purpose artificial intelligence models unless the relevant customer or individual has expressly agreed to a clearly described arrangement.
- For account administration, billing, support, security and our own business operations, Super Basic normally acts as the controller. For information a customer collects from its own clients, attendees, bookers or payers through an app, the customer normally acts as controller and Super Basic acts as processor.
- We may use proportionate security, fraud, abuse and availability controls. We do not routinely read private Customer Content, but authorised people may access it where reasonably necessary to provide support, investigate a report, protect the platform, comply with law or establish legal claims.
- We share information only with the customer or recipient involved, service providers and integrations needed to operate the service, professional advisers, a buyer of the business under appropriate safeguards, or authorities where disclosure is lawful.
- Customers must keep their own copies of important records. We normally allow 30 days to export information after account termination and may retain residual backups for up to 90 days.
- You have data protection rights. You may contact support@superbasic.net or use the relevant feedback form to make a request or complaint.
1. About us and this Privacy Notice
1.1 SUPER BASIC LIMITED is a company registered in England and Wales under company number 16274977, with its registered office at CF5 The Terrace, Grantham Street, Lincoln, England, LN2 1BD. In this Privacy Notice, "Super Basic", "we", "us" and "our" mean SUPER BASIC LIMITED.
1.2 This Privacy Notice explains how we collect, use, disclose, retain and protect personal information when we act as a controller. It also explains our role when we process information for a Super Basic customer.
1.3 "Personal information" and "personal data" mean information relating to an identified or identifiable person. They do not include information that has been irreversibly anonymised so that no person is reasonably identifiable.
1.4 "Customer" means the person or organisation that creates an account, subscribes to or uses a Super Basic service. "Account User" means an individual who uses a Customer account. "End User" means someone who scans, visits, books, registers, receives an invoice, makes a payment or otherwise interacts with a Customer through a Super Basic app. "Customer Content" includes information, files, links, adverts, booking data, attendee data, invoices, payment requests and other material submitted to or generated through a service.
1.5 This Privacy Notice does not replace a Customer's own privacy notice. A Customer is responsible for explaining its own purposes and lawful bases where it decides why personal information is collected through a Super Basic app.
2. When Super Basic is controller and when it is processor
The legal role depends on why and how information is used. The following is the normal position.
Account creation, subscriptions, billing, product announcements, support, service analytics and security
- Usual role of Super Basic
- Controller, because we decide why and how this information is used for our service and business operations.
- Usual role of the Customer
- Separate controller for its own account administration and employee or contractor access.
A Customer collects booking, attendee, invoice, payment-request, form or contact information from an End User
- Usual role of Super Basic
- Processor acting on the Customer's documented instructions, except for limited controller uses such as security logs, fraud prevention and legal compliance.
- Usual role of the Customer
- Controller, because it decides the purpose, questions, recipients, retention and lawful basis.
An End User contacts Super Basic directly about platform support, security or a complaint
- Usual role of Super Basic
- Controller for that communication and investigation.
- Usual role of the Customer
- May remain controller for the underlying booking, event, invoice, payment or service dispute.
A Customer enables a third-party integration
- Usual role of Super Basic
- Controller or processor depending on the information and purpose, as explained in this notice, the Data Processing Agreement and the integration information.
- Usual role of the Customer
- Responsible for authorising the integration and ensuring its use is lawful.
2.1 Where we act as processor, our Data Processing Agreement at https://superbasic.net/legal/data-processing-agreement forms part of the Customer contract. The Customer should normally handle End User rights requests first. We will provide reasonable assistance as required by law and the Data Processing Agreement.
2.2 We may still act as controller for limited information connected with Customer processing, including account records, usage metering, audit trails, security logs, abuse reports, fraud prevention, billing, legal compliance and the establishment or defence of claims.
3. Personal information we collect
3.1 Account, identity and contact information
This may include name, email address, telephone number, username, password hash, multi-factor authentication details, account identifier, business name, role, team membership, communication preferences and confirmation that a person has authority to act for a Customer. We do not need or want a plain-text copy of a password.
3.2 Subscription, billing and transaction information
This may include plan, renewal date, price, billing address, VAT status, invoices, credits, payment status, payment-provider identifiers, the last four digits and brand of a payment card where supplied by the payment provider, chargeback or failed-payment information, and communications about a subscription. Full card details are normally collected and controlled by the connected payment provider rather than stored by Super Basic.
