1. Record of Processing Activities (ROPA)
Controller: La Soluzione Web Ltd (trading as MoneyZoe)
Contact: support [at] moneyzoe.com
ICO Registration Number: ZB859987
Activity | Categories of Data | Purpose of Processing | Legal Basis | Data Subjects | Recipients/Sub-processors |
---|---|---|---|---|---|
Website analytics | IP address, UUID, device/browser info, interactions | Site performance, usage analysis | Legitimate interests | Website visitors | Google LLC, Meta Platforms, LinkedIn |
Newsletter signups | Name, email | Newsletter, Guide delivery | Consent | Subscribers | Internal systems only |
Affiliate tracking | Clicks, device ID, referral URL | Attribution and commission tracking | Legitimate interests | Website visitors | Awin, CJ Affiliate, Rakuten, financeAds, etc. |
Contact form | Name, email, message content | Responding to user inquiries | Consent / Contract | Inquirers | Hosting provider, internal systems |
Hosting and security | IP address, device data | Secure and reliable website operation | Legitimate interests | All site users | Hostinger, AWS, Cloudflare, Defiant |
Review cycle: Annually or when new processing is introduced.
2. Data Breach Response Procedure (Simplified)
- Identify and confirm the breach (e.g., unauthorized access, loss, or misuse).
- Contain the breach (e.g., shut down affected accounts or services).
- Assess the risk to individuals.
- Notify the ICO within 72 hours (if risk is likely to rights/freedoms).
- Notify affected users without undue delay if there is a high risk.
- Document the breach, decisions taken, and actions performed.
- Review and implement security improvements.
3. DSAR Procedure (Data Subject Access Request)
- Data subjects can submit requests directly at: https://moneyzoe.com/submit-gdpr-request/
- The form includes all standard rights: access, rectification, erasure, restriction, portability, objection, and withdrawal of consent.
- We will acknowledge receipt of the request within 3 business days.
- We will respond within 30 days as required by GDPR. If more time is needed due to complexity, the user will be informed.
- Identity may be verified if necessary.
- Data is provided in a structured, commonly used format.
- No fee is charged unless the request is excessive or unfounded.
4. Data Subject Rights Procedure (Right to be Forgotten, etc.)
- Requests to erase, rectify, or restrict data are accepted by email.
- Requests are assessed and, where valid, completed within one month.
- If objection is based on marketing, the request is honored immediately.
- Users are informed of outcomes and given appeals path if rejected.
5. Data Sharing Processes
- Data is only shared with third parties listed in the Privacy Policy and DPA.
- All third-party services are reviewed for GDPR compliance.
- International transfers are protected using SCCs or adequacy mechanisms.
- No unnecessary or informal data sharing is permitted.
Reviewed: 30 March 2025
Maintained by: Christian Morano, Data Protection Lead