1. Introduction
SoftLaundry (“SoftLaundry”, “we”, “us” or “our”) respects your privacy and is committed to protecting personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the Maltese Data Protection Act (Chapter 586 of the Laws of Malta), and other applicable data protection and privacy legislation.
This Privacy Policy explains how personal data is collected, used, disclosed, stored and protected when you visit https://softlaundry.com/, contact us, request a demonstration, purchase or use SoftLaundry services, or otherwise interact with us.
Because SoftLaundry is business software, the service may process personal data entered into the system by our business customers (“Customers”) about their own customers, employees, suppliers and other individuals. In those circumstances, the Customer will generally determine the purposes and means of processing, while SoftLaundry processes that data on the Customer’s documented instructions as a data processor.
2. Who is responsible for your personal data?
For personal data that SoftLaundry collects and uses for its own purposes—for example, website enquiries, demo requests, account administration, contracts, billing, support and marketing—SoftLaundry is generally the data controller.
The legal entity operating SoftLaundry, its registered address, company registration details and privacy contact details should be inserted here before publication:
Legal name: SoftLaundry
Privacy contact email: info@softlaundry.com
Website: https://softlaundry.com/
Where SoftLaundry processes personal data solely on behalf of a Customer through the SoftLaundry platform, the Customer is generally the controller and SoftLaundry is generally the processor. The precise allocation of responsibilities depends on the particular processing activity and contractual arrangements.
3. What personal data may we collect?
Depending on how you interact with SoftLaundry, we may process the following categories of personal data:
• Identification and contact information, such as name, business name, postal address, email address and telephone number.
• Account information, such as username, login details, account status, roles and permissions.
• Business information, such as company details, job title, branch information and business preferences.
• Customer and operational information entered into the SoftLaundry platform, such as laundry orders, collection and delivery details, service selections, notes, invoices, payment status and customer communications.
• Transaction and billing information, such as subscription, invoice and payment-related records. Payment card details should generally be handled by the relevant payment service provider rather than stored directly by SoftLaundry.
• Technical information, such as IP address, browser type, device information, operating system, access times, diagnostic information and application logs.
• Support information, such as messages, support requests, attachments and records of communications with our team.
• Marketing preferences and records of consent or objection to direct marketing.
• Information provided through forms, demonstrations, telephone calls, emails or other communications.
• Any other personal data that a Customer or user lawfully chooses to enter into the platform.
4. Customer-entered data and the role of SoftLaundry
SoftLaundry is designed to help laundry and related service businesses manage their operations. Customers may therefore enter personal data relating to their own customers, employees or other individuals.
Where a Customer uses SoftLaundry to process personal data for its own business purposes, the Customer is responsible for determining why and how that data is processed and for ensuring that it has an appropriate legal basis and provides any required privacy information to the individuals concerned.
SoftLaundry will process Customer Data in accordance with the Customer’s instructions, the applicable service agreement and any applicable Data Processing Agreement (“DPA”). We will not use Customer Data for unrelated purposes except where required or permitted by applicable law.
Customers should not enter special-category personal data or other highly sensitive information into SoftLaundry unless this is necessary, lawful and specifically supported by the relevant service and contractual arrangements.
5. How do we collect personal data?
We may collect personal data:
• Directly from you when you contact us, request a demonstration, create an account, subscribe to a service, communicate with support or otherwise use our services.
• From your organisation when your employer or another Customer provides or authorises your account.
• Automatically through your use of our website, application and services, including technical and security logs.
• From service providers that support our business, where permitted by law.
• From publicly available sources where reasonably necessary for legitimate business purposes.
6. Why do we use personal data?
We may process personal data for the following purposes:
• To provide, operate and maintain SoftLaundry.
• To create and administer user and customer accounts.
• To provide demonstrations, quotations and requested information.
• To process subscriptions, contracts, invoices and payments.
• To provide customer service and technical support.
• To communicate important service information, including security notices, maintenance announcements and changes to the service.
• To personalise or improve the functionality, performance and usability of our services.
• To detect, prevent and investigate fraud, abuse, security incidents and unauthorised access.
• To maintain system logs, backups and business continuity.
• To comply with legal, regulatory, accounting and tax obligations.
• To establish, exercise or defend legal claims.
• To send marketing communications where permitted by law and, where required, with your consent.
