PRTO

Privacy Policy

Last updated: 20 July 2026

This Privacy Policy explains how PRTO ("we", "us", or "our") collects, uses, discloses, and protects your personal data. It applies to all users of PRTO, a productivity web application accessible at prto.app.

By using PRTO, you agree to the collection, use, and disclosure of your personal data as described in this Privacy Policy. If you do not agree with these practices, please do not use PRTO.


1. Data Controller

PRTO is the data controller responsible for your personal data. We are incorporated in Brunei Darussalam.

Data Protection Officer (DPO):

Afiq Rosli

Contact: afiq_rosli@live.com

Our DPO is responsible for overseeing our compliance with applicable data protection laws, including the Brunei Personal Data Protection Order (PDPO) 2025 and the Singapore Personal Data Protection Act (PDPA). You may contact our DPO with any questions or requests regarding your personal data.


2. Personal Data We Collect

We collect the following categories of personal data:

2.1 Account and Authentication Data

  • Name — provided during registration or via Google Sign-In
  • Email address — used for account creation, verification, and communication
  • Profile image — from Google Sign-In or user upload
  • Hashed password — stored securely using industry-standard hashing (we never see your plain-text password)
  • Email verification status — whether you have verified your email address
  • Session tokens — used to keep you logged in securely
  • IP address — collected during login, session activity, and account changes
  • User agent — browser and device information collected during sessions
  • OAuth tokens — if you sign in with Google (access token, refresh token, ID token)

2.2 User Content Data

  • Areas — titles, descriptions, icons, colors, and priority depth settings you create
  • Things — titles, descriptions, status, priority levels, due dates, and nesting depth you create
  • Notes — titles and content you attach to Things
  • Activities — records of actions you take, including type, description, IP address, user agent, and timestamp

2.3 Organization Data

  • Organization name, slug, logo, description, and metadata (industry, size) — if you create or join an organization
  • Member roles — your role within an organization (admin, member, or owner)
  • Invitation data — email addresses of people you invite, their roles, invitation tokens, and status

2.4 Waitlist Data

If you join our waitlist before full registration:

  • Contact email
  • Feature preferences, pricing preferences, private beta preferences
  • Early supporter tier, payment prevention reason, likelihood to subscribe
  • Polar checkout ID, payment completed status, payment amount
  • IP address and user agent

2.5 Feedback Data

If you submit feedback through our in-app feedback tool:

  • Feedback type and description
  • Route path (the page you were on when submitting feedback)
  • User ID (if you are logged in)
  • IP address and user agent

2.6 Technical and Usage Data

  • IP addresses — collected during sessions, activities, waitlist submissions, and feedback
  • User agents — browser type, operating system, device information
  • Color mode preference — light/dark theme choice (stored in your browser's localStorage)
  • Analytics data — page views, referrer, browser, operating system, device type, and country (collected via Umami, which is cookieless and does not collect personally identifiable information)

2.7 Data We Do NOT Collect

  • Credit card numbers — payment processing is handled by Polar, our merchant of record. We never see or store your full credit card details.
  • Precise geolocation — we do not use GPS or precise location tracking. Country-level data is derived from IP address via our analytics provider.
  • Cookies for tracking or advertising — we do not use advertising cookies or cross-site tracking cookies. Our analytics provider (Umami) is cookieless and does not track you across other websites.

3. How We Use Your Personal Data

We use your personal data for the following purposes:

3.1 Providing the Service

  • Creating and managing your account
  • Authenticating your identity (email/password or Google Sign-In)
  • Storing and displaying your Areas, Things, Notes, and Activities
  • Managing organization memberships and invitations
  • Sending transactional emails (email verification, password resets, email change confirmations)
  • Processing payments and managing subscriptions (via Polar)

3.2 Communicating With You

  • Sending service-related notifications (account security, product updates)
  • Responding to your feedback and support requests
  • Sending waitlist updates and early access invitations

3.3 Improving and Securing PRTO

  • Analyzing usage patterns to improve features and user experience (via anonymized analytics)
  • Detecting and preventing fraud, abuse, and security incidents
  • Maintaining audit logs of account activity
  • Rate limiting and DDoS protection
  • Complying with legal obligations under Brunei PDPO 2025, Singapore PDPA, and other applicable laws
  • Responding to lawful requests from authorities
  • Maintaining records as required by law

Where the EU/UK GDPR applies, we rely on the following lawful bases for processing your personal data:

