OnWeb24
    Home

    ONWEB24 - PRIVACY POLICY

    ONWEB24 - PRIVACY POLICY

    Last updated: April 10, 2026

    This Privacy Policy explains how OnWeb24 collects and processes personal data when you use the OnWeb24 modules (customers, affiliate, referral, team panel) and related websites.

    1) Data Controller

    Revolution Marketing LLC

    28 Geary St STE 650 Suite #281, San Francisco, CA 94108, United States

    EIN: 612116500

    Contacts:

    2) Legal Framework and Legal Bases

    We process data under applicable laws (including, where relevant, GDPR, UK GDPR, CCPA/CPRA, LGPD). Main legal bases:

    • contract performance;
    • legal obligation;
    • legitimate interest (security, anti-fraud, product improvement);
    • consent (for example optional marketing/cookies).

    3) Categories of Data Processed

    3.1 Technical data:

    IP, browser/device data, technical logs, performance, errors, timestamps.

    3.2 Account data:

    email, phone number, protected credentials, access verification data, roles.

    3.3 Customer website project data:

    questionnaire answers, text, media, design preferences, technical settings.

    3.4 Domain and publishing data:

    domain registration/assignment data, DNS, URLs, deployment metadata.

    3.5 Support data:

    tickets, chat, emails, attachments, support metadata.

    3.6 Payment data:

    payment events, subscription status, transaction identifiers. Note: payment/invoicing data are mainly processed by Paddle as Merchant of Record and, for many activities, as an independent controller.

    3.7 Partner data (affiliate/referral):

    tracking links/clicks, attribution, active paying states, waived status, commissions, statements, payout metadata.

    4) Main Purposes

    • delivery of customer/partner/team panel modules;
    • security, anti-fraud, abuse prevention;
    • billing and subscription management;
    • technical and administrative support;
    • legal and tax compliance;
    • product and performance improvement.

    5) Third-Party Data Entered by Users

    If a user enters third-party personal data (for example own clients, testimonials, contacts), the user is responsible for having a valid legal basis. OnWeb24 processes such data only as needed to provide the requested service.

    6) Data Recipients

    Data may be processed by:

    • authorized OnWeb24 personnel;
    • technical providers (hosting, database, support, monitoring, email);
    • Paddle and subprocessors for checkout, invoicing, refunds;
    • competent authorities, when required by law.

    An up-to-date list of OnWeb24 sub-processors is published at https://onweb24.com/sub-processors and is updated whenever a material change occurs. Sub-processors currently in use include (categories and main vendors):

    • Cloud hosting & CDN: Vercel, Inc. (USA), Hetzner Online GmbH (Germany)
    • Database-as-a-Service: Supabase, Inc. (USA)
    • AI content generation: Anthropic, PBC (USA), OpenAI, Inc. (USA)
    • AI image/media generation: fal.ai, Inc. (USA)
    • Domain registration: Namecheap, Inc. (USA)
    • Payments (Merchant of Record): Paddle.com Market Limited (United

    Kingdom / Ireland)

    • Email & webhook relays: N8N (self-hosted, EU) and equivalent

    transactional email providers

    • Analytics & monitoring: privacy-respecting error tracking tools

    (no third-party marketing trackers)

    All sub-processors are bound by Standard Contractual Clauses (SCC 2021) where applicable and/or covered by the EU-US Data Privacy Framework where available. Revolution Marketing LLC reviews sub-processor arrangements annually.

    7) International Transfers

    Some data processing and sub-processors are located in the United States. Where GDPR applies and data is transferred outside the EEA/UK, OnWeb24 relies on the EU-US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795) for sub-processors covered by DPF adequacy, and on the Standard Contractual Clauses 2021 (Commission Implementing Decision (EU) 2021/914, Module Two Controller-to-Processor) for all other transfers. A Transfer Impact Assessment (TIA) pursuant to Schrems II (CJEU Case C-311/18) is maintained internally by OnWeb24 and is available to competent supervisory authorities upon request.

    8) Data Retention

    We retain data only for as long as necessary for the stated purposes and legal obligations. Typically:

    • technical/security logs: up to 30 days, unless forensic/legal needs apply;
    • support data: up to 24 months, unless legal needs apply;
    • account/project/partner data: relationship duration plus administrative/legal retention periods.

    9) Security

    We apply reasonable technical and organizational measures: access controls, segregation, backups, monitoring, auditing. Measures are applied within components directly under OnWeb24's operational control. Third-party components/providers may have their own controls and responsibilities. No system is 100% secure.

    10) Automated Decisions

    We may use automated anti-abuse/anti-fraud rules. Unless specifically communicated, we do not make solely automated decisions with legal or similarly significant effects under GDPR Article 22.

    11) Data Subject Rights and Privacy Requests (DSARs)

    Where applicable, you can exercise:

    • access;
    • rectification;
    • erasure;
    • restriction;
    • portability;
    • objection;
    • consent withdrawal;
    • complaint to a competent authority.

    11.1 How to submit a request

    Send your request to privacy@help.onweb24.com with subject: "DSAR OnWeb24". For security reasons, we may require reasonable identity verification before handling the request.

    11.2 Response times

    OnWeb24 responds without undue delay and, where applicable, within 30 days of receipt. For complex or multiple requests, the deadline may be extended as allowed by law, with a reasoned notice.

    11.3 Structured complaint channel

    For privacy complaints, contact:

    Please include at least: account email, relevant module (customers/affiliate/referral/team panel), issue summary, and requested action.

    12) Minors

    The service is not intended for minors below the legally required age.

    13) Policy Updates

    OnWeb24 may update this policy for legal, technical, or business reasons. The current version is published with an updated date.