This Privacy Policy explains how GmTrend.Com, collects, uses, shares, retains and protects personal data in connection with our website, orders, monitoring products and support. It also explains the choices and rights available to individuals.
1. Controller and contact details
GmTrend.Com is the controller of the personal data described in this policy unless we expressly state that we act as a processor on a customer’s documented instructions. The business address is 22 Arlington Ave, London, N1 7AX, United Kingdom.
Privacy questions and rights requests may be sent to [email protected]. Support-related communications should be sent to [email protected].
2. Personal data we may collect
Identity and contact information
This may include a name, organisation, billing details, country, email address, telephone number where provided, account identifier and communications preferences.
Order and transaction information
This may include product selection, order number, amount, currency, payment status, refund or dispute status, billing location, tax information where required and limited payment-provider references. Full card details are handled by the payment provider and are not intentionally stored in our support systems.
Technical and usage information
This may include IP address, browser and device characteristics, operating system, referring page, timestamps, pages viewed, session and security logs, cookie identifiers, diagnostic data and information about interaction with our website or customer account.
Monitoring configuration and service records
This may include an authorised domain, URL, endpoint, IP address, expected response, monitoring interval, alert destination, setup instructions, status results, timestamps, incident history and technical records required to operate or troubleshoot the purchased product.
Communications and support information
This may include emails, contact-form submissions, support requests, order evidence, feedback and non-sensitive screenshots or logs supplied to help us investigate an issue.
Fraud, security and compliance information
This may include risk indicators, payment verification outcomes, abuse reports, evidence of authority to monitor, account-security events, records of policy enforcement and information reasonably necessary to establish, exercise or defend legal claims.
3. How we obtain personal data
We obtain information directly when a person checks out, creates or uses access, submits a form, configures a target, contacts support or otherwise communicates with us. We also receive limited information from payment providers, fraud-prevention providers, hosting and security providers, analytics tools, email providers and publicly available or customer-authorised technical sources.
Where an organisation purchases for its staff, clients or administrators, it is responsible for ensuring that it has a lawful basis to provide their contact information and that they receive appropriate privacy information.
4. Purposes and lawful bases
Providing products and fulfilling orders
We use identity, contact, order, configuration and service data to accept payment, deliver access, configure monitoring, send alerts, provide support and administer your licence and support entitlement. The usual lawful basis is performance of a contract or taking steps requested before entering a contract.
Operating, securing and improving the service
We use technical, diagnostic and security data to maintain availability, prevent abuse, troubleshoot faults, improve product performance and protect customers and infrastructure. The usual lawful basis is our legitimate interest in operating a reliable and secure service, balanced against individual rights.
Payment, accounting and legal compliance
We use order and transaction records to process payments and refunds, maintain tax and accounting records, respond to lawful requests, meet company obligations and manage disputes. The lawful basis may be performance of a contract, compliance with a legal obligation or our legitimate interest in establishing and defending claims.
Fraud prevention and authorised use
We may assess orders, access patterns and monitoring targets to prevent fraud, account takeover, unauthorised monitoring and harmful use. The usual lawful basis is our legitimate interest in protecting customers, payment systems, third parties and our business. Where law requires a different basis, we will use that basis.
Communications and marketing
We send transactional and operational communications because they are necessary to provide the service. We send optional marketing only where permitted by law, relying on consent where required or another lawful basis available for an existing customer relationship. Every eligible marketing message will provide a practical method to unsubscribe.
Consent-based processing
Where we rely on consent, such as for certain non-essential cookies or marketing, consent may be withdrawn at any time. Withdrawal does not make earlier lawful processing unlawful.
5. Monitoring data and customer roles
Most configured targets are organisational or technical identifiers rather than information intended to identify a person. However, a URL, endpoint, log entry or alert address can contain personal data. Customers must avoid submitting unnecessary personal data and must not use our service for unlawful surveillance or profiling.
Depending on the product and configuration, we may act as a controller for account, order and service-administration records and as a processor for limited customer-provided data processed solely to operate an authorised monitoring configuration. Where a separate data-processing agreement is required, customers should contact us before submitting regulated or higher-risk information.
