Privacy Policy

1. Who we are

SystematicBooks operates the website systematicbooks.com. For the purposes of applicable data protection laws, SystematicBooks is the controller of the personal data described in this Privacy Policy.

Contact details for privacy matters:

  • Email (general privacy inquiries and rights requests): privacy@systematicbooks.com
  • Data Protection Officer (DPO): dpo@systematicbooks.com

2. Scope of this Privacy Policy

This Privacy Policy explains how we collect, use, disclose, secure, and retain personal data when you visit systematicbooks.com or its subdomains, create an account, make a purchase, sign up for communications, interact with customer support, or otherwise engage with our services (collectively, the “Services”).

This Privacy Policy applies worldwide. Depending on where you live, additional rights and disclosures may apply (for example, under the EU/EEA and UK GDPR, the California Consumer Privacy Act as amended by the CPRA, or other local laws). Where we refer to “personal data,” we mean any information that identifies or can reasonably be linked to an identified or identifiable individual.

3. What data we collect

We collect the following categories of personal data:

  • Information you provide to us:
    • Account and profile data (e.g., name, email address, password, display name, preferences).
    • Order and delivery data (e.g., billing and shipping addresses, items purchased, transaction totals, order history).
    • Communications and support data (e.g., messages you send us, support tickets, survey responses, product reviews).
    • Marketing preferences (e.g., newsletter opt-ins, consent settings).
    • Content you submit (e.g., comments, ratings, uploaded materials you choose to share).
  • Payment information:
    • We collect limited payment details necessary to process your order (e.g., payment method, transaction identifiers).
      Payment card details are processed by our payment service providers and are not stored by us in full.
  • Data collected automatically:
    • Device and usage data (e.g., IP address, browser type and version, operating system, device identifiers, pages viewed, time and date of visits, referring/exit pages, clickstream data, and general location inferred from IP address).
    • Cookies and similar technologies (see Section 6).
    • Security and fraud prevention data (e.g., logs and signals used to detect abusive or unauthorized activity).
  • Data from third parties:
    • We may receive information about you from service providers and partners (e.g., payment processors, analytics providers, fulfillment and delivery partners), and from publicly available sources where permitted by law.
    • If you interact with us via social media or choose to link or sign in through a third-party platform, we may receive account information from that platform according to its privacy settings and policies.

Sensitive data: We do not require or intentionally collect sensitive personal data (such as health data) to provide the Services. Please do not submit sensitive data to us. If processing of sensitive data becomes necessary, we will obtain your explicit consent or rely on another lawful basis where required by law.

Children’s data: Our Services are not directed to children under 13, and we do not knowingly collect personal data from them. If you believe a child under 13 has provided data to us, contact privacy@systematicbooks.com so we can delete it. If you are in the EEA/UK, you must be old enough to consent to data processing in your country; otherwise, a parent or guardian must consent.

4. Purposes and legal bases for processing

We process personal data for the purposes and, where applicable, under the legal bases described below:

  • Provide and operate the Services (e.g., account creation, order processing, delivery, customer support)
    • Legal bases: performance of a contract; legitimate interests in providing and improving the Services.
  • Process payments and prevent fraud
    • Legal bases: performance of a contract; legitimate interests in ensuring secure transactions; compliance with legal obligations (e.g., tax, accounting, anti-fraud).
  • Communicate with you (e.g., transactional emails, service announcements)
    • Legal bases: performance of a contract; legitimate interests in keeping you informed about your account or orders.
  • Send marketing communications and personalize content (where permitted)
    • Legal bases: your consent where required; legitimate interests in promoting our Services where consent is not required. You can opt out at any time.
  • Analytics, research, and service improvements
    • Legal bases: legitimate interests in understanding usage and improving the Services; your consent where required (for example, for non-essential cookies in the EEA/UK).
  • Security, compliance, and enforcement
    • Legal bases: legitimate interests in protecting our Services and users; compliance with legal obligations; establishment, exercise, or defense of legal claims.
  • Business operations and corporate transactions (e.g., restructuring, acquisition)
    • Legal bases: legitimate interests in running and developing our business; performance of a contract.

Where we rely on consent, you can withdraw it at any time by contacting privacy@systematicbooks.com or adjusting your device or browser settings. Withdrawal does not affect prior lawful processing.

5. Data retention

We keep personal data only as long as necessary for the purposes described in this Privacy Policy, including to comply with legal, accounting, and reporting obligations, to resolve disputes, and to enforce agreements. Typical retention periods include:

  • Account data: for as long as your account is active and up to 24 months after the last activity, unless you request deletion earlier.
  • Order and transaction records: generally 7 years from the end of the financial year in which the transaction occurred (or longer if required by applicable law).
  • Customer support records: up to 3 years after resolution.
  • Marketing preferences and consent records: until you opt out or withdraw consent, or up to 24 months after your last interaction with our marketing communications.
  • Security and audit logs: typically 12 months, unless needed longer to investigate an incident.
  • Cookies: see Section 6; non-essential cookies in the EEA/UK are not kept for more than 13 months.

When we no longer need personal data, we will delete or anonymize it. If deletion is not possible (for example, because the data is stored in backup archives), we will securely store the data and isolate it from further processing until deletion is possible.

6. Cookies and similar technologies

We use cookies, web beacons, pixels, local storage, and similar technologies to operate the site, measure performance, understand usage, remember your preferences, and, where permitted, personalize content.