3.3 Customer Content and service information
The information depends on the app and the choices made by the Customer. It can include:
- QR8.to: link destinations, slugs, QR codes, folders, schedules, fallback destinations, scan or visit events and associated analytics;
- Linkads.to: campaigns, adverts, sponsor material, destination pages, impressions, clicks, campaign settings and reports;
- Bookin.to: services, availability, staff, appointments, customer contact details, answers to booking questions, consultation information, communications and connected-calendar identifiers;
- Entry.to: events, ticket or RSVP information, attendee contact details, answers, check-in records, discount codes and transaction references;
- Justinvoice.to: customer and supplier details, invoice and quotation content, line items, tax and payment information, bank details chosen by the Customer and delivery status;
- Payup.to: merchant and payment-request details, payer contact information, payment status, refund or dispute references and receipt information; and
- other Super Basic apps: the information entered, uploaded, generated or connected through the relevant feature.
A Customer decides what optional fields to request. Customers must not collect information merely because a field is available.
3.4 End User information
When an End User interacts with a Customer page, we may receive information entered by that End User, information supplied by the Customer, transaction or status information from a connected provider, and technical or security information generated by the interaction. Most content entered into a Customer form is processed for the Customer.
3.5 Device, usage, log and security information
This may include IP address, approximate location derived from IP address, browser and device type, operating system, language, time zone, referring page, requested URL, timestamps, session and account identifiers, authentication events, feature use, error reports, performance data, rate-limit events, suspected bot or spam signals, and audit records of significant account actions.
We may combine signals across connected Super Basic apps where reasonably necessary to operate the shared account, meter plan limits, prevent abuse, investigate fraud, protect accounts and understand service reliability. We do not use this shared-account information for third-party behavioural advertising without any consent required by law.
3.6 Support, feedback and communications
This may include messages, feedback form submissions, screenshots, files, call or meeting notes, issue history, complaint records, survey responses and information needed to verify identity or authority. We will tell you before recording a call where recording is not obvious or legally expected.
3.7 Marketing and preference information
This may include marketing choices, unsubscribe records, consent records, campaign engagement, areas of interest and whether a message was delivered, opened or clicked, where the relevant technology is lawfully enabled. We maintain suppression information so that we can respect an objection or unsubscribe request.
3.8 Integrations and third-party information
If a Customer connects a calendar, payment provider, email service, identity provider, messaging service, social platform or other integration, we may receive account identifiers, permissions, tokens, status information and the data required to operate that connection. We may also receive information from payment providers, anti-fraud services, app administrators, team members, public sources, regulators, law enforcement, complainants and people reporting abuse or infringement.
3.9 Special category and criminal offence information
Super Basic does not require special category or criminal offence information for an ordinary account. A Customer may configure a service, particularly Bookin.to or a form feature, to collect health, allergy, accessibility, religious, biometric or other sensitive information. In that situation, the Customer must have a valid lawful basis and any required additional condition, minimise what it collects, apply suitable safeguards and avoid using Super Basic as an emergency or permanent clinical-record system.
We may process information about suspected fraud, abuse, criminal activity or threats where necessary and lawful to secure the service, investigate reports, protect people, establish legal claims or cooperate with competent authorities.
4. How we obtain personal information
- directly from you when you register, subscribe, configure an app, contact us or exercise a right;
- from a Customer, account administrator or team member who adds you to an account or enters information about you;
- from an End User who interacts with a Customer page;
- automatically from browsers, devices, servers, logs, cookies and similar technologies;
- from payment, messaging, calendar, identity, hosting, security and other providers connected to a service;
- from public sources or third parties where necessary to verify authority, investigate misuse, enforce rights or comply with law; and
- by creating limited derived information, such as usage totals, risk indicators, plan-limit calculations and aggregated service statistics.
5. How and why we use personal information
We use a lawful basis appropriate to each purpose. More than one basis can apply to the same information in different circumstances.
Create and administer accounts, provide apps, process subscriptions and deliver requested features
- Typical information
- Account, contact, plan, transaction, Customer Content, End User and integration information.
- Lawful basis
- Performance of a contract; steps requested before entering a contract; legitimate interests where an organisation is the contracting party.
Authenticate users, manage permissions, maintain audit trails and secure accounts and services
- Typical information
- Account, device, login, IP, session, audit, risk and usage information.
- Lawful basis
- Performance of a contract; legitimate interests in security, fraud prevention and protecting users; recognised legitimate interests or legal obligation where applicable.
