RITSUMS — PRIVACY POLICY Last updated: 4 August 2026 Eric Daniele, trading as Owner Software, of Rueda 1805 Piso 1, Departamento 3 ("we", "us"), is the controller of personal data processed in Ritsums, the Ritsu Management System (the "Service"). This policy explains what personal data we collect, why, and what rights you have. 1. Data we collect - Account data: name, email address, password hash, profile photo, job title, department, and the role grants that determine what you can access. - Content you submit: projects, issues, comments, documents, uploaded files, time entries, meetings and any personal data you choose to put inside them. - Usage and technical data: log records of actions taken in the Service, IP address, browser and device information, and session cookies. - Integration data: where you connect Google Calendar, the calendar events and tokens needed to sync them. - Billing data: name, billing address, and the transaction records needed for invoicing and tax. Card details are handled by our payment provider, Paddle, and are never stored by us. 2. Why we use it To provide and operate the Service; to authenticate you and enforce access control; to send transactional email (invitations, password resets, notifications); to bill for paid plans; to keep the Service secure and debug faults; and to comply with legal obligations. Where we rely on legitimate interests, those are operating and securing the Service. 3. Cookies We use strictly necessary cookies to keep you signed in and to protect the session. We do not use advertising cookies or third-party tracking. 4. Sharing We share data only with processors that operate the Service on our behalf: Convex (application database, file storage and backend hosting), Vercel (application hosting), Resend (transactional email), Google (calendar sync, where you connect it) and Paddle (payments, our merchant of record). We do not sell personal data. We may disclose data where required by law. 5. Customer workspaces Ritsums is sold to organisations, and a customer organisation administers its own workspace: it issues the invitations, decides who holds which role, and can read the content its members put into its projects. If your account was created by your employer or client, that organisation controls the workspace and we process the data in it on their behalf. 6. International transfers Our providers may process data outside your country, including in the United States. Transfers are made under the safeguards those providers offer, such as Standard Contractual Clauses. 7. Retention Account and content data is retained while the account is active and for a reasonable period afterwards to allow recovery, then deleted. Billing and tax records are kept for as long as the law requires. 8. Security Access is invitation-only and every request is checked server-side against your role grants. Data is encrypted in transit. No system is perfectly secure; report any suspected issue to the contact below. 9. Your rights Depending on where you live, you may request access to, correction of, deletion of, or a copy of your personal data, and you may object to or restrict certain processing. If your workspace is administered by your employer or client, raise the request with them first; you may also write to us directly at the address below. You may also complain to your local data protection authority. 10. Children The Service is a business tool and is not directed at anyone under 16. 11. Changes We may update this policy. Material changes will be notified through the Service or by email. 12. Contact Eric Daniele, trading as Owner Software Rueda 1805 Piso 1, Departamento 3 Privacy questions and data requests: ericdaniele34@gmail.com Related documents: /terms /refunds /pricing