CashProjection Pro

Privacy Policy

Version 1.0 · Date: 28th February 2026

1. Who are we; What do we do?

The team at Projectify ("Projectify", "we" or "us") understands that privacy is important to all our users. We respect and value the privacy of everyone who visits or uses www.cashprojectionpro.com ( "the Platform") and will only collect and use personal data in ways that are described here, and in a way that is consistent with our obligations and the data subject's rights under the law.

First things first, some important definitions.

TermDefinition
AccountThe primary means of accessing and using the Projectify Solutions.
ClientThe individual or entity who accepted the ToU.
Client DataAll personal data that is inserted, uploaded or inputted by the Client to the Platform.
Data Protection LegislationThe GDPR, the Data Protection Act, Chapter 586 of the Laws of Malta and any relevant subsidiary legislation.
GDPREU Regulation 2016/679.
Projectify SolutionsAll features and functionalities available on or through the Platform.
Terms of Use (ToU)The terms of use governing the use of the Platform, as accessible through https://cashprojectionpro.com/TermsAndConditions.
UserThe individual or entity who is authorised by the Client to access the Account.

Throughout this document, we will be using certain specific terms. Since our intention is that this document is easily understood, we would like to clarify what these terms are intended to refer to. Naturally, if anything is unclear, please do not hesitate to get in touch with us.

In terms of Data Protection Legislation, the term "personal data" is defined as 'any information relating to an identified or identifiable natural person ('data subject')'. Furthermore, the term "processing" is also given a wide meaning and is defined as 'any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means.' This includes collection, recording, storage, adaptation, and use of personal data. A "data controller" is a person or organisation, who alone or jointly determines the purposes and means of the processing of personal data.

2. What does this policy cover?

This policy provides an overview of the personal data we process when we act as data controllers in connection with the use of our Platform, including the delivery of our Projectify Solutions. As a data controller, we determine the purposes and means of certain processing of personal data. For example, we act as a data controller when a Client opens an Account or a User contacts our customer support. In these situations, we determine the purposes and methods of processing of the underlying personal data, and we ensure that it is handled in compliance with data protection regulations. This policy also provides details on how, in the situations where we act as data controllers, we collect personal data, how we use it, and how we ensure its protection.

However, there are also circumstances where we act as a data processor. In these cases, this privacy policy is not applicable. Instead, we process personal data on behalf of another company or organization (the Client), which is the data controller. In such situations, the Client, as the data controller, is responsible for deciding why and how that relevant personal data is processed, and their privacy policy—not this one—will govern how such data is handled.

3. What types of personal data will we be processing as data controller? How do we get such personal data?

We have grouped the personal data that we receive, use or otherwise process in the following categories:

CategoryDescriptionSource
Profile InformationIncludes details provided when creating an Account, such as name, surname, and email address; details provided when purchasing a subscription plan; and any other information required to manage and operate your Account.Provided directly by you (the Client or User) when the Account is created or during ongoing Account management.
Interaction InformationInformation exchanged with us that is not included in other categories, including messages, feedback, and support interactions.Provided directly by you (Client/User) through communications and interactions with our Platform or support team.
Financial InformationData necessary to process subscriptions and payments, including fees owed, banking information, and payment transaction details.Provided directly by you during financial transactions or subscription payments.
Usage InformationInformation automatically collected when you access or use the Platform or Projectify Solutions. This may include pages or features accessed, frequency and duration of use, device and browser data (MAC address, device ID, operating system, browser type, manufacturer/model), and IP address.Automatically collected by the Platform through log files and similar technical processes.

4. International Transfers and SCCs

Where personal data is transferred outside the European Economic Area (EEA), Projectify ensures adequate safeguards are in place, in accordance with GDPR and the Standard Contractual Clauses (SCCs) adopted by the European Commission.

Such transfers may occur when engaging third-party service providers outside the EEA for hosting, support, analytics, or payment processing.

Projectify requires all third-party recipients to implement appropriate technical and organizational measures to protect your personal data in accordance with GDPR and SCC requirements.

By using the Platform, you consent to these transfers under the protections provided by the SCCs and this Privacy Policy.

5. How do we use personal data? What is the legal basis for processing personal data?

Our primary objectives in processing personal data are to manage Accounts, provide access to our SaaS cash flow projection Platform ("Projectify Solutions"), handle subscriptions, and ensure smooth delivery of our services. We also process personal data to comply with legal obligations and contractual commitments, including those under the Terms of Use.

