Privacy Policy
Last Updated: May 2026
Effective Date: May 6, 2026
1. Introduction
Net-3.co.uk Ltd ("Company", "We", "Us", "Our") operates the Reflex platform (the "Service"). We are committed to protecting your privacy and ensuring you have a positive experience on our website and service.
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service, including any related applications, websites, and services that link to this Privacy Policy (collectively, the "Services").
Please read this Privacy Policy carefully. If you do not agree with our policies and practices, please do not use our Services.
2. Information We Collect
2.1 Information You Provide Directly
Account Registration:
- Name
- Email address
- Billing address
- Company name and details
- Payment method information (processed securely by Stripe or PayPal)
- Phone number (optional)
SSH Keys and Credentials:
- SSH public keys (encrypted at rest)
- API tokens for server management (encrypted at rest)
- Other server credentials needed to manage your infrastructure
Communication:
- Support requests and emails
- Feedback, surveys, and customer inquiries
- Chat communications with our support team
2.2 Information Collected Automatically
Usage Data:
- Pages and features accessed
- Actions taken within the dashboard
- Time spent on pages
- Click paths and interactions
Server Performance Telemetry:
- CPU, memory, disk usage on your servers
- Deployment logs and outcomes
- Agent health status and check-in frequency
- Error logs and performance metrics
Device Information:
- Device type, operating system, and browser type
- IP address
- Device identifiers
Analytics:
- Google Analytics data (see Cookie Policy)
- Conversion tracking
- User behavior patterns
2.3 Information from Third Parties
Payment Processors:
- Stripe and PayPal provide transaction confirmation and status updates
- We do not store full payment card information
GitHub:
- Repository names, public data, and deployment information (for users who integrate GitHub)
Log Data:
- Our servers automatically record access logs
- Server request/response data
3. How We Use Your Information
We use collected information for the following purposes:
3.1 Service Delivery
- Providing, maintaining, and improving the Service
- Processing transactions and sending transaction confirmations
- Managing your account and user profile
- Delivering customer support and handling inquiries
- Sending service-related announcements and updates
3.2 Communication
- Responding to your questions and support requests
- Sending transactional emails (password resets, receipts, billing updates)
- Sending product updates, feature announcements, and newsletters (with your consent)
- Marketing communications (only if you've opted in)
3.3 Analytics and Improvement
- Analyzing usage patterns to improve the Service
- Identifying bugs, performance issues, and security vulnerabilities
- A/B testing and feature optimization
- Understanding customer needs and preferences
3.4 Compliance and Legal
- Compliance with legal obligations and tax requirements
- Fraud detection and prevention
- Protecting against unauthorized access or misuse
- Enforcing our Terms of Service and other agreements
- Responding to legal requests from authorities
3.5 Security
- Monitoring for suspicious activity
- Protecting against security threats and data breaches
- Encrypting sensitive data
4. Data Storage and Security
4.1 Data Location
Your data is hosted on DigitalOcean servers located in London, United Kingdom. This ensures compliance with UK and EU data protection requirements.
4.2 Security Measures
We implement industry-standard security measures to protect your information:
- Encryption in Transit: TLS/SSL encryption for all data transmitted between your device and our servers
- Encryption at Rest: SSH keys and sensitive credentials are encrypted using AES-256 encryption
- Access Controls: Role-based access control (RBAC) and principle of least privilege
- Authentication: Secure password hashing using industry-standard algorithms
- Firewalls and Network Security: Firewalls and network segmentation to prevent unauthorized access
- Regular Security Audits: Penetration testing and vulnerability assessments
- Employee Access: Strict controls on employee access to customer data
- API Security: Rate limiting, authentication, and authorization controls on all APIs
No method of transmission over the Internet or storage is 100% secure. While we use industry-standard protections, we cannot guarantee absolute security.
4.3 Data Breaches
In the event of a confirmed data breach affecting personal data, we will:
- Notify affected customers without undue delay
- Cooperate with law enforcement and regulatory authorities
- Provide guidance on protective measures
- Maintain a log of breaches
5. Data Retention
We retain your information for as long as necessary to provide the Service and fulfill the purposes outlined in this Privacy Policy:
- Account Data: Retained while your account is active and for 30 days after cancellation, then deleted
- Billing Records: Retained for 7 years to comply with UK tax requirements
- Server Telemetry & Logs: Retained for 90 days, then archived or deleted
- Support Communications: Retained for 1 year for quality assurance, then deleted
- Analytics Data: Retained according to Google Analytics default retention policy (26 months)
- Backup Data: May be retained longer and deleted on our standard backup schedule
You may request deletion of your data at any time (subject to legal compliance requirements) by contacting support@expertweb.tools.
