import Script from 'next/script';

Privacy Policy

AKOLLEKT LTD — redline. Proposed amendments by ANPI, 7 August 2026; second round, 11 August 2026, reflecGng the technical confirmaGons received from the development team. Scope of distribuGon: EEA, United Kingdom, United States, Canada, New Zealand

Effective Date: 08.07.2026

Last Updated: 08.07.2026

Data Controller: AKOLLEKT LTD, a company registered in England and Wales under company number 08557811, Suite 12, 2nd Floor, Queens House, 180 Tottenham Court Road, London W1T 7PD, United Kingdom.

Privacy Contact: [privacy@akollekt.com]

EU Representative (Article 27, EU GDPR): [name, address and email of the representative appointed in an EU Member State].

Data Protection Officer: [name and contact details, if a DPO has been appointed].

Privacy Officer — New Zealand (s 201, Privacy Act 2020): [name and contact details].

Privacy Officer — Canada (PIPEDA, Principle 1): [name and contact details].

Important Privacy Notice

This Privacy Policy explains how we collect, use, store, and protect personal information when you access or use our applications, websites, digital tools, or related services. It applies to the websites, applications and digital services operated by AKOLLEKT LTD, which acts as the data controller in relation to the personal data described below. It does not apply to third-party websites, applications or services that may be linked to or integrated with our services; those are governed by their own privacy policies.

Depending on the specific service you use, we may ask you to provide certain basic information, such as your name, email address, device preferences, account settings, and usage-related information. Some information may be optional and can be skipped during registration or onboarding. Where information is required to create an account or provide a paid service, we will indicate this at the point of collection.

We may also automatically collect technical data, including device type, operating system, browser information, language settings, IP address, and interaction data. This information helps us maintain service functionality, personalize user experience, improve performance, prevent misuse, and, where permitted, provide relevant marketing or advertising content.

You may manage certain privacy preferences through the settings available in our applications, websites, or your device/browser settings.

Regional disclosures. If you are located in the European Economic Area, the United Kingdom, the United States, Canada or New Zealand, additional rights and disclosures apply to you. See Section 14 (Regional Privacy Disclosures).

For questions about this Privacy Policy or to exercise your privacy rights, please contact us at:

Email: [privacy@akollekt.com]

1. General Information

By using our services, you acknowledge that you have read and understood this Privacy Policy.

Acknowledging this Privacy Policy is not, by itself, consent to every processing activity described in it. Different purposes rely on different legal grounds. Where consent is required by law — for example for marketing communications, non-essential cookies or advertising identifiers — we obtain it separately, and you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.

You also confirm that you are at least 18 years old or have the legal authority required to use the services in your jurisdiction. If you do not agree with this Privacy Policy, you should stop using the services and may request deletion of your account and associated personal data. Requests for deletion are handled as described in Section 7 and are subject to the legal retention obligations described in Section 10.

The English version of this Privacy Policy is the official version and prevails over any translations.

2. Personal Data We Collect

We may collect personal data in several ways.

Information You Provide Directly

This may include:

Name

Email address

Account details

Device or service preferences

Information submitted through forms, support requests, or account settings

Content, messages and attachments you submit to customer support, including the contents of your correspondence with us

Subscription and transaction data relating to purchases, renewals, cancellations and refunds

Marketing preferences and consent records

Information Received from Third Parties

We may receive limited information from third-party services when you choose to connect or sign in through them, such as Apple login, productivity platforms, payment providers, or other integrated services.

The exact data received depends on your settings with those third-party services.

Information Collected Automatically

When you use our services, we may collect technical and usage information, including:

Device model

Operating system

Browser type

IP address

Language and region settings

App or website activity

Feature usage

Crash reports and diagnostic data

Login and security records, including login history, User-Agent string, device information and webhook event data

Approximate location (country and region) derived from your IP address

Cookie identifiers, advertising identifiers and session identifiers, as described in Section 8 and in our Cookie Policy

We derive approximate location from your IP address and region settings. We do not collect or use precise geolocation (GPS) data. Neither our applications nor our servers integrate any SDK or third-party service that obtains the coordinates of your device.

Special and Sensitive Categories of Data

We do not intentionally collect special category data, such as data revealing health, biometric, genetic, racial or ethnic origin, religious or philosophical beliefs, political opinions, trade union membership, sex life or sexual orientation, unless this is specifically required and permitted by applicable law. If you submit such data to us voluntarily — for example in a support message — we process it only as necessary to respond to your request.

