---
title: "EU Data Protection — Churnkey GDPR Compliance"
description: "Churnkey's GDPR compliance policies: data storage, user rights, cookies, third-party services, data retention, security, breach handling, and data export/deletion."
canonical: "https://churnkey.co/legal/gdpr"
category: "legal"
related:
  - /pricing/churnkey-pricing.html.md
  - /how-it-works/index.html.md
last_updated: "2026-02-25"
---

# EU Data Protection

Effective: September 10, 2020.

## How Do We Store Your Data?

We securely store your data at our service providers, who are GDPR compliant. We will keep your data for as long as required by law, until we no longer have a valid reason for keeping it, or until you request us to stop using it. Once this time period has expired, we will delete your personal information from our servers and databases.

## Data Protection Rights Under GDPR

Every user located in a country which has adopted the GDPR is entitled to the following rights:

- **Right to access** — You have the right to request copies of your data.
- **Right to rectification** — You have the right to request that Churnkey correct any information you believe is inaccurate or complete any information you believe is incomplete.
- **Right to erasure** — You have the right to request that we erase your data, under certain conditions.
- **Right to restrict processing** — You have the right to request that we restrict the processing of your data, under certain conditions.
- **Right to object to processing** — You have the right to object to our processing of your data, under certain conditions.
- **Right to data portability** — You have the right to request that we transfer the data we have collected to another organization, or directly to you, under certain conditions.

If you make a request, we have one month to respond. Contact support@churnkey.co to exercise any of these rights. We may ask you to verify your identity before responding.

## Information Collected

Churnkey collects the following data about users:

- Username
- Email address
- Company Name (optional)
- Phone Number (optional)
- Job Title (optional)
- IP addresses (to support secure authentication)
- Churnkey usage statistics (e.g., user content created)

The following additional information may be collected by third parties but is not stored directly by Churnkey:

- Billing information (Stripe)
- Helpdesk tickets (HubSpot)
- Customer activity (HubSpot)

## Information Use

Data is collected only when required and is primarily used for:

- Verifying and creating accounts
- Providing essential software services
- Communicating with users about support tickets and service updates
- Ascertaining location to ensure compliance with local laws and regulations

## Cookies and Session Tracking

Churnkey uses cookies to collect standard account data and visitor behavior information. Cookies help us understand your preferences based on previous or current site activity.

**Collected information may include:** date and time of use, referring URL, exit page, interactions, average pages visited, average time spent, and IP address.

**Cookie types used:**
- **Functionality cookies** — used to recognize you and remember your account preferences.
- **Advertising cookies** — used to collect information about your visit. Some limited data may be shared with advertising partners.

You can set your browser to not accept cookies. Google Analytics is used for website analysis; you can opt out via the [Google Analytics Opt-out Browser Add-on](https://tools.google.com/dlpage/gaoptout).

## Third-Party Service Access

We do not sell, rent, trade, or otherwise transfer your personally identifiable information to outside parties without advance notice. Third-party services that may access your data:

- Google Analytics
- Amazon AWS
- Stripe
- Heap
- Google Fonts
- HubSpot

## Data Retention

We retain data only for as long as necessary to fulfill the purposes outlined in this agreement, comply with legal obligations, resolve disputes, and enforce agreements.

## Data Storage and Security

Data is securely stored in industry-leading data centers with PGP encryption protocols, SSL certificates, and regularly cycled passwords and API keys.

Additional precautions:
- Database access is strictly limited to those requiring it
- Server access is strictly limited to those requiring it
- Administrator roles are designed so routine tasks do not grant access to irrelevant data

## Handling a Potential Data Breach

In the unlikely case of a data breach:

1. Site, server, and database access will be temporarily disabled
2. All passwords and security certificates will be changed
3. Users will be notified via email
4. An internal investigation will be conducted
5. Systems will be re-enabled once verified as secure
6. Changes will be documented to prevent future breaches
7. A follow-up email will detail findings and preventive measures

## How Can I Delete My Data?

Contact support@churnkey.co to request your account and associated data be deleted from Churnkey servers.

## How Can I Export My Data?

Contact support@churnkey.co to request your account and associated data be exported from Churnkey.

## Data Protection Officer

Nick Fogle — support@churnkey.co

## Related

- [Pricing](/pricing/churnkey-pricing.html.md) — All plans are SOC-2 secured and GDPR compliant
- [How It Works](/how-it-works/index.html.md) — Platform overview
