This Privacy Policy explains how IT-BUSINESS SOLUTIONS LIMITED (“MobiusApp”, “we”, “us”) collects and uses personal data on mobiusapp.io and in the MobiusApp platform. We are established in the European Union, so the General Data Protection Regulation (EU) 2016/679 applies to this processing directly.
1. Who is responsible for your data
1.1. For the data collected on this website and in the MobiusApp management panel, the controller is IT-BUSINESS SOLUTIONS LIMITED, a Private Limited Company registered in Cyprus under number HE 309568, of 20 Ionos str., 2nd Floor, Office 205, Nicosia 2406, Cyprus. Contact: support@mobiusapp.io.
1.2. For the data of shoppers using a mobile application built on MobiusApp, the controller is the merchant who operates that application. In that case we act as a processor on the merchant's instructions. If you are a shopper with a question about your data, contact the merchant whose app you used.
2. What we collect
2.1. Contact details you give us. Name, email, phone number, company name and website when you request a demo, book a call, apply to the partner programme or write to us. Legal basis: performance of a contract, or steps taken at your request before entering into one.
2.2. Account data. Email, name, role and authentication data for users of the management panel. Legal basis: performance of a contract.
2.3. Billing data. Company details and invoice records. Payment card details are handled by our payment providers and never reach our servers. Legal basis: performance of a contract and legal obligation.
2.4. Technical data. IP address, browser and device type, pages visited, and referring source. Legal basis: our legitimate interest in operating and securing the site, or your consent where the data comes from analytics cookies.
2.5. Support correspondence. What you write to us and our replies. Legal basis: performance of a contract and legitimate interest in maintaining a support history.
3. What we use it for
- Responding to demo requests, enquiries and support tickets.
- Providing, operating and improving the Service.
- Issuing invoices and meeting accounting obligations.
- Sending service messages about your account, releases and incidents.
- Sending marketing emails, where you have opted in. You can unsubscribe from any of them.
- Detecting and preventing abuse, fraud and security incidents.
We do not sell personal data, and we do not share it with advertising networks for their own purposes.
4. Cookies and analytics
4.1. Strictly necessary cookies keep the site working — sessions, security, form submission, and remembering your cookie choice itself. They are set without consent because the site cannot function without them, and they cannot be switched off.
4.2. Analytics cookies help us understand how the site is used. They are set only after you accept them. Until you do, no analytics script runs and no analytics cookie is written: consent is signalled to Google Consent Mode, which holds measurement in a denied state by default.
4.3. We ask once and remember the answer for 180 days in a cookie named mobius_cookie_consent. Declining is as easy as accepting — the two buttons are equal.
4.4. You can change or withdraw your choice at any time using the Cookie settings link at the bottom of every page. Withdrawing consent stops any further analytics collection; it does not retroactively erase data already collected, which you can request separately under clause 8.
4.5. You can also clear or block cookies in your browser settings. Blocking strictly necessary cookies will break parts of the site.
4.6. We do not use advertising cookies and do not share data with advertising networks for their own purposes.
5. Who we share data with
5.1. Service providers acting on our instructions: hosting, email delivery, analytics, CRM and payment processing. Each is bound by a contract limiting what they may do with the data.
5.2. App stores. Publishing an application requires sharing the listing details you provide with Apple and Google.
5.3. Authorities, where we are legally required to disclose data.
5.4. We do not transfer personal data to anyone else without a legal basis for doing so.
6. International transfers
6.1. We are established in the European Union, and personal data is processed within the European Economic Area wherever we can arrange it that way.
6.2. Some of our service providers operate outside the EEA. Where personal data is transferred out of the EEA, we rely on a legal basis for that transfer under Chapter V of the GDPR: an adequacy decision of the European Commission where one covers the destination country, and otherwise the European Commission's Standard Contractual Clauses together with supplementary measures where the transfer risk assessment calls for them.
6.3. On request we will tell you which safeguard applies to a specific transfer and provide a copy of the relevant clauses.
7. How long we keep it
- Enquiries that did not lead to a contract — 12 months from the last contact.
- Account and Customer Data — for the life of the account, plus 30 days after termination.
- Invoices and accounting records — for the period required by the applicable tax law.
- Support correspondence — 24 months.
8. Your rights
8.1. Under the GDPR you have the right to access your data, to have it corrected or erased, to restrict or object to its processing, to receive it in a portable format, and to withdraw consent at any time without affecting the lawfulness of processing carried out before the withdrawal.
8.2. If you are in California, you may also have the right to know what personal information is collected, to request its deletion, and not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined by the CCPA/CPRA.
8.3. To exercise any of these rights, write to support@mobiusapp.io. We respond within one month, and may extend that by two further months for complex requests, telling you why.
8.4. If you believe we have handled your data unlawfully, you may lodge a complaint with our supervisory authority — the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus (dataprotection.gov.cy) — or with the supervisory authority of the EEA state where you live or work.
9. Security
9.1. We use encryption in transit, access control, network segregation and regular backups. Access to personal data is limited to employees who need it for their work.
9.2. No system is perfectly secure. If a personal data breach is likely to result in a risk to your rights and freedoms, we notify our supervisory authority within 72 hours of becoming aware of it, and we notify you directly where the risk is high — as required by Articles 33 and 34 of the GDPR.
10. Children
The Service is intended for business use and is not directed at children. We do not knowingly collect personal data from children.
11. Changes
We may update this Policy. The current version is always published at https://mobiusapp.io/legal/privacy/ with its version date at the top. Material changes are announced by email to account holders.