Whatsapp Logo

Commercium

Commercium
by ConstaCloud Private Limited
GDPR Compliant  ·  Data Secure

Privacy Policy

Last Updated: 8th May, 2026
This Privacy Policy describes how ConstaCloud Private Limited (India) and ConstaCloud LLC (USA) (collectively, “ConstaCloud”, “we”, “our”, or “us”) collect, use, disclose, and protect personal data in connection with the Commercium platform.

Commercium is designed as a secure data infrastructure layer, enabling businesses to connect and synchronize data across marketplaces, ERP systems, e-commerce platforms, and other third-party systems.
2

Data Protection Roles

Depending on the context:

Data Controller

For account registration, billing, website usage, and support interactions.

Data Processor

For all customer data processed through Commercium on behalf of our clients.

We process customer data strictly on documented instructions.

3

Categories of Data We Process

A. Account & Business Data
  • Name, email, company details
  • Billing and subscription information
Purpose: Account management Legal Basis: Contract performance - (Article 6(1)(b))
B. Customer Data (Processed on behalf of clients)
  • Customer names, email addresses, phone numbers
  • Shipping and billing addresses
  • Order details, transaction records
  • Customer messages (if integrated via support systems)
  • Payout and settlement data
Purpose: Data synchronization across connected systems Legal Basis: Contract performance - (Article 6(1)(b))
C. Technical & Usage Data
  • IP address, device information
  • Logs and system activity
  • API usage data
Security, monitoring, and service improvement Legal Basis: Legitimate interests - (Article 6(1)(f))
D. Website Analytics Data
  • Collected via tools like Google Analytics and Mouseflow
Purpose: Website performance and user behavior insights Legal Basis: Consent - (Article 6(1)(a))
4

How We Use Data

We use personal data to:

  • Provide and operate the Commercium platform
  • Synchronize data between integrated systems
  • Monitor performance and ensure reliability
  • Provide customer support
  • Ensure platform security and fraud prevention
5

Sub-Processors

We use trusted third-party providers to support our services.

Provider Purpose
AWS Hosting and infrastructure
Cloudflare CDN, security, and DDoS protection
Google Workspace Email communication
Google Analytics Website analytics
Mouseflow User behavior analytics
Rollbar Error monitoring
Pulsetic Uptime monitoring
Tawk.to Customer support
SE Rankings SEO monitoring (limited use)

All sub-processors are contractually bound to protect data and comply with applicable data protection laws.

6

International Data Transfers

Personal data may be processed outside the European Economic Area (EEA), including in the United States and India. Where such transfers occur, we rely on:

  • Standard Contractual Clauses (SCCs)
  • Other legally recognized safeguards
7

Data Retention

We retain data as follows:

Data Type Retention Period
Account data 60 days after termination
System logs 30 days
Backup data 60 days

After these periods, data is securely deleted or anonymized.

8

Security Measures

We implement industry-standard security practices, including:

🔐Encryption at rest (AES-256)
🔒Encryption in transit (TLS 1.2+)
👤Role-based access control (RBAC)
📋Audit logging & monitoring
☁️Secure cloud infrastructure (AWS)
9

Data Subject Rights

Under GDPR, individuals have the right to:

Access their data
Correct inaccurate data
Request deletion
Restrict processing
Data portability
Object to processing

Requests can be submitted to [email protected]. We respond within 30 days.

10

Breach Notification

In the event of a personal data breach, we will notify affected customers without undue delay, in accordance with applicable laws.

11

Automated Decision-Making

We do not engage in automated decision-making or profiling that produces legal or significant effects.

12

Cookies & Tracking

We use cookies and similar technologies for:

  • Analytics (Google Analytics)
  • User behavior tracking (Mouseflow)

Users may manage cookie preferences via browser settings or consent mechanisms.

13

Data Processing Agreement (DPA)

A Data Processing Addendum (DPA) is available upon request and governs our obligations as a data processor.

14

Updates to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or platform notification.

15. Contact Information

ConstaCloud Private Limited — India
ConstaCloud LLC — Delaware, USA
✉️  [email protected]