1. Scope
This Notice applies where the EU General Data Protection Regulation (Regulation 2016/679) or the UK GDPR governs our processing of your personal data. It also reflects our obligations under Sri Lanka's Personal Data Protection Act No. 9 of 2022, under which we are established.
The data controller for FreelioPro account data is Swift Byte Solutions (Private) Limited, Registration No. PV 00347854, of No:22/6A, Sri Sarananda Road, Hingurugamuwa, Badulla, Uva Province, Sri Lanka.
2. Who is Responsible for Which Data
This is the most important thing to understand before making a request, because it determines who you should contact.
- If you are a Freelancer with a FreelioPro account, we are the controller of your account data — your name, email, credentials, subscription status, and the security logs relating to your logins. Contact us directly.
- If you are a Client invited into a project portal, the Freelancer who invited you is the controller of the data held about you. They chose to collect it, they decided why, and they can delete it. We are only their processor. Contact that Freelancer first.
We will always help a Client who cannot reach the relevant Freelancer, and we will pass requests on, but we cannot make decisions about a Freelancer's project data on their behalf — including deleting it — except where the law requires us to.
3. Legal Bases for Processing
| Purpose | Legal basis (Art. 6) |
|---|---|
| Creating and operating your account; providing projects, portals, file delivery, messaging and invoicing | Performance of a contract — Art. 6(1)(b) |
| Processing your clients' data in the Service | On your instructions as controller — Art. 28; we act as processor |
| Authentication, session management, access logging, rate limiting, abuse and intrusion detection | Legitimate interests in securing the Service — Art. 6(1)(f); security obligation under Art. 32 |
| Transactional email: password resets, one-time codes, security and billing notices | Performance of a contract — Art. 6(1)(b) |
| Aggregate, cookieless usage analytics to maintain and improve the Service | Legitimate interests — Art. 6(1)(f) |
| Providing support and responding to enquiries | Performance of a contract and legitimate interests — Art. 6(1)(b), 6(1)(f) |
| Investigating abuse reports; responding to legal requests; establishing or defending legal claims | Legal obligation and legitimate interests — Art. 6(1)(c), 6(1)(f) |
| Verifying that users are 18 or over | Performance of a contract and legitimate interests — Art. 6(1)(b), 6(1)(f) |
We do not rely on consent for any of the above, because none of it is optional to the operation of the Service. We send no marketing email, so there is no marketing consent to give or withdraw. We carry out no automated decision-making or profiling that produces legal effects.
4. Your Rights
Subject to the conditions and exemptions in the GDPR, you have the right to:
- Be informed about how your data is used — this Notice and our Privacy Policy serve that purpose.
- Access the personal data we hold about you and receive a copy.
- Rectification of inaccurate or incomplete data.
- Erasure of your data where there is no continuing lawful reason for us to hold it.
- Restrict processing in certain circumstances, for example while a dispute about accuracy is resolved.
- Data portability — to receive data you provided in a structured, commonly used, machine-readable format where processing is based on contract or consent and carried out by automated means.
- Object to processing based on legitimate interests.
- Withdraw consent where processing is based on consent.
- Lodge a complaint with a supervisory authority.
5. How to Exercise Your Rights
Freelancers: all of these rights can be exercised directly in the application. You can view and edit your account and profile data, delete individual projects, portals and files, download your files as ZIP archives, export your records as spreadsheets, and delete your entire account - including all associated project data - from Account Settings. Account deletion is confirmed by a code emailed to your account address. For anything else, or if you cannot access that email, contact legal@freeliopro.com or support@freeliopro.com.
Clients: contact the Freelancer who invited you to the portal. If that is not possible, email legal@freeliopro.com with the portal address and we will forward your request and assist as far as our processor role permits.
We respond within one month of receiving a request, and may extend this by two further months for complex or numerous requests, telling you if we do. We may ask you to verify your identity first. Requests are free of charge, except where they are manifestly unfounded or excessive.
Please note one practical limit: deleted data may persist in our weekly server snapshot for up to 7 days before being overwritten, and a deleted file remains in object storage until an automated job confirms its removal, so erasure completes shortly after your request rather than instantly.
6. International Transfers
We are established in Sri Lanka and our infrastructure is located primarily in the United States, so personal data is transferred outside the EEA and the UK. Where no adequacy decision covers a transfer, we rely on the European Commission's Standard Contractual Clauses (Module Two, controller-to-processor) and, for UK transfers, the UK International Data Transfer Addendum. These are incorporated into our Data Processing Addendum, which also sets out our supplementary technical measures and our commitment to notify and challenge government access requests.
A full list of our sub-processors, their processing activities and locations, is published in Annex III of the Data Processing Addendum.
7. Data Minimization and Retention
Our compliance posture rests mostly on collecting little in the first place:
- No third-party analytics, advertising, retargeting, or cross-site tracking, and no third-party cookies.
- Our own analytics store no cookie and no raw IP address — only a salted, daily-rotating hash that cannot be reversed or linked across days.
- No artificial intelligence features; no user content is sent to any external model provider, and no data is used for model training.
- No card or banking data: subscription payments are handled entirely by our Merchant of Record.
- Passwords and portal passcodes are stored only as hashes and cannot be recovered by us.
- Security and access logs are deleted after a maximum of 90 days; analytics after a maximum of 90 days; billing event records from our payment provider after 120 days; portal sessions on expiry or revocation. No category is kept longer than 120 days.
- Special-category data is prohibited from the Service by contract, and the Service is not designed to hold it.
8. Security and Breach Notification
Our technical and organizational measures under Article 32 are listed in Annex II of the Data Processing Addendum.
If a personal data breach occurs, we will notify affected Freelancers without undue delay and within 48 hours of becoming aware of it. Where we are the controller, we will notify the competent supervisory authority within 72 hours where the breach is likely to result in a risk to individuals' rights and freedoms, and notify affected individuals where the risk is high. Where we are the processor, we notify the Freelancer so that they can meet their own obligations as controller.
One limitation deserves stating plainly: portal passcodes are transmitted to Clients by Freelancers, outside our Service and through a channel of their choosing. Unauthorized access resulting from a passcode being misdirected, forwarded, or shared is outside our control and is the responsibility of the Freelancer who sent it.
9. Complaints
If you are unhappy with how we have handled your data or your request, please contact us first at legal@freeliopro.com so we can try to resolve it.
You also have the right to complain to a data protection authority. In the EEA this is the supervisory authority of the Member State where you live or work, or where the alleged infringement occurred. In the UK it is the Information Commissioner's Office. In Sri Lanka it is the Data Protection Authority established under the Personal Data Protection Act No. 9 of 2022.
10. Representative
We operate the Service from Sri Lanka and offer it globally without targeting any particular jurisdiction. We have not appointed a representative in the European Union or United Kingdom under Article 27 of the GDPR. All data protection enquiries, from any jurisdiction, are handled directly by the Company at the address below and are answered by the Company's management.
11. Changes to This Notice
We may update this Notice to reflect changes in law or in our processing. We will post the revised Notice here and update the effective date. Where a change is material, we will notify Freelancers by email at least 30 days in advance.
12. Contact
- Entity: Swift Byte Solutions (Private) Limited
- Registration No: PV 00347854
- Location: No:22/6A, Sri Sarananda Road, Hingurugamuwa, Badulla, Uva Province, Sri Lanka
- Data Protection Contact: legal@freeliopro.com
- General Support: support@freeliopro.com