We will only process personal data when we have a lawful basis to do so. The legal bases we rely upon for processing personal data are outlined in the table below:

PurposeTypes of Personal DataLawful Basis (GDPR Article)
Account Onboarding
Setting up Accounts, verifying Client/User identity, and granting access to the Platform.
Profile Information; Interaction InformationLegal obligation (6(1)(c)); Legitimate interests (6(1)(f)) – to administer onboarding and safeguard our platform and reputation
Subscription and Account Management
Managing Accounts, communicating subscription benefits, and providing access to platform features.
Profile Information; Interaction Information; Subscription InformationPerformance of a contract (6(1)(b)); Legitimate interests (6(1)(f)) – to ensure platform functionality and service delivery
Customer Support & Relationship Management
Handling inquiries, providing support, and maintaining effective communication with Clients/Users.
Profile Information; Interaction Information; Shared ContentContractual necessity (6(1)(b)); Legal obligation (6(1)(c)); Legitimate interests (6(1)(f)) – to maintain accurate records and provide high-quality support; Consent (6(1)(a)) when applicable
Payment Processing & Billing
Processing subscription fees, refunds, and managing financial transactions.
Profile Information; Financial Information; Interaction InformationContractual necessity (6(1)(b)); Legitimate interests (6(1)(f)) – to collect payments securely
Marketing & Communications
Sending information about updates, new features, promotions, or newsletters.
Profile Information; Service Information; Interaction InformationConsent (6(1)(a)); Legitimate interests (6(1)(f)) – to maintain and grow our client base responsibly
Business Intelligence & Analytics
Analyze anonymized data to improve user experience.
Profile Information; Service Information; Interaction InformationLegitimate interests (6(1)(f)) – to optimize the Platform and user experience
Security & Risk Management
Monitoring, preventing, and responding to security threats, fraud, intellectual property violations, or other unlawful activity.
Profile Information; Interaction Information; Service Information; Financial Information; Usage InformationLegitimate interests (6(1)(f)) – to safeguard the Platform, our users, and infrastructure; Legal obligation (6(1)(c))
Corporate Transactions
Sharing information with prospective buyers, partners, or advisors in connection with mergers, sales, acquisitions, or other business transactions.
Profile Information; Interaction Information; Service Information; Financial InformationLegitimate interests (6(1)(f)) – to facilitate potential business transactions

6. Change of purpose

We only use personal data for the purposes for which it was initially collected. If we need to use personal data for a new, unrelated purpose, we will notify you and explain the legal basis that allows such processing.

7. Is the provision of personal data mandatory?

While we respect the choices of data subjects not to provide personal data, please note that certain information is essential for the proper use of our SaaS Platform and Projectify Solutions.

We require specific personal data to:

  • Create and manage user Accounts
  • Grant access to subscription-based features
  • Process payments and subscription fees
  • Deliver our services effectively and securely

Without the necessary data, you may be unable to access certain features of the Platform, receive important updates, or fully benefit from the functionality of the Projectify Solutions.

8. What about data concerning third parties? Are there any additional obligations or duties?

The Client is responsible for ensuring that a valid legal basis for processing exists at the time of transferring the relevant Personal Data to Projectify and that Projectify is permitted to Process the relevant Personal Data for the purposes set out in these Terms. Upon Projectify's request, the Client undertakes, in writing, to account for and/or provide documentation of the basis for processing. In addition, the Client warrants that the data subjects to which the personal data pertains have been provided with sufficient information on the processing of their personal data.

Where relevant, and to the extent that it is applicable, the Client also undertakes to provide any third-party data subject with a copy of this Privacy Policy in a timely manner.

9. Do we collect special categories of data?

Under the GDPR, certain personal data such as racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for unique identification, health information, or data concerning a person's sex life or sexual orientation—are classified as "special categories of personal data" and require stricter protections.

For the purposes of using the Projectify SaaS cash flow Platform, we do not collect, process, or store any special categories of personal data.

10. Do we collect data related to criminal convictions and offences?

No

11. Do we share or make personal data available with third parties?

We will share personal data with third parties where required by law, where it is necessary to administer the relationship with our clients, and as otherwise provided hereunder.

