Privacy Policy
How tocancel handles the data behind each operation: detection, optimisation, claims, cancellation and proof.
1. Defined terms
Capitalised words have the meaning set out below wherever they appear in this policy.
- Controller
- Tocancel Limited (C 116018), publisher of https://www.tocancel.com, which decides the purposes and means of the processing described here.
- Subscriber
- Any person holding an account on tocancel.com, on the paid trial or on a monthly plan.
- Operation
- Any of the five acts tocancel performs for a Subscriber: Detection, Optimisation, Claim, Cancellation, Proof.
- Detection
- Identifying the recurring charges and active subscriptions attached to a Subscriber.
- Optimisation
- Comparing a detected charge with the alternatives and reporting where the Subscriber overpays.
- Claim
- Preparing and lodging a request for a sum a merchant owes the Subscriber.
- Cancellation
- Ending a detected subscription in the Subscriber's name, by registered letter where the merchant requires one.
- Proof
- The certified, timestamped record of a Cancellation or a Claim, downloadable from the account.
- Processor
- A supplier named in clause 10, handling Subscriber data on the Controller's written instructions and on no other basis.
2. Controller and contact routes
https://www.tocancel.com is published by Tocancel Limited (C 116018), registered office , VAT MT3288-7409. It is the Controller for everything set out in clauses 4 to 8.
- Data protection questions and rights requests: [email protected].
- An ongoing Operation, an account or a dispatch: [email protected].
- Billing records and invoice copies: [email protected].
3. Instruments that apply
- Regulation (EU) 2016/679, the GDPR, for Subscribers located in the European Union.
- Law No. 78-17 as amended, the French Data Protection Act, for Subscribers in France.
- The Personal Data Protection Law (PDPL) as it applies in Malta, where the Controller is registered.
4. Detection: what is collected before and during the scan
Nothing is gathered that an Operation does not need. Detection draws on five sets:
- Identification: surname, first name, postal address, email address, telephone number, country.
- Account: username, password held in hashed form, plan history, issued invoices.
- Payment: card number and bank identifiers are entered into and held by Stripe. The Controller receives a token and a status, and never sees the card number.
- Charge records: merchant, amount, currency, date and frequency of each recurring payment identified.
- Technical: IP address, device type, browser, server logs, and the cookies listed in clause 12.
5. Optimisation and Claim: what is added afterwards
Optimisation reuses the charge records from clause 4 and adds the plan level, options and usage the Subscriber declares. No further identity data is asked for.
A Claim adds the sum claimed, the merchant reference, the dates in dispute and any receipt uploaded in support.
Claim and cancellation letters are drafted with help from an AI text interface, which keeps no personal data once the draft has been returned.
6. Cancellation and Proof: what leaves the platform and what stays
- Documents uploaded by the Subscriber and templates created in the account.
- Sender and recipient postal addresses, passed to the print and postal partner for delivery.
- Dispatch history and the tracking events the postal operator returns.
- The certificate and timestamp forming the Proof, retained under clause 8.
7. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Running the Operations, drafting, printing and dispatch included | Performance of the contract |
| Account administration and invoicing | Performance of the contract |
| Administrative and contractual messages about the Service | Performance of the contract |
| Assistance and technical support | Performance of the contract |
| Fraud screening and payment security | Legitimate interest |
| Site improvement and service performance | Legitimate interest |
| Invoice retention, accounting records, anti-money-laundering checks | Legal obligation |
| Handling rights requests under clause 13 | Legal obligation |
| Account creation, non-essential cookies, marketing messages | Consent |
8. Retention periods
| Category | Kept for |
|---|---|
| Account data | While the account is open, then 3 years after deletion |
| Billing data | 10 years, under accounting obligations |
| Dispatched mail and Proof data | The subscription term plus 6 months |
| Technical data and server logs | 12 months |
| Analytical cookies | 13 months at most |
Files and documents supplied by the Subscriber are erased automatically when the subscription ends or the account is closed.
9. Hosting, backups and transfers outside the Union
Data sits on secured servers of OVHcloud (OVH SAS)., 61 Lordou Vironos Street, 6023 Larnaca, Cyprus (https://www.ovhcloud.com), inside the European Union, in Lithuania and the Netherlands.
Backups and part of the technical administration are carried out from Malta.
Where data leaves the Union for support or technical reasons, the Controller relies on the European Commission's Standard Contractual Clauses under Article 46 of the GDPR and on the equivalent safeguards required by the PDPL, so the transfer does not weaken protection.
10. Recipients and processors
Personal data is neither sold nor rented. Disclosure is limited to the recipients below, for the task stated against each.
- Stripe Payments Europe Ltd.: card payment processing.
- OVHcloud (OVH SAS).: hosting and backups.
- Google LLC: audience measurement through Google Analytics 4.
- Postal operators and print partners: production and delivery of registered letters.
- An AI text generation API (OpenAI): drafting assistance, keeping no personal data after processing.
- Support, routing and other technical suppliers under contract.
- Administrative or judicial authorities, where the law compels disclosure.
Every Processor is bound in writing to confidentiality and to the security obligations in clause 11.
We use Stripe for payment, analytics, and other business services. Stripe collects identifying information about the devices that connect to its services. Stripe uses this information to operate and improve the services it provides to us, including for fraud detection. You can learn more about Stripe and read its privacy policy at https://stripe.com/privacy.
11. Security measures
- SSL/TLS encryption of traffic to and from the platform.
- Passwords stored only as hashes.
- Firewalling and retention of access logs.
- Separation of production from other environments.
- Access granted by role, restricted to named staff.
- Internal audits against recognised international standards.
12. Cookies
- Technical cookies, without which the Service does not run.
- Analytical cookies (Google Analytics 4), used to measure audience.
- Functional cookies, which record language and display preferences.
Cookies are managed from the consent banner or the browser settings. Declining the technical cookies leaves the Operations unusable.
13. Subscriber rights under the GDPR and the PDPL
- Access to the data held.
- Rectification of inaccurate data.
- Erasure, the right to be forgotten.
- Restriction of processing.
- Objection to processing.
- Portability: export of the data in reusable form.
- Post-mortem directives, European Union only.
Requests go to [email protected] and are answered within 30 days at the latest. An identity document may be requested first where the Controller cannot otherwise confirm who is asking.
14. Complaints and revisions
A Subscriber in the European Union may also complain to the supervisory authority of their own country.
This policy may be revised. The version that governs is the one published on tocancel.com on the day it is read. Substantial changes are announced by email or inside the customer account.