Privacy Policy
Last updated: 27 July 2026
1. Introduction
OVERLORD Team LTD ("OVERLORD," "we," "us," or "our") explains in this Privacy Policy how we collect, use, store, and share personal data when you use our marketing website, client portal (dashboard), and related professional services. If you do not agree, please do not use those services.
2. Who is responsible
Controller: OVERLORD Team LTD, United Kingdom.
Email: info@overlord.team
Website: https://overlord.team
3. Data we collect
Account and profile data
When you register or manage your profile we may process: name, email address, password (stored as a secure hash), optional company name, profile photo / avatar URL, email verification status, and optional authenticator (TOTP) / backup-code settings for two-factor authentication.
Authentication providers
If you sign in with Google or GitHub (where enabled), we receive identifiers and profile fields those providers share (typically name, email, and profile image) to create or link your account.
Portal / project data
To run the client portal we process: service requests and briefs; project (assignment) records, statuses, milestones, and tasks; comments; support tickets and messages; file attachments you or our team upload; billing notes, paid/outstanding flags, billing event history, and generated invoice summaries; in-app notifications; and optional web-push subscription endpoints if you enable browser notifications.
Contact and marketing-site data
Contact form submissions may include name, email, subject, and message. We may use Cloudflare Turnstile to reduce spam/bots. Messages may be forwarded to our internal notification channels (for example Telegram) so we can respond.
Technical and usage data
- IP address, browser/user-agent, and approximate location derived from IP
- Device and session information needed for security and sign-in
- Server logs, error diagnostics, and security audit events
- Website analytics via Google Analytics (measurement ID configured on the site)
Engagement / work product
When you hire us, we may process project materials you provide (code, configs, credentials you choose to share, business information) solely to deliver the engagement under confidentiality obligations.
4. Why we process data (purposes & bases)
- Contract / pre-contract: create accounts, operate the portal, deliver projects, tickets, and billing records, and respond to service requests.
- Legitimate interests: secure the platform, prevent abuse, improve the site and portal, and communicate about active work.
- Consent: optional marketing messages, non-essential cookies / analytics where consent is required, and optional push notifications.
- Legal obligation: tax, accounting, and regulatory requirements where applicable.
5. Cookies and similar technologies
- Essential: session / authentication cookies for the portal (Better Auth), CSRF/security, and load balancing.
- Security: Cloudflare Turnstile tokens for forms and auth flows.
- Analytics: Google Analytics cookies/scripts to understand site traffic (you can block these via browser settings or consent tools where offered).
Disabling essential cookies will prevent sign-in and portal use.
6. Sharing and processors
We do not sell personal data. We share data only as needed with:
- Hosting & database: infrastructure providers that host the application and MariaDB data (currently including Hostinger environments).
- Email delivery: SMTP providers used to send password resets, verification, and transactional mail.
- Cloudflare: Turnstile bot protection and, where used, CDN/security.
- Google / GitHub: if you choose OAuth sign-in.
- Google Analytics: website usage measurement.
- Telegram: if configured, to deliver contact-form or operational alerts to our team.
- Push services: browser push infrastructure when you subscribe (endpoint keys stored for your account).
- Payoneer: hosted Request a Payment pages when a client pays an outstanding bill (name, email, company, and amount as needed to complete the request). We do not store card numbers.
- Professional advisors / law enforcement: when legally required or to protect rights and safety.
Payments for professional work may be collected through Payoneer Request a Payment. The client completes payment on Payoneer’s hosted page. We do not store payment card numbers. Payoneer processes the transaction under its own terms and privacy policy.
7. International transfers
Servers and processors may be located outside your country (including outside the UK/EEA). Where required, we use appropriate safeguards such as standard contractual clauses or provider terms that offer equivalent protection.
8. Retention
- Account data: for the life of the account, then deleted or anonymised within a reasonable period after closure (unless law requires longer).
- Projects, tickets, attachments, billing history: for the engagement and a reasonable period afterward for support, disputes, and accounting.
- Contact-form messages: as needed to respond, then routine deletion.
- Security logs / audit events: for security and investigation windows.
9. Security
We apply measures appropriate to a client portal, including TLS in transit, hashed passwords, session controls, role-based access (client vs admin), optional 2FA, bot checks on public forms, and operational logging. No method is perfectly secure; please use a strong unique password and enable 2FA when available.
10. Your rights
Depending on applicable law (including UK GDPR / EU GDPR), you may have rights to access, rectify, erase, restrict or object to processing, data portability, and to withdraw consent. You may also complain to your supervisory authority (in the UK, the ICO).
Portal users can update many profile fields directly. For other requests email info@overlord.team. We aim to respond within 30 days.
11. Children
The Services are directed to businesses and adults. We do not knowingly collect data from children under 18. Contact us if you believe we have done so.
12. Third-party links
Links to Trustpilot, social networks, OAuth providers, or other sites are governed by those parties' policies, not ours.
13. Changes
We may update this Policy by posting a new version with a revised "Last updated" date. Material changes affecting portal users may also be notified by email or in-product notice when practical.
14. Contact
Your acknowledgement
By using our website or client portal, you acknowledge this Privacy Policy. See also our Terms of Service.
Privacy questions? Contact us