Processing Activity Legal Basis
Account creation and authentication Contract — necessary to provide the service you requested
Storing and displaying your content Contract — necessary to provide the service
Sending transactional emails (verification, password reset) Contract — necessary to provide the service
Processing payments Contract — necessary to process your subscription
Sending service notifications Legitimate interests — keeping you informed about your account
Responding to feedback and support requests Legitimate interests — providing customer support
Analytics and product improvement Legitimate interests — improving our service (using anonymized data)
Fraud prevention and security Legitimate interests — protecting our service and users
Waitlist management Consent — you voluntarily provide your email and preferences
Marketing communications (if any) Consent — you opt in to receive marketing emails

Under the Brunei PDPO 2025 and Singapore PDPA, we process your personal data based on your consent or deemed consent, and for purposes that a reasonable person would consider appropriate in the circumstances. You may withdraw your consent at any time (see Section 10).


5. Data Sharing and Third-Party Processors

We do not sell, rent, or trade your personal data. We share personal data only with the following third-party service providers who process data on our behalf or as separate controllers:

5.1 Data Processors (acting on our behalf)

Provider Purpose Data Shared Location
Neon, LLC (Databricks affiliate) Database hosting and storage All user data stored in the application Singapore (ap-southeast-1, hosted on AWS)
Netlify, Inc. Web hosting, content delivery, serverless functions Static assets, server-side processing United States (global CDN)
Plus Five Five, Inc. (Resend) Transactional email delivery Email addresses, email content, derived names Tokyo, Japan (ap-northeast-1, hosted on AWS)
Polar Software, Inc. Payment processing (merchant of record) Checkout IDs, payment amounts, customer email United States
Redis Ltd. In-memory caching (Redis Cloud) IP addresses and user IDs for rate limiting (transient, TTL 60s–15min) Singapore (ap-southeast-1, hosted on AWS)

5.2 Separate Controllers

Provider Purpose Data Shared Location
Google LLC Authentication (Google Sign-In) Email, name, profile image, Google ID Global
Google LLC Web fonts (Poppins, Roboto, Lexend) IP address (in font request), font identifiers Global CDN

Google Sign-In: When you use Google Sign-In, Google is a separate data controller for the data you share with it. Your use of Google is subject to Google's Privacy Policy. You can revoke PRTO's access to your Google data at any time through your Google Account settings.

Polar checkout: When you make a purchase through Polar, Polar acts as the merchant of record and processes your payment data as a controller for checkout transactions. Your use of Polar is subject to Polar's Privacy Policy.

5.3 Analytics Provider

Provider Purpose Data Shared Location
Umami Cloud Privacy-focused web analytics Page views, referrer, browser, OS, device, country (all anonymized, no cookies, no PII) European Union

Umami is GDPR and CCPA compliant by design. It does not use cookies and does not collect personally identifiable information. All analytics data is anonymized.

5.4 Data Processing Agreements

We have Data Processing Agreements (DPAs) with each of our processors. These agreements include:

  • Standard Contractual Clauses (SCCs) for international data transfers (where applicable)
  • Data Privacy Framework (DPF) certification (where applicable — Neon, Netlify, Resend, and Google are DPF certified)
  • Confidentiality and security obligations
  • Breach notification requirements
  • Data return or deletion upon termination of services

5.5 Sub-Processors

Our processors may engage their own sub-processors. Key sub-processors include:

We may disclose your personal data to law enforcement or government authorities if required by law, court order, or other legal process, or if we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.


6. Cookies and Tracking Technologies

PRTO uses minimal cookies and tracking technologies. We do not use advertising cookies or cross-site tracking cookies. The only cookies we set are essential authentication cookies required to keep you logged in. All other preferences are stored in your browser's local or session storage, which you can clear at any time.

6.1 Essential Cookies

Cookie Purpose Duration Type
prto_auth.* Authentication session — keeps you logged in 7 days First-party, essential

These cookies are strictly necessary for the service to function. You cannot use PRTO without them.

6.2 Preference Storage

Storage Purpose Location Type
nuxt-color-mode UI theme preference (light/dark) Browser localStorage First-party, non-essential
prto-navigation-rail Navigation rail collapsed/expanded state Browser localStorage First-party, non-essential
waitlist_email_sent Tracks whether your waitlist email was sent (persists across Polar checkout redirects) Browser localStorage First-party, non-essential
prto-waitlist-survey Saves waitlist survey form progress (expires after 24 hours) Browser localStorage First-party, non-essential
prto:focus:show-completed-sub-things Toggles visibility of completed sub-items on the Focus page Browser sessionStorage First-party, non-essential

These values are stored in your browser's local or session storage, not as cookies. They are never transmitted to our servers. You can clear them at any time through your browser settings.

