← Submitto

Privacy Policy

Last updated July 20, 2026

Effective date: July 20, 2026

Submitto (“Submitto”, “we”, “us”) is operated by Submitto Software Inc., a company incorporated in British Columbia, Canada.

This policy explains what personal information we handle, why we handle it, who we share it with, where it goes, how long we keep it, and the rights and choices you have. We wrote it to be read. If anything is unclear, email us at hello@submitto.io.

1. What this policy covers

One policy covers both of our websites:

  • The app — app.submitto.io. Where Organizers create accounts and Events, and where Submitters upload files through public links.
  • The marketing site — submitto.io. Our public website describing the product. It has no login and no forms; it runs visitor analytics (described in §6).

A few words we capitalize throughout, because they have a specific meaning:

  • Organizer — the account holder; our customer. Organizers create Events and invite Submitters.
  • Submitter — a person who uploads files or information through an Organizer’s public link. Submitters do not create accounts and are not our customers.
  • Event — an Organizer’s collection workspace in the app (called an “event” in the product even when used for non-event collection).
  • Content — the files and information Submitters or Organizers put into an Event.
  • Viewer links — read-only share links to a sanitized view of an Event.

Our Terms of Service govern use of the service. Organizers subject to GDPR or UK GDPR can also rely on our Data Processing Addendum (DPA), available on request at hello@submitto.io. A short plain-language notice for Submitters appears on every public upload page.

2. Our two legal roles: controller and processor

Submitto plays two different legal roles depending on whose information is involved. This distinction shapes the whole policy:

We are the controller of Organizer, account, and site-visitor data. A “controller” is the business responsible for the data — the one that decides what to collect and why. For your account details, your billing records, our security logs, and analytics on the marketing site, that business is us. You deal with us directly about this data.

We are the processor (service provider) of Submitter data. When a Submitter uploads files or types their details into an Organizer’s form, the Organizer is the controller of that information and we are their processor: we handle it only to run their collection, on their instructions. The Organizer decides what their form asks for, who is invited, what emails go out, and who sees the results. We never use Submitter Content for our own marketing, advertising, or profiling, and we never sell it.

What this means if you are a Submitter: if you want your information accessed, corrected, or deleted, the fastest path is the Organizer who invited you — they control that data and have in-app tools to honour your request. You can also contact us at hello@submitto.io: we will pass your request to the Organizer, help them honour it, and honour any rights the law gives you against us directly.

A note for Organizers: you are responsible for having a lawful basis to collect what your form asks for and to email your Submitters. The Terms of Service and the DPA set out this split in detail, including a hard ban on using Submitto to collect certain high-risk categories of data (health or medical records, government-issued ID numbers, payment-card numbers, biometric data, and government-classified or export-controlled material).

3. The information we handle

The tables below are a complete plain-language inventory, split by these two roles.

3.1 Organizer and account information (we are the controller)

WhatWhat it includesWhy we have it
Account detailsName, email address, company name, and your password (stored only as a one-way hash — we cannot see it)Creating and securing your account
Consent recordWhich version of the Terms and this policy you agreed to, and whenProving what you agreed to
Two-factor authentication (MFA)Your authenticator-app secret (encrypted at rest), enrolment date, and one-time recovery codes (stored only as hashes)Optional extra sign-in security (required for our own staff admin accounts)
Sign-in recordsSession records (we store only a fingerprint of the session cookie, never the cookie value), a short-lived MFA step record, password-reset and email-verification links (stored only as fingerprints), and a rough “last seen” timestampKeeping you signed in and letting you recover access
Co-manager listThe email addresses of up to 2 people an Organizer invites to co-manage an EventGranting shared access to an Event
Purchase recordsPaddle transaction ID, amount, currency, what was bought, and completion/refund timestamps — never card numbers or payment details (see §7)Fulfilling and accounting for purchases
Voucher recordsAdmin-issued free-Event codes, including the email address the voucher was issued toGranting and tracking complimentary Events
FeedbackYour message, the page you were on, your browser type, a snapshot of your email address, and — if you use the feedback button, in the app or on the read-only viewer — a screenshot of your current browser viewport, captured when you open it, whether or not you have an accountInvestigating bugs and improving the product
Beta-program recordsApplications from our beta period (name, email, company, message) and the related invitation listsHistorical record of beta access

