Skip to content
myownsecure.space
  • Features
  • Privacy
  • Storage
  • How it works
  • Extend your account
  • FAQ
  • Contact
  • English
  • Español
  • Français
  • Italiano
Log in

Privacy Policy

Effective date: 1st September 2026 (v02)

This Privacy Policy explains how CONNEXT handles personal data in connection with myownsecure.space.

Our approach is to collect as little identity information as reasonably necessary to provide the service.

1. Who is responsible for your personal data?

The controller responsible for the processing described in this Privacy Policy is:

CONNEXT L.T.D.
str. Dunav no. 35
Sofia, p.c. 1000
Bulgaria

Privacy and general enquiries:

info@myownsecure.space

CONNEXT has not appointed a Data Protection Officer.

2. What this policy covers

This Privacy Policy applies to personal data processed through:

  • the myownsecure.space service;
  • the web-based interface;
  • supported mobile and desktop access;
  • synchronization functions;
  • chat and calling functions;
  • the informational website; and
  • support contacts and web forms.

It describes personal data processed by CONNEXT as the service provider.

3. You do not have to identify yourself to create a normal account

myownsecure.space does not require you to provide a real name, postal address, telephone number or other identity details as a condition of ordinary service use.

Your account starts with the user ID and initial password supplied on your coupon.

However, this does not mean that no personal data is processed.

Technical information such as IP addresses, session information and security logs may be processed automatically when you use an online service. The optional information described below may also become personal data if you choose to provide it.

4. Optional profile information

You may choose to provide:

  • email address;
  • full name;
  • status message;
  • profile picture.

These fields are optional.

You can use the service without completing them.

Email address

If you provide an email address, it may be used:

  • as an alternative login name instead of your coupon user ID;
  • for password reset;
  • for important service notices;
  • for notices concerning changes to legal terms where appropriate; and
  • to respond to support or privacy enquiries where you contact us by email.

Providing an email address is not required for ordinary use of the service.

If you do not provide an email address and lose your password, there is no manual password-recovery process.

5. Account and authentication data

To operate your account, the service processes information needed for authentication and account administration, including:

  • your coupon user ID;
  • authentication-related credential information;
  • session identifiers;
  • account status;
  • storage allocation;
  • service validity period;
  • account-extension information; and
  • security settings associated with the account.

If you enable two-factor authentication, information necessary to provide TOTP authentication and backup-code functionality is also processed.

6. User content

The service stores and processes content that you choose to place in your account, such as:

  • files;
  • documents;
  • photographs;
  • videos;
  • calendar information;
  • messages; and
  • other content you create, upload or synchronize.

User content may contain personal data about you or about other people, depending entirely on what you choose to store.

CONNEXT does not require you to place personal information in your files or other content.

Automated processing of user content takes place as technically necessary to store, deliver, synchronize and otherwise provide the functions you request.

CONNEXT does not analyze the contents of your files, documents, calendar, chats or calls for advertising, behavioral profiling or unrelated commercial purposes.

7. Chat and call information

To provide chat and calling functions, the system processes limited information needed for those functions.

This may include:

  • participants’ account identities;
  • conversation or room membership;
  • message timestamps;
  • call timestamps;
  • call participation;
  • call duration;
  • invite or room identifiers; and
  • relevant session information.

Where STUN/TURN or similar connection services are used to establish or support calls, technical connection information may also be processed, including:

  • IP addresses;
  • network ports;
  • session information;
  • timestamps; and
  • call-quality diagnostics.

This information is used to provide, secure and troubleshoot communication functionality.

Retention point to confirm before publication: persistent chat/call metadata that forms part of a user’s account should be mapped against the actual system deletion behavior. Technical chat/call event logs currently follow the technical-log rotation described in Section 12.

8. Staff access to user content

CONNEXT does not use ordinary staff access to inspect user content.

CONNEXT staff may technically access user content only where access is necessary for:

  1. security-incident response; or
  2. a valid legal or official request.

Any such access should be limited to what is necessary for that purpose.

This restriction does not prevent the automated technical processing required to provide the service.

It also does not prevent support staff from viewing information, screenshots or other material that you deliberately send to support as part of a support request.

9. Support information

You can contact support by email or through the available web form.

A support request may contain:

  • your email address or other contact information;
  • your user ID;
  • coupon information;
  • screenshots;
  • technical details;
  • a description of the problem; and
  • any other information you choose to provide.

Please avoid providing passwords, TOTP codes, backup codes or unnecessary personal information.

Support records are retained for 30 days after the support ticket is closed and are then deleted.

10. Why we process personal data

CONNEXT processes personal data only where there is an appropriate legal basis.

Providing the service

Account information, authentication information, user-requested profile features, storage functions, document functions, calendar functions, synchronization and communication information are processed where necessary to provide the service you requested and perform the service contract.

The proposed legal basis is Article 6(1)(b) GDPR — performance of a contract or steps requested before entering a contract.

This also covers optional functions that you actively choose to use, such as providing an email address for login/password reset or adding optional profile information where the processing is necessary to provide that feature.

