PRIVACY POLICY

[DIRECTIVE] DISCLOSING GDPR DATA PRIVACY CONTROLLERS, SECURE TRANSFER ENCRYPTION PROTOCOLS, AND AUTOMATED MODEL SANITIZATION POLICIES INSTANTLY.

GDPR-COMPLIANT DATA INFRASTRUCTURE

1. DATA CONTROLLER

+
Controller within the meaning of the General Data Protection Regulation (GDPR): David Krippl, c/o flexdienst – #20185, Kurt-Schumacher-Straße 76, 67663 Kaiserslautern, Germany.
+
Privacy Contact: privacy@parsehook.com

2. DATA COLLECTION, PURPOSES & LEGAL BASES

+
Account Registration: Email address and secure password hashes are processed to establish, manage, and secure your user account. Legal basis: Article six(one)(b) GDPR (Performance of a contract).
+
Email Parsing Stream: When you forward emails to your unique ParseHook inbound addresses, the raw email body, subject, and headers are parsed dynamically to generate structured JSON outputs. Legal basis: Article six(one)(b) GDPR (Performance of a contract).
+
Parsed JSON Payloads: Structured results are temporarily archived to display them within your secure user dashboard. Legal basis: Article six(one)(b) GDPR.
+
Webhook & System Logs: Delivery metadata (response codes, execution duration, and log histories) are recorded to enable system monitoring, ensure IT security, and assist you in debugging. Legal basis: Article six(one)(f) GDPR (Legitimate interests of the controller to maintain system stability and security).
+
Payment Processing: Subscription billing and customer transactions are executed directly by our external payment provider Stripe. We do not store or process raw financial cards on our servers. Legal basis: Article six(one)(b) GDPR.

3. DATA RETENTION & STORAGE DURATION

+
Account Data: Stored for the entire active lifecycle of your subscription. Upon deleting your account via your settings, all profile credentials and linked configs are erased from active systems immediately and from backups within the backup rotation cycle (maximum thirty days).
+
Email Content & Parsed Payloads: Automatically purged from our active databases after your configured retention window (seven days for Free/Pro plans, up to thirty days for Business/Enterprise plans) to comply with data minimization standards.
+
Webhook & Error Logs: Permanently deleted after a maximum of thirty days.
+
System Backups: Encrypted disaster-recovery database snapshots are cycled and fully overwritten within thirty days.

4. SERVER INFRASTRUCTURE & DATA RECIPIENTS

+
Core Hosting (Netcup): Core parsing, database, and processing infrastructure runs on VPS servers provided by Netcup GmbH, located physically in Germany.
+
Frontend Hosting (Netlify): Our user interface is hosted and distributed globally via secure content delivery networks (Netlify, Inc.) to guarantee performance and protect against DDoS attacks. Legal basis: Article six(one)(f) GDPR.
+
Data Recipients (Sub-Processors): To provide our services, we engage trusted sub-processors including Netcup GmbH (Germany), Supabase, Inc. (Auth and Database, EU-hosted), Resend, Inc. (Inbound Email Processing and Transactional Email), Stripe, Inc. (Payment Processing), and Netlify, Inc. (Frontend Hosting).
+
Transport Security: All data streams between you, your email forwarders, our servers, and your target webhook endpoints are protected using state-of-the-art encryption protocols (TLS 1.3 in transit, AES-256 at rest).

5. MULTI-MODEL AI PROCESSING & INTERNATIONAL DATA TRANSFERS

+
To perform template-free semantic data extraction, our engine securely forwards raw email payloads to external AI language processing APIs. Core parsing, database, and processing infrastructure runs in Germany (EU). Email content may be transmitted to Resend, Inc. for inbound email processing and to AI sub-processors for semantic extraction. Both are covered by appropriate safeguards (SCCs) where processing occurs outside the EU.
+
Utilized AI Sub-Processors: May include Anthropic, OpenAI, Google, Moonshot AI, Zhipu AI, Xiaomi, xAI, and other enterprise API providers. A complete and current list of AI sub-processors is available upon request and can be found in our Data Processing Agreement.
+
Data Handling & No-Training Guarantee: Under our commercial API agreements, AI providers are prohibited from using customer content to train their models. Processing occurs transiently and is subject to strict data protection terms. Some providers may retain data for a limited period for security and abuse prevention, as required by law or their terms of service. We select providers based on their privacy posture and contractual guarantees.
+
Legal Safeguards for US/International Transfers: Since AI sub-processors may operate in the United States or other third countries, we strictly enforce EU Standard Contractual Clauses (SCCs) as approved by the European Commission, combined with strict supplementary technical safety measures under Article forty-six GDPR.

6. COOKIES & LOCAL STORAGE

+
ParseHook uses essential session cookies for authentication and, with your explicit consent, a privacy-preserving device fingerprint hash for abuse prevention. No marketing or advertising cookies are used. For detailed information, please review our Cookie Policy.

7. COOKIELESS WEB ANALYTICS (UMAMI)

+
We measure page performance anonymously using a self-hosted instance of Umami Analytics.
+
Umami does not use cookies, does not store persistent identifiers, and does not track users across external web domains. Your IP address is hashed and anonymized immediately upon connection. No user profiles are created, meaning no consent banner is legally required under GDPR standards.

8. YOUR GDPR RIGHTS & COMPLAINTS

+
You have the right to request access, rectification, erasure, restriction of processing, data portability, and to object to processing based on legitimate interests. Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal.
+
You can manage most of these rights directly from your settings panel (including data export in clean CSV/JSON format and account deletion).
+
Right to Lodge a Complaint: Under Article seventy-seven GDPR, you have the right to lodge an official complaint with a competent data protection supervisory authority if you believe that our processing of your personal data violates European privacy regulations.

9. NO AUTOMATED DECISION-MAKING / PROFILING

+
ParseHook acts solely as a structural data extraction utility. We do not use any automated profiling, credit scoring, or automated decision-making processes (pursuant to Article twenty-two GDPR) that produce legal or similarly significant effects concerning our users.