6.3 Analytics

We use Umami Cloud for web analytics. Umami is cookieless — it does not use cookies or local storage to track users. All analytics data is anonymized and does not include personally identifiable information. Umami collects: page views, referrer, browser, operating system, device type, and country (derived from IP address, not stored).

6.4 Third-Party Resources

When you load PRTO, your browser may make requests to third-party CDNs:

  • Google Fonts — requests fonts from Google's CDN. Google may receive your IP address as part of this request. No cookies are set by Google Fonts.
  • jsdelivr CDN — serves the Polar checkout embed script. No user data is transmitted.

6.5 Managing Cookies

Since we only use essential authentication cookies, there is no cookie consent banner. You can manage or clear cookies through your browser settings at any time. Note that clearing authentication cookies will log you out of PRTO.


7. Cross-Border Data Transfers

PRTO is incorporated in Brunei Darussalam, but we use service providers located in other countries. Your personal data may be transferred to and processed in the following jurisdictions:

7.1 Transfer Map

Destination Provider Data Transferred Transfer Mechanism
Singapore Neon (database) All user data SCCs (in DPA) + EU-U.S. Data Privacy Framework
United States Netlify (hosting) Static assets, server-side processing SCCs (in DPA) + EU-U.S. Data Privacy Framework
Tokyo, Japan Resend (email) Email addresses, email content SCCs (in DPA) + EU-U.S. Data Privacy Framework
United States Polar (payments) Checkout data, customer email DPA referencing GDPR
European Union Umami (analytics) Anonymized usage data No PII transferred (anonymized)
Singapore Redis Cloud (rate limiting, hosted on AWS) IP addresses, user IDs (transient rate-limit counters) Redis DPA + SCCs
Global Google (OAuth, fonts) Email, name, profile image (OAuth); IP address (fonts) Controller-Controller DPT + DPF

7.2 Transfer Protections

To ensure your personal data receives a standard of protection comparable to the laws applicable in your jurisdiction, we rely on:

  • Standard Contractual Clauses (SCCs) — European Commission-approved contractual safeguards for transfers to providers outside the EU/EEA
  • EU-U.S. Data Privacy Framework (DPF) — Our processors Neon, Netlify, Resend, and Google are certified under the EU-U.S. DPF, UK Extension, and Swiss-U.S. DPF
  • Data Processing Agreements (DPAs) — Contractual agreements with all processors ensuring comparable protection standards
  • Brunei PDPO Section 24 — We ensure that transfers outside Brunei Darussalam provide a standard of protection comparable to the PDPO through our DPAs and processor certifications
  • Singapore PDPA Transfer Limitation Obligation — We ensure that transfers to other jurisdictions meet the comparable protection standard through DPAs and processor certifications (PDPA Section 26)

7.3 Japan APPI Cross-Border Transfer Information

For users located in Japan, the following information is provided in accordance with Article 24 of the Act on the Protection of Personal Information (APPI):

  • Destination countries: Singapore (Neon, Redis Cloud, hosted on AWS), Japan (Resend, hosted on AWS), European Union (Umami), United States (Netlify, Polar, Google)
  • Data protection system of destination countries: The United States has a mixed data protection framework. Our U.S.-based processors maintain compliance with the EU-U.S. Data Privacy Framework, SOC 2, ISO 27001, and other recognized standards.
  • Recipient protection measures: Each processor has established systems conforming to APPI standards through data transfer agreements, DPF certification, and industry-recognized security certifications (SOC 2, ISO 27001/27701).

8. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, and as required by applicable law. We are actively working to implement automated retention enforcement for all data categories listed below. The table reflects our current retention behavior — some categories include target retention periods that we are in the process of implementing via scheduled cleanup tasks.