For the purposes of United States state privacy laws, the only category of sensitive personal information we process is your account log-in credentials. We do not process precise geolocation, biometric or health information, or any other category treated as sensitive personal information under those laws. We do not use or disclose sensitive personal information for any purpose other than those permitted without a right to limit, and we do not sell it.

3. Payment Information

If you purchase paid services, subscriptions, or digital products, payments are processed by authorised third-party payment processors and acquiring partners. Our current payment providers are TrueGate and Stripe. We do not process card payments directly and do not operate our own payment infrastructure.

We do not collect or store full payment card numbers (PAN) or card security codes (CVV). Card data is captured directly by our payment processors, which maintain PCI DSS compliance. However, we may receive limited transaction-related information, such as:

Transaction ID

Payment status

Billing email address

Partial billing details, if provided

Purchase or subscription status

Billing country and currency

Payment method type and masked card details (card brand, card BIN and the last four digits), together with a card token issued by our payment processor

Refund status, payment dispute and chargeback information

We may share relevant transaction data with payment processors, acquiring banks, fraud prevention providers, tax compliance providers and other parties involved in authorising, processing, reconciling or disputing payments, and with tax and accounting authorities where required by law.

Your use of a payment provider is governed by that provider’s own privacy policy and terms of service. Payment processors generally act as independent data controllers in relation to the payment data they collect from you directly.

4. How We Use Personal Data and Legal Basis for Processing

We may use personal data for the following purposes:

To provide, operate, and maintain our services

To personalize features and improve user experience

To manage accounts, subscriptions, and customer support requests

To process transactions and confirm payment status

To send service-related notices, security alerts, and administrative messages

To send promotional communications, where permitted by law, and, where consent is required, only with your consent

To analyze usage trends and improve functionality

To detect, prevent, and respond to fraud, abuse, technical issues, or legal violations

To comply with legal obligations and enforce applicable agreements

To process refunds, subscription cancellations, payment disputes and chargebacks

To reconcile transactions with payment processors and acquiring partners

To prevent payment fraud and assess transaction risk

To calculate, collect and report applicable sales, use, VAT, GST and similar taxes

To comply with tax, accounting, financial and anti-money-laundering obligations

Legal Basis for Processing

Where the EU GDPR or the UK GDPR applies to you, we process personal data only where we have a valid legal basis. Depending on the purpose, we rely on:

Performance of a contract — to create and manage your account, provide the services, process subscriptions and payments, and respond to service-related requests.

Compliance with legal obligations — for tax, accounting, fraud prevention, consumer protection, regulatory and law enforcement requirements

Legitimate interests — to secure our services, prevent misuse and payment fraud, analyse performance, improve functionality and operate our business, where those interests are not overridden by your rights and freedoms.

Consent — for marketing communications, non-essential cookies, advertising technologies and any other optional processing.

Where Canadian federal or provincial privacy legislation applies, we rely on your express or implied consent, except where collection, use or disclosure without consent is permitted or required by law.

Where the New Zealand Privacy Act 2020 applies, we collect personal information only for a lawful purpose connected with our functions and activities, and only where the information is necessary for that purpose, in accordance with the Information Privacy Principles.

Automated Decision-Making

The only decision we take by solely automated means is the control of access to the services on the basis of your subscription status. If your subscription expires, is cancelled or is not renewed, access to the paid features is restricted automatically and the device registered to your account may be deactivated automatically, without human involvement. The logic is limited to checking whether a valid subscription is in force; the consequence is the loss of access to the paid features until a subscription is renewed. This processing is necessary for the performance of our contract with you.

We do not use automated blocking or suspension of accounts, automated refusal of registration, automated profiling or scoring of users, or any other automated decision that produces legal effects concerning you or similarly significantly affects you. Decisions arising from anti-fraud and risk checks are taken manually by our staff. Our payment providers may apply their own automated risk and fraud controls when authorising a transaction; those decisions are made by them and are governed by their own privacy policies.

If access to the services has been restricted automatically and you believe this is incorrect, you may contact us at [privacy@akollekt.com] to obtain human review of the decision, to express your point of view and to contest it.

5. Data Sharing

We may share personal data with trusted third parties only when necessary for business, operational, legal, or technical purposes.

This may include:

Cloud hosting and infrastructure providers

Analytics and diagnostics providers

Payment processors

Customer support tools

Advertising and marketing platforms

Legal, compliance, or security service providers

Acquiring banks and card scheme participants

Fraud prevention and risk management providers

Tax calculation and tax compliance providers

Email and communications providers

Identity and access management providers

Professional advisers, auditors and insurers

These service providers are authorized to process personal data only as needed to provide services to us and must handle such information in accordance with applicable data protection requirements.