Furthermore, we may sometimes contract with third parties to supply certain functionalities on our Platform and this may require that personal data is disclosed to third parties. We may share personal data with the following:

Recipient CategoryPurpose & Activity carried out
Data Storage and Hosting (e.g., AWS, DigitalOcean)Stores website data and ensures the site is hosted on reliable, scalable servers to maintain uptime and performance.
Online Forms and Surveys (e.g., Typeform, Google Forms)Allows for easy creation of online forms, surveys, and questionnaires to collect user feedback and data.
Live Chat Support (e.g., Tawk.to, LiveChat)Provides real-time support to users through live chat on the website, improving customer service and engagement.
Payment Gateway (e.g., PayPal, Stripe)Processes customer payments securely and handles transactions, including credit card processing and fraud detection.
Analytics Provider (e.g., Google Analytics, Plausible)Tracks user behavior, collects traffic data, monitors website performance, and provides insights for improving user experience.
CRM – like NetHuntManages the database of our clients, leads and contacts.
Email Marketing Service (e.g., Mailchimp, SendinBlue)Manages email lists, automates marketing campaigns, sends newsletters, and tracks email engagement and conversions.
Security Service (e.g., Cloudflare, Sucuri)Provides protection from security threats such as DDoS attacks, malware, and enhances website security and load performance.
Customer Support Tools (e.g., Zendesk, Intercom)Offers customer service through live chat, ticketing systems, and helps manage customer inquiries efficiently.
Content Delivery Network (CDN) (e.g., AWS CloudFront, Akamai)Accelerates content delivery by distributing website assets globally to ensure faster loading times for users.
Social Media Integration (e.g., Facebook Pixel, Twitter Cards)Allows for social sharing, tracks user engagement from social platforms, and helps with targeted advertising and retargeting.
Advertising and Remarketing (e.g., Google Ads, Facebook Ads)Supports advertising efforts, enables user retargeting, and helps optimize ad performance and conversions.
User Authentication (e.g., Auth0, Firebase Authentication)Manages user authentication, allowing users to sign in with credentials or third-party login options like Google or Facebook.
Review and Rating Tools (e.g., Trustpilot, Yotpo)Enables customers to leave reviews, ratings, and feedback on products or services.
Compliance and Cookie Consent (e.g., OneTrust, Cookiebot)Ensures compliance with GDPR, CCPA, and other data privacy laws by managing cookie consent and data collection practices.
SEO Tools (e.g., Yoast SEO, SEMrush)Provides recommendations and tools to optimize the website for search engines and improve ranking in search results.
Payment Fraud Detection (e.g., Riskified, Signifyd)Provides fraud prevention services by analyzing transactions for potential fraudulent activities.
Backup and Recovery (e.g., BackupBuddy, CodeGuard)Automatically backs up website data and provides recovery options in case of data loss or website failure.
A/B Testing Tools (e.g., Optimizely, Google Optimize)Enables A/B testing of website elements to determine the most effective versions for user experience and conversions.

Furthermore, we will also share personal data as follows:

  • Third party contractors or service providers such as our external developers, IT support and outsourced customer care representatives, legal, accounting and consulting services, providers of cybersecurity and penetration testing.
  • Our insurers and insurance brokers;
  • Regulatory authorities, departments or law enforcement agencies, when we are required, or permitted to do so by law;
  • Any other person or entity but solely when we are expressly authorised to do so;
  • A prospective buyer or any of its advisors, where relevant, in the course of a due diligence exercise or as part of a corporate transaction. In this situation we will, so far as possible, share anonymised data with the other parties before the transaction completes.

We may also process personal data to comply with our regulatory requirements or in the course of dialogue with our regulators as applicable, which may include disclosing personal data to government, regulatory or law enforcement agencies in connection with enquiries, proceedings or investigations by such parties anywhere in the world or where compelled to do so.

Prior to sharing data with a third-party service provider, we require them to commit in implementing appropriate security measures to protect personal information in line with our policies. We do not allow our third-party service providers to use personal data we provide for their own purposes. We only permit them to process personal data for specified purposes and in accordance with our instructions.

12. Is the information transferred outside of the EEA?

All personal data is primarily processed in Malta and the European Economic Area (EEA). However, it may sometimes be transferred outside of the EEA, for example, when we engage third-party service providers or contractors to support our Platform and Projectify Solutions.

When personal data is transferred outside the EEA, Projectify ensures that such transfers comply with GDPR and maintain an adequate level of data protection by implementing Standard Contractual Clauses (SCCs) approved by the European Commission.