• To conduct legitimate business administration, reporting and service development.
7. Legal bases for processing
Depending on the circumstances, we rely on one or more of the following GDPR legal bases:
• Contract – where processing is necessary to provide SoftLaundry, manage an account, fulfil an agreement or take steps at your request before entering into a contract.
• Legal obligation – where processing is necessary to comply with applicable legal, accounting, tax, regulatory or other obligations.
• Legitimate interests – where processing is necessary for legitimate interests pursued by SoftLaundry or a third party, provided those interests are not overridden by your rights and freedoms. Examples may include service security, fraud prevention, business administration, service improvement and limited business-to-business communications.
• Consent – where we ask you to provide consent, such as for certain marketing or non-essential cookies. You may withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
• Vital interests or other legal bases – where applicable under Article 6 of the GDPR.
8. Direct marketing
Where permitted by applicable law, we may use business contact information to send information about SoftLaundry, product updates, events, features and related services.
Where consent is legally required, we will seek it before sending relevant marketing communications. You can unsubscribe from marketing communications at any time by using the unsubscribe mechanism provided or by contacting us.
Service and transactional communications are not marketing communications and may continue where they are necessary to operate your account or provide the services.
9. Cookies and similar technologies
Our website and application may use cookies and similar technologies. These may include strictly necessary technologies required for security, authentication and website functionality, as well as analytics, preference or marketing technologies where applicable.
Where consent is required for non-essential cookies, we will request consent through an appropriate cookie mechanism. You can manage cookies through your browser and, where available, our cookie preference tool.
A separate Cookie Policy should be published if SoftLaundry uses analytics, advertising, tracking, embedded media or other non-essential technologies.
10. Who may receive personal data?
We may disclose personal data to:
• Employees and authorised personnel who require access for legitimate business purposes.
• Hosting, cloud infrastructure, backup, security and technical service providers.
• Customer relationship management, email, communications and support providers.
• Payment processors and financial service providers where necessary.
• Professional advisers, auditors, insurers and legal representatives where appropriate.
• Government authorities, regulators, courts or law-enforcement bodies where required or permitted by law.
• A purchaser, investor or successor entity in connection with a merger, acquisition, restructuring or sale of all or part of the business, subject to applicable legal requirements.
Third-party service providers processing personal data on our behalf will be subject to appropriate contractual and data protection requirements.
11. International transfers
Some service providers used by SoftLaundry may process or store personal data outside Malta or the European Economic Area (“EEA”).
Where personal data is transferred outside the EEA, SoftLaundry will use an appropriate transfer mechanism recognised under applicable data protection law, such as an adequacy decision, applicable Standard Contractual Clauses, or another lawful safeguard.
Information about material international transfers and relevant safeguards should be documented in SoftLaundry’s internal processing records and, where required, made available to customers or data subjects.
12. How long do we keep personal data?
We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide services, maintain accounts, meet contractual obligations, comply with legal and accounting requirements, resolve disputes, enforce agreements and protect our legitimate interests.
Retention periods vary depending on the type of data and the reason for processing. When personal data is no longer required, we will delete, anonymise or securely dispose of it in accordance with our retention procedures, subject to legal or contractual requirements.
For Customer Data processed on behalf of a Customer, retention and deletion will generally be governed by the applicable agreement or DPA. Following termination, Customer Data should be returned or deleted in accordance with the applicable contractual arrangements, subject to legal retention obligations and legitimate backup procedures.
13. Security
SoftLaundry takes reasonable technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
Depending on the nature of the processing, safeguards may include access controls, authentication, permissions management, encryption where appropriate, secure hosting, logging, monitoring, backups, vulnerability management, confidentiality obligations and procedures for handling security incidents.
No internet-based service can guarantee absolute security. Users and Customers are responsible for maintaining appropriate account credentials, access permissions and security practices.
14. Personal data breaches
SoftLaundry maintains procedures for identifying, assessing and responding to personal data breaches.
Where SoftLaundry acts as a processor, it will notify the relevant Customer of a personal data breach in accordance with the applicable DPA and contractual requirements, so that the Customer can meet its own obligations as controller.
Where SoftLaundry acts as controller, it will assess and report personal data breaches to the competent supervisory authority and affected individuals where required by applicable law.