3.2 Submitter information we handle for Organizers (we are the processor)

WhatWhat it includesWhy it exists
Roster entriesThe details the Organizer’s form asks for — typically first name, last name, email address, and a title — plus any custom fields the Organizer adds (custom fields can include phone numbers, URLs, or anything else the Organizer chooses to ask)Tracking who is expected to submit what
Uploaded filesThe files themselves, the original filename you chose, and a renamed copy of the filename built from your form answers — filenames can therefore contain personal details such as your name or companyThe core of the service: collecting files for the Organizer
File previewsFor PDFs and images, a small preview image of the first page, generated by us with all hidden metadata strippedLetting the Organizer preview files without opening them
Unmatched uploadsUploads that didn’t perfectly match a roster entry, held (with the details you typed) for the Organizer to sort outMaking sure no submission is silently lost
Seat-meter recordsOne record per distinct person who has submitted to an Event, containing the submitted email address (or, where no email was given, the submitted name, title, and custom-field answers)Billing integrity. Plainly: seats count people who have submitted; an Organizer removing someone from the roster does not free their seat. This is deliberate, to prevent seat-limit abuse
Email logsFor every email sent through an Event: the recipient address, subject, the full text of the message, and its delivery statusShowing the Organizer what was sent to whom, and proving it
File flagsProblem reports raised on the read-only viewer (a note, plus the reporter’s name and email if they choose to give them)Letting AV techs and venues report file problems
In-progress uploadsA short-lived record of an upload that has started but not finished (removed by a daily cleanup, normally within a day, if abandoned)Making direct-to-storage uploads safe

Two points to note:

  • Custom form fields are the Organizer’s choice. We do not require any sensitive field, and the Terms of Service ban Organizers from collecting the high-risk categories listed in §2. If you are unsure why a form asks for something, ask the Organizer.
  • The seat-meter record is kept for our own billing purpose, even though it contains Submitter identifiers, and it is stored in readable form (not hashed). It is deleted when the Event is deleted.

3.3 Operational records about everyone (we are the controller)

WhatWhat it includesWhy we have it
Audit logA security ledger of important actions — sign-ins (including failed attempts, with whatever email address was typed), MFA steps, file downloads, co-manager changes, deletions, blocked infected uploads, and billing events — each with the IP address involvedInvestigating security incidents and account misuse; this log deliberately survives account and Event deletion, and each entry is automatically deleted 24 months after creation (§9)
Rate-limit countersShort-lived counters keyed to your IP address (and, for some sign-in protections, an email address), counting recent requestsThrottling abuse (login floods, spam submissions); deleted within a day or two of the window closing
Bot-challenge dataOn signup, on sign-in after repeated failures, and on public upload pages, the Cloudflare Turnstile widget runs in your browser (Cloudflare sees browser signals), and we forward your IP address to Cloudflare to verify the challengeBlocking bots without passwords or accounts
Error telemetryWhen something breaks, technical error reports (stack traces and internal record IDs) go to Sentry, our error-monitoring provider. We have configured it not to receive IP addresses, cookies, or session data, and we use no session replay. One known exception: if recording an email bounce fails, the error report can include the affected recipient’s email addressFinding and fixing bugs
Email delivery eventsBounce and complaint notices from our email provider (recipient address + subject line)Not re-mailing dead or hostile addresses
Suppression and opt-out listsEmail addresses that have bounced/complained (suppression) or clicked unsubscribe (opt-out)Making sure “stop emailing me” keeps working — see §5
Breached-password checkWhen you set a password, we check it against the Have I Been Pwned breach database using a privacy-preserving method: only the first 5 characters of a cryptographic fingerprint ever leave our server — never your password, never your identityBlocking known-breached passwords

3.4 Marketing-site visitors (we are the controller)

The marketing site (submitto.io) has no forms and collects nothing directly — the only contact option is an email link that opens your own mail program, and its buttons link to the app. It runs two analytics tools:

  • Google Analytics 4 (GA4): page views plus one custom event when you click a “Create Account” button linking to the app (recording the button text, the link, and the page you were on). GA4 sets cookies in your browser (see §6).
  • Vercel Web Analytics: aggregate page-view analytics which Vercel describes as cookie-free and anonymized.

