Legal Document

Privacy Policy

Last updated: March 23, 2026 • Effective immediately for all users

Duplica (“we,” “us,” or “our”) is committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform at https://duplica.com.

1Information We Collect

1.1 Information You Provide Directly

  • Account registration data: full name, email address, phone number, country, username, and password
  • Profile information you optionally provide
  • Payment and billing information processed securely via PayPal (we do not store full card numbers)
  • Communications you send us via email, support, or WhatsApp
  • Lead form submissions from referral pages

1.2 Information Collected Automatically

  • Device information (browser type, operating system, device type)
  • Referral link click data for performance analytics
  • Login timestamps and activity logs
  • IP address (anonymized after 30 days)
  • Training module progress and challenge completion data

2How We Use Your Information

We use your personal information for the following legitimate purposes:

Account Management

To create, maintain, and secure your account on the platform

Transactional Emails

Welcome emails, subscription renewals, activation alerts, and team notifications

Analytics & Reporting

To generate referral performance stats visible to you in your dashboard

Platform Security

Fraud prevention, abuse detection, and maintaining platform integrity

Team Management

To connect members with their referrers and enable the team hierarchy

Customer Support

To respond to your inquiries, resolve disputes, and provide assistance

3Data Sharing and Disclosure

We do not sell your personal data.

We never sell, rent, or trade your personal information to third parties for their marketing purposes. Period.

We may share your information only in these limited circumstances:

Your Referrer

Your username, name, plan, and country may be visible to the person who referred you, for team management purposes.

Partner Companies

If you select a partner company (YES Global, Renata Health World, Dynace Global), your intent to activate a package may be shared with the relevant partner administrator for verification purposes only.

Service Providers

We use Supabase (database hosting), Resend (email delivery), and PayPal (payments). These providers process data on our behalf under strict data processing agreements.

Legal Requirements

We may disclose information when required by law, court order, or government request, or when necessary to protect our rights, your safety, or the safety of others.

Business Transfer

In the event of a merger, acquisition, or sale of company assets, user data may be transferred as part of the transaction. We will notify you via email prior to any such transfer.

4Data Retention

We retain your personal information for as long as your account is active or as needed to provide you services. Specifically:

Data TypeRetention Period
Account profile dataDuration of account + 2 years after deletion request
Payment & billing records7 years (legal/tax compliance)
Email communications3 years
Link click analytics2 years
Training progress dataDuration of account
Verification history5 years
IP addressesAnonymized after 30 days

5Your Rights

Depending on your location, you may have the following rights regarding your personal data:

Right to Access

Request a copy of the personal data we hold about you

Right to Rectification

Request correction of inaccurate or incomplete data

Right to Erasure

Request deletion of your personal data (subject to legal obligations)

Right to Object

Object to the processing of your data for certain purposes

Right to Portability

Request your data in a portable, machine-readable format

Right to Restrict

Request restriction of processing under certain circumstances

To exercise any of these rights, contact us at legal@duplica.com. We will respond within 30 days.

6Security Measures

We implement industry-standard security measures to protect your information:

Encrypted passwords (bcrypt)
Row-Level Security (Supabase)
TLS/HTTPS everywhere
Encrypted database storage
JWT-based authentication
No admin backdoors to passwords

While we implement these measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security, but we will notify you promptly if we become aware of any breach affecting your data.

7Cookies and Tracking

We use minimal cookies and browser storage mechanisms solely for platform functionality:

Authentication Session

Functional

Keeps you logged in. Expires when you log out or after inactivity.

localStorage preferences

Functional

Stores dismissed announcements and milestone tracking locally in your browser only. Never sent to our servers.

sessionStorage tracking

Analytics

Single-session referral click tracking to avoid duplicate counts. Cleared when you close your browser.

We do not use advertising cookies, tracking pixels, or third-party behavioral analytics.

8International Data Transfers

Duplica operates globally and your information may be transferred to and processed in countries other than your own. Our infrastructure relies on Supabase (hosted on AWS) which operates under standard contractual clauses and GDPR-compliant data processing agreements. By using our service, you consent to these transfers under appropriate safeguards.

9Children's Privacy

The Duplica platform is intended solely for users aged 18 years and older. We do not knowingly collect personal information from individuals under 18. If we become aware that a minor has provided us with personal information, we will promptly delete it. If you are a parent or guardian and believe your child has provided us with information, please contact us at legal@duplica.com.

10Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last Updated” date at the top of this page. For material changes, we will notify you via email or a prominent notice on the platform at least 14 days before the change takes effect. Your continued use of Duplica after any changes constitutes your acceptance of the new Privacy Policy.

Contact Us About Privacy

If you have questions, concerns, or requests regarding this Privacy Policy or the handling of your personal data, please contact our Privacy team:

Privacy Email

legal@duplica.com

General Support

support@duplica.com

© 2026 Duplica. All rights reserved.

Talk with Us