6. Payment information
Payments are processed by the payment providers offered at checkout. Those providers may independently process identity, device, transaction and risk information under their own privacy notices and legal obligations. We receive information such as payment status, transaction reference, amount, currency, risk or dispute status, but we do not intentionally receive or store a complete card number in our normal order and support systems.
7. Cookies and similar technologies
We use cookies and similar technologies to operate essential website and checkout functions, protect sessions, remember choices, understand use and, where consent has been obtained, support analytics or marketing. Our Cookie Policy provides further information about categories, duration and choices.
8. Sharing personal data
We may share only the information reasonably necessary with:
- payment processors, banks and fraud-prevention providers;
- website hosting, cloud infrastructure, content delivery and security providers;
- email, customer-support, monitoring and operational service providers;
- analytics or consent-management providers where lawfully enabled;
- professional advisers, auditors and insurers under appropriate duties;
- courts, regulators, law-enforcement bodies or public authorities where legally required; and
- a purchaser, investor or successor involved in a genuine corporate transaction, subject to appropriate confidentiality and data-protection measures.
We do not sell personal data for money. We do not permit service providers to use data for unrelated purposes merely because they process it for us.
9. International transfers
Some suppliers may process information outside the United Kingdom. Where a restricted transfer occurs, we use an appropriate legal mechanism where required, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another lawful safeguard. We also consider technical and organisational measures appropriate to the nature and risk of the transfer.
10. Retention
We keep personal data only for as long as reasonably necessary for the purpose collected, including delivery, support, security, accounting, fraud prevention and legal claims. Retention depends on the type of record, licence duration, contractual need, risk, legal limitation period and statutory accounting or tax obligation.
Order and accounting records may be retained for the period required by applicable financial and tax law. Support and technical records are generally retained for a shorter operational period unless needed to resolve an ongoing issue, investigate abuse or defend a claim. When data is no longer required, we delete, anonymise or securely restrict it.
11. Security
We use technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures may include access control, least-privilege permissions, encryption in transit where appropriate, secure hosting, logging, updates, backups, supplier assessment and incident procedures.
No internet service can promise absolute security. Customers should use strong unique passwords, protect access links, restrict administrative access and notify us promptly of suspected compromise. Sensitive credentials, private keys and full card details should never be sent to us by ordinary email.
12. Individual rights
Depending on the circumstances and applicable law, an individual may have the right to:
- request access to personal data and information about its use;
- ask us to correct inaccurate or incomplete data;
- request deletion where there is no continuing lawful reason to retain the data;
- request restriction of processing in specified circumstances;
- object to processing based on legitimate interests or to direct marketing;
- receive certain data in a structured, commonly used and machine-readable format;
- withdraw consent where processing relies on consent; and
- complain to a supervisory authority.
Rights are not absolute and exemptions can apply. We may request proportionate information to verify identity and protect another person’s data. We normally respond within the period required by applicable law and will explain if an extension or refusal is lawful.
13. Automated decisions
Payment and fraud-prevention providers may use automated tools to assess transaction risk. We may use risk indicators to decide whether to request verification, pause activation or reject a high-risk order, but we aim to include appropriate human review where a decision has a significant effect and the law requires it. Contact us if you believe an order was incorrectly affected.
14. Children’s data
Our products are intended for adults and organisations, not children. We do not knowingly market monitoring products directly to children or knowingly collect personal data from a child who cannot lawfully provide it. If you believe a child has provided personal data without appropriate authority, contact us so that we can investigate and take suitable action.
15. Third-party websites
Our website may link to third-party websites or services. Their privacy practices are controlled by them, not by this policy. Customers should read the relevant third-party notice before submitting personal data.
16. Complaints
Please contact us first so that we can investigate a privacy concern. Individuals in the United Kingdom also have the right to complain to the Information Commissioner’s Office. Information about making a complaint is available at ico.org.uk. This right does not prevent other legal remedies.
17. Changes to this policy
We may update this policy when our products, suppliers, legal obligations or processing activities change. The revision date appears at the top. Where a change is material, we will take reasonable steps to bring it to the attention of affected users.
18. Contact
Privacy enquiries: [email protected]
GmTrend.Com
22 Arlington Ave, London, N1 7AX, United Kingdom.