8.1 Retention Periods

Data Category Current Retention Period Target Retention Period (In Progress) Rationale
Account data (name, email, profile) While account is active. Deleted immediately upon account deletion request (cascade delete). 30-day grace period with account restoration before permanent deletion Account management
User content (Areas, Things, Notes) While account is active. Soft-deleted with a 30-day restore window. Permanently retained until manual cleanup. Permanent deletion 90 days after soft-delete (cleanup task in development) User content management; 30-day restore window for accidental deletions
Activity logs Retained indefinitely (no automatic cleanup currently implemented) 90-day automatic cleanup (scheduled task in development) Security monitoring and audit trail
Session data (tokens, IP, user agent) 7-day session lifetime (enforced via token expiry). Expired session records may persist in the database. Expired session records purged 30 days after expiry Authentication and security
Waitlist data Retained indefinitely until you request deletion. No automatic cleanup currently implemented. Deletion upon request or when waitlist is closed Waitlist management
Feedback data Retained indefinitely (no automatic cleanup currently implemented) 12-month automatic cleanup (scheduled task in development) Product improvement reference
Organization data While organization is active. Deleted immediately upon deletion request (cascade delete). 30-day grace period with organization restoration before permanent deletion Organization management
Payment records (checkout IDs, payment amounts) Retained indefinitely. No automatic cleanup currently implemented. 7-year retention with automated cleanup after expiry Legal and tax compliance; payment processing via Polar
Rate-limit data (IP addresses, user IDs in Redis Cloud) 60 seconds – 15 minutes (TTL-based, auto-expiring) Enforced Security and abuse prevention

8.2 Data Deletion

When you delete your account:

  1. Your account and profile data are permanently deleted immediately (cascade delete removes sessions, accounts, and OAuth tokens). We are implementing a 30-day grace period with account restoration capability.
  2. Your user content (Areas, Things, Notes) is soft-deleted — you can restore it within 30 days. After 30 days, content remains in the database until manual cleanup is performed. We are implementing automated permanent deletion 90 days after soft-delete.
  3. Activity logs associated with your account are retained indefinitely. We are implementing automated 90-day cleanup.
  4. Payment records (checkout IDs, payment amounts) are retained indefinitely. We are implementing 7-year retention with automated cleanup.
  5. Anonymized analytics data is not affected (it cannot be linked to you)

To request immediate and permanent deletion of all your data (including activity logs, feedback, and waitlist submissions) before automated cleanup is available, contact our DPO at afiq_rosli@live.com. We will manually process your deletion request within 30 days.

8.3 Retention Enforcement Roadmap

We are actively implementing automated retention enforcement to close the gaps between our current behavior and our target retention policy. Our engineering roadmap includes:

  1. Scheduled cleanup tasks — Daily automated tasks to purge expired data (soft-deleted records, activity logs, feedback, expired sessions)
  2. Soft-delete for accounts and organizations — Adding grace periods with restoration capability before permanent deletion
  3. Formal payment records retention — Implementing 7-year retention with automated expiry

We expect to complete implementation of these retention mechanisms by Q4 2026. Until then, you may request immediate deletion of any of your data at any time by contacting our DPO.

We may retain certain personal data beyond the periods stated above where required by law, to comply with legal obligations, resolve disputes, or enforce our agreements.


9. Security Measures

We implement reasonable security arrangements to protect your personal data from unauthorised access, collection, use, disclosure, copying, modification, disposal, or loss.

9.1 Technical Measures

  • Password hashing — Passwords are hashed using industry-standard algorithms (via better-auth). We never store or see plain-text passwords.
  • Encryption in transit — All data transmitted between your browser and our servers uses HTTPS/TLS encryption
  • Encryption at rest — Database and storage providers encrypt data at rest
  • Security headers — Content Security Policy (CSP), X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and HSTS are configured
  • Rate limiting — API endpoints are rate-limited to prevent abuse
  • Session management — Secure session tokens with 7-day expiry
  • OAuth token security — Google OAuth tokens are stored securely and encrypted

9.2 Organizational Measures

  • Data Protection Officer — A designated DPO oversees data protection compliance
  • Access controls — Access to personal data is restricted to authorized personnel only
  • Processor due diligence — We select processors that demonstrate sufficient security guarantees (SOC 2, ISO 27001, DPF certification)
  • Data Processing Agreements — Contractual security obligations with all processors
  • Incident response — We have procedures for assessing and responding to data breaches
  • Staff awareness — Data protection policies are communicated to relevant team members

9.3 Processor Security

Our processors maintain the following certifications and standards:

  • Neon: SOC 2 Type 1 & 2, ISO 27001, ISO 27701, HIPAA
  • Netlify: SOC 2, DPF certified
  • Resend: SOC 2 Type II, ISO 27001, DPF certified
  • Polar: Industry data security standards; payment processing via Stripe (PCI DSS compliant)
  • Redis: SOC 2 Type II, ISO 27001, ISO 27017, ISO 27018, ISO 42001, CSA STAR
  • Google: SOC 2/3, ISO 27001/27701, DPF certified

9.4 Limitations

While we implement robust security measures, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee absolute security of your personal data.


