PRIVACY POLICY

Last updated: December 11, 2025

1. Introduction

ECO™ ("we," "our," or "us") is committed to protecting your privacy and ensuring transparency in how we collect, use, and safeguard your personal data. This Privacy Policy explains our practices in compliance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

By joining our waitlist or using our services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not provide us with your personal information.

2. Data Controller

The data controller responsible for your personal data is:

ECO™

Email: [email protected]

Data Protection Officer: [email protected]

3. Personal Data We Collect

We collect the following categories of personal data when you join our waitlist:

3.1 Information You Provide

  • Email address (required for waitlist registration and communications)
  • Name (optional, for personalized communications)
  • Referral code (if you were referred by another user)

3.2 Automatically Collected Data

  • IP address (for security and fraud prevention)
  • Browser type and version
  • Device information (operating system, screen resolution)
  • Usage data (pages visited, time spent, referral source)
  • Cookies and similar tracking technologies (see Section 8)

4. Legal Basis for Processing

We process your personal data based on the following legal grounds under GDPR Article 6:

Consent (Art. 6(1)(a))

When you join our waitlist, you provide explicit consent for us to process your email and name for the purpose of notifying you about ECO™ launch and updates.

Legitimate Interest (Art. 6(1)(f))

We process usage data and analytics to improve our website, prevent fraud, and ensure security. Our legitimate interest is balanced against your privacy rights.

Legal Obligation (Art. 6(1)(c))

We may process data to comply with legal obligations, such as responding to lawful requests from authorities or enforcing our Terms of Service.

5. How We Use Your Data

We use your personal data for the following purposes:

  • To manage your waitlist registration and send you launch notifications
  • To send you updates, newsletters, and promotional communications (you can opt out anytime)
  • To track referrals and reward users who invite others
  • To analyze website usage and improve user experience
  • To prevent fraud, spam, and abuse of our services
  • To comply with legal obligations and enforce our Terms of Service
  • To respond to your inquiries and provide customer support

6. Data Sharing and Disclosure

We do not sell your personal data. We may share your data with the following third parties under strict confidentiality agreements:

6.1 Service Providers

We use trusted third-party service providers for email delivery (Resend), analytics (self-hosted Umami), and hosting (Manus infrastructure). These providers process data on our behalf and are contractually obligated to protect your data.

6.2 Legal Requirements

We may disclose your data if required by law, court order, or government request, or to protect our rights, property, or safety.

6.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, your data may be transferred to the new owner, subject to the same privacy protections.

7. Your Rights Under GDPR

As a data subject under GDPR, you have the following rights:

Right to Access

You can request a copy of all personal data we hold about you.

Right to Rectification

You can request correction of inaccurate or incomplete data.

Right to Erasure

You can request deletion of your data ("right to be forgotten").

Right to Restriction

You can request limitation of how we process your data.

Right to Portability

You can request your data in a machine-readable format.

Right to Object

You can object to processing based on legitimate interest.

Right to Withdraw Consent

You can withdraw consent at any time without affecting lawfulness of prior processing.

Right to Complain

You can lodge a complaint with your local data protection authority.

To exercise any of these rights, please contact us at [email protected]. We will respond within 30 days.

8. Cookies and Tracking Technologies

We use cookies and similar technologies to enhance your experience and analyze website usage. Our cookies are:

Essential Cookies

Required for basic website functionality (session management, security). These cannot be disabled.

Analytics Cookies

We use self-hosted Umami analytics (privacy-focused, no personal data stored) to understand how visitors use our site. These cookies do not track you across other websites.

You can control cookies through your browser settings. However, disabling cookies may affect website functionality.

9. Data Retention

We retain your personal data only as long as necessary for the purposes outlined in this policy:

  • Waitlist data: Retained until ECO™ launches or until you request deletion
  • Email communications: Retained until you unsubscribe or request deletion
  • Analytics data: Aggregated and anonymized after 12 months
  • Legal compliance: Some data may be retained longer to comply with legal obligations (e.g., tax records, dispute resolution)

After the retention period, we securely delete or anonymize your data.

10. International Data Transfers

Your data may be transferred to and processed in countries outside the European Economic Area (EEA). We ensure adequate protection through:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions for countries with equivalent data protection standards
  • Binding Corporate Rules for intra-group transfers

11. Data Security

We implement industry-standard security measures to protect your data from unauthorized access, alteration, disclosure, or destruction:

  • Encryption in transit (HTTPS/TLS) and at rest
  • Regular security audits and vulnerability assessments
  • Access controls and authentication mechanisms
  • Employee training on data protection and confidentiality

However, no method of transmission over the internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

12. Children's Privacy

ECO™ is not intended for children under 16 years of age. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us immediately at [email protected], and we will delete it promptly.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of material changes by:

  • Posting the updated policy on this page with a new "Last updated" date
  • Sending an email notification to waitlist members
  • Displaying a prominent notice on our website

Your continued use of our services after changes become effective constitutes acceptance of the updated policy.

14. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Email: [email protected]

Data Protection Officer: [email protected]

Response time: Within 30 days

You also have the right to lodge a complaint with your local supervisory authority if you believe we have not adequately addressed your concerns.