Privacy Policy
How personal data is collected, used, shared and protected across the directory, software, jobs, accounts, leads and commercial services.
2.1 Controller and contact
Website management and technical administration is provided by PixelServices.net. Privacy, commercial and general inquiries may be sent to info@software-directory.com, which is the contact point for data-protection requests and for exercising the rights described below.
2.2 Data we may process
| Context | Examples of data |
|---|---|
| Visitors | IP address, device/browser information, timestamps, requested URLs, referrer, security logs, consent choices and analytics data where enabled. |
| Accounts / claimed listings | Name, business email, account identifier, password hash, authentication/session data, TOTP configuration data or recovery-code hashes, security events and profile permissions. |
| Business / company listings | Company name, website, corporate address, category, services, technologies, industries, logos/images, public business contacts, verification data, source and freshness metadata. |
| Software / product records | Product/vendor data, features, prices, integrations, official links, verification dates and data-source metadata. |
| Jobs | Job title, employer, location, job metadata, source/feed identifier, original apply URL, dates and categorisation. Applications normally occur on the employer/feed destination unless the website explicitly provides an application form. |
| Leads / quote requests | Name, email, telephone, company, project requirements, budget/range, location, request text, chosen providers, routing and status. |
| Business submissions | Submitter identity/contact details, authority/ownership evidence, listing content, corrections and correspondence. |
| Payments / subscriptions | Customer identifiers, plan, invoice/payment status, transaction references and billing metadata. Full card data is handled by the payment processor rather than stored by Software-Directory. |
| Advertising | Advertiser contact data, campaign details, creatives, click/impression records and billing metadata. |
| Support / inquiries | Contact details and the content of messages sent to info@software-directory.com or through website forms. |
2.3 Sources of personal data
- Directly from users, business owners, advertisers, account holders and people who submit leads or inquiries.
- From employers, authorised job feeds, APIs, data partners or business submissions.
- From publicly accessible business websites, public registers or other sources where the intended use is lawful and documented.
- Automatically from server logs, security systems, cookies or similar technologies where applicable.
- From payment, email, analytics or anti-abuse providers where needed to provide or secure the service.
2.4 Purposes and legal bases
| Purpose | Typical legal basis under GDPR |
|---|---|
| Provide accounts, claims, paid plans, advertising or requested services | Performance of a contract or steps requested before entering a contract. |
| Respond to inquiries, support and correction requests | Contractual steps, legitimate interests in customer support and service administration, or legal obligation where applicable. |
| Operate and secure the website | Legitimate interests in security, fraud prevention, debugging, availability and abuse prevention; legal obligation where applicable. |
| Publish business-directory records | Legitimate interests in operating a useful B2B directory and providing accurate factual business information, subject to balancing and data-minimisation requirements; contract/consent for owner-supplied content where appropriate. |
| Route a user’s lead to selected/relevant providers | Consent or performance of the user-requested service, with clear pre-submit disclosure of recipient categories. |
| Send direct marketing | Consent where required, or legitimate interests/soft-opt-in rules where lawfully applicable; always provide an opt-out. |
| Analytics / advertising cookies | Consent where required by ePrivacy/cookie rules. Essential cookies rely on necessity for the requested service. |
| Billing, tax, accounting and fraud records | Contract and legal obligations. |
| Establish or defend legal claims | Legitimate interests and applicable legal provisions. |
2.5 Public-source and third-party business data
Software-Directory may create or enrich company records from authorised feeds, public registers, business websites or other documented sources. Public availability does not automatically make all data free of privacy, copyright or database-right restrictions. The platform retains source/provenance metadata and minimises personal data. Where a business record identifies a natural person (for example a sole trader, named employee, personal business email or direct mobile number), the controller assesses the lawful basis and the information duties applicable to data not collected directly from that person.
Where GDPR Article 14 applies, the controller provides the required information within the legally applicable timeframe or relies only on a documented exception where one genuinely applies. A clear directory-data page and a straightforward correction/removal/objection channel remain available.
2.6 Recipients and processors
Personal data may be disclosed to service providers acting under contract, such as hosting/infrastructure, transactional email, analytics (if enabled), anti-spam/security, payment processing, customer support and backup providers. Leads are disclosed to the provider(s) or categories of provider clearly described before submission. Data may also be disclosed to authorities or advisers where required by law or necessary to establish or defend legal claims.
The website is hosted on Hostinger infrastructure. Additional processors (such as a transactional-email service or a payment processor) are engaged only where the corresponding feature is enabled, and this section reflects the processors actually used.
2.7 International transfers
If a service provider processes personal data outside the European Economic Area or another protected jurisdiction, the controller uses an appropriate transfer mechanism where required, such as an adequacy decision, Standard Contractual Clauses, or another legally valid safeguard.
2.8 Retention
| Data class | Suggested operational rule — verify before launch |
|---|---|
| Account data | For the life of the account plus a limited period for security, disputes and legal obligations. |
| Security / authentication logs | Typically months rather than indefinitely; a documented security retention window is set. |
| Leads | Kept only as long as necessary for routing, quality control, billing, dispute handling and legally required records. |
| Support / inquiries | Kept for the period needed to resolve the matter and document the outcome. |
| Billing / tax records | Retained for the legally required accounting/tax period. |
| Business directory facts | Retained while current/relevant, with freshness/expiry rules; suppression records preserved where needed to prevent re-import after a valid removal. |
| Jobs | Expired or archived promptly after the job closes or the source no longer reports it as active. |
| Consent records | Evidence of consent/withdrawal kept as long as needed to demonstrate compliance. |
2.9 Your rights
Depending on applicable law, individuals may have rights to access, rectify, erase, restrict or object to processing, withdraw consent, receive data portability where applicable, and lodge a complaint with a supervisory authority. Requests may be sent to info@software-directory.com or via the correction/removal form. The controller may request proportionate information to verify identity before acting on a request.
If the controller is established in Spain, the competent authority is generally the Spanish Data Protection Agency (AEPD), subject to the GDPR rules on lead supervisory authorities. If the controller is established elsewhere, the appropriate authority applies instead.
2.10 Security
The service uses reasonable technical and organisational measures designed to protect personal data, including access controls, HTTPS, password hashing, mandatory TOTP for high-privilege administrator access, session controls, backups, logging, rate limiting and role-based permissions. No system can guarantee absolute security.
2.11 Children
Software-Directory is a business and professional service and is not intentionally directed at children. We do not knowingly collect children’s personal data through lead, account or advertising workflows unless a specific lawful and age-appropriate process is implemented.
2.12 Changes
Material changes to this Privacy Policy are reflected by updating the “Last updated” date and, where appropriate, giving additional notice to affected users or obtaining fresh consent where required.