3.5 What we do NOT collect or do

  • No analytics or tracking of any kind inside the app — no trackers, no advertising pixels, no session recording. (Usage statistics we show ourselves are computed from our own database, in aggregate.)
  • No card numbers or payment details, ever — Paddle hosts the checkout (§7).
  • No precise location, no advertising identifiers, no biometric data.
  • No open- or click-tracking in the emails we send — no tracking pixels.
  • We never sell personal information, and we never use it for third-party advertising.
  • No automated decision-making with legal or similarly significant effects, and no profiling.

4. Why we use information (purposes and legal bases)

Where GDPR or UK GDPR applies, the law requires us to name a legal basis for each purpose. In Canada, the same purposes are ones a reasonable person would consider appropriate, and rest on your express or implied consent; where consent is the basis, you can withdraw it (§14).

PurposeInformation involvedLegal basis (GDPR/UK GDPR)
Running the service for Organizers: accounts, Events, dashboards, downloadsAccount and Event dataContract
Handling Submitter Content on an Organizer’s behalfSubmitter data (§3.2)Processed on the Organizer’s documented instructions; the Organizer must hold its own lawful basis
Sending email: upload confirmations, invitations and reminders on an Organizer’s behalf, account noticesNames, email addresses, message contentContract / the Organizer’s instructions; consent where required — the Organizer is responsible for consent to their commercial mail (§5)
Security: sign-in protection, bot challenges, rate limiting, audit logging, malware scanning, breached-password screeningOperational data (§3.3), files being scannedLegitimate interests (keeping the service and the data in it safe)
Billing: seat metering, purchase and refund records, tax/financial recordsSeat-meter records, purchase recordsContract; legitimate interests (billing integrity); legal obligation (tax and accounting records)
Fixing errors and improving reliabilityError telemetry, feedback (including screenshots)Legitimate interests
Marketing-site analytics (submitto.io only)GA4 / Vercel Analytics data (§3.4, §6)Legitimate interests — see the cookie-consent note in §6
Legal compliance: lawful requests, breach notification, record-keepingAs requiredLegal obligation

5. Email we send — and how to stop it

All email from Submitto — including invitations and reminders an Organizer composes — is sent from our own address (do-not-reply@submitto.io), on the Organizer’s behalf. It is visibly Submitto-branded, and it never comes from the Organizer’s own address.

  • Commercial mail (invitations, reminders, and other Organizer-composed messages to Submitters) always carries an unsubscribe link, a one-click unsubscribe that mail programs like Gmail can trigger natively, and our sender name and legal identification.
  • Unsubscribing is platform-wide: one unsubscribe stops commercial mail to your address from every Organizer and every Event on Submitto, and it is checked both when mail is queued and again when it is sent. There is no way to re-subscribe an address — the choice is permanent.
  • Transactional mail is not affected by unsubscribing — messages you need, such as a confirmation that your upload was received, password resets, email verification, and a warning before your Event is permanently deleted, may still be sent.
  • Suppression: addresses that hard-bounce or mark us as spam are automatically added to a suppression list and are never mailed again, by any Organizer.
  • The suppression and opt-out lists survive account and Event deletion by design — that’s how “stop emailing me” keeps working (§10).
  • We do no open- or click-tracking on any email.

Organizers, not Submitto, choose who receives their invitations and reminders. Under our Terms of Service, the Organizer warrants that they have the consent or other lawful basis required (for example under CASL, Canada’s anti-spam law) to email the people on their roster. We supply the identification footer and the unsubscribe machinery on every commercial message.

6. Cookies

The app (app.submitto.io)

The app sets exactly two cookies, both first-party and both strictly necessary:

CookieWhat it doesHow long it lasts
submitto_sessionKeeps you signed in7 days — or 30 days if you tick “remember me”
submitto_mfaCarries the middle step of a two-factor sign-in10 minutes

Both are httpOnly and secure (not readable by page scripts, sent only over HTTPS). The app sets no analytics, advertising, or tracking cookies of any kind.

Two embedded third-party tools may set their own cookies, under their own policies:

  • Cloudflare Turnstile (the bot challenge on signup, on sign-in after repeated failures, and on public upload pages) loads from challenges.cloudflare.com.
  • Paddle’s checkout overlay (only when an Organizer opens the checkout) loads from Paddle’s domains.

The marketing site (submitto.io)

The site’s own code sets no cookies. Google Analytics 4, however, sets cookies when the site loads — in standard deployments _ga and a _ga_…cookie, lasting about two years per Google’s documentation. Vercel Web Analytics is described by Vercel as cookie-free.