Bill Customers, administer VAT, reconcile payments and maintain business and tax records
- Typical information
- Billing, transaction, invoice, account and payment-provider information.
- Lawful basis
- Performance of a contract; legal obligation; legitimate interests in financial administration and debt recovery.
Provide support, investigate bugs, respond to feedback and communicate service information
- Typical information
- Contact, account, technical, support and relevant Customer Content.
- Lawful basis
- Performance of a contract; legitimate interests in support, service quality and resolving issues; legal obligation where the communication is a rights request or complaint.
Operate, test, troubleshoot, maintain and improve products and infrastructure
- Typical information
- Usage, error, performance, account, feature and appropriately minimised content information.
- Lawful basis
- Legitimate interests in reliable, useful and efficient products; consent where required for optional storage or access technologies.
Prevent, detect and investigate spam, phishing, malware, harmful or illegal activity, fraud, payment abuse and attacks
- Typical information
- Content, reports, logs, IP, device, account, payment status and risk signals.
- Lawful basis
- Legitimate interests and recognised legitimate interests in crime prevention, safeguarding and security; legal obligation where applicable.
Enforce terms, resolve disputes, protect legal rights and establish, exercise or defend claims
- Typical information
- Account, content, communications, billing, logs, reports and complaint information.
- Lawful basis
- Legitimate interests in protecting the business and users; legal obligation; establishment, exercise or defence of legal claims.
Send operational notices, security alerts, renewal messages and material service updates
- Typical information
- Account, contact, plan, security and preference information.
- Lawful basis
- Performance of a contract; legal obligation; legitimate interests in service administration. These are not optional marketing messages.
Send relevant Super Basic marketing and measure its effectiveness
- Typical information
- Contact, business, interest and preference information, and lawful engagement data.
- Lawful basis
- Consent where required by PECR; otherwise legitimate interests in promoting related services to appropriate business contacts. You may object at any time.
Comply with lawful requests, court orders, regulatory obligations and reporting duties
- Typical information
- Information relevant to the request or obligation.
- Lawful basis
- Legal obligation; recognised legitimate interests; substantial public interest or other lawful condition where applicable.
Plan or complete a corporate transaction, investment, restructuring or sale
- Typical information
- Account, contract, financial, operational and due-diligence information, normally minimised or aggregated.
- Lawful basis
- Legitimate interests in financing, restructuring or transferring the business, subject to confidentiality and legal safeguards.
5.1 Where we rely on legitimate interests, the interests may include operating a sustainable SaaS business, providing support, improving usability, securing systems, preventing fraud, understanding service performance, communicating with business customers, enforcing contracts and protecting legal rights. We consider necessity, reasonable expectations and the effect on individuals before relying on this basis.
5.2 Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect use that was lawful before withdrawal. Refusing optional consent should not prevent use of the core service, although the optional feature may not work.
5.3 We may use personal information for a compatible new purpose. If a new purpose is not compatible, we will identify a new lawful basis and provide any additional notice required before using the information.
6. Privacy commitments and limits
We do not sell or rent personal information. We do not provide it to data brokers. We do not use Customer Content or End User Content to train general-purpose AI models without express agreement.
6.1 We aim to design services so that the Customer controls what is collected and can export or delete information. Optional fields should remain optional unless genuinely needed for the Customer's purpose.
6.2 We do not routinely read or manually inspect private Customer Content. Access may occur on a need-to-know basis where reasonably necessary to provide requested support, debug a fault, restore data, investigate a report, prevent harm, comply with law, enforce our terms or establish legal claims.
6.3 We may use automated filters, rate limits, reputation signals, malware checks and other proportionate controls. These controls can restrict, quarantine or temporarily suspend activity while a matter is reviewed. They do not mean that we monitor or approve all content.
6.4 We may create aggregated or anonymised statistics about app usage, reliability, market demand and product performance. Where information is genuinely anonymised so that a person is no longer reasonably identifiable, data protection law does not treat it as personal information and we may use it for lawful business purposes.
6.5 Privacy does not prevent us from keeping proportionate evidence needed to prevent repeat abuse, enforce a suspension, maintain a suppression list, recover money, respond to a regulator or defend a claim. We minimise and restrict access to such records and keep them only for as long as reasonably necessary.
7. Public pages, links and information chosen for publication
7.1 Some Super Basic apps allow Customers to publish links, profiles, adverts, event pages, booking pages, invoices, payment requests or other material. Information intentionally made public can be viewed, copied, shared, indexed, cached or archived by search engines and third parties.
