Data Processing
This page sets out, in one place, how data is handled across Vistredo's operations. It is written for banks, payment processors, advertising platforms and prospective partners carrying out a compliance or onboarding review, and it complements the Privacy Policy, which covers this website specifically.
1. The entity
| Legal entity | Vistredo LTD |
|---|---|
| Company number | 17413715 |
| Jurisdiction | England and Wales |
| Registered office | 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom |
| Applicable law | UK GDPR and the Data Protection Act 2018; EU GDPR where we offer products to users in the EEA |
| Contact | Vistredoltd@gmail.com |
2. Our role
Vistredo LTD builds and operates its own consumer applications and acquires their users itself. We are therefore a controller in respect of the personal data of the users of those applications: we determine why it is processed and how. We do not act as a processor for third-party clients, because we do not sell development or marketing services — our revenue comes from consumer subscriptions to our own products.
Where we engage suppliers — hosting, payment processing, attribution, customer support tooling — those suppliers act as our processors under written terms, except where a supplier is an independent controller in its own right, which is typically the case for app stores and advertising platforms.
3. Categories of processing
3.1 This website
No forms, no accounts, no cookies, no analytics, no third-party requests. The only processing is the connection data our hosting provider needs to serve a page and defend the service. See the Privacy Policy and Cookie Policy.
3.2 Consumer applications
Each application has its own privacy notice, presented in-app and on its store listing, which governs that product. Broadly, the categories processed are:
- Account and identity data — where a product offers accounts.
- Subscription and payment records — plan, term, billing period, renewal and cancellation events, refunds and chargebacks. Card details are handled by the payment provider or the app store and are not stored by us.
- Product usage events — activation, session and feature events used to operate and improve the product.
- Attribution data — the campaign, creative, country and price point a cohort originated from, retained with the cohort so that revenue can be attributed correctly.
- Support correspondence.
3.3 Purposes and legal bases
Providing the product and administering a subscription is performed on the basis of contract. Fraud prevention, service security, and measuring and improving our own products rest on legitimate interests. Advertising and measurement identifiers, where a product uses them, rest on consent, obtained through the platform's own permission framework where one applies. Retention of accounting and tax records rests on legal obligation.
4. Sub-processors and independent controllers
The categories of recipient we use are set out below. A current, named list is provided to counterparties on request under a compliance review.
| Hosting, CDN and network security | Cloudflare, Inc. — processor |
|---|---|
| Cloud infrastructure and storage | Processor |
| Payment processing and subscription billing | Processor or independent controller, depending on the provider's role |
| App stores | Apple and Google — independent controllers for store transactions |
| Attribution and product analytics | Processor |
| Advertising platforms and networks | Independent controllers for their own platform data |
| Email and support tooling | Processor |
Every processor is engaged under terms meeting Article 28 UK GDPR: processing only on documented instructions, confidentiality obligations, security measures, sub-processing controls, assistance with data subject rights, and deletion or return at the end of the engagement.
5. International transfers
Several of our suppliers are established outside the United Kingdom, principally in the United States. Transfers are made under an adequacy regulation where one applies, and otherwise under the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum issued by the Information Commissioner, supported by a transfer risk assessment. Copies of the relevant safeguards are available to counterparties on request.
6. Retention
Personal data is kept only as long as it is needed for the purpose it was collected for. Subscription and transaction records are retained for the period required by UK accounting and tax law. Product event data is retained in identifiable form only for as long as it is needed for the cohort analysis it supports, and is aggregated or deleted thereafter. Support correspondence is deleted once the matter and any follow-up are closed, subject to any retention needed to defend a legal claim.
7. Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit, access control on the principle of least privilege, separation of production and development environments, logging and monitoring, and periodic review of supplier security posture. This website itself is static, holds no database and accepts no input, and is served under a strict Content Security Policy with HSTS.
8. Data subject requests
Requests to access, correct, delete, restrict, port or object to the processing of personal data can be sent to Vistredoltd@gmail.com, or through the mechanism provided inside the relevant application. We respond within one month, extendable by two further months for complex requests, and will tell you if an extension applies.
9. Personal data breaches
We maintain an internal procedure for identifying, assessing and escalating personal data breaches. Where a breach is likely to result in a risk to the rights and freedoms of individuals, we notify the Information Commissioner's Office without undue delay and, where feasible, within 72 hours of becoming aware of it, and we notify affected individuals where the risk is high. Where a breach affects a counterparty's data, we notify that counterparty without undue delay.
10. Supervisory authority
Our lead supervisory authority is the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom — ico.org.uk.