GDPR Compliance
Last updated: August 5, 2026
This page explains how Penci.ly handles personal data for users in the EU, EEA, and UK, and how you can exercise your rights under the General Data Protection Regulation. It complements our Privacy Policy, which is the fuller description of what we collect and why.
1. Controller and Contact
The data controller for account data, board content, and everything else processed to provide Penci.ly is Daniel Halabi, a sole operator based in Germany, reachable at privacy@penci.ly.
We are not required to appoint a data protection officer under Article 37 and have not appointed one: we do not carry out large-scale systematic monitoring, and we do not process special categories of data as a core activity. Requests reach the operator directly at the address above.
Because we are established in the EU, we do not need an Article 27 representative. For users in the UK, the UK GDPR applies in parallel and we honour the same rights on the same timelines.
2. Processors and Sub-Processors
Our infrastructure providers act as processors or sub-processors under their own data processing agreements, and are permitted to process personal data only to provide their service to us:
- Vercel provides hosting and edge-network services.
- Convex stores account and board content.
- Clerk provides authentication and session management.
- Cloudinary stores and delivers uploaded media.
- Paddle will process billing and payment data as merchant of record once billing is live.
- PostHog processes product analytics in its EU region, and only for visitors who accepted the analytics banner. It receives page views, referring domains, named product events, and your account identifier and plan. Never your email address, your name, or board content.
When we add or replace a processor we update this list and, where the change is material, notify users directly.
3. Personal Data We Process
- Account details such as your email address, username, display name, and profile image.
- Boards and the content you add to them, including text, images, links, tasks, and connections.
- Sharing information, including collaborators and their roles.
- Limited presence data used to show who is currently viewing a board.
- Usage counters used to enforce plan limits and rate limits.
- Subscription and payment outcome data, once you buy a paid plan.
- A record of the emails we send you and your notification preferences.
- Technical request data processed by our infrastructure providers for security and abuse prevention.
We do not intentionally collect special categories of personal data under Article 9. Board content is free-form, so you could put such data into a board yourself. Please do not, and be aware that you would be the one deciding to do so.
See our Privacy Policy for the complete description of the data we process and how we use it.
4. Legal Bases for Processing
- Contractual necessity, Article 6(1)(b): providing the service you signed up for: your account, your boards, real-time sync, sharing, transactional email, and billing.
- Legitimate interests, Article 6(1)(f): security, abuse prevention, enforcing plan and rate limits, keeping our own administrative access reviewable, and the optional notifications you can switch off. We have balanced each of these against your rights and expectations, and you can object at any time.
- Consent, Article 6(1)(a): product analytics, which collects nothing before you accept the banner, and marketing email, which is off unless you turn it on. You may withdraw either at any time, as easily as you gave it.
- Legal obligations, Article 6(1)(c): where we must process data to comply with applicable law or valid legal process. Tax and invoice records relating to a purchase are held by our merchant of record under its own obligations.
We do not carry out automated decision-making producing legal or similarly significant effects, within the meaning of Article 22, and we do not profile you for advertising.
5. Your Data Protection Rights
Subject to the conditions and exceptions in applicable law, Articles 15–21 give you the right to:
- Access the personal data we hold about you, and receive a copy of it.
- Rectify inaccurate or incomplete personal data.
- Erase your personal data, subject to the narrow exceptions in section 7.
- Restrict how we process your personal data while a dispute about it is resolved.
- Port your data: receive it in a structured, commonly used, machine-readable format.
- Object to processing based on legitimate interests, including any direct marketing, which we stop on request without exception.
- Withdraw consent at any time where processing relies on it, without affecting processing already carried out.
Several of these are self-service and take effect immediately: account deletion and notification preferences live in your account settings, your analytics choice can be changed from your browser, and every optional email carries a one-click unsubscribe. Requests for a full data export beyond board PDF export are currently handled manually.
6. Exercising Your Rights
Send requests to privacy@penci.ly, preferably from the address on your account. We may need to verify your identity before completing a request, so that we do not disclose or delete data for the wrong person.
We aim to respond within 30 days, as required by Article 12(3). If a request is unusually complex, or you have made a number of them, the GDPR allows an extension of up to two further months, in which case we will tell you within the first month and explain why. Exercising your rights is free; we may charge a reasonable fee or decline only where a request is manifestly unfounded or excessive, and we will say which and why.
7. Data Retention and Deletion
Your content is retained while your account exists. Deleting a board removes it, every element on it, every board nested inside it, and the images and files uploaded to any of them. Deleting your account removes your boards and their contents, your uploaded files, your profile, your subscription and usage records, and the record of emails we sent you, and removes you from boards owned by other people, including invitations sent to your address that you never accepted.
We keep a record of security-relevant actions on shared boards (who was added or removed, and when) for up to 180 days, under our legitimate interest in being able to investigate unauthorised access. When an account is deleted, its email address is removed from those records; the remaining entries no longer identify a person once the associated account no longer exists.
Actions taken by our own staff (granting a plan, exporting an account's data, deleting an account) are kept for up to 400 days, together with the reason given and the network address the action came from, under the same legitimate interest. The longer period is deliberate: these records are what make our own access to your account reviewable, and a period shorter than an annual review cycle would not serve that purpose.
Two things outlive an erasure request, for reasons the GDPR recognises. An address that permanently bounced or reported us as spam stays on a suppression list holding the address and the reason only, because forgetting it is precisely how someone gets emailed again after asking us to stop. Article 21(3) requires us to keep enough information to honour an objection. And records of a purchase are retained by our merchant of record for as long as tax and accounting law requires, under Article 17(3)(b).
8. International Data Transfers
Our analytics provider is configured to its EU region so that data stays within the EEA. Other providers may process data outside your country, including in the United States. When EU, EEA, or UK personal data is transferred internationally, we rely on safeguards offered by those providers under Article 46: Standard Contractual Clauses, the EU to US Data Privacy Framework where the provider is certified, or an equivalent mechanism, together with the UK Addendum where the UK GDPR applies. You can ask which safeguard applies to a given provider at privacy@penci.ly.
9. Security
Traffic is encrypted in transit using HTTPS/TLS. Convex encrypts structured account and board data at rest using AES-256, and Cloudinary encrypts uploaded media at rest. Clerk provides authentication, so Penci.ly never stores your raw password, and two-factor authentication is available in your account settings. Administrative access to an account is restricted, requires re-authentication, and is recorded.
Penci.ly does not provide end-to-end encryption. Our backend must be able to process board content in order to render and synchronize it and to provide features such as link previews and PDF export.
10. Personal Data Breaches
We assess every suspected personal-data breach. Where a breach is likely to result in a risk to your rights and freedoms, we notify the competent supervisory authority within 72 hours of becoming aware of it, as required by Article 33. Where the risk to you is high, we also notify you directly under Article 34, describing what happened, what it means for you, and what we are doing about it.
11. Compliance Reviews
To keep these commitments current, we:
- Review our processor and sub-processor list quarterly for changes to certifications, terms, and data processing agreements.
- Run dependency and vulnerability reviews quarterly.
- Review authorization and access controls semi-annually.
- Review this page, the Privacy Policy, and the Terms of Service annually, and whenever our practices materially change.
12. Complaints and Contact
If you have a question, complaint, or data-rights request, contact privacy@penci.ly. We would rather hear about a problem than have you discover it elsewhere.
You also have the right under Article 77 to lodge a complaint with a supervisory authority, in the EU or EEA country where you live, where you work, or where the alleged infringement took place. Because we operate from Germany, the German state data protection authority for the operator's place of business is also competent. In the UK, that authority is the Information Commissioner's Office.