Some of these third parties act as our data processors and process personal data solely on our documented instructions. Others — in particular payment processors, acquiring banks and advertising platforms — act as independent data controllers under their own privacy policies. A current list of our sub-processors is available on request.

Third-Party Services We Currently Use

The third-party services that receive personal data from our systems are:

TrueGate — payment provider

Stripe — payment processing

Mailgun (European Union region) — sending transactional emails

Sentry — error monitoring and technical information about requests

Amazon Web Services (S3) — storage of files and attachments you submit through our contact form

An advertising tracker (currently Binom or an equivalent affiliate tracker) — measurement of advertising conversions; we transmit only a click identifier (click_id) used to attribute the advertising campaign

We do not transmit advertising identifiers, cookie identifiers, pixel identifiers or SDK identifiers from our servers to any third party. Databases, caches, task queues, secret management and other infrastructure components that we operate ourselves are not third-party recipients of personal data. This list is current as at the date of this Privacy Policy; an up-to-date list is available on request.

We may also disclose or transfer personal data in connection with a merger, acquisition, corporate restructuring, financing or the sale of all or part of our business. We will notify you and, where required by law, obtain your consent before your personal data becomes subject to a materially different privacy policy.

We may also disclose information where required by law, court order, government request, or to protect our rights, users, systems, or services.

Sale and Sharing of Personal Information (United States)

We do not sell personal information in exchange for money. From our servers, the only information we disclose to an advertising partner is a click identifier (click_id) transmitted in a conversion postback and used to attribute the advertising campaign that referred you; we do not transmit advertising identifiers, cookie identifiers, pixel identifiers or SDK identifiers. Where cookies, pixels or similar technologies used on our websites or in our applications make online identifiers or usage data available to advertising partners, that activity may be treated as a “sale” or “share” under certain US state privacy laws, and you may opt out at any time as described in Section 14.2. We have not sold or shared the personal information of consumers we know to be under 16 years of age.

6. Advertising and Marketing

We may use third-party advertising or marketing tools to measure campaign performance, show relevant content, or understand how users interact with our services.

We do not operate retargeting, audience matching or personalised advertising mechanisms, and we do not build audience segments from your activity across other websites and apps. Our own measurement is limited to conversion attribution: when a purchase or other conversion takes place, our servers send a postback to our advertising tracker containing only the click identifier associated with the advertising campaign that referred you.

Where required by law, we will request your consent before using certain tracking technologies. You may manage advertising, cookie, and tracking preferences through app settings, browser settings, or device-level privacy controls.

In jurisdictions that operate an opt-out rather than an opt-in model, including most US states, we do not ask for prior consent but you may opt out at any time. Where required by law, we treat a Global Privacy Control (GPC) or equivalent browser or device signal as a valid opt-out request.

You may opt out of marketing emails at any time by using the unsubscribe link in the email or by contacting us directly.

You have the right to object to the use of your personal data for direct marketing at any time. This right is unconditional and we will stop such processing on request.

Where we send commercial electronic messages to recipients in Canada, we do so in accordance with Canada’s Anti-Spam Legislation (CASL), which requires express or implied consent, clear identification of the sender, and a functioning unsubscribe mechanism that remains valid for at least 60 days. Where we send commercial electronic messages to recipients in New Zealand, we do so in accordance with the Unsolicited Electronic Messages Act 2007.

7. Your Privacy Rights

Depending on your location, you may have the right to:

Request access to your personal data

Request correction of inaccurate or outdated data

Request deletion of your personal data

Object to or restrict certain processing activities

Withdraw consent where processing is based on consent

Request a copy of your data in a portable format

Opt out of marketing communications

Object to processing carried out on the basis of our legitimate interests

Opt out of the sale or sharing of personal information and of targeted advertising

Not be subject to a decision based solely on automated processing where such decisions are made

Not receive discriminatory treatment for exercising any of these rights

Lodge a complaint with a competent data protection or privacy regulator

To submit a privacy request, contact us using the details provided below.

We may need to verify your identity before processing certain requests. We will only use information provided for verification for that purpose. An authorised agent may submit a request on your behalf where permitted by law, subject to proof of authorisation.

We will respond to a valid request within the period required by applicable law — generally one month under the EU and UK GDPR (extendable by two further months for complex requests), 45 days under most US state privacy laws (extendable by a further 45 days), 30 days under PIPEDA, and 20 working days under the New Zealand Privacy Act 2020.