There is currently no cookie-consent banner on the marketing site; GA4 cookies are set on the first page view.

7. Who we share information with

We never sell personal information. We share it only in these ways:

  1. With the Organizer who collected it. Submitter Content goes to the Organizer of the Event it was submitted to — that is the product working as described. Organizers can also share a read-only Viewer link to a sanitized view of an Event (Submitter email addresses, original filenames, and unmatched uploads are all stripped from that view). A Viewer link works until the Organizer regenerates it; it does not expire on its own.
  2. With the service providers (“subprocessors”) that run Submitto, each bound by contract to process data only to provide their service to us. In summary: Vercel (hosting), Neon (database), Cloudflare (file storage and bot protection), Resend (email delivery), Sophos (malware scanning), and Sentry (error monitoring); plus, on the marketing site only, Google (GA4) and Vercel (analytics). Paddle, our merchant of record, is covered separately below — it handles Organizer billing data only and is not a subprocessor for Submitter data. The full, current list — each provider’s role, the data it touches, and where it processes — is available on request at hello@submitto.io. We update that list before adding or replacing a provider.
  3. Paddle, for purchases. Purchases are processed by Paddle, our merchant of record — Paddle is the seller of the transaction, hosts the checkout, handles payment details (we never see card numbers), and calculates and remits applicable sales taxes. You enter your payment and billing details directly with Paddle; we receive and store only transaction metadata (transaction ID, amount, currency, status).
  4. Malware scanning. Uploaded files are scanned by SophosLabs Intelix: we send a cryptographic fingerprint of every scanned file, and for files the scanner has not seen before, the full file content together with its original filename, to Sophos’s United States service for analysis. Scanning is best-effort, not a guarantee (§11).
  5. In a corporate transaction (merger, acquisition, or sale of assets) — with notice to you, and with this policy continuing to apply to your data.
  6. When the law requires it — in response to valid legal demands. We push back on demands that are overbroad.

We also use Have I Been Pwned’s breached-password service as described in §3.3; because only a partial fingerprint prefix is ever transmitted, no personal information reaches them.

8. Where information goes (international transfers)

We are a Canadian company. Our service providers process data primarily in the United States (malware scanning in particular runs on a US service — no Canadian region exists for it). Exact processing locations per provider are on the subprocessor list, available on request at hello@submitto.io. Wherever data is processed, this policy and our contracts follow it. While your information is in another jurisdiction, it is subject to the laws of that jurisdiction and may be accessible to its courts, law enforcement, and national-security authorities under those laws.

  • From the EU/EEA: Canada holds a European Commission adequacy decision (renewed January 2024) for data handled under PIPEDA, so transfers to us are permitted. For onward transfers to US providers, our DPA incorporates the EU Standard Contractual Clauses (EU-approved contract terms that protect personal data sent outside Europe), plus provider-level safeguards such as Data Privacy Framework certifications (a US program the EU recognizes as adequate protection) where they exist.
  • From the UK: the UK has retained Canada’s adequacy; onward US transfers rely on the UK Addendum/IDTA mechanisms incorporated through the DPA.

You can ask us for a copy of the safeguards that apply to a given transfer at hello@submitto.io.

9. How long we keep information

The core of our retention story is the Event lifecycle, which is automatic:

  1. After an Event’s end date passes, the Event is automatically archived — hidden from the main list, all data kept.
  2. About 27 days after archiving, we email the Organizer a warning: the Event will be permanently deleted in 3 days, including all of its files and contact information.
  3. About 30 days after archiving, the Event and its data are permanently deleted: the files in storage, the roster, email logs, and seat-meter records. Manually archiving an Event starts the same 30-day clock; unarchiving stops it (and a re-archived Event gets a fresh warning).

Deletion runs on a daily schedule, so “30 days” means “at least 30 days, normally within a day or two after that.”