6. Sharing of Information
We do not sell your personal data. We share information only in the following circumstances:
6.1 Service Providers
We share data with third-party service providers who assist us in operating the Service:
- Stripe & PayPal: Payment processing (limited to transaction data needed for billing)
- DigitalOcean: Cloud infrastructure provider (your data is hosted on their infrastructure)
- Google Analytics: Analytics and usage tracking (see Cookie Policy for opt-out options)
- Email Services: SendGrid or similar for transactional emails
- GitHub: For users who integrate GitHub repositories (limited to public repo data)
These service providers are contractually obligated to use your data only as necessary to provide services and to maintain confidentiality.
6.2 Legal Requirements
We may disclose your information if required by law, including:
- Court orders, subpoenas, or legal process
- Requests from government or law enforcement agencies
- Protection of our legal rights or the rights of others
- Prevention of fraud or illegal activity
6.3 Business Transfers
If Net-3.co.uk Ltd is acquired, merged, or sold, your information may be transferred as part of that transaction. We will provide notice if such a change occurs.
6.4 With Your Consent
We may share information with third parties if you explicitly consent to do so.
7. Your Rights and Choices
7.1 Access and Portability
You have the right to:
- Request a copy of the personal data we hold about you
- Receive your data in a portable, machine-readable format
- Transfer your data to another service
To request: Contact support@expertweb.tools
7.2 Correction and Deletion
You have the right to:
- Correct inaccurate personal data
- Request deletion of your personal data (subject to legal retention requirements)
- Restrict processing of your data in certain circumstances
To request: Contact support@expertweb.tools
7.3 Opt-Out Options
- Marketing Emails: Use the Unsubscribe link in any marketing email (one-click URL at
/unsubscribe/{token}), or contact reflex@expertweb.tools - Status page alerts: Use the unsubscribe link in the alert email for that team’s public status page (
/status/teams/{slug}/unsubscribe/{token}) - Cookies: See Cookie Policy for opt-out and management options
- Analytics: Opt out of Google Analytics tracking using the Google Analytics opt-out browser extension
7.4 EU/UK Data Subject Rights (GDPR/UK GDPR)
If you are located in the EU or UK, you have additional rights under GDPR and UK Data Protection Act 2018:
- Right to access, rectify, erase, and restrict processing
- Right to data portability
- Right to object to processing
- Right to lodge a complaint with your supervisory authority
To exercise these rights, contact support@expertweb.tools
8. Cookies
Please see our Cookie Policy for detailed information about how we use cookies and how to manage your cookie preferences.
9. Third-Party Links
Our Services may contain links to third-party websites and services that are not operated by us. This Privacy Policy applies only to information collected through our Services. We are not responsible for the privacy practices of third-party websites.
We recommend reviewing the privacy policies of any third-party sites before providing your information.
10. Children's Privacy
The Service is not intended for children under 13 years of age. We do not knowingly collect personal data from children under 13. If we become aware that we have collected data from a child under 13, we will delete such information promptly.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, and other factors. We will notify you of any material changes by:
- Posting the updated Privacy Policy on our website
- Updating the "Last Updated" date at the top of this policy
- Sending you an email notification if the changes are material
Your continued use of the Service after changes are posted constitutes your acceptance of the updated Privacy Policy.
12. Contact Us
If you have questions about this Privacy Policy or our privacy practices, please contact us:
Net-3.co.uk Ltd
41 Sandsend Road
Redcar, TS10 5DG
United Kingdom
📧 Email: support@expertweb.tools
🌐 Website: https://reflex.expertweb.tools
Data Protection Officer Contact: support@expertweb.tools
If you are located in the EU/UK and are not satisfied with our response to a privacy inquiry, you have the right to lodge a complaint with your local supervisory authority.
This Privacy Policy is provided for informational purposes. For legal advice, please consult with a qualified attorney.