Privacy

Privacy Notice

This notice explains the categories of personal data BADWEB processes, why they are processed, how they are protected, when they may be shared and how account holders can exercise available data controls.

Last updated 2026-09-06

Who is responsible

The BADWEB platform operator is serjo. Contact for privacy or support questions: serjomicoyan@gmail.com. A customer using BADWEB may also be independently responsible for personal data that customer places into its Business Website.

Data we process

  • Account data: email address, account status, activation and recovery records, password hashes and session/security records.
  • Business setup data: business name, industry descriptor, timezone, selected product and capacity level, tenant and product identifiers.
  • Product data: content, settings, media and visitor/contact information entered into or collected through a Business Website.
  • Billing metadata: plan, amount, currency, subscription status and identifiers received from the billing provider. BADWEB does not need to store raw payment-card numbers in its application database to operate Paddle checkout.
  • Support and data-request information that you submit through the account.
  • Security and operational records such as audit events, request correlation data, rate-limit fingerprints, product health state and service events.
  • For generated Business Websites, optional analytics events may be recorded when the site’s consent configuration requires consent and the visitor has accepted optional analytics storage.

Why we process data

Data is processed to create and operate requested products, authenticate users, enforce permissions and capacity, administer trials and subscriptions, deliver activation and service emails, provide support, respond to data requests, prevent abuse, maintain security and auditability, diagnose failures, meet legal obligations where applicable and improve reliability.

Legal basis

The appropriate legal basis depends on the context and jurisdiction. Common bases can include performance of a contract, steps requested before entering a contract, legitimate interests in security and service operation, legal obligations, and consent where consent is specifically requested. A customer who uploads visitor or contact data remains responsible for determining the basis that applies to that customer’s own processing.

Where the data comes from

Most account and setup information comes directly from the person or business using BADWEB. Product records come from authorised users of the customer product. Billing status and provider identifiers come from Paddle after checkout or billing events. Security and operational records are generated by the platform when requests, authentication, provisioning, health checks or administrative actions occur. BADWEB does not state that it purchases hidden marketing profiles about customers.

Required and optional information

Information marked as required in a creation, activation, authentication, billing or support flow is needed to perform that requested step or protect the service. If required information is not provided, BADWEB may be unable to create the product, authenticate the user, process the requested subscription or complete the request. Optional analytics on a generated Business Website remains optional where the site is configured to require visitor consent.

Customer and platform roles

For account, platform-security, billing and direct support data, the BADWEB operator determines the platform purposes described in this notice. For personal data a customer chooses to place in its own Business Website, the customer normally determines the business purpose and permitted users. The exact legal classification of the parties can depend on the processing and applicable law, so this public notice does not invent a controller/processor status that has not been legally established for a specific customer arrangement.

Service providers and disclosure

BADWEB uses infrastructure and operational service providers to deliver the service. The codebase integrates PostgreSQL for data storage, AWS S3 for media objects, AWS SQS for queues, AWS SES for email delivery, Caddy for managed web/TLS routing, and Paddle for billing. Data is shared with service providers only as needed for their role, subject to their applicable terms and the operator’s configuration.

Data may also be disclosed when required by applicable law or reasonably necessary to protect users, the platform or legal rights. BADWEB does not describe customer conversations or account data as being sold to advertisers.

Retention and deletion

Retention depends on the access type, record, account state, billing lifecycle, security requirements and applicable law. Business Website selected-plan trial lasts exactly seven calendar days from first READY. After it expires, free access is closed and the customer may activate a paid plan. Data retention is governed separately and never extends or restarts selected-plan trial.

Expiration of selected-plan trial does not itself create a second free window or a billing grace period. Paid access begins only after verified provider state is synchronized. Account holders also have self-service export and controlled correction/deletion requests, subject to billing, security, integrity and applicable legal safeguards.

Security

BADWEB uses password hashing, secure HTTP-only session cookies, separate owner authentication, MFA for the platform owner, role-based permissions, tenant isolation controls, CSRF/origin protections, rate limiting, media quarantine and processing, audit records and managed TLS routing. More detail is available on the Security page. No system is risk-free, and customers should use strong unique passwords and protect authorised devices.

International processing

Cloud and payment providers may process data in countries different from the user’s location. The operator is responsible for configuring appropriate contractual and legal safeguards where required by applicable data-protection law. This notice does not claim a certification or transfer mechanism that is not established in the running configuration.

Your choices and rights

Depending on applicable law, you may have rights to access, correct, delete, restrict or object to processing, receive portable data, withdraw consent where processing relies on consent, or complain to a competent data-protection regulator. The account includes export and controlled data-request features. Contact serjomicoyan@gmail.com if a request cannot be completed through the account. Withdrawing consent does not make earlier consent-based processing unlawful.

Automated processing

BADWEB automates product assembly, capacity enforcement, readiness checks, security controls and operational workflows. The current public product flow is not described as making a legally significant decision about a person solely from profiling or hidden behavioural scoring. If a future feature introduces that kind of decision-making, the notice should be updated before that processing is relied upon.

Children

BADWEB is a business software platform and is not designed as a service directed to children. Customers are responsible for ensuring that any personal data they enter into their products is collected and used lawfully.

Changes

This notice may change as the platform, providers or legal requirements change. The current page shows its last-updated date. Material changes should be reflected in the public notice before or when the changed processing begins, where required.

Need to act now?

Account holders can use the account area for billing, security, support, export and controlled data requests.

Open account