DataHow long we keep it
An Event and its data (files, roster, email logs, seat-meter records, flags)Until the Organizer deletes it, or automatically ~30 days after archiving (see above)
Email logs (full message copies, §3.2)Message bodies are automatically removed 12 months after sending; the send record (recipient, subject, delivery status, time) stays until the Event is deleted
Audit log (security ledger with IP addresses)Each entry is automatically deleted 24 months after it was created
Organizer accountUntil you delete it — deletion is immediate (§10)
Purchase and voucher recordsRetained as tax and financial records after account/Event deletion
Suppression and email opt-out listsKept indefinitely, by design — deleting them would restart unwanted email (§5)
Feedback (including screenshots)No automatic deletion today; removed manually, or on request
Beta-program recordsNo automatic deletion; removed manually, or on request
Sign-in sessions7 days (30 with “remember me”); expired records purged daily
Password-reset links60 minutes
Email-verification links24 hours
Two-factor sign-in stepValid for 10 minutes; the record is deleted when used, and expired records are purged daily
Rate-limit counters (IP addresses)Deleted within a day or two of the counting window closing
Abandoned in-progress uploadsRemoved by the daily cleanup once the abandoned upload is about an hour old — within about a day
Database backupsDeleted database records can persist in encrypted backups for up to 7 days, then roll off. Deleted file content is not in backups — file deletion from storage is immediate and unrecoverable

The email-log and audit-log cleanups above are built and tested; their system switches are turned on in the same release that publishes this policy, so these numbers are true from day one.

When a file is deleted, the file itself — and any preview image we generated from it — is removed from storage immediately.

10. Deleting your account — and what survives

Organizers can delete an Event, an individual submission, an individual file, or their whole account at any time from inside the app. Account deletion is self-serve (under Account), requires your password, and takes effect immediately — there is no grace period or undo.

When you delete your account, we delete your account, your Events, and their files; Events you co-managed for someone else are not affected (they belong to their owner). Some records we must keep survive: billing records, audit and email logs, and unsubscribe/suppression lists. In plain terms:

  • Purchase records survive because they are tax and financial records.
  • The security audit log survives (including the email address and IP entries in it) because a security record that vanished with the account it concerns would be useless. Audit entries still age out on their normal schedule — each is deleted 24 months after it was created (§9).
  • “Email logs” here means entries that sit in someone else’s Event: deleting your account deletes your own Events’ email logs along with those Events, but mail sent to your address from another Organizer’s Event stays in that Organizer’s Event logs (with its message body removed 12 months after sending, per §9).
  • Suppression and opt-out entries survive by design — that’s how “stop emailing me” keeps working.
  • Feedback you sent us (including its email snapshot and any screenshot) is kept until removed manually or on request.

Deleted database records can also persist in encrypted backups for up to 7 days (§9).

Submitters do not have accounts, so there is nothing for a Submitter to self-delete; deletion requests route to the Organizer (who has in-app tools to delete a person or a file), or to us, and we will assist (§2, §14).

11. How we protect information

A summary of our safeguards — no system is perfect, and we do not claim these are:

  • Encryption in transit (HTTPS/TLS everywhere) and encryption at rest provided by our database and file-storage providers. Two-factor secrets and stored access-link tokens are additionally encrypted at the application level.
  • Passwords are stored only as strong one-way hashes (Argon2id) and are screened against known breaches at signup and on every change.
  • Two-factor authentication (authenticator app) is available to every account and mandatory for our own staff admin accounts.
  • Files are private. There are no public file URLs; uploads and downloads use signed, single-purpose URLs that expire within minutes, and downloads are forced to arrive as inert attachments. The app never opens or executes uploaded files; previews are server-generated images with metadata stripped.
  • Access control: an Event is visible only to its Organizer, the co-managers they invite (at most 2), and holders of a Viewer link the Organizer chooses to share — and the viewer sees a sanitized view (§7). Every file download is recorded in the audit log.
  • We scan uploads for malware and reject infected files before they are stored. Scanning is best-effort, not a guarantee — very large files and scanner outages can result in a file being stored unscanned.
  • Abuse throttling (rate limiting) and bot challenges protect sign-in and the public upload pages.
  • Security event logging (the audit log, §3.3) supports incident investigation.
  • An extensive automated test suite guards these protections against regression.

We do not currently hold formal security certifications (such as SOC 2 or ISO 27001), and we do not claim independent security audits.

12. Submitto is for adults (18+)

You must be at least 18 years old to create an account, and Submitters must also be at least 18 to upload. Organizers are responsible for ensuring the people they invite meet this requirement. We do not knowingly collect personal information from anyone under 18; if we learn that we hold it, we will delete it.

