GDPR Compliance
Last updated: July 25, 2026
This page explains how Penci.ly handles personal data for users in the EU, EEA, and UK and how you can exercise your rights under the General Data Protection Regulation.
1. Our Role
Penci.ly is the data controller for account data, board content, and other personal data processed to provide the service. Our infrastructure providers act as processors or sub-processors under their own data processing agreements.
- Vercel provides hosting and edge-network services.
- Convex stores account and board content.
- Clerk provides authentication and session management.
- Cloudinary stores and delivers uploaded media.
- LemonSqueezy will process billing and payment data as merchant of record once billing is live.
- PostHog processes product analytics in its EU region, and only for visitors who accepted the analytics banner. It receives page views, referring domains, named product events, and your account identifier and plan — never your email address, your name, or board content.
2. Personal Data We Process
We process the personal data needed to operate Penci.ly, including:
- Account details such as your email address, username, display name, and profile image.
- Boards and the content you add to them, including text, images, links, tasks, and connections.
- Sharing information, including collaborators and their roles.
- Limited presence data used to show who is currently viewing a board.
- Technical request data processed by our infrastructure providers for security and abuse prevention.
See our Privacy Policy for the complete description of the data we process and how we use it.
3. Legal Bases for Processing
- Contractual necessity: We process account and board data to provide the service you signed up for.
- Legitimate interests: We process limited data for security, abuse prevention, and service improvement, balanced against your rights and expectations.
- Consent: Future marketing communications, if introduced, will be consent-based and include a way to opt out.
- Legal obligations: We may process data where necessary to comply with applicable law or valid legal process.
4. Your Data Protection Rights
Subject to the conditions and exceptions in applicable law, GDPR Articles 15–21 may give you the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete personal data.
- Request erasure of your personal data.
- Restrict how we process your personal data.
- Receive your data in a portable format.
- Object to processing based on legitimate interests.
- Withdraw consent at any time where processing relies on consent.
Account deletion is available as a self-service action. Requests for a full data export beyond board PDF export are currently handled manually.
5. Exercising Your Rights
Send requests to privacy@penci.ly. We may need to verify your identity before completing a request so that we do not disclose or delete data for the wrong person.
We aim to respond within 30 days, as required by GDPR Article 12(3). If a request is unusually complex or numerous, the GDPR may allow an extension, in which case we will explain the delay.
6. Data Retention and Deletion
Your content is retained while your account exists. Deleting a board removes it, every element on it, every board nested inside it, and the images and files uploaded to any of them. Deleting your account removes your boards and their contents, your uploaded files, your profile, and your subscription and usage records, and removes you from boards owned by other people — including invitations sent to your address that you never accepted.
We keep a record of security-relevant actions on shared boards — who was added or removed, and when — for up to 180 days, under our legitimate interest in being able to investigate unauthorised access. When an account is deleted, its email address is removed from those records; the remaining entries no longer identify a person once the associated account no longer exists.
Actions taken by our own staff — granting a plan, exporting an account's data, deleting an account — are kept for up to 400 days, together with the reason given and the network address the action came from, under the same legitimate interest. The longer period is deliberate: these records are what make our own access to your account reviewable, and a period shorter than an annual review cycle would not serve that purpose.
7. International Data Transfers
Our providers may process data outside your country, including in the United States. When EU, EEA, or UK personal data is transferred internationally, we rely on safeguards offered by those providers, such as Standard Contractual Clauses or equivalent transfer mechanisms.
8. Security
Traffic is encrypted in transit using HTTPS/TLS. Convex encrypts structured account and board data at rest using AES-256, and Cloudinary encrypts uploaded media at rest. Clerk provides authentication so Penci.ly does not store your raw password.
Penci.ly does not currently provide end-to-end encryption. Our backend must be able to process board content to render and synchronize it and to provide features such as link previews and PDF export.
9. Compliance Reviews
To keep our commitments current, we plan to:
- Review our processor and sub-processor list quarterly for changes to certifications, terms, and data processing agreements.
- Run dependency and vulnerability reviews quarterly.
- Review authorization controls semi-annually.
- Review the Privacy Policy and Terms of Service annually and whenever our practices materially change.
- Assess every suspected personal-data breach and, where required, notify the relevant supervisory authority and affected users within 72 hours of becoming aware of it.
10. Complaints and Contact
If you have a question, complaint, or data-rights request, contact privacy@penci.ly. You may also have the right to lodge a complaint with the data protection supervisory authority in your country.