1. Introduction
GDPRKit ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our GDPR compliance assessment tool and services at gdprkit.eu ("Service").
We comply with the General Data Protection Regulation (GDPR) (EU) 2016/679 and all applicable data protection laws. By using our Service, you agree to the collection and use of information in accordance with this policy.
2. Data Controller
3. Data We Collect
3.1 Information You Provide
- •Account Data: Email address, password (hashed), company name, full name
- •Assessment Data: Responses to GDPR compliance questions
- •Payment Data: Processed via Stripe (we don't store card details)
- •Communication Data: Support tickets, emails, feedback
3.2 Automatically Collected Data
- •Usage Data: Pages viewed, features used, time spent
- •Technical Data: IP address, browser type, device information
- •Cookie Data: Session cookies, preference cookies
4. How We Use Your Data
We process your personal data for the following purposes:
- •Service Delivery: To provide and maintain our Service
- •Account Management: To manage your account and authentication
- •Assessment Processing: To generate compliance scores and documents
- •Payment Processing: To process your transactions (via Stripe)
- •Communication: To send service updates and support responses
- •Improvement: To analyze usage and improve our Service
- •Legal Compliance: To comply with legal obligations
- •Security: To detect and prevent fraud and unauthorized access
5. Legal Basis for Processing
Under GDPR, we process your data based on:
- •Contract: Processing necessary to provide the Service you requested (GDPR Art. 6(1)(b))
- •Legitimate Interest: Improving our Service and preventing fraud (GDPR Art. 6(1)(f))
- •Consent: Marketing communications (GDPR Art. 6(1)(a)) - you can withdraw anytime
- •Legal Obligation: Tax, accounting, and regulatory requirements (GDPR Art. 6(1)(c))
6. Data Sharing
We share your data only with:
Service Providers (Data Processors)
- •Supabase: Database and authentication (EU/US, GDPR-compliant)
- •Stripe: Payment processing (EU/US, GDPR-compliant)
- •Vercel: Hosting and deployment (EU/US, GDPR-compliant)
- •Resend: Email delivery (EU/US, GDPR-compliant)
All processors have Data Processing Agreements (DPAs) in place.
Legal Requirements
We may disclose data if required by law, court order, or to protect our rights.
We never sell your data to third parties.
7. Data Retention
We retain your data as follows:
- •Account Data: Until you delete your account + 30 days
- •Assessment Data: Until you delete your account + 30 days
- •Payment Records: 7 years (legal requirement)
- •Support Tickets: 2 years after resolution
- •Usage Logs: 90 days
After deletion, data is anonymized or permanently deleted within 30 days.
8. Your Rights Under GDPR
You have the following rights:
- •Access: Request a copy of your personal data (Art. 15)
- •Rectification: Correct inaccurate data (Art. 16)
- •Erasure: Request deletion ("right to be forgotten") (Art. 17)
- •Restriction: Limit how we process your data (Art. 18)
- •Portability: Receive your data in a machine-readable format (Art. 20)
- •Object: Object to processing based on legitimate interests (Art. 21)
- •Withdraw Consent: For marketing communications (Art. 7(3))
- •Complain: Lodge a complaint with your data protection authority
To exercise your rights, email [email protected]. We respond within 30 days.
9. Security Measures
We implement industry-standard security measures:
- •Encryption: TLS/SSL for data in transit, AES-256 for data at rest
- •Authentication: Bcrypt password hashing, secure session management
- •Access Control: Role-based access, least privilege principle
- •Monitoring: Security logs, intrusion detection
- •Backups: Daily encrypted backups with 30-day retention
- •Incident Response: Breach notification procedures (within 72 hours)
While we strive for maximum security, no method is 100% secure. Please use a strong password.
11. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices or legal requirements. We will:
- •Notify you via email for material changes
- •Update the "Last Updated" date
- •Maintain previous versions in our version history
Continued use of the Service after changes constitutes acceptance.
12. Contact Us
For privacy-related questions or to exercise your rights:
Email: [email protected]
Data Protection Officer: [email protected]
Response Time: Within 30 days
Supervisory Authority: Your local data protection authority