Privacy Policy
This Privacy Policy explains how [YOUR_COMPANY] ("we", "us", "our") collects, uses, and protects your personal data when you use [YOUR_APP_NAME] ("the Service"). We are committed to GDPR compliance and your data sovereignty.
1.Data Controller
[YOUR_COMPANY]
[YOUR_ADDRESS]
Email: [YOUR_EMAIL]
For all data protection enquiries, please contact us at the email above. We will respond within 30 days.
2.Data We Collect
We collect the following categories of personal data:
- Account data: email address, full name, password (hashed — we never see it in plain text).
- Organisation data: organisation name and URL slug you choose.
- Usage data: page visits, feature usage, error logs — to improve the Service.
- Billing data: handled directly by Stripe. We store only your Stripe customer ID and subscription status — never your card number.
- Consent records: timestamps and choices recorded when you accept terms or opt in/out of marketing.
We do not sell your data. We do not use it for advertising.
3.Legal Basis for Processing (GDPR Art. 6)
- Contract performance (Art. 6(1)(b)): processing your account and organisation data to deliver the Service.
- Consent (Art. 6(1)(a)): marketing emails — you can withdraw consent at any time by clicking "unsubscribe" or emailing us.
- Legitimate interest (Art. 6(1)(f)): usage analytics and security logging to maintain and improve the Service.
- Legal obligation (Art. 6(1)(c)): tax records and billing history where required by law.
4.Sub-processors
We use the following third-party processors. All have executed Data Processing Agreements with us:
- Supabase Inc. — database and authentication. Data stored in eu-central-1 (Frankfurt, Germany). Privacy policy.
- Vercel Inc. — application hosting (edge functions process requests; no personal data is stored at edge nodes). Privacy policy.
- Stripe Inc. — payment processing. Stripe is independently PCI-DSS compliant. Privacy policy.
5.International Data Transfers
Your personal data is stored in Frankfurt, Germany (EU) by default. Some of our sub-processors (Vercel, Stripe) are headquartered in the United States. Data transfers to the US are covered by the EU–US Data Privacy Framework or Standard Contractual Clauses (SCCs) pursuant to GDPR Art. 46.
6.Data Retention
- Active account data: retained for the duration of your account.
- Deleted accounts: soft-deleted immediately; hard-deleted after 30 days. Backups purged within 90 days.
- Billing records: retained for 7 years as required by tax law.
- Consent logs: retained for 5 years as evidence of lawful processing.
- Usage logs: aggregated and anonymised after 90 days.
7.Your Rights Under GDPR
You have the following rights regarding your personal data:
- Access (Art. 15): request a copy of all data we hold about you.
- Rectification (Art. 16): correct inaccurate data.
- Erasure (Art. 17): request deletion of your account and associated data.
- Portability (Art. 20): receive your data in a machine-readable format (JSON).
- Restriction (Art. 18): request that we restrict processing while a dispute is resolved.
- Objection (Art. 21): object to processing based on legitimate interest.
- Withdraw consent: for marketing emails, at any time, without affecting prior processing.
To exercise any right, email [YOUR_EMAIL]. We will respond within 30 days. You may also submit a request from your account settings.
If you believe we have violated your rights, you may lodge a complaint with the German Federal Commissioner for Data Protection (BfDI) at bfdi.bund.de, or with the supervisory authority in your country of residence.
9.Security
We implement appropriate technical and organisational measures including:
- AES-256 encryption at rest (Supabase managed)
- TLS 1.3 in transit
- Row-Level Security enforced at the database layer
- Service-role API keys never exposed to the client
- Passwords hashed with bcrypt (handled by Supabase Auth)
In the event of a data breach, we will notify affected users and the relevant supervisory authority within 72 hours as required by GDPR Art. 33.
10.Changes to This Policy
We will notify you of material changes by email and/or by posting a notice in the application at least 14 days before the change takes effect. Continued use of the Service after that date constitutes acceptance of the updated policy.