7.2 Removing public content from Super Basic does not necessarily remove copies already held by recipients, search engines, web archives, payment providers or other independent organisations. A Customer should not publish confidential or unnecessary personal information.
7.3 Customers are responsible for having permission and a lawful basis for public information they publish about another person. We may remove, restrict or preserve content where reasonably necessary to investigate a report or comply with law.
8. Cookies, analytics and similar technologies
8.1 We use cookies and related storage or access technologies as described in our Cookie Policy at https://superbasic.net/legal/cookies and in the live Cookie Settings panel for the relevant domain.
8.2 Essential technologies may be used for authentication, security, session management, load balancing, checkout and user-requested preferences. Optional analytics, advertising, replay, social or similar technologies will be used only where we have a valid legal basis, including consent where required.
8.3 A Customer may add an embed, integration or external link that uses its own technology. The Customer is responsible for additional notices and choices where it determines that use.
9. Artificial intelligence and automated processing
9.1 We do not use Customer Content or End User Content to train general-purpose artificial intelligence models unless the relevant Customer or individual expressly agrees to a clearly described arrangement. We may use code, documentation, test data or information that has been suitably anonymised for development and quality purposes.
9.2 If we offer an optional AI-assisted feature, we will explain the purpose, the provider or category of provider, the information transmitted and any material retention or training position before or when the feature is enabled. A Customer remains responsible for reviewing outputs before relying on them.
9.3 We may use automated processing to identify security threats, abuse, fraud, invalid traffic, plan-limit breaches or unusual activity. This may produce a temporary restriction or risk flag. Super Basic does not ordinarily make solely automated decisions that have legal or similarly significant effects on individuals. Where the law requires safeguards, a person may ask to make representations, challenge the decision and obtain human intervention by contacting support@superbasic.net.
10. Who we share personal information with
We disclose information only where reasonably necessary and lawful. Recipients may include:
- the Customer, Account Users and End Users involved in the relevant page, booking, event, invoice, payment request or communication;
- hosting, database, storage, security, monitoring, email, messaging, analytics, customer-support, identity, payment and infrastructure providers acting under contract;
- third-party integrations that a Customer or Account User deliberately connects or uses;
- payment providers, banks, card schemes, fraud services and tax or accounting providers connected with a transaction;
- professional advisers, auditors, insurers and contractors who need the information and are subject to confidentiality duties;
- courts, regulators, law enforcement, emergency services and public bodies where disclosure is required or otherwise lawful and proportionate;
- a complainant, rights holder or affected party where reasonably necessary to investigate or resolve abuse, fraud, infringement or a legal dispute, taking account of confidentiality and safety;
- actual or prospective investors, lenders, purchasers or transaction advisers in connection with financing, due diligence, restructuring, merger or sale, subject to appropriate confidentiality and minimisation; and
- another person where you direct us to disclose information or give valid consent.
10.1 We do not disclose personal information to third parties so that they can independently market unrelated products to individuals without a lawful basis and any consent required by electronic-marketing law.
10.2 Our current provider categories and transfer locations should be listed at https://superbasic.net/legal/subprocessors. Providers can change as the platform develops. We will update the list and provide contractual notice where the Data Processing Agreement requires it.
11. Third-party services and integrations
11.1 Third-party services have their own terms and privacy notices. Where a Customer enables an integration, the Customer instructs us to exchange the information reasonably necessary to operate it. Disconnecting an integration prevents future exchanges through that connection but does not automatically delete information already received by the third party.
11.2 Payment providers such as Stripe, Square, PayPal or another supported provider may act as independent controllers for merchant onboarding, payment processing, identity checks, fraud, chargebacks, settlement and legal compliance. Super Basic normally receives status and reference information rather than full card details.
11.3 We are not responsible for an independent organisation's privacy practices, although we aim to select reputable providers and assess processors used for core services.
12. International transfers
12.1 Some providers or their support teams may process personal information outside the United Kingdom. Where a restricted transfer occurs, we will use a lawful transfer mechanism, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved EU standard contractual clauses, binding corporate rules or a lawful exception.
12.2 Where appropriate, we assess relevant transfer risks and require contractual, technical or organisational safeguards. The Subprocessor List should identify the principal location or transfer mechanism for core providers.
12.3 You may contact support@superbasic.net for further information about the safeguards relevant to a particular transfer. We may provide a summary rather than commercially sensitive contracts or security material.