10. Your Data Protection Rights

You have certain rights regarding your personal data. The specific rights available to you depend on your jurisdiction, but we provide the following rights to all users regardless of location:

10.1 Rights Available to All Users

  • Right to access — You can request a copy of the personal data we hold about you
  • Right to correction — You can request that we correct inaccurate or incomplete personal data
  • Right to delete your account — You can request deletion of your account and associated data by contacting our DPO at afiq_rosli@live.com
  • Right to withdraw consent — You can withdraw any consent you have given for the collection, use, or disclosure of your personal data
  • Right to object — You can object to the processing of your personal data for certain purposes
  • Right to data portability — You can request your personal data in a structured, machine-readable format

10.2 How to Exercise Your Rights

To exercise any of these rights, contact our DPO at afiq_rosli@live.com. We will respond to your request:

If we need more time, we will inform you of the reason and extension period.

10.3 Additional Rights Under EU/UK GDPR

If you are located in the EU, EEA, or UK, you also have:

  • Right to erasure ("right to be forgotten") — Request deletion of your personal data in certain circumstances
  • Right to restrict processing — Request that we limit how we use your data
  • Right to object to automated decision-making — PRTO does not use automated decision-making that produces legal or similarly significant effects
  • Right to lodge a complaint — You can complain to your local data protection authority. For the EU, you can find your authority at edpb.europa.eu. For the UK, contact the ICO.

10.4 Additional Rights Under CCPA/CPRA

If you are a California resident, you also have:

  • Right to know — Categories of personal information collected, sources, purposes, and categories of third parties shared with
  • Right to opt-out of sale or sharing — PRTO does not sell or share your personal information
  • Right to limit use of sensitive personal information — PRTO does not collect sensitive personal information as defined by CCPA
  • Right to non-discrimination — We will not discriminate against you for exercising your rights

10.5 Verification

To protect your personal data, we may need to verify your identity before responding to certain requests. We will only ask for information necessary to verify your identity.


11. Children's Privacy

PRTO is not directed at children and we do not knowingly collect personal data from anyone under the age of 13.

  • If we learn that we have collected personal data from a child under 13, we will delete that data promptly.
  • For users under 16 (where CCPA applies), we do not sell or share personal information without affirmative authorization.
  • Under the EU GDPR, information society services are generally not offered to children under 16 without parental consent (member states may lower this to 13).
  • Under Japan APPI, parental consent is required for individuals under 15.

If you believe a child has provided us with personal data, please contact our DPO at afiq_rosli@live.com.


12. Data Breach Notification

We take data breaches seriously and have procedures in place to assess, respond to, and notify about data breaches.

12.1 Our Commitment

If a data breach occurs that is likely to result in significant harm to you or is of significant scale, we will:

  1. Assess the breach — Conduct a reasonable and expeditious assessment to determine if the breach is notifiable
  2. Notify the relevant authority — Report to the applicable data protection authority:
    • AITI (Brunei) — Within 3 days of assessment (PDPO Section 28)
    • PDPC (Singapore) — Within 3 calendar days of assessment (PDPA Section 26D)
    • Supervisory authority (EU/UK) — Within 72 hours of becoming aware (GDPR Article 33)
    • PPC (Japan) — Promptly, approximately 3–5 days for preliminary report (APPI Article 26)
  3. Notify affected individuals — Inform you of the breach, what data was affected, and what steps you can take to protect yourself
  4. Take corrective action — Implement measures to prevent recurrence

12.2 Processor Breach Notification

Our processors are contractually required to notify us of any data breach without undue delay. We will then assess the breach and notify you and the relevant authorities as required.


13. Direct Marketing

We may send you service-related communications (account notifications, product updates, security alerts). These are sent as part of our service to you and do not require separate consent.

If we send marketing communications:

  • We will obtain your consent before sending marketing emails
  • You can opt out of marketing communications at any time by clicking the unsubscribe link in the email or contacting our DPO
  • Under the Brunei PDPO, specific consent is required for direct marketing messages to Brunei Darussalam telephone numbers. We do not currently send SMS marketing.

