Skip to main content

Records of Processing Activities

GDPR Article 30 register — last reviewed: 2026

Controller

The Company (the Service) is the data controller for the processing activities described below. Privacy / DSAR contact: support@example.com.

Processing activities

PurposeData categoriesLawful basisRetentionRecipients / processors
Account creation and authenticationEmail address, name, hashed password (if applicable), OAuth provider identifiersArt. 6(1)(b) — performance of contractActive account + 30 days after deletionAuth provider (SaaS Factory Auth, AWS Cognito, Microsoft Entra, Google, GitHub, or Okta — depending on configured providers)
Service operation (the product's core functionality)Whatever data the user submits to the product, plus diagnostic logsArt. 6(1)(b) — performance of contractActive subscription + 30 days; logs 30 daysVercel (hosting), Neon (database), Cloudflare (CDN)
Billing and payment processingName, email, billing address, payment method metadata (card last 4, brand)Art. 6(1)(b) — performance of contract; Art. 6(1)(c) — legal obligation (tax records)7 years (tax records)Calmony Pay (payment processor) — full PAN never touches the controller's systems
Customer support and incident responseEmail address, name, support ticket content (which may include screenshots)Art. 6(1)(b) — performance of contract; Art. 6(1)(f) — legitimate interest in operating the service3 years from ticket closeInternal support team
Product improvement and analyticsAggregated usage events (page views, feature usage), pseudonymous device identifierArt. 6(1)(f) — legitimate interest in improving the service13 monthsInternal analytics only — no third-party analytics processors
Security and fraud preventionIP address, user agent, failed login attempts, suspicious activity flagsArt. 6(1)(f) — legitimate interest in service security12 monthsInternal security team

International transfers

Hosting and processing infrastructure is primarily located within the European Economic Area (Vercel EU regions, Neon EU regions). Where data is transferred outside the EEA — typically to US-based sub-processors — those transfers rely on Standard Contractual Clauses (SCCs) or equivalent safeguards.

Data subject rights

EU/UK residents have the right to access, rectify, erase, restrict, port, or object to processing of their personal data, and to withdraw consent for processing based on consent. Exercise these rights by emailing support@example.com; we respond within 30 days.

Supervisory authority

If we fail to address your concerns, you may lodge a complaint with your local supervisory authority. In the UK that is the ICO (ico.org.uk).