Security and protection of the service

Technical and security data may be processed to:

  • secure accounts;
  • identify login failures or suspicious activity;
  • maintain technical integrity;
  • investigate security incidents; and
  • protect the service and its users.

The proposed legal basis is Article 6(1)(f) GDPR — legitimate interests, namely CONNEXT’s legitimate interest in operating and protecting a secure service.

Where processing is specifically required by applicable law, Article 6(1)(c) GDPR — compliance with a legal obligation may apply instead.

Legal and official requests

Where CONNEXT is legally required to process, preserve or disclose information in response to a valid request or order from a competent public authority, the proposed legal basis is Article 6(1)(c) GDPR.

Support and enquiries

Information submitted in connection with support may be processed where necessary to provide support relating to your service contract.

General enquiries may also be processed on the basis of CONNEXT’s legitimate interest in responding to correspondence and operating the service.

The GDPR requires controllers to identify the purposes and legal bases for processing and to explain relevant retention, recipients and rights to data subjects.

11. Cookies and browser storage

myownsecure.space does not use advertising or analytics cookies under the current service configuration.

The service uses only cookies or browser storage associated with service functionality.

Session cookie

A session cookie is used to maintain your authenticated session and provide the requested service.

It is a session-based cookie.

Session-encryption cookie

A session-encryption cookie is used as part of the service’s session functionality.

It is used for service operation rather than advertising or analytics.

“Remember me”

The login page offers an optional “remember me” function.

It is:

  • unchecked by default;
  • activated only if you choose it; and
  • stored for 15 days.

Language preference

The informational website uses a language-preference cookie named:

mos_lang

Its purpose is to remember your chosen website language.

It has a lifetime of one year.

CSRF protection

The service uses a per-session token for CSRF protection.

This token is not stored as a cookie.

Browser localStorage

The login page uses a limited browser localStorage entry to remember which login method you used last.

This information does not contain sensitive data and is used only to make the next login more convenient.

12. Technical and security logs

The service creates technical and security logs necessary for operation and security.

Depending on the event, these logs may include:

  • IP addresses;
  • browser and device information;
  • login attempts;
  • successful logins;
  • failed logins;
  • session identifiers;
  • administrative actions;
  • file-access events;
  • file-sharing events;
  • chat and call events;
  • security alerts; and
  • timestamps.

IP address and browser/device information may be recorded automatically as part of system log entries.

Current log-retention model

Technical and security log records are retained for 30 days.

After the 30-day retention period, the relevant log records are deleted.

This retention period applies to technical and security information such as IP addresses, browser and device information, login events, session identifiers, administrative actions, file-access and sharing events, chat and call event logs, security alerts, and associated timestamps.

The logs are retained for the limited purposes of operating and securing the service, investigating technical or security incidents, and protecting the service against unauthorized or abusive activity.

13. Administrative actions and access logs

Where administrative actions occur, the service may keep a record of those actions for security and accountability purposes.

Administrative access to user content itself is restricted as explained in Section 8.

CONNEXT does not use administrative access for general inspection, advertising profiling or analysis of users’ stored content.

14. Recipients of personal data

CONNEXT does not currently use third-party subprocessors or external hosting providers for the processing described in this policy.

Access within CONNEXT is limited according to operational need.

Personal data may be disclosed to a government, police body or other competent public authority where CONNEXT is required or lawfully permitted to respond to a valid official request.

CONNEXT staff may process support information that you voluntarily submit.

15. EU-based processing and international transfers

The service’s servers are based in the European Union.

CONNEXT does not currently transfer personal data outside the EU/EEA as part of the service described in this Privacy Policy.

16. How long we keep data

We do not keep every category of data for the same period.

Account and optional profile information

Account information and optional profile information are generally retained while the account remains active, unless you remove optional information earlier using available account functions.

User files and other content

Content remains in the account until:

  • you delete it;
  • the account expires and the grace period ends; or
  • another lawful deletion event applies.

Recycle bin / trash

When you delete user content, it is moved to the recycle bin or trash for 30 days.

You can delete content from the recycle bin or trash manually before that period ends.

There are no separate provider backups of user content.

Expired accounts

When the prepaid service period expires, the account enters a one-month read-only grace period.

If you renew during that period, normal access is restored and the account continues.

If you do not renew, the account and associated user data are deleted immediately after the grace period.

Support records

Support records are deleted 30 days after the ticket is closed.

Technical logs

Technical logs are currently governed by the size-based rotation described in Section 12 rather than a fixed age-based period.

Technical records after account termination

When an account is terminated or deleted, CONNEXT does not create a separate archive of technical records relating to that account.

Technical and security log entries that already exist at the time of account termination may remain in the logging system for the remainder of their normal 30-day retention period. They are then deleted automatically in accordance with the standard log-retention policy.

Account termination does not extend the retention period for those records.

17. No provider backups

CONNEXT does not maintain a separate backup copy of user data.

This means that when data have been permanently removed from active storage and any applicable recycle bin or trash, they cannot be restored from a provider backup.

Users should keep their own independent backup of important information.

