This policy explains how SenSub collects, uses, and protects the personal data of our users and their customers.
Last Updated: December 1, 2025
This Privacy Policy applies to the use of the SenSub software-as-a-service ("Service") provided by SenSub, Inc. ("we," "us," or "our"). We adhere to the principles of the EU General Data Protection Regulation (GDPR).
By using our Service, you agree to the collection and use of information in accordance with this policy.
When you register for a SenSub account or use our Service, we collect:
In order to provide the subscription management service, we retrieve and store specific non-financial data from your linked PayPal account:
payment.received, subscription.created, and subscription.cancelled.⚠️ Financial Data
We do not store full credit card numbers, bank account numbers, or any sensitive payment instruments used by your customers. This information is handled exclusively by PayPal, the payment processor. SenSub only stores data necessary to link and manage the subscription within our dashboard.
We automatically collect certain information when you visit our website or use our Service:
We process Personal Data only when we have a valid legal basis to do so under Article 6 of the GDPR.
For the collection and use of your Personal Data (User Data), we rely on the following legal bases:
As the Data Processor, we process Service Data solely on your documented instructions and contractual relationship with you, the Data Controller. You are responsible for ensuring you have a lawful basis (e.g., Contractual Necessity, Legitimate Interest, or Consent) to collect and process your customers' data and that this is clearly communicated in your own privacy policy.
We do not sell your Personal Data or your customers' data. We may share information only in the following limited circumstances:
SenSub, Inc. operates from Morocco, meaning the data you provide (User Data) and the data we process on your behalf (Service Data) may be transferred to, and stored at, a destination outside the European Economic Area (EEA).
ℹ️ Safeguards for International Transfers
Where your data is transferred outside the EEA, we ensure that an adequate level of protection is afforded by implementing appropriate safeguards, such as entering into the Standard Contractual Clauses (SCCs) approved by the European Commission, or by ensuring the recipient country has been deemed to provide an adequate level of protection by the European Commission.
As the Data Controller for your customers' data (Service Data), you have specific responsibilities:
We strive to use commercially acceptable means to protect your Personal Data, including technical and organizational measures such as:
We retain User Data only for as long as necessary to provide the Service and for essential business purposes. If you delete your account, we will delete or anonymize your data within 30 days, except where retention is required for legal compliance (e.g., financial/billing records).
In the event of a Personal Data breach that is likely to result in a risk to your rights and freedoms, we are committed to:
Notifying the relevant Supervisory Authority within 72 hour of becoming aware of the breach, where feasible, and notifying you (the Data Controller) without undue delay. We will also communicate the breach to affected individuals if the breach is deemed high-risk.
If you are a resident of the EEA, you have the following rights regarding the Personal Data we hold about you (User Data). To exercise any of these rights, please contact us using the details in Section 10.
Our Service is not intended for use by anyone under the age of 18 ("Children"). We do not knowingly collect personally identifiable information from anyone under 18. If you are a parent or guardian and you are aware that your Children has provided us with Personal Data, please contact us. If we become aware that we have collected Personal Data from children without verification of parental consent, we take steps to remove that information from our servers.
We may update our Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page or via email, typically 30 days prior to the change becoming effective. Your continued use of the Service after the revised Policy has become effective indicates that you have read, understood, and agreed to the current version of the Policy.
If you have questions about this Privacy Policy, wish to exercise your data rights, or need assistance, please contact us:
Data Protection Contact: contact@ialae.com
Address: Route Tétouan, 140 ET2, N6. Tangier, Morocco
Right to Lodge a Complaint: If you are a resident of the European Economic Area (EEA) and believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local data protection supervisory authority.