Skip to main content

Records of Processing Activities

GDPR Article 30 register

Controller

The Company (the Service) is the data controller for the processing activities described below. Privacy / DSAR contact: support@example.com.

Processing activities

PurposeData categoriesLawful basisRetentionRecipients / processors
Account creation and authenticationEmail address, name, hashed password (if applicable), OAuth provider identifiersArt. 6(1)(b) — performance of contractActive account + 30 days after deletionAuth provider (SaaS Factory Auth, AWS Cognito, Microsoft Entra, Google, GitHub, or Okta — depending on configured providers)
Service operation (the product's core functionality)Whatever data the user submits to the product, plus diagnostic logsArt. 6(1)(b) — performance of contractActive subscription + 30 days; logs 30 daysVercel (Application hosting); Neon (Primary database); Cloudflare (CDN + R2 object storage (UK IDTA + EU SCCs))
Billing and payment processingName, email, billing address, payment method metadata (card last 4, brand)Art. 6(1)(b) — performance of contract; Art. 6(1)(c) — legal obligation (tax records)7 years (tax records)Stripe (Payment processing — Stripe Payments Europe Ltd (IE), onward to Stripe, Inc. US (UK IDTA + EU SCCs)) — full PAN never touches the controller's systems
Customer support and incident responseEmail address, name, support ticket content (which may include screenshots)Art. 6(1)(b) — performance of contract; Art. 6(1)(f) — legitimate interest in operating the service3 years from ticket closeInternal support team; SaaS Factory platform backends (SF Core support ingress, relayed to SF Success for triage); Anthropic (AI inference — Claude (UK IDTA + EU SCCs)) — automated safety/sentiment classification of ticket content
Product improvement and analyticsAggregated usage events (page views, feature usage), pseudonymous device identifierArt. 6(1)(f) — legitimate interest in improving the service13 monthsNo third-party analytics processors; Vercel (Application hosting); Neon (Primary database)
Security and fraud preventionIP address, user agent, failed login attempts, suspicious activity flagsArt. 6(1)(f) — legitimate interest in service security12 monthsInternal security team; Vercel (Application hosting); Neon (Primary database); Cloudflare (CDN + R2 object storage (UK IDTA + EU SCCs))

International transfers

Hosting and processing infrastructure is located within the European Economic Area / United Kingdom: Neon (eu-west-1), AWS / Tigris (eu-west-2), Apify (eu-cz).

The following sub-processors process personal data outside the EEA/UK: Vercel (fra1); Cloudflare (global-edge); Anthropic (us); Resend (us); Stripe (eu-ie + us); Twilio (configurable); Microsoft 365 (configurable); Google Workspace (configurable). Those transfers rely on Standard Contractual Clauses (SCCs), the UK IDTA, or an equivalent safeguard.

Data subject rights

EU/UK residents have the right to access, rectify, erase, restrict, port, or object to processing of their personal data, and to withdraw consent for processing based on consent. Exercise these rights by emailing support@example.com; we respond within 30 days.

Supervisory authority

If we fail to address your concerns, you may lodge a complaint with your local supervisory authority. In the UK that is the ICO (ico.org.uk).