Privacy Policy

Your privacy matters to us. This policy explains how we handle your data.

Last updated: December 29, 2024GDPR Compliant

1. Introduction

GDPRKit ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our GDPR compliance assessment tool and services at gdprkit.eu ("Service").

We comply with the General Data Protection Regulation (GDPR) (EU) 2016/679 and all applicable data protection laws. By using our Service, you agree to the collection and use of information in accordance with this policy.

2. Data Controller

Company: GDPRKit

Address: [Your Address]

Email: [email protected]

DPO Contact: [email protected]

3. Data We Collect

3.1 Information You Provide

  • Account Data: Email address, password (hashed), company name, full name
  • Assessment Data: Responses to GDPR compliance questions
  • Payment Data: Processed via Stripe (we don't store card details)
  • Communication Data: Support tickets, emails, feedback

3.2 Automatically Collected Data

  • Usage Data: Pages viewed, features used, time spent
  • Technical Data: IP address, browser type, device information
  • Cookie Data: Session cookies, preference cookies

4. How We Use Your Data

We process your personal data for the following purposes:

  • Service Delivery: To provide and maintain our Service
  • Account Management: To manage your account and authentication
  • Assessment Processing: To generate compliance scores and documents
  • Payment Processing: To process your transactions (via Stripe)
  • Communication: To send service updates and support responses
  • Improvement: To analyze usage and improve our Service
  • Legal Compliance: To comply with legal obligations
  • Security: To detect and prevent fraud and unauthorized access

6. Data Sharing

We share your data only with:

Service Providers (Data Processors)

  • Supabase: Database and authentication (EU/US, GDPR-compliant)
  • Stripe: Payment processing (EU/US, GDPR-compliant)
  • Vercel: Hosting and deployment (EU/US, GDPR-compliant)
  • Resend: Email delivery (EU/US, GDPR-compliant)

All processors have Data Processing Agreements (DPAs) in place.

Legal Requirements

We may disclose data if required by law, court order, or to protect our rights.

We never sell your data to third parties.

7. Data Retention

We retain your data as follows:

  • Account Data: Until you delete your account + 30 days
  • Assessment Data: Until you delete your account + 30 days
  • Payment Records: 7 years (legal requirement)
  • Support Tickets: 2 years after resolution
  • Usage Logs: 90 days

After deletion, data is anonymized or permanently deleted within 30 days.

8. Your Rights Under GDPR

You have the following rights:

  • Access: Request a copy of your personal data (Art. 15)
  • Rectification: Correct inaccurate data (Art. 16)
  • Erasure: Request deletion ("right to be forgotten") (Art. 17)
  • Restriction: Limit how we process your data (Art. 18)
  • Portability: Receive your data in a machine-readable format (Art. 20)
  • Object: Object to processing based on legitimate interests (Art. 21)
  • Withdraw Consent: For marketing communications (Art. 7(3))
  • Complain: Lodge a complaint with your data protection authority

To exercise your rights, email [email protected]. We respond within 30 days.

9. Security Measures

We implement industry-standard security measures:

  • Encryption: TLS/SSL for data in transit, AES-256 for data at rest
  • Authentication: Bcrypt password hashing, secure session management
  • Access Control: Role-based access, least privilege principle
  • Monitoring: Security logs, intrusion detection
  • Backups: Daily encrypted backups with 30-day retention
  • Incident Response: Breach notification procedures (within 72 hours)

While we strive for maximum security, no method is 100% secure. Please use a strong password.

10. Cookies and Tracking

We use the following cookies:

Essential Cookies (No Consent Required)

  • Session Cookie: Maintains your login session
  • CSRF Token: Prevents cross-site request forgery

Analytics Cookies (Consent Required)

Coming soon: We plan to use privacy-friendly analytics (Plausible or similar). You can opt out anytime.

We do not use advertising cookies or third-party tracking.

11. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or legal requirements. We will:

  • Notify you via email for material changes
  • Update the "Last Updated" date
  • Maintain previous versions in our version history

Continued use of the Service after changes constitutes acceptance.

12. Contact Us

For privacy-related questions or to exercise your rights:

Email: [email protected]

Data Protection Officer: [email protected]

Response Time: Within 30 days

Supervisory Authority: Your local data protection authority