15. Your GDPR rights
Subject to applicable legal conditions and exemptions, individuals may have the following rights:
• Right of access – to obtain confirmation as to whether personal data concerning you is being processed and, where applicable, a copy of that data.
• Right to rectification – to have inaccurate or incomplete personal data corrected.
• Right to erasure – to request deletion of personal data in certain circumstances.
• Right to restriction – to request that processing be restricted in certain circumstances.
• Right to data portability – to receive certain personal data in a structured, commonly used and machine-readable format and, where technically feasible and legally applicable, have it transmitted to another controller.
• Right to object – to object to certain processing based on legitimate interests or public tasks, and to object to direct marketing at any time.
• Right to withdraw consent – where processing is based on consent.
• Rights relating to automated decision-making – where applicable under GDPR provisions concerning solely automated decisions producing legal or similarly significant effects.
We will normally respond to valid data subject requests without undue delay and, in principle, within one month of receipt. This period may be extended where permitted by the GDPR, in which case we will explain the reason for the extension.
16. How to exercise your rights
To exercise your rights, contact us using the privacy contact details stated in Section 2.
We may need to verify your identity before responding to a request. We will not request unnecessary identification information.
If you use SoftLaundry through an organisation that is our Customer, your organisation may be the appropriate first point of contact for requests concerning data that it controls. SoftLaundry will assist its Customers with data subject requests where required under the applicable DPA and GDPR.
17. Right to complain
If you believe that your personal data has been processed unlawfully or that your data protection rights have not been respected, you have the right to lodge a complaint with the competent data protection supervisory authority.
For Malta, the supervisory authority is the Information and Data Protection Commissioner (IDPC). More information is available from the IDPC website at https://idpc.org.mt/.
You may also have the right to lodge a complaint with the supervisory authority in the EU/EEA Member State where you live, work or where an alleged infringement occurred, subject to the applicable rules.
18. Children
SoftLaundry is primarily a business-to-business service and is not directed at children. We do not knowingly seek to collect personal data directly from children through our website.
Where Customers enter information concerning individuals into the SoftLaundry platform, the Customer remains responsible for ensuring that such processing complies with applicable data protection law and any requirements concerning children.
19. Automated decision-making and profiling
SoftLaundry does not intend to make decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects on individuals unless this is expressly disclosed and permitted by applicable law.
If such functionality is introduced, the relevant privacy information and safeguards will be updated before or when the processing is introduced, as required.
20. Third-party websites and services
Our website or services may contain links to third-party websites, applications or services. SoftLaundry is not responsible for the privacy practices of third parties that operate independently from us.
You should review the privacy notices of third-party services before providing them with personal data.
21. Data Processing Agreements
Where SoftLaundry acts as a processor for a Customer, the parties should enter into an appropriate Data Processing Agreement where required by GDPR Article 28.
The DPA should describe the subject matter and duration of processing, nature and purpose of processing, types of personal data, categories of data subjects, confidentiality, security, sub-processors, assistance with data subject rights, breach notification, audits and deletion or return of data, as appropriate.
22. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to our services, processing activities, technology, legal requirements or business practices.
The updated version will be published on this page with a revised “Last updated” date. Where required by law, we will provide additional notice of material changes.
23. Contact us
If you have questions about this Privacy Policy, wish to exercise your data protection rights, or have a privacy or security concern, please contact:
SoftLaundry
Legal entity: SoftLaundry
Email: info@softlaundry.com
Website: https://softlaundry.com/
If SoftLaundry has appointed a Data Protection Officer, the DPO contact details should also be inserted here.
24. Information SoftLaundry should complete before publication
The following items should be completed and verified before publishing this policy:
1. Legal entity name and registered address.
2. Company registration number.
3. Dedicated privacy/data protection email address.
4. Whether a Data Protection Officer is appointed and, if so, DPO contact details.
5. Hosting provider and principal cloud locations.
6. Analytics and cookie technologies actually used on softlaundry.com and within the application.
7. Payment processors actually used.
8. Email, CRM, customer-support and communication providers.
9. Any other sub-processors that can access Customer Data.
10. Actual data retention periods.
11. Whether Customer Data is transferred outside the EEA and the safeguards used.
12. Final Data Processing Agreement for SoftLaundry Customers.
13. Cookie Policy, if non-essential cookies are used.
14. Security and personal data breach procedures.
15. Whether any special-category data is intentionally processed by the platform.