Where we decline a request in whole or in part, we will explain why and, in US states that provide for it, tell you how to appeal that decision. If your appeal is denied you may escalate to the relevant state Attorney General.

These rights are not absolute. We may be required or permitted to retain certain personal data notwithstanding a deletion request — in particular transaction, billing, tax and accounting records, fraud prevention records, and records needed to establish, exercise or defend legal claims. We will tell you where an exception applies.

8. Cookies and Tracking Technologies

Our websites and digital services may use cookies, pixels, SDKs, or similar technologies to support functionality, remember preferences, analyze performance, and improve services. These technologies operate in your browser and in our applications; our servers do not set cookies and do not generate advertising identifiers.

We use four categories of these technologies: strictly necessary, functional, performance and analytics, and advertising and targeting. Our Cookie Policy describes each category, the third parties involved and applicable retention periods in full, and forms part of this Privacy Policy.

In the EEA, the United Kingdom and Switzerland, non-essential cookies are set only after you give consent through our consent banner, and you may withdraw consent at any time through the cookie settings panel. Rejecting non-essential cookies is as easy as accepting them. Continued use of the service is not treated as consent.

You can control cookies and tracking technologies through your browser settings, device settings, or available consent tools.

Disabling some cookies or tracking technologies may affect certain features or functionality.

9. International Data Transfers

Your personal data may be processed or stored in countries other than the country where you live.

When personal data is transferred internationally, we use appropriate safeguards as required by applicable law. These may include contractual protections, Standard Contractual Clauses, technical security measures, and organizational controls.

Where personal data is transferred out of the United Kingdom, we rely on UK adequacy regulations or on the International Data Transfer Agreement or the UK Addendum to the European Commission’s Standard Contractual Clauses. Where personal data is transferred out of the European Economic Area, we rely on an adequacy decision or on the Standard Contractual Clauses adopted by the European Commission, supported by a transfer risk assessment where required.

Where the New Zealand Privacy Act 2020 applies, we disclose personal information to an overseas recipient only where that recipient is subject to comparable safeguards, as required by Information Privacy Principle 12.

If you are located in Canada, your personal data may be stored or processed outside Canada and may be accessible to courts, law enforcement and national security authorities of those jurisdictions under their applicable laws.

Our transactional email provider processes personal data in the European Union. Certain other providers, including our payment, error-monitoring and cloud storage providers, may process personal data in the United States or in other countries outside the European Economic Area and the United Kingdom; where they do, we rely on the safeguards described above.

You may contact us to request further information about the safeguards we use for international transfers.

10. Data Retention

We retain personal data only for as long as reasonably necessary to provide services, maintain accounts, comply with legal obligations, resolve disputes, prevent fraud, and enforce agreements.

Retention periods may vary depending on the type of information, the purpose of processing, and applicable legal requirements.

Unless a longer period is required by law, we apply the following retention periods:

Account and profile data — for as long as the account remains active, and for [12] months after the account is closed.

Transaction, billing and tax records — for [7] years, as required by applicable tax, accounting and financial legislation.

Customer support records, including messages, attachments and files stored with our cloud storage provider — for [24] months after the request is resolved.

Consent records, including your acceptance of this Privacy Policy and your marketing preferences — for as long as the consent remains valid and for [24] months afterwards, to evidence compliance.

Security records, including IP address, User-Agent string, login history, device information and webhook event data — for [12] months.

Technical and diagnostic data — for [12] months, unless aggregated or anonymised earlier. Error reports held by our error-monitoring provider are retained in accordance with that provider’s own retention policy.

Content of transactional emails sent to you — for [24] months.

Product analytics data — not stored on our servers.

When personal data is no longer needed, we will delete, anonymize, or securely restrict access to it.

11. Data Security

We use reasonable technical and organizational measures to protect personal data against unauthorized access, loss, misuse, alteration, or disclosure. These measures include access controls and role-based permissions, encryption of data in transit, secure authentication, logging and monitoring, vendor security review, incident response procedures, and data minimisation and retention controls.

However, no digital service, transmission method, or storage system can be guaranteed to be completely secure. Users are responsible for maintaining the confidentiality of their account credentials and device access.

Data Breach Notification

If a personal data breach occurs, we will notify the competent supervisory authority and affected individuals where required by applicable law and within the applicable deadlines. This includes notification to the Information Commissioner’s Office or the relevant EEA supervisory authority within 72 hours where the breach is likely to result in a risk to individuals; notification to the Office of the Privacy Commissioner of Canada and affected individuals where the breach creates a real risk of significant harm, together with maintenance of breach records for 24 months; notification to the Office of the Privacy Commissioner of New Zealand and affected individuals as soon as practicable where the breach is likely to cause serious harm; and notification under applicable United States state breach notification laws.

