This Privacy Policy describes how Toxtab ("we," "us," or "our"), operated at www.toxtab.com, collects, uses, and protects personal data that we may obtain about you ("User") during your use of the Service. By using the Service, you agree to the terms of this Privacy Policy. If you do not agree, you must stop using the Service.

1. Definitions

1.1
"Use of the Service" means any interaction by the User with the software or hardware developed or operated by Toxtab.
1.2
"Service Administration" means authorized Toxtab staff who manage the Service, process personal data, and determine the purposes and scope of such processing.
1.3
"Personal Data" means any information relating to the User.
1.4
"Processing of Personal Data" means any operation performed on personal data, including collection, recording, organization, storage, updating, retrieval, use, transfer, anonymization, blocking, deletion, or destruction.
1.5
"Confidentiality of Personal Data" means the obligation of the Service Administration not to disclose User data without the User's consent or another lawful basis.

2. General Provisions

2.1
By using the Service, the User agrees to this Privacy Policy and to the processing of their personal data as described herein.
2.2
This Privacy Policy applies solely to the Toxtab Service. We do not control and are not responsible for third-party software, hardware, or websites that the User may interact with while using the Service.
2.3
We are not responsible for any security incidents caused by the User's own actions, including use of outdated or compromised software, weak or improperly stored passwords, or unauthorized third-party access to the User's email account.
2.4
We do not verify the accuracy of personal data provided by the User.

3. Scope of This Policy

3.1
This Privacy Policy sets out the obligations of the Service Administration to protect personal data that the User provides when using the Service.
3.2
We treat the following as personal data: information automatically transmitted during use of the Service, such as IP address, cookies, browser information, and similar technical data.

4. Purposes of Data Collection

4.1
Identifying the User when accessing the Service.
4.2
Providing the User with access to personalized features and resources.
4.3
Communicating with the User, including sending notifications, responding to requests, and providing support.
4.4
Determining the User's approximate location for fraud prevention purposes.
4.5
Verifying the accuracy of personal data provided by the User.
4.6
Creating and maintaining a User account, where the User has consented to account creation.
4.7
Providing effective customer and technical support in connection with the use of the Service.
4.8
Enabling access to partner services or platforms for the purpose of receiving related products, updates, or services.
4.9
Ensuring the correct operation of features that are useful to the User within the Service.

5. Data Processing and Storage

5.1
Personal data is processed for an indefinite period using any lawful means, including automated information systems.
5.2
The User agrees that we may share personal data with third parties where necessary to provide the Service — for example, with email delivery providers used to send notifications to the User.
5.3
In the event of loss or unauthorized disclosure of personal data, we will notify the User and take prompt measures to eliminate the cause of the breach.
5.4
We implement necessary organizational and technical measures to protect personal data against unauthorized or accidental access, destruction, modification, blocking, copying, or distribution.
5.5
We do not use biometric data for automated identification of any User.
5.6
We do not guarantee the complete absence of subjective human error when our staff performs visual comparison of photo images as part of the attendance verification feature.
5.7
Check-in event photos (attendance records) are stored for a maximum of 4 months, after which they are permanently deleted.
5.8
A User's reference photo is automatically deleted from the system if no check-in activity is recorded for that User for 6 consecutive months.
5.9
A User may request deletion of their data from the Service at any time, without waiting for automatic deletion.

6. Obligations of the Parties

6.1
The User is obliged to:
  • provide personal data necessary for using the Service;
  • update their personal data if it changes.
6.2
The Service Administration is obliged to:
  • use collected data solely for the purposes described in Section 4 of this Policy;
  • keep personal data confidential and not sell, exchange, publish, or otherwise disclose it, except as described in clauses 5.2 of this Policy;
  • take precautionary measures to protect the confidentiality of personal data;
  • block personal data relating to a specific User upon that User's request or upon a request from an authorized data protection authority, for the duration of any investigation into inaccurate or unlawfully processed data.

7. Liability

7.1
The Service Administration shall be liable for failure to fulfill its obligations under this Privacy Policy to the extent permitted by applicable law.
7.2
The Service Administration shall not be liable for loss or disclosure of confidential information if:
  • the information became publicly available before its loss or disclosure;
  • the information was received from a third party before it was received by the Service Administration;
  • the information was disclosed with the User's consent.

8. Dispute Resolution

8.1
Before initiating any legal proceedings, the parties must first attempt to resolve any dispute through a written claim submitted electronically and a good-faith negotiation process.
8.2
The receiving party must respond to a claim within 30 calendar days of receipt.
8.3
If no agreement is reached, the dispute shall be referred to a competent court or arbitration body in accordance with applicable law.

9. Additional Terms

9.1
We reserve the right to amend this Privacy Policy at any time without prior consent from the User.
9.2
A new version of the Privacy Policy takes effect upon its publication on the Service, unless otherwise stated in the updated version.
9.3
Questions or comments regarding this Privacy Policy should be directed to: www.toxtab.com/support
9.4
The current version of this Privacy Policy is available at: www.toxtab.com/legal/privacy