18. Your data-protection rights

Subject to the conditions and exceptions in applicable data-protection law, you may have the right to:

  • obtain information about how your personal data is processed;
  • access personal data concerning you;
  • correct inaccurate personal data;
  • complete incomplete personal data;
  • request deletion of personal data;
  • request restriction of processing;
  • object to processing based on legitimate interests;
  • receive qualifying personal data in a portable format where the legal requirements for portability apply; and
  • lodge a complaint with a competent data-protection supervisory authority.

These rights arise under the GDPR, including Articles 15–21.

Using account controls

Because myownsecure.space is designed not to require verified identity information, the safest and most reliable way to access, correct, export or delete account data is generally through the functions available while you are logged in to your account.

Requests by email

Questions about privacy can be sent to:

info@myownsecure.space

However, CONNEXT does not operate a manual identity-verification or manual account-recovery system.

This is important for privacy requests. CONNEXT cannot disclose, alter or delete account information merely because someone sends an email claiming to own an account where CONNEXT cannot reliably establish that person’s control of the account.

Where CONNEXT cannot identify the person making a request and cannot safely connect that person to the relevant data, some rights may not be capable of being fulfilled through an administrative action unless the requester can provide information that makes identification possible.

GDPR Article 11 specifically addresses situations in which the purposes of processing do not require a controller to identify a data subject and provides rules for rights requests where the controller cannot identify the person.

CONNEXT will not collect additional identity information solely for the purpose of creating an identification system unless this becomes necessary under applicable law or the service model changes.

19. Password and account recovery privacy

An email address is optional.

If you choose not to provide one, you should understand that CONNEXT cannot manually recover the account if you lose your password.

If you enable two-factor authentication, you should also retain your TOTP access and backup codes securely.

This design reduces the amount of identity information CONNEXT needs to hold, but it also places greater responsibility on you to protect your credentials.

20. Security

CONNEXT uses technical and organizational measures intended to protect the service and personal data against unauthorized access, loss, misuse or alteration.

Security measures include account authentication, technical logging and optional two-factor authentication.

No online system can be described as completely risk-free. This Privacy Policy therefore does not promise absolute security.

Users also play an important role by:

  • choosing a strong password;
  • keeping passwords private;
  • enabling two-factor authentication where appropriate;
  • protecting backup codes; and
  • keeping independent backups of important data.

The GDPR requires controllers to use appropriate technical and organizational security measures taking account of the relevant risks.

21. Children and age

myownsecure.space does not impose a separate service-specific age limit and does not require users to submit their date of birth.

However, rules concerning a minor’s ability to enter into a contract and special rules concerning children’s personal data may apply under national and EU law.

Where applicable law requires action by a parent, guardian or other legal representative, those requirements remain applicable.

22. No advertising analysis or profiling

CONNEXT does not analyze user files, documents, calendars, chats or calls for advertising or behavioral profiling.

CONNEXT does not use the technical logs described in this policy to build advertising profiles.

This does not prevent the limited processing needed to:

  • provide requested functions;
  • maintain the service;
  • secure accounts;
  • diagnose technical problems;
  • respond to security incidents; or
  • comply with applicable legal obligations.

23. Changes to this Privacy Policy

This Privacy Policy may be updated if:

  • the service changes;
  • data-processing practices change;
  • security or operational practices change; or
  • legal requirements change.

The current version will be published on the myownsecure.space website.

Where an update is material and additional notice is appropriate or legally required, CONNEXT may also provide an in-service notice or send information to the optional email address associated with the account.

24. Language

The original and prevailing version of this Privacy Policy is English.

Translations may later be made available in Spanish, French and Italian.

If there is a difference between a translation and the English version, the English version prevails to the extent permitted by applicable law.

Mandatory transparency or language requirements under applicable law remain unaffected.

25. Contact

For privacy questions or enquiries about this policy:

info@myownsecure.space

Controller:

CONNEXT L.T.D.
str. Dunav no. 35
Sofia, p.c. 1000
Bulgaria

Plain-language summary

  • You do not need to give us your real name or email address just to use the service.
  • Your email, full name, status message and profile picture are optional.
  • If you provide an email, you can use it to log in and reset your password.
  • Without an email, there is no manual password-recovery route.
  • Technical information such as IP addresses, login events and device/browser information is processed for operation and security.
  • Limited metadata is processed to provide chat and calls.
  • CONNEXT does not analyze your stored content for advertising or behavioral profiling.
  • Staff can technically access user content only for security-incident response or a valid legal request.
  • Support records are kept for 30 days after a ticket closes.
  • Deleted content stays in the trash for 30 days unless you remove it sooner.
  • CONNEXT does not keep separate backups of your user data.
  • Servers are based in the EU and no personal-data transfers outside the EU/EEA are currently used.
  • Your GDPR rights remain available, but because CONNEXT does not maintain a verified identity system, many account-level actions are safest through your logged-in account.
  • The full Privacy Policy above is the legally relevant text; this summary is only an explanation.

← Back to home

myownsecure.space

Your digital private space and communication.

Site

  • Features
  • Storage
  • How it works
  • Extend your account
  • FAQ

Legal

  • Terms & Conditions
  • Privacy Policy

Contact

  • info@myownsecure.space

© 2026 myownsecure.space. All rights reserved.