12. Children’s Privacy

Our services are not intended for users under the age of 18.

We do not knowingly collect personal data from minors. If we become aware that a minor has provided personal data without appropriate legal authorization, we will delete such information promptly and, where required, notify the relevant regulator

Different jurisdictions set different thresholds for children’s privacy protections. In the United States, the Children’s Online Privacy Protection Act applies to children under 13, and California law requires opt-in consent before the sale or sharing of the personal information of consumers aged 13 to 16. In the EEA, the age of consent for information society services is between 13 and 16 depending on the Member State; in the United Kingdom it is 13. In Quebec, parental consent is required for individuals under 14.

If you believe that a person under the age of 18 has provided us with personal data, please contact us at [privacy@akollekt.com]. We will investigate and delete or restrict the relevant data where required, and confirm the outcome to you.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our services, legal requirements, or data processing practices. We review this Privacy Policy at least once every 12 months.

When changes are made, we will update the effective date above. In some cases, we may provide additional notice through the service, email, or other appropriate communication methods.

Continued use of the services after an updated Privacy Policy becomes effective means that you acknowledge the updated terms.

Where changes materially affect how we process personal data, we will give you advance notice and, where required by law, obtain renewed consent. Continued use of the services is not treated as consent to a materially different processing purpose where the law requires separate consent.

14. Regional Privacy Disclosures

14.1 European Economic Area and United Kingdom

AKOLLEKT LTD is the controller. Our EU representative under Article 27 of the EU GDPR is Director. You have the rights set out in Section 7, including the right to object to processing based on legitimate interests and the right to data portability. You may lodge a complaint with the Information Commissioner’s Office (ico.org.uk) if you are in the United Kingdom, or with the supervisory authority of your Member State of residence, place of work or the place of the alleged infringement if you are in the EEA.

14.2 United States

This section applies to residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana and other states with comprehensive privacy legislation, to the extent that legislation applies to us.

Categories of personal information we have collected in the preceding 12 months: identifiers (name, email address, IP address, account and device identifiers); commercial information (subscription and purchase records); internet or other electronic network activity information (app and website activity, feature usage, diagnostic data); and approximate location (country and region) derived from your IP address. We do not collect precise geolocation. The sources, purposes and recipients of each category are described in Sections 2, 4 and 5.

Your rights: to know and access the personal information we hold about you; to delete it; to correct it; to obtain it in a portable format; to opt out of the sale or sharing of personal information and of targeted advertising; to limit the use and disclosure of sensitive personal information; to opt out of profiling in furtherance of decisions producing legal or similarly significant effects; and to be free from discrimination for exercising these rights. In states that provide an appeal mechanism, you may appeal a refused request as described in Section 7.

To opt out of the sale or sharing of personal information, use the “Do Not Sell or Share My Personal Information” link on our website, adjust your preferences in the cookie settings panel, or contact us at [privacy@akollekt.com]. We honour Global Privacy Control signals where required by law.

California residents may also request, once per calendar year, information about disclosures of personal information to third parties for their direct marketing purposes under California Civil Code section 1798.83.

This Privacy Policy is intended to be accessible to individuals with disabilities. If you require it in an alternative format, contact us at [privacy@akollekt.com].

14.3 Canada

We process personal information in accordance with the Personal Information Protection and Electronic Documents Act and applicable provincial legislation, including Quebec’s Law 25. Our Privacy Officer is Director, contactable at [privacy@akollekt.com]. You may request access to and correction of your personal information, withdraw consent subject to legal and contractual restrictions, and request that your personal information be transferred to another organisation in a structured, commonly used technological format. If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada, or to the Commission d’accès à l’information du Québec if you are resident in Quebec.

14.4 New Zealand

We process personal information in accordance with the Privacy Act 2020 and the Information Privacy Principles. Our Privacy Officer is Director, contactable at [privacy@akollekt.com]. You may request access to your personal information under Principle 6 and correction under Principle 7; where we decline to correct information, you may ask us to attach a statement of the correction sought. We will respond within 20 working days. You may complain to the Office of the Privacy Commissioner (privacy.org.nz).

15. Contact Information

AKOLLEKT LTD

Mobile App Development & Digital Publishing

contact@akollekt.com

Suite 12, 2nd Floor, Queens House, 180 Tottenham Court Road, London W1T 7PD, United Kingdom

Registered company number: 08557811

© 2026. All rights reserved.