Specifically, we safeguard international transfers in the following ways:

  • Adequacy Decisions: We will transfer personal data only to countries for which the European Commission has issued an adequacy decision under Article 45 of the GDPR.
  • Contractual Safeguards: Where personal data is transferred to countries without an adequacy decision, we rely on SCCs that impose legally binding obligations on the recipients to protect personal data in accordance with GDPR standards.
  • Technical and Organizational Measures: In addition to contractual safeguards, we implement appropriate technical and organizational measures to ensure data security, confidentiality, and integrity when data is processed abroad.

By using our Platform, you acknowledge and consent to such international transfers under these safeguards.

13. Data Subject Rights

The GDPR grants data subjects a number of rights that can be exercised in certain circumstances, including:

RightDescription
Right of access (subject access request)This right allows data subjects to request and obtain confirmation on whether we are processing their personal data. Data subjects can also access details about the processing and receive a copy of the data being held.
Right of rectificationData subjects have the right to request that we correct any inaccuracies or incomplete personal data held about them.
Right of erasureCommonly known as the "Right to be Forgotten," data subjects can request the deletion of their personal data under certain circumstances, particularly when the data is no longer necessary for the purpose for which it was collected.
Right of restrictionData subjects can request the limitation of the processing of their personal data in specific situations. This right is relevant, for instance, when the data subject is contesting the accuracy of the data, or the processing is deemed unlawful.
Right to objectThis right enables the data subjects to object to the processing of their personal data, including profiling, for reasons related to their particular situation.
Right of data portabilityData subjects have the right to receive their personal data in a structured, commonly used, and machine-readable format.

We do not carry out any fully automated decision-making or profiling.

In those occasions where we have indicated that we are basing our processing on our legitimate interest, please note that in terms of Article 21 GDPR, data subjects have the right to object to that processing.

Where the legal basis of processing is based solely on the data subject's consent, the data subjects may withdraw such consent at any time by notifying us accordingly. This shall be without prejudice to the lawfulness of processing based on consent before such withdrawal.

For more information about these rights and how to exercise them (when we are acting in our capacity as data controllers), kindly contact us on the contact details set out hereunder.

14. For how long do we retain personal data?

The length of time for which we hold personal data depends on a number of factors, such as regulatory rules and any legal requirements. We also consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of personal data, the purposes for which we process personal data and whether we can achieve those purposes through other means.

For further information about our data retention policies, please get in touch with our data privacy manager on the contact details set out hereunder.

15. Do you need more information about our data handling policies?

If you need more information about this privacy notice or how we handle personal information, please contact our data privacy manager, on hello@useprojectify.com.

Any correspondence can also be addressed to:

Projectify,
58, Valley Road,
Birkirkara BKR 9013, Malta

16. What responsibilities do clients and data subjects have regarding the processing of personal data?

Privacy and data protection is a two-way street, and while we strive to uphold it diligently, the active participation of everyone is crucial. This means that along with enjoying privacy rights, data subjects also have certain responsibilities. As part of these obligations, we anticipate that data subjects take reasonable measures to assist us in effectively safeguarding and managing your privacy.

For instance, to ensure that we maintain accurate, complete, and up-to-date personal information, we kindly ask you to promptly notify us if personal details previously submitted to us become inaccurate, incomplete, or outdated.

17. Is it possible to file a complaint?

We go to great lengths to ensure that we handle personal data responsibly. If there are any concerns or issues with anything related to these matters, please do not hesitate to get in touch with us and we assure you that we will do our utmost to address your concerns.

In any case, if you are not satisfied with the way we manage personal data, you have the right to file a complaint with any relevant data protection authority (particularly the one situated where you habitually reside). Contact details of the competent authority in Malta are as follows:

Address - Information and Data Protection Commissioner, Floor 2, Airways House, High Street, Sliema, SLM 1549, Malta.
Telephone - (+356) 2328 7100
Email - idpc.info@idpc.org.mt

Version 1 · Date: 28th February 2026

Changes to the Privacy Policy - We may alter these terms at any time, but in any case we will inform you accordingly, by means we deem reasonable in the circumstances. In the event of any conflict between the current version of these terms and any previous version(s), the provisions current and in effect shall prevail unless it is expressly stated otherwise.

Questions? Contact us at hello@useprojectify.com