13. If something goes wrong (data breaches)

We keep a register of security incidents. If a breach creates a real risk of significant harm, we notify affected individuals and the Office of the Privacy Commissioner of Canada as soon as feasible, as PIPEDA requires. Where GDPR/UK GDPR applies to data we control, we notify the competent supervisory authority within the required timeframe. For Submitter data we process on an Organizer’s behalf, we notify the affected Organizer without undue delay so they can meet their own obligations — this duty is also written into the DPA. In every case we will tell you what happened, what data was involved, and what we are doing about it.

14. Your rights

14.1 Everyone, everywhere

Wherever you live, you can ask us to:

  • Access — tell you what personal information we hold about you and give you a copy. There is no one-click export in the app today; we compile access requests manually. (Organizers can view and edit their account details in the app and download their Event’s files file-by-file at any time.)
  • Correct — fix inaccurate information (Organizers: self-serve in the app).
  • Delete — Organizers: self-serve (§10); Submitters: through your Organizer or us (§2).
  • Withdraw consent — where consent is the basis for processing.
  • Stop email — unsubscribe from commercial email (§5).

How: email hello@submitto.io. If you are a Submitter, the fastest path is the Organizer who invited you — but you are always welcome to come to us, and we will assist either way. We verify identity before acting on a request, respond within 30 days (one month where GDPR applies), explain any refusal and how to challenge it, and will never penalize you for exercising a right.

14.2 Canada — PIPEDA and BC PIPA

We comply with the federal Personal Information Protection and Electronic Documents Act (PIPEDA) and British Columbia’s Personal Information Protection Act (PIPA), including their fair-information principles. You may access and correct your personal information and complain to us using the contacts in §16. If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca) or the Office of the Information and Privacy Commissioner for British Columbia (oipc.bc.ca).

14.3 Quebec — Law 25

If you are a Quebec resident, you additionally have the rights to withdraw consent, to request cessation of dissemination (de-indexing), and to data portability (a machine-readable copy you can take elsewhere), and you may complain to the Commission d’accès à l’information du Québec (cai.gouv.qc.ca). Confidentiality incidents presenting a risk of serious injury are reported to the CAI and to affected individuals. Our person in charge of the protection of personal information is identified in §16.

14.4 EEA and United Kingdom — GDPR / UK GDPR

For Organizer, account, and site-visitor data, the controller is Submitto Software Inc. (§16). For Submitter data, the controller is your Organizer and we are their processor under our DPA. The legal bases for each purpose are in §4. We do no automated decision-making with legal or similarly significant effects.

You have the rights of access (a copy of your data), rectification (correction), erasure (deletion), restriction of processing (pausing use of your data), data portability (a machine-readable copy you can take elsewhere), and objection (telling us to stop a use) under Articles 15–21, the right to withdraw consent at any time without affecting prior processing, and the right to lodge a complaint with your supervisory authority — your local EU data-protection authority, or in the UK the Information Commissioner’s Office (ico.org.uk). If you complain to us directly, we will acknowledge your complaint within 30 days and tell you the outcome.

We have not appointed a Data Protection Officer.

14.5 Other regions

We do not sell personal information or use it for targeted advertising, so there is nothing to opt out of under US state privacy laws; where such a law applies to you, we honour its access, correction, deletion, and appeal rights through the process in §14.1, and we act as a service provider/processor for Submitter data.

15. Changes to this policy

We will post changes here with an updated effective date. For material changes we will give Organizers advance notice — by email or a notice in the app — before they take effect. Signup records which version of this policy each account agreed to.

16. Contact, accountability, and complaints

Submitto Software Inc.
Email: hello@submitto.io

Our Privacy Officer is accountable for our compliance with this policy and receives access requests and complaints at the address above.

Complaining to us first is welcome but never required. The regulators for each region are:

  • Canada: Office of the Privacy Commissioner of Canada (priv.gc.ca)
  • British Columbia: Office of the Information and Privacy Commissioner for BC (oipc.bc.ca)
  • Quebec: Commission d’accès à l’information du Québec (cai.gouv.qc.ca)
  • EU/EEA: your local data-protection supervisory authority
  • UK: Information Commissioner’s Office (ico.org.uk)

Related documents: Terms of Service · Refund Policy: app.submitto.io/refunds · Data Processing Addendum, Subprocessor list and Submitter notice: available on request at hello@submitto.io.