1. Information clause (Art. 13) Full text in the Privacy Policy. Summary: we collect data only to provide the service, store it in the EU, and do not transfer it outside the EEA.
2. Security measures (Art. 32) Encryption in transit (TLS) across the site, app, and API. Passwords hashed with bcrypt (cost factor 12); sessions in httpOnly cookies. Role-based access control (RBAC) for workspaces and admin actions. Admin actions are logged in an audit trail. Regular backups with time-limited retention.
3. Data Protection Officer (DPO) DPO: Jan Kowalski, contact [email protected]. Rights requests — response in 72h, substantive decision within 30 days.
4. List of sub-processors Stripe Payments Europe Ltd. Payments IE ✓ Stripe DPAHostinger International Ltd. Hosting (EU servers) LT / DE ✓ Hostinger DPAResend Inc. Transactional e-mail US (SCC) ✓ Resend DPAGoogle LLC (Tag Manager / Analytics 4) Marketing-site tag container and traffic analytics (consent) US (SCC) ✓ Google Ads Data Processing TermsMicrosoft Corporation (Clarity) Marketing-site UX analytics / session replay (consent; inputs masked) US (SCC) ✓ Microsoft Products and Services DPA
5. Data Protection Impact Assessment (DPIA) We assess the privacy impact of features that process personal data before shipping them. Documentation available on request.
6. Breach notification procedure We notify the supervisory authority within 72 hours and the affected users. Zero-day disclosure: [email protected].