GDPR Privacy Notice
Last Updated: September 17, 2026
This notice supplements our Privacy Policy for individuals in the European Economic Area ("EEA"), European Union, United Kingdom, and Switzerland. It explains how Elastisoft LLC handles personal data under the EU General Data Protection Regulation, UK GDPR, and related data-protection laws.
1. Controller
Elastisoft LLC is the controller of personal data processed through TrafficUnderground.com and Pajes.app unless a specific feature states otherwise.
Elastisoft LLC
1711B Bruce Dr, Anderson, CA 96007, USA
support@trafficunderground.com
2. Purposes and Legal Bases
| Purpose | Typical data | Legal basis |
|---|---|---|
| Create and administer accounts; provide tools, content, and support | Account, profile, project, content, and support data | Performance of our contract and steps requested before entering a contract |
| Verify purchases, provide entitlements, administer subscriptions and refunds | Account and transaction records | Contract; legal obligations; legitimate interests in preventing fraud |
| Secure, troubleshoot, and maintain the Services | IP address, device, access, security, and diagnostic records | Legitimate interests in reliable and secure operation; legal obligations where applicable |
| Send essential account and service communications | Name, email, account and transaction status | Contract and legitimate interests |
| Send newsletters and promotional communications | Name, email, preferences, engagement data | Consent where required; otherwise legitimate interests subject to applicable direct-marketing law |
| Use optional analytics, advertising, and referral technologies | Online identifiers, device, usage, referral, and event data | Consent where required |
| Meet legal obligations and protect legal rights | Relevant account, transaction, consent, and security records | Legal obligation and legitimate interests in establishing, exercising, or defending claims |
Where we rely on legitimate interests, we consider the necessity of the processing and its effect on your rights. You may object as described below.
3. Recipients and Processors
We use providers for hosting and databases, email and newsletters, payments and purchase verification, analytics and advertising where consented, customer support, security, AI features, and connected integrations. These may include Replit, Resend, AWeber, Google, Meta, payment processors, and affiliate marketplaces, depending on the Service and features you use. Providers process only the information necessary for their function and are subject to contractual or legal obligations. Our Privacy Policy contains additional recipient categories.
4. International Transfers
We operate from the United States. Personal data may therefore be transferred outside the EEA, UK, or Switzerland. Where required, we use an approved transfer mechanism such as an adequacy decision, the European Commission's Standard Contractual Clauses, the UK Addendum or International Data Transfer Agreement, together with supplementary safeguards where appropriate. Contact us to request information about the applicable safeguards.
5. Retention
We keep personal data only as long as necessary for the purpose collected, including providing an active account, meeting tax and accounting duties, resolving disputes, enforcing agreements, preventing fraud, preserving security records, and honoring marketing suppression requests. We then delete or de-identify it, subject to scheduled backup expiration and legally required retention. Because retention depends on the record and legal context, a privacy request can be used to obtain more specific information about data associated with you.
6. Your GDPR Rights
Subject to applicable conditions and exceptions, you may:
- Access your personal data and receive information about its processing;
- Rectify inaccurate or incomplete personal data;
- Erase personal data when there is no lawful reason to retain it;
- Restrict processing in circumstances provided by law;
- Object to processing based on legitimate interests and object at any time to direct marketing;
- Receive portable data you provided to us when processing is automated and based on consent or contract;
- Withdraw consent at any time, without affecting prior lawful processing;
- Complain to the data-protection authority where you live or work, or where you believe an infringement occurred; and
- Request safeguards used for relevant international transfers.
Automated tools may assist with content, recommendations, security, or fraud detection. We do not use solely automated processing to make decisions producing legal or similarly significant effects about you unless we disclose that use and provide the protections required by law.
7. Exercising Your Rights
Email support@trafficunderground.com with the subject "GDPR Request." Include the relevant Service and enough information to locate your account. Do not send passwords, payment-card numbers, government identification, or other sensitive information in the initial email. We may request proportionate information to verify identity or an agent's authority.
We normally respond within one month after receiving a valid request. The period may be extended by up to two additional months for complex or numerous requests, in which case we will explain the delay. Requests are generally free, although the law permits a reasonable fee or refusal for manifestly unfounded or excessive requests.
8. Cookies and Direct Marketing
Strictly necessary technologies operate without optional consent where permitted. Analytics, advertising, and referral technologies are held back until the required consent is provided. You may change your choices through Cookie Preferences. You may object to direct marketing at any time by using an unsubscribe link or contacting us.
9. Personal Data Breaches
We maintain procedures to assess and respond to personal-data breaches. Where required, we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of a reportable breach. Where a breach is likely to create a high risk to affected individuals, we notify those individuals without undue delay unless a legal exception applies.
10. EU or UK Representative and Data Protection Officer
Where the law requires appointment of an EU or UK representative or a data protection officer, we will publish the applicable contact details here. The absence of a listed representative or officer does not limit your right to contact us or complain to a supervisory authority.
11. Contact
Questions and requests may be sent to:
Elastisoft LLC
1711B Bruce Dr, Anderson, CA 96007, USA
support@trafficunderground.com