13. How long we keep personal information
We keep information only for as long as reasonably necessary for the relevant purpose, including legal, tax, accounting, security and dispute requirements. The periods below describe our normal approach.
- Account and profile information
- For the life of the account, then normally deleted or anonymised after the 30-day post-termination export period. Residual backups may remain for up to 90 days.
- Customer Content and End User Content
- As configured or deleted by the Customer; after account termination, normally available for export for 30 days, then removed from live systems. Residual backups may remain for up to 90 days unless law, security or a dispute requires longer.
- Inactive accounts
- An account may be deleted after no login for three years, normally following advance warnings to the registered email address. Required legal, security and financial records may be retained separately.
- Billing, invoices, tax and core contract records
- Normally six years after the relevant accounting period or contract ends, or longer where law, an audit or a dispute requires it.
- Security, access and technical logs
- Normally up to 12 months. Relevant extracts may be retained for up to three years or longer where needed to investigate an incident, prevent repeat abuse or establish legal claims.
- Support and ordinary account communications
- Normally three years after the issue or account relationship ends. Important contract, complaint or dispute records may be kept for up to six years or while proceedings remain possible.
- Marketing records
- Until consent is withdrawn, an objection is made or the information is no longer useful. A minimal suppression record may be retained for as long as needed to ensure we do not resume unwanted marketing.
- Rights requests and data protection complaints
- Normally six years after completion, so that we can demonstrate how the request or complaint was handled.
- Fraud, abuse and enforcement records
- For as long as reasonably necessary to protect the service and users, prevent repeat misuse, comply with law or defend claims, with access restricted and periodic review.
13.1 We may retain information for longer where required by law, court order, regulatory request, payment dispute, tax enquiry, security incident or legal claim. We may shorten retention where the information is no longer needed.
13.2 Deletion from live systems may not immediately remove information from encrypted backups, immutable logs, recipients or independent third parties. Backup information is isolated, not used for ordinary business activity and removed through the normal backup cycle unless restoration is required.
13.3 Where possible, Customers should use in-product deletion and export tools. Customers remain responsible for retaining independent copies of records they are legally or commercially required to keep.
14. Security
14.1 We use reasonable and appropriate technical and organisational measures designed for the nature of the service and information. These may include access controls, least-privilege permissions, password hashing, encrypted connections, provider security controls, backups, logging, monitoring, rate limits, vulnerability management and incident procedures.
14.2 Access to personal information is limited to people and providers who reasonably need it for their role. They are expected to follow confidentiality and security obligations.
14.3 No online service can guarantee absolute security, permanent availability or that information will never be lost, corrupted, delayed or accessed unlawfully. Customers must protect credentials, configure permissions carefully, keep devices secure and export information they cannot afford to lose.
14.4 If we identify a personal data breach, we will investigate, contain and document it, notify affected Customers or individuals where required, and report it to the relevant regulator within the applicable period where the legal threshold is met.
15. Children
15.1 A person must normally be at least 18 to open a paid Super Basic account or enter into a contract with us. The services are designed for businesses and adults rather than directed at children.
15.2 An End User under 18 may interact with a Customer page only where this is lawful and any required parent, guardian, school, club or organisational authorisation has been obtained. The Customer is responsible for deciding whether its service is appropriate for children and for giving child-friendly privacy information where required.
15.3 Customers must not collect children's information through Super Basic unless it is necessary, proportionate and lawful. If we learn that information has been collected unlawfully, we may restrict access, require deletion or close the relevant feature or account.
16. Your data protection rights
Depending on the circumstances, you may have the right to:
- be informed about the collection and use of your personal information;
- request access to personal information we hold about you;
- ask us to correct inaccurate or incomplete information;
- ask us to erase information where there is no lawful reason to keep it;
- ask us to restrict use of information in certain circumstances;
- receive information you provided in a structured, commonly used, machine-readable format and transmit it to another controller where the right to portability applies;
- object to processing based on legitimate interests, taking account of the particular circumstances;
- object at any time to use of your information for direct marketing, including related profiling;
- withdraw consent at any time where consent is the lawful basis; and
- challenge a qualifying solely automated decision and request human intervention where the law provides that safeguard.
You have an absolute right to object to direct marketing. Use the unsubscribe link in a marketing email or contact support@superbasic.net. Service, security, billing and legal notices may still be sent where necessary.
16.1 To exercise a right, contact support@superbasic.net or use the relevant feedback form. Please identify the account, app and information concerned. If Super Basic is processing the information for a Customer, we may refer the request to that Customer or ask you to contact it directly.
