- Personal Data
- Any information that can identify a specific individual β name, email address, IP address, cookie identifier, or location data.
- Data Controller
- The business or person that determines the purposes and means of processing personal data β typically the website owner.
- Data Processor
- A third party that processes personal data on behalf of the controller, such as an email marketing platform or cloud hosting provider.
- Cookie
- A small text file stored on a user's device by a website, used to remember preferences, track sessions, or collect analytics data.
- GDPR
- The General Data Protection Regulation β EU law governing data collection and processing that applies to any business with users in the European Economic Area.
- CCPA
- The California Consumer Privacy Act β a US state law giving California residents the right to know, delete, and opt out of the sale of their personal data.
- Data Retention
- The defined period for which a business keeps personal data before deleting or anonymizing it.
- Opt-Out
- A mechanism allowing users to withdraw consent for a specific data use β such as marketing emails or behavioral tracking β after initially agreeing.
- Legitimate Interest
- A legal basis under GDPR allowing data processing without explicit consent when the business has a genuine, proportionate purpose that does not override the user's rights.
- Data Breach
- An unauthorized access, disclosure, or loss of personal data that may require notification to regulators and affected users within a defined timeframe.
- Third-Party Sharing
- Disclosure of user data to external companies β advertisers, analytics providers, or payment processors β identified in the privacy policy.