Last updated: 9 October 2026
This policy explains how Reykjanes Tech ehf. ("we", "us") handles personal data when you visit pim.is, contact us, or use the PIM application, its API and the PIM kiosk app (together, "PIM").
1. Who we are
Reykjanes Tech ehf. is a company registered in Iceland and is the controller of the personal data described in this policy. You can reach us about privacy at security@rnt.is. As Iceland is part of the European Economic Area, we follow the General Data Protection Regulation (GDPR) as implemented by Icelandic Act No. 90/2018.
2. Data our customers put into PIM
Our customers use PIM to manage their product information. If that content includes personal data, we process it on the customer's behalf and on their instructions, as a processor. The customer is the controller of that data. If you have a question about such data, please contact the business that uses PIM. Customers can request a data processing agreement from us at security@rnt.is.
3. What we collect
- Account data: your name, email address, password (stored only in hashed form by our sign-in provider), profile picture if you add one, and the team accounts you belong to.
- Security and usage records: sign-in events, two-factor authentication settings, and records of API credential use and integration syncs, which we keep to secure the service and help you troubleshoot.
- Billing data: your plan, invoices and billing contact. Payments are handled by our payment provider; we never see or store full card numbers.
- Messages you send us: the name, email address and message you submit through our contact form or by email.
- Technical data: IP address, browser and device information, and request logs created by our hosting providers when you use pim.is or PIM.
- Kiosk devices: a device identifier, its pairing code, when it was last online and the location name you give it. This is information about the device, not about the people using it.
- Cookies: see our Cookie Policy. We do not currently use analytics or advertising cookies.
4. Why we use it, and on what basis
- To provide PIM, including your account, teams, integrations, kiosks and support: necessary for our contract with you or your organisation.
- To bill for subscriptions and keep accounting records: contract, and our legal obligations under Icelandic bookkeeping law.
- To keep PIM secure, prevent misuse and fix problems: our legitimate interest in running a safe and reliable service.
- To answer your messages and send service information, such as changes to PIM or these terms: our legitimate interest in communicating with customers and prospects.
- Analytics and marketing, if we add them: only with your consent, which you can withdraw at any time in Cookie settings.
We do not sell personal data, and we do not use it for profiling.
5. Who we share it with
We use the following service providers to run PIM. They process personal data only on our behalf and under data processing terms:
- Supabase: Database, sign-in and file storage, hosted in the EU.
- Vercel: Hosting of pim.is and the PIM web app.
- Railway: Hosting of the PIM API and background processing.
- Our payment provider: Checkout, payments, invoices and sales tax for paid plans.
- Our email delivery provider: Sign-in, invitation and notification emails, and replies to messages you send us.
- Google and Microsoft: Only if you choose to sign in with your Google or Microsoft account.
Systems you connect. When you connect an integration (such as DK, WooCommerce, Medusa or Plytix), an AI tool or any other software through the PIM API, we send data to it on your instruction. Your use of those services is governed by their own terms and privacy policies.
We may also disclose information if the law requires it, or to protect our rights, our users or the public.
6. Where your data is stored
Your PIM data is stored in the European Union. Some of our service providers are based in the United States and may access limited data from outside the EEA, for example for support or billing. Where that happens, the transfer is protected by the EU Standard Contractual Clauses or the EU–US Data Privacy Framework.
7. How long we keep it
- Account and workspace data: for as long as your account is active. You can delete your personal account and team accounts in the app, and the data is then deleted, apart from backups, which expire on a rolling basis.
- Billing records: for seven years, as required by Icelandic bookkeeping law.
- Messages you send us: for as long as needed to handle your request and any follow-up.
- Technical logs: for a limited period set by our hosting providers, used for security and troubleshooting.
8. How we protect it
Data is encrypted in transit. Access to each account's data is enforced at the database level. Integration credentials are stored encrypted, API keys are stored hashed, and you can turn on two-factor authentication for your account.
9. Your rights
You have the right to access your personal data, have it corrected or deleted, restrict or object to its processing, receive it in a portable format, and withdraw consent at any time. To use these rights, email security@rnt.is. We reply within one month.
You can also complain to the Icelandic Data Protection Authority, Persónuvernd, or to the data protection authority where you live.
10. Children
PIM is a service for businesses and is not intended for children. We don't knowingly collect personal data from anyone under 16.
11. Changes to this policy
We will update this page when our practices change and change the date at the top. If a change is significant, we will also let customers know by email or in the app.
12. Contact
Reykjanes Tech ehf., Iceland. security@rnt.is