GDPR Article 30 register
This page has not been configured for this product.
The text below still contains placeholder values and is not a valid statement of who the contracting party is or how to reach them. Set NEXT_PUBLIC_COMPANY_NAME, NEXT_PUBLIC_APP_NAME, NEXT_PUBLIC_SUPPORT_EMAIL and redeploy.
The Company (the Service) is the data controller for the processing activities described below. Privacy / DSAR contact: support@example.com.
| Purpose | Data categories | Lawful basis | Retention | Recipients / processors |
|---|---|---|---|---|
| Account creation and authentication | Email address, name, hashed password (if applicable), OAuth provider identifiers | Art. 6(1)(b) — performance of contract | Active account + 30 days after deletion | Auth provider (SaaS Factory Auth, AWS Cognito, Microsoft Entra, Google, GitHub, or Okta — depending on configured providers) |
| Service operation (the product's core functionality) | Whatever data the user submits to the product, plus diagnostic logs | Art. 6(1)(b) — performance of contract | Active subscription + 30 days; logs 30 days | Vercel (Application hosting); Neon (Primary database); Cloudflare (CDN + R2 object storage (UK IDTA + EU SCCs)) |
| Billing and payment processing | Name, email, billing address, payment method metadata (card last 4, brand) | Art. 6(1)(b) — performance of contract; Art. 6(1)(c) — legal obligation (tax records) | 7 years (tax records) | Stripe (Payment processing — Stripe Payments Europe Ltd (IE), onward to Stripe, Inc. US (UK IDTA + EU SCCs)) — full PAN never touches the controller's systems |
| Customer support and incident response | Email address, name, support ticket content (which may include screenshots) | Art. 6(1)(b) — performance of contract; Art. 6(1)(f) — legitimate interest in operating the service | 3 years from ticket close | Internal support team; SaaS Factory platform backends (SF Core support ingress, relayed to SF Success for triage); Anthropic (AI inference — Claude (UK IDTA + EU SCCs)) — automated safety/sentiment classification of ticket content |
| Product improvement and analytics | Aggregated usage events (page views, feature usage), pseudonymous device identifier | Art. 6(1)(f) — legitimate interest in improving the service | 13 months | No third-party analytics processors; Vercel (Application hosting); Neon (Primary database) |
| Security and fraud prevention | IP address, user agent, failed login attempts, suspicious activity flags | Art. 6(1)(f) — legitimate interest in service security | 12 months | Internal security team; Vercel (Application hosting); Neon (Primary database); Cloudflare (CDN + R2 object storage (UK IDTA + EU SCCs)) |
Hosting and processing infrastructure is located within the European Economic Area / United Kingdom: Neon (eu-west-1), AWS / Tigris (eu-west-2), Apify (eu-cz).
The following sub-processors process personal data outside the EEA/UK: Vercel (fra1); Cloudflare (global-edge); Anthropic (us); Resend (us); Stripe (eu-ie + us); Twilio (configurable); Microsoft 365 (configurable); Google Workspace (configurable). Those transfers rely on Standard Contractual Clauses (SCCs), the UK IDTA, or an equivalent safeguard.
EU/UK residents have the right to access, rectify, erase, restrict, port, or object to processing of their personal data, and to withdraw consent for processing based on consent. Exercise these rights by emailing support@example.com; we respond within 30 days.
If we fail to address your concerns, you may lodge a complaint with your local supervisory authority. In the UK that is the ICO (ico.org.uk).