Types of cookies we may use:

  • Strictly necessary cookies: required for core site functions such as navigation, security, and checkout.
  • Performance and analytics cookies: help us understand how visitors use our site to improve it.
  • Functional cookies: remember choices you make to provide enhanced features.
  • Advertising or personalization cookies: tailor content or measure the effectiveness of our communications (used only where permitted by law).

Consent and controls:

  • In the EEA/UK and where required, non-essential cookies are used only with your consent. You can withdraw consent at any time by changing your browser settings to block or delete cookies. Note that disabling cookies may affect site functionality.
  • Some browsers and extensions allow you to send an opt-out preference signal (such as Global Privacy Control). Where legally required, we treat such signals as requests to opt out of certain processing, including applicable analytics or advertising cookies.

7. How we share personal data

We share personal data only as described below and with appropriate safeguards:

  • Service providers and processors: companies that host our website, provide cloud and storage services, process payments, fulfill and deliver orders, provide customer support, send communications, conduct analytics, and support security and fraud prevention. These providers are bound by contractual obligations to protect personal data and use it only on our instructions.
  • Professional advisors: lawyers, accountants, auditors, and insurers, where necessary for the services they provide.
  • Authorities and legal disclosures: when required by law or in response to valid legal process; to protect our rights, users, or the public; or to enforce our terms and policies.
  • Business transfers: in connection with any actual or proposed merger, acquisition, reorganization, or sale of assets, your personal data may be transferred as part of that transaction, subject to appropriate protections.
  • With your direction or consent: when you ask us to share information or otherwise consent to sharing.

We do not sell personal information. We also do not share personal information for cross-context behavioral advertising or targeted advertising in jurisdictions where such sharing requires an opt-out.

8. International data transfers

Our Services may be provided using resources and servers located in various countries. As a result, your personal data may be transferred to and processed in a country that is different from your country of residence and that may have data protection laws that differ from those in your country.

Where we transfer personal data from the EEA, UK, or Switzerland to countries that have not been deemed to provide an adequate level of data protection, we implement appropriate safeguards such as the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum or equivalent instruments, along with supplementary measures where necessary. You can request more information or a copy of the relevant transfer safeguards by contacting privacy@systematicbooks.com.

9. Your privacy rights

Depending on your location, you may have some or all of the rights listed below regarding your personal data. We will not discriminate against you for exercising your rights.

  • Access: request confirmation of whether we process your personal data and receive a copy.
  • Rectification: request correction of inaccurate or incomplete personal data.
  • Erasure: request deletion of your personal data, subject to legal exceptions.
  • Restriction: request that we limit the processing of your personal data in certain circumstances.
  • Portability: receive personal data you provided in a structured, commonly used, machine-readable format and request that we transmit it to another controller where technically feasible.
  • Objection: object to processing based on our legitimate interests, including profiling; we will honor your request unless we have compelling legitimate grounds or the processing is needed for legal claims.
  • Withdraw consent: where processing is based on consent, you may withdraw it at any time.
  • Automated decisions: request human review of decisions that produce legal or similarly significant effects, where applicable.
  • Regional rights:
    • EEA/UK/Switzerland: you also have the right to lodge a complaint with a supervisory authority in your country of residence or work, or where you believe an infringement has occurred.
    • California and certain US states: you may have the right to know, correct, and delete personal information, and to opt out of certain processing such as targeted advertising or profiling where applicable. You may also use a recognized opt-out preference signal supported by your browser or extension.
    • Brazil: you may have rights under the LGPD, including confirmation of processing, access, correction, anonymization, blocking or deletion, portability, information about sharing, withdrawal of consent, and review of automated decisions, where applicable.

To exercise your rights, email privacy@systematicbooks.com. We may need to verify your identity before responding. We aim to respond within one month (or within the timeframe required by applicable law). If we cannot fulfill your request, we will explain why.

10. Data security

We implement technical and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, or destruction. These measures include access controls, encryption in transit, network and application security, logging and monitoring, least-privilege practices, regular reviews of our safeguards, and staff training. No method of transmission over the internet or electronic storage is completely secure; therefore, we cannot guarantee absolute security. If we become aware of a data breach involving your personal data, we will notify you and regulators as required by law.

11. Automated decision-making and profiling

We do not use personal data to make decisions that produce legal or similarly significant effects on you without human involvement. We may use limited profiling for purposes such as analytics and service improvements, and for optional personalization where permitted by law and, where required, with your consent.

12. Third-party services and links

Our Services may include integrations with or links to third-party websites, applications, or services. Those third parties have their own privacy practices. We are not responsible for their content or privacy policies. We encourage you to review their privacy information before interacting with them.

13. International users

By using the Services, you understand that your personal data may be processed in countries with different data protection laws than your own. We will take steps to ensure appropriate protection as described in Section 8.

14. How to contact our DPO or us about privacy

If you have questions about this Privacy Policy or our handling of personal data, or if you wish to exercise your rights, please contact:

  • Data Protection Officer: dpo@systematicbooks.com
  • General privacy contact: privacy@systematicbooks.com

15. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will update the “Effective date” below and, where appropriate, notify you by a prominent notice within the Services. Please review this Privacy Policy periodically to stay informed about our practices.

Effective date: 08 December 2025