Information & policies
Privacy Policy
1. Who controls your data
The operator of MakeSomeoneHappyOrNot acts as data controller for information processed through this service. Full controller identity and a dedicated privacy contact must be added before commercial launch.
2. Data we process
We may process the purchaser's name, email address, billing details, recipient and sender names, personalized message content, template choices, payment status and identifiers, IP address, security logs and technical device information. Payment providers process card or wallet data under their own privacy terms.
3. Why we process it
We process data to create and deliver the requested surprise, complete and document payment, send the purchased link, provide support, prevent abuse, secure the service, comply with tax and legal obligations and establish or defend legal claims.
4. Legal bases
Depending on the activity, processing is necessary to perform the contract, comply with legal obligations, pursue legitimate interests in service security and improvement, or act on consent where consent is specifically requested.
5. Recipients and processors
Data may be handled by hosting, email, payment, security and professional-service providers only as needed to provide the service. Current providers may include Hostinger and the payment provider selected at checkout, such as Cardlink.
6. International transfers
Where a provider processes data outside the European Economic Area, appropriate safeguards must be used as required by applicable data-protection law.
7. Retention
Gift links and their personalized content are retained for the displayed link lifetime and a limited operational period thereafter. Purchase and accounting records may be retained for the period required by tax and commercial law. Security logs are kept only as long as reasonably necessary.
8. Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability or objection, and may withdraw consent without affecting earlier lawful processing. You may also complain to the Hellenic Data Protection Authority or another competent supervisory authority.
9. Data about recipients
A purchaser may provide limited information about another person. Purchasers must avoid sensitive or unnecessary information and must have a lawful basis for sharing it. Recipients may contact us to request review or removal.
10. Security and contact
We use proportionate technical and organizational safeguards. No system is completely secure. Use the Contact page for privacy requests and do not send card details or passwords by email.