16.2 We may ask for proportionate proof of identity, authority or clarification. This protects information from unauthorised disclosure and helps us locate what is requested. Do not send unnecessary identity documents unless asked.
16.3 We normally respond without undue delay and within one month. The law may allow an extension for complex or numerous requests. We will explain an extension where required.
16.4 Rights are not absolute. We may retain or withhold information where an exemption applies, another person's rights would be affected, disclosure would reveal protected confidential material, or information is needed for legal claims. Requests are normally free, but the law may allow a reasonable charge or refusal where a request is manifestly unfounded or excessive.
17. Data protection complaints
17.1 You may make a data protection complaint if you believe we have used personal information unlawfully, failed to keep it appropriately secure, or mishandled a rights request. Email support@superbasic.net or use the electronic feedback form in the relevant app. Please describe what happened, the app or account involved, the effect on you and the outcome you are seeking.
17.2 We will acknowledge the complaint without undue delay, investigate it, keep an appropriate record and provide an outcome as soon as reasonably possible, normally within one calendar month. If more time is reasonably required, we will explain the delay and keep you informed.
17.3 We may ask for additional information or proportionate proof of identity or authority. We may combine a complaint with a related rights request where that is more efficient, but we will still explain the outcome.
17.4 We would appreciate the opportunity to resolve the issue first. You also have the right to complain to the Information Commissioner's Office, the UK regulator for data protection: ico.org.uk, telephone 0303 123 1113, or Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.
18. Marketing communications
18.1 We may send existing Customers and appropriate business contacts information about related Super Basic services where lawful and reasonably expected. We will obtain consent where electronic-marketing law requires it.
18.2 Every marketing email should identify Super Basic and provide a simple unsubscribe method. An objection can also be sent to support@superbasic.net. We will action it promptly and keep a minimal suppression record.
18.3 Operational messages about an account, payment, renewal, security, legal change, outage or requested support are not marketing and may still be sent while relevant.
18.4 A Customer using Super Basic to communicate with its own contacts is responsible for its mailing list, lawful basis, consent where required, sender identification and unsubscribe handling. Super Basic may suspend sending that appears unlawful, deceptive or abusive.
19. Business transfers and changes of ownership
19.1 If Super Basic seeks investment, finance, restructuring, a merger, acquisition or sale, relevant information may be reviewed by professional advisers and potential counterparties under confidentiality and minimisation controls.
19.2 If the business or service is transferred, personal information may transfer to the successor so it can continue operating the service and honouring contracts. We will provide notice where required and the successor must use the information lawfully.
20. Changes to this Privacy Notice
20.1 We may update this Privacy Notice to reflect product, provider, legal or operational changes. The version and effective date appear at the beginning.
20.2 For a material change that significantly affects how we use information, we will take reasonable steps to provide prominent notice, such as an account message or email. We will request fresh consent where the law requires it.
20.3 Previous versions may be retained for legal and audit purposes. Continued use of a service does not create consent where consent is legally required.
21. Contacting us
- Privacy enquiries, rights requests and complaints: support@superbasic.net
- General support: support@thesuperbasic.com
- Legal notices: legal@thesuperbasic.com
- Post: SUPER BASIC LIMITED, CF5 The Terrace, Grantham Street, Lincoln, England, LN2 1BD
When contacting us, include the relevant app, account email and enough detail to locate the issue. Do not send passwords, full payment-card details, unnecessary health information or unnecessary identity documents.
Appendices — example layered wording
Appendix 1 — Layered notice wording for Customer pages
The following wording can be adapted for booking, event, invoice and payment pages. It is not a replacement for the Customer's own privacy notice:
The organisation named on this page decides why the information you enter is collected and is normally the data controller. Super Basic provides the software and normally processes the information for that organisation. Super Basic also uses limited technical, security and service information for its own lawful purposes. Read the organisation's privacy notice and the Super Basic Privacy Notice at superbasic.net/legal/privacy.
Appendix 2 — Account sign-up wording
We use your account details to create and secure your shared Super Basic account, provide the apps you choose, administer billing and send essential service messages. Read the Super Basic Privacy Notice at superbasic.net/legal/privacy. Optional marketing choices are separate and can be changed at any time.
Appendix 3 — Marketing choice wording
Email me occasional Super Basic product news, offers and useful updates. This is optional. You can unsubscribe at any time. Essential account, billing and security messages are unaffected.