Last updated: 19th August 2026

1. Who we are

cr0bar Limited ("we", "us", "our") is the data controller for the personal data described in this policy. We are a company registered in England and Wales under company number 07332447, with registered office at Suite 5 Admirals Yard, Low Road, Hunslet, Leeds, England, LS10 1AE. We are registered with the UK Information Commissioner's Office (ICO), registration reference ZA902799.

You can contact us about privacy matters at legal@mysso.net or by post to the address above.

2. What personal data we collect

  • Account data — your username, email address, and account status (e.g. verified, active, suspended).
  • Authentication data — a securely hashed version of your password (we never store it in plain text), one-time passcode (TOTP) secrets, and public key credentials if you register a passkey or security key. We do not receive or store biometric data itself — that stays on your device.
  • Security and log data — sign-in timestamps, IP addresses, browser/device information, and an activity log of security-relevant events on your account (e.g. sign-ins, password changes, app authorisations).
  • Invitation data — if someone invites you, or you invite someone else, we process the email address and invitation status.
  • Connected app data — which third-party applications you have authorised to use your account, and the scope of access you granted each one.
  • Cookies — strictly necessary cookies used to keep you signed in and to protect the Service. See our Cookie Policy for details.

We do not knowingly collect special category data (such as health, biometric-identity, or religious data) about you.

3. How we use your data, and our legal basis

PurposeLegal basis (UK GDPR Art. 6)
Creating and administering your account, authenticating you, and letting you sign in to connected appsPerformance of a contract with you
Keeping the Service secure — detecting abuse, fraud, and unauthorised access, and maintaining audit logsLegitimate interests (keeping our systems and your account secure)
Responding to support requests and sending service or security notices (e.g. password reset, new sign-in alerts)Performance of a contract with you / legitimate interests
Complying with legal obligations, responding to lawful requests from authorities, and establishing or defending legal claimsLegal obligation / legitimate interests

Where we rely on legitimate interests, we have considered that our use of your data is proportionate and does not unduly impact your rights. We do not use your personal data for advertising, and we do not sell your personal data.

4. Who we share data with

  • Connected apps you authorise — only the specific profile information and scopes you approve when you sign in to a third-party app through the Service (for example, your name, email address, or username). You can review and revoke these authorisations from your account at any time.
  • Service providers (processors) — companies that support our infrastructure, such as hosting and email delivery, who process data on our behalf and under contract, only as needed to provide the Service.
  • Legal and safety — where we're required to by law, court order, or to protect the rights, property, or safety of us, our users, or others.
  • Business transfers — if we're involved in a merger, acquisition, or asset sale, your data may be transferred as part of that transaction, subject to this policy continuing to apply.

We do not share your personal data with third parties for their own marketing purposes.

5. International data transfers

Where any of our service providers process personal data outside the UK, we ensure an appropriate safeguard is in place before the transfer happens — such as the UK's International Data Transfer Addendum, an adequacy decision by the UK government, or UK Standard Contractual Clauses. Contact us if you'd like more information about the safeguards used for a specific transfer.

6. How long we keep your data

  • Account data is kept for as long as your account is active, and for a limited period afterwards in case you wish to reactivate it or as needed for legal or security purposes.
  • Security and activity logs are kept for a limited retention period sufficient to investigate incidents and meet our security obligations, after which they are deleted or anonymised.
  • If you delete your account, we delete or anonymise your personal data within a reasonable period, except where we need to keep limited records to comply with law, resolve disputes, or enforce our agreements.

7. Your rights under UK GDPR

You have the right to:

  • Access the personal data we hold about you;
  • Rectify inaccurate or incomplete data;
  • Erase your data in certain circumstances ("right to be forgotten");
  • Restrict or object to certain processing, including processing based on legitimate interests;
  • Port your data to another service in a structured, machine-readable format, where technically feasible; and
  • Withdraw consent at any time where we rely on consent (this doesn't affect processing carried out before you withdrew it).

To exercise any of these rights, contact us at legal@mysso.net. We'll respond within one month, as required by law. You also have the right to complain to the ICO at any time — see section 10 below.

8. Automated decision-making

We may use automated rules to flag suspicious sign-in activity or rate-limit abusive requests, but we do not make decisions that produce legal or similarly significant effects about you using automated processing alone, without human review.

9. How we protect your data

We use technical and organisational measures appropriate to the risk, including encrypting data in transit, hashing passwords, supporting multi-factor authentication and passkeys, and restricting internal access to personal data on a need-to-know basis. No system is completely secure, and we encourage you to also use a strong, unique password and enable an additional sign-in method on your account.

10. Complaints

We'd appreciate the chance to address any concerns directly — please contact us first at legal@mysso.net. You also have the right to lodge a complaint with the UK's supervisory authority:

Information Commissioner's Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline: 0303 123 1113 · ico.org.uk

11. Children

The Service is not directed at children, and you must be at least 16 years old to create an account.

12. Changes to this policy

We may update this policy from time to time. We'll post the updated version here with a new "last updated" date, and where changes are material we'll take reasonable steps to let you know.