FeedHeat Privacy Policy
Effective date: 27 August 2026
Version: 2.0
1. Who we are
Nocode LTD, a company incorporated in the Republic of Cyprus, trading as FeedHeat, registered office at Griva Digeni, 51, ATHINAION COURT, Flat/Office 202, Paphos 8047, Cyprus. VAT number CY60023829V.
We are the data controller for the personal data described in this policy. That means we decide why and how it is processed, and we are accountable for it.
Contact us about anything in this policy at [email protected].
2. Who this policy covers
This policy applies to:
- Website visitors — anyone browsing feedheat.com; and
- People who contact us — anyone who submits a form on the website, requests a demo, or emails us.
It does not cover the social platforms our services relate to. When you use Reddit, LinkedIn, X, Quora or Facebook you are subject to those platforms' own privacy policies, and we have no control over how they process your data.
3. What we collect
When you submit a form or request a demo — the details you provide, such as your name, email address, company and website, and anything else you choose to include.
When you contact us — emails, support messages and our replies, including anything you choose to put in them.
When you visit the website:
- IP address, browser type, device type, operating system
- Pages visited, referring page, time on site
- Cookie and similar identifiers (see section 8)
4. Why we process it, and our legal basis
Under the GDPR we must have a lawful basis for each purpose. Ours are:
To respond to your inquiry and arrange a demo — steps taken at your request prior to entering into a contract, and legitimate interests (responding to people who contact us).
To communicate with you — legitimate interests, or performance of a contract where we have one with you.
To send you marketing about FeedHeat — consent, which you can withdraw at any time.
To run and improve the website — legitimate interests for essential operation; consent for analytics and marketing cookies.
To establish, exercise or defend legal claims — legitimate interests.
To meet legal obligations — accounting and similar requirements — legal obligation.
Where we rely on legitimate interests, we have considered your rights and concluded our interest does not override them. You can ask us for the details of that assessment, and you can object (section 9).
6. International transfers
We are in Cyprus, inside the EEA. Some of our providers are outside it. Where we transfer personal data outside the EEA, we rely on one of:
- an adequacy decision by the European Commission for that country; or
- Standard Contractual Clauses approved by the European Commission, together with any additional safeguards required.
You can ask us for a copy of the safeguards we use.
7. How long we keep it
| Data | Retention |
|---|---|
| Demo requests and form submissions | 24 months from your last contact with us |
| Support correspondence | 2 years |
| Website analytics | 14 months |
After these periods we delete or irreversibly anonymise the data. We may keep it longer where a legal claim is live or reasonably anticipated, or where the law requires it.
9. Your rights
If the GDPR applies to you, you have the right to:
- Access — get a copy of the personal data we hold about you
- Rectification — have inaccurate data corrected
- Erasure — have data deleted, where we have no overriding reason to keep it
- Restriction — have processing paused while a dispute is resolved
- Portability — receive data you gave us in a machine-readable format, or have it sent to another controller
- Object — object to processing based on legitimate interests, including profiling, and to object to direct marketing at any time, absolutely and without needing a reason
- Withdraw consent — at any time, without affecting processing already carried out
To exercise any of these, email [email protected]. We will respond within one month. We may extend this by two further months for complex requests, and we will tell you if we do. We may ask you to verify your identity first. Exercising these rights is free, unless a request is manifestly unfounded or excessive.
10. Complaints
If you think we have handled your data badly, please tell us first — we would rather fix it.
You can also complain to a supervisory authority. Ours is the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus, Iasonos 1, 1082 Nicosia, Cyprus — [email protected]. If you live in another EEA country or the UK, you may complain to the authority there instead.
11. Automated decision-making
We do not make decisions that produce legal or similarly significant effects for you based solely on automated processing.
12. Security
We use access controls, encryption in transit, and restricted internal access to protect your data. No system is completely secure, and we cannot guarantee absolute security. If a breach occurs that is likely to result in a high risk to your rights, we will tell you without undue delay.
13. Children
Our website and services are for businesses and people aged 18 and over. We do not knowingly collect data from anyone under 18. If we learn we have, we will delete it.
14. Changes to this policy
We may update this policy. The version and effective date at the top of this page always tell you which version is current.
Nocode LTD, trading as FeedHeat
Griva Digeni, 51, ATHINAION COURT, Flat/Office 202, Paphos 8047, Cyprus
VAT: CY60023829V