14. Complaints

If you have a complaint about how we handle your personal data, we want to hear from you.

14.1 Contact Our DPO

First, please contact our DPO at afiq_rosli@live.com with details of your complaint. We will:

  1. Acknowledge your complaint within 5 business days
  2. Investigate and respond within 30 days
  3. Work with you to resolve the issue

14.2 Contact a Regulator

If you are not satisfied with our response, or if you believe we have not handled your personal data in accordance with the law, you have the right to lodge a complaint with your local data protection authority:


15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the services we offer.

15.1 How We Communicate Changes

  • Material changes — We will notify you by email and/or display a prominent notice in the app at least 30 days before the changes take effect
  • Minor changes — We will update the "Last updated" date at the top of this policy
  • New purposes — If we intend to use your personal data for a new purpose, we will notify you and seek your consent before doing so (where required by law)

15.2 Reviewing the Policy

The current version of this Privacy Policy is always available at prto.app/privacy-policy. We recommend reviewing it periodically.


16. Jurisdiction-Specific Disclosures

16.1 Brunei Darussalam — PDPO 2025

This Privacy Policy is designed to comply with the Personal Data Protection Order, 2025 (PDPO) of Brunei Darussalam, administered by AITI.

Key PDPO disclosures:

Deemed consent by notification: Under Section 12 of the PDPO, if we intend to use your personal data for a new purpose that is compatible with the original purpose, we may notify you of the new purpose and proceed unless you opt out. You will have a reasonable period to object before the new processing begins.

16.2 Singapore — PDPA

This Privacy Policy is designed to comply with the Personal Data Protection Act 2012 (PDPA) of Singapore, administered by the PDPC.

Key PDPA disclosures:

  • DPO: Afiq Rosli — afiq_rosli@live.com (PDPA Section 11(3), Accountability Obligation)
  • Notification: Purposes listed in Section 3 (PDPA Section 20, Notification Obligation)
  • Consent: You may withdraw consent at any time (PDPA Section 16, Consent Obligation)
  • Purpose limitation: We only collect, use, and disclose data for reasonable purposes (PDPA Section 18, Purpose Limitation Obligation)
  • Access and correction: You may request access to and correction of your personal data (PDPA Sections 21 and 22)
  • Transfer limitation: Cross-border transfers meet comparable protection standards (PDPA Section 26, Transfer Limitation Obligation; see Section 7.2 of this policy)
  • Data breach notification: To PDPC within 3 calendar days of assessment and to affected individuals for notifiable breaches (PDPA Section 26D)
  • Data protection by design: We embed data protection principles in our system design and architecture

16.3 EU/UK — GDPR

This Privacy Policy is designed to comply with the General Data Protection Regulation (EU) 2016/679 (GDPR) and the UK GDPR.

Key GDPR disclosures:

  • Controller: PRTO, Brunei Darussalam
  • DPO: Afiq Rosli — afiq_rosli@live.com
  • EU representative: PRTO does not currently have an appointed EU representative under GDPR Article 27. We will appoint one before actively targeting or marketing to EU users. If you are an EU user, you may contact our DPO directly for any GDPR-related matters.
  • Lawful bases: Listed in Section 4 of this policy (GDPR Article 6)
  • Data subject rights: Listed in Section 10 of this policy (GDPR Articles 15–22)
  • Response timeframe: Within one month of receipt of request (GDPR Article 12(3))
  • Cross-border transfers: Section 7, using SCCs and DPF certification (GDPR Chapter V)
  • Automated decision-making: PRTO does not use automated decision-making that produces legal or similarly significant effects (GDPR Article 22(1))
  • Data Protection Impact Assessment (DPIA): We conduct assessments for high-risk processing activities where applicable (GDPR Article 35)

16.4 California — CCPA/CPRA

This Privacy Policy is designed to comply with the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA).

