Deze pagina is vertaald door AI en kan fouten bevatten.

Privacy Policy

Last updated: 2026-03-21

1. Controller

EUDAssist is operated by Alex K., reachable at info@eudassist.com. This privacy policy explains how we collect, use, and protect your personal data in accordance with the EU General Data Protection Regulation (GDPR).

2. Data We Collect and Why

Account data

Email address and hashed password, collected when you create an account. If you register or sign in using a third-party provider (e.g. Google), completing that sign-in constitutes your acceptance of our Terms of Service and this Privacy Policy. Purpose: providing and managing your account. Legal basis: performance of contract.

Watchlist and certificate data

The manufacturers and EUDAMED certificates you choose to monitor. Purpose: delivering the certificate monitoring and alerting service. Legal basis: performance of contract. Retention: retained until you delete the item or your account.

Notification email address

An alternative email address you may optionally provide for alert delivery. Purpose: sending certificate expiry and revocation alerts. Legal basis: performance of contract. Retention: retained until you remove it or delete your account.

Alert logs

Records of which alert emails were sent, to which address, and when. Purpose: preventing duplicate alerts. Legal basis: legitimate interests. Retention: 90 days.

API tokens

If you generate a Personal Access Token (PAT) to connect an AI assistant via MCP, we store a SHA-256 hash of the token, its expiry date, and the timestamp of its last use (last_used_at). The raw token is never stored. Purpose: authenticating API requests and monitoring token health. Legal basis: performance of contract. Retention: deleted when you revoke the token or delete your account.

Subscription and billing data

Subscription status and Stripe customer identifiers. Payment card details are processed exclusively by Stripe and are never stored on our servers. Purpose: managing paid subscriptions. Legal basis: performance of contract.

3. Cookies

We use only technically necessary cookies. We do not use tracking, advertising, or analytics cookies.

  • Session cookie (set by Supabase), maintains your logged-in state. Expires with your session or after token rotation (approximately one week).
  • preferred_locale, stores your chosen interface language (e.g. en or de) so you are redirected to the correct language after login. Expires after 30 days. Contains no personally identifying information.

4. Sub-processors

We share personal data with the following third-party service providers. Where these providers are based in the United States, transfers are made under the EU-US Data Privacy Framework adequacy decision or Standard Contractual Clauses (SCCs).

ProviderRoleData sharedLocation
SupabaseDatabase & authenticationAll account and application dataEU / US
ResendTransactional emailEmail address, alert contentUS
SentryError monitoringAnonymised error reportsUS
VercelApplication hostingHTTP traffic (including IP addresses)US / EU
StripePayment processingBilling informationUS

5. Your Rights

Under the GDPR you have the following rights:

  • Access, request a copy of the personal data we hold about you.
  • Erasure, delete your account at any time via Settings → Danger Zone. This immediately removes all your data. You may also contact us at info@eudassist.com.
  • Rectification, correct inaccurate personal data.
  • Portability, receive your data in a structured, machine-readable format. Contact us at info@eudassist.com and we will provide it manually.
  • Objection, object to processing based on legitimate interests. To stop receiving alert emails, disable alerts in your account Settings.
  • Restriction, request that we restrict processing of your data in certain circumstances.

To exercise any of these rights, contact us at info@eudassist.com. We will respond within 30 days.

6. Security

All data is encrypted in transit (TLS) and at rest. Access to personal data is restricted to the service components that require it.

7. Changes to This Policy

If we make material changes we will update the “Last updated” date at the top of this page. Continued use of the service after the effective date constitutes acceptance of the revised policy.

8. Complaints

If you believe we have not handled your personal data correctly, you have the right to lodge a complaint with a supervisory authority. In Germany, this is the Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI).

9. Contact

Questions about this privacy policy: info@eudassist.com