Key CCPA disclosures (past 12 months):

  • Categories of personal information collected: Identifiers (name, email, IP address), commercial information (payment records), internet activity (usage data, page views), geolocation data (country-level, derived from IP)
  • Categories of sources: Directly from you (registration, usage), automatically (cookies, analytics, server logs)
  • Business or commercial purposes: Providing the service, communicating with you, improving the service, security and fraud prevention, legal compliance
  • Categories sold or shared: None. PRTO does not sell or share your personal information.
  • Categories disclosed to service providers: Identifiers (email, name, IP address, user ID), commercial information (payment data) — disclosed to Neon, Netlify, Resend, Polar, and Redis for service provision
  • Children's data: We do not knowingly collect personal information from children under 13. We do not sell or share personal information of consumers under 16 without affirmative authorization.
  • Sensitive personal information: PRTO does not collect sensitive personal information as defined by CCPA.
  • Retention periods: Listed in Section 8 of this policy

"Do Not Sell or Share My Personal Information": PRTO does not sell or share your personal information, so this right is not applicable. We do not need to display a "Do Not Sell or Share" link.

Opt-out preference signals: We honour Global Privacy Control (GPC) signals. Since we do not sell or share personal data, these signals do not change how we process your data.

16.5 Japan — APPI

This Privacy Policy is designed to comply with the Act on the Protection of Personal Information (APPI), administered by the Personal Information Protection Commission (PPC).

Key APPI disclosures:

  • Purpose of use: Listed in Section 3 of this policy (APPI Article 18)
  • Third-party provision: We do not provide your personal data to third parties without your consent, except to our processors (entrustment) who process data on our behalf under contractual obligations (APPI Article 23)
  • Cross-border transfers: Section 7.3 of this policy provides the information required under APPI Article 24
  • Data subject rights: You have the right to request disclosure (APPI Article 28), correction (APPI Article 29), suspension of use (APPI Article 30), and explanation of reason for non-compliance (APPI Article 31)
  • Breach notification: We report certain data breaches to the PPC and notify affected individuals (APPI Article 26)

16.6 Other US State Privacy Laws

PRTO also aligns with other US state privacy laws where applicable, including but not limited to Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), and other states with comprehensive privacy legislation. These laws generally provide similar rights to CCPA (access, deletion, correction, opt-out of sale/targeted advertising) and we handle all such requests through the process described in Section 10.


17. Automated Decision-Making and Profiling

PRTO does not use automated decision-making or profiling that produces legal or similarly significant effects on users. We do not use artificial intelligence or machine learning to make decisions about you. Any analytics we perform are for aggregate, anonymized product improvement purposes only.


18. Data We Do Not Sell

PRTO does not sell your personal data to any third party. We do not share your personal data for cross-context behavioral advertising. We do not rent or trade your personal data. This statement applies across all jurisdictions, including where "sale" or "sharing" is defined by CCPA, GDPR, PDPO, PDPA, or APPI.


19. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact:

Data Protection Officer: Afiq Rosli

Email: afiq_rosli@live.com

Website: prto.app

We are committed to working with you to resolve any concerns you may have about your personal data.


20. Definitions

Term Definition
Personal data Information relating to an identified or identifiable individual
Data controller The entity that determines the purposes and means of processing personal data (PRTO)
Data processor An entity that processes personal data on behalf of the data controller (e.g., Neon, Netlify, Resend, Polar, Redis)
DPO Data Protection Officer — the individual responsible for overseeing data protection compliance
DPA Data Processing Agreement — a contract between controller and processor governing data processing
SCCs Standard Contractual Clauses — EU-approved contractual safeguards for international data transfers
DPF Data Privacy Framework — a framework for transfers between the EU/UK/Switzerland and the US
PDPO Personal Data Protection Order, 2025 (Brunei Darussalam)
PDPA Personal Data Protection Act 2012 (Singapore)
GDPR General Data Protection Regulation (EU) 2016/679
UK GDPR UK General Data Protection Regulation
CCPA California Consumer Privacy Act (as amended by CPRA)
APPI Act on the Protection of Personal Information (Japan)
AITI Authority for Info-Communications Technology Industry of Brunei Darussalam
PDPC Personal Data Protection Commission (Singapore)
PPC Personal Information Protection Commission (Japan)
ICO Information Commissioner's Office (UK)
CPPA California Privacy Protection Agency

This Privacy Policy is provided for informational purposes and constitutes a statement of our data protection practices. It does not constitute legal advice. While we have made every effort to ensure compliance with applicable data protection laws, this policy should be reviewed by qualified legal counsel licensed in the relevant jurisdictions before publication. Particularly, Brunei PDPO 2025 and Singapore PDPA are specialized jurisdictional laws that may benefit from external counsel review.


Privacy Policy v1.0 Last updated: 20 July 2026 Prepared by: PRTO DPO: Afiq Rosli — afiq_rosli@live.com