1. Overview
Preppsy is fully committed to GDPR (Regulation (EU) 2016/679) compliance. This page documents our compliance measures, your rights, and how to exercise them.
Data Controller
Preppsy Ltd. determines purposes/means of processing
Data Processor
We process on your behalf; subprocessors listed below
2. Lawful Basis for Processing
| Purpose | Lawful Basis (Art. 6) | Categories of Data |
|---|---|---|
| Account authentication | Contract (b) | Email, name, hashed password, OAuth tokens |
| Learning service delivery | Contract (b) | Mastery data, attempts, session logs, preferences |
| Analytics & improvement | Legitimate Interest (f) | Aggregated usage, performance metrics |
| Marketing communications | Consent (a) | Email, preferences (opt-in only) |
| Legal compliance | Legal Obligation (c) | Audit logs, access requests |
| AI processing (OpenRouter) | Contract (b) + Consent (a) | Uploaded content, questions, context |
3. Your Rights (Articles 15-22)
Right of Access (Art. 15)
Obtain confirmation of processing and copy of your data
How to exercise: Dashboard → Compliance → Export Data
Right to Rectification (Art. 16)
Correct inaccurate or incomplete personal data
How to exercise: Dashboard → Settings → Profile
Right to Erasure (Art. 17)
Request deletion of your personal data ('Right to be Forgotten')
How to exercise: Dashboard → Compliance → Delete Account
Right to Restriction (Art. 18)
Limit processing while verifying accuracy or objection
How to exercise: Email [email protected]
Right to Portability (Art. 20)
Receive data in structured, commonly used format (JSON/CSV)
How to exercise: Dashboard → Compliance → Export Data
Right to Object (Art. 21)
Object to processing based on legitimate interest or direct marketing
How to exercise: Dashboard → Settings → Preferences
Rights re Automated Decision-Making (Art. 22)
Not subject to decisions based solely on automated processing
How to exercise: No solely automated decisions with legal effect
4. Data Processing Agreement (DPA)
For institutional customers acting as Data Controllers, we offer a standard DPA incorporating EU Standard Contractual Clauses (2021/914).
DPA Includes:
- Subject matter, duration, nature, purpose of processing
- Categories of personal data and data subjects
- Controller/Processor obligations (Art. 28)
- Subprocessor management with prior authorization
- Data subject rights assistance
- Security measures (Art. 32)
- Breach notification (Art. 33-34)
- International transfer safeguards
- Audit rights and certifications
- Termination and data return/deletion
Download Standard DPA (PDF) or email [email protected] for executed copy.
5. Technical & Organizational Measures (Art. 32)
Technical Measures
- • TLS 1.3 encryption in transit
- • AES-256 encryption at rest (PostgreSQL, Redis, S3)
- • Row-level security for multi-tenant isolation
- • Better Auth: secure sessions, CSRF, rate limiting
- • Automated vulnerability scanning (GitHub Dependabot, Trivy)
- • WAF and DDoS protection (Cloudflare)
- • Immutable audit logs (append-only)
Organizational Measures
- • DPO appointed (Art. 37)
- • Data Protection Impact Assessments (Art. 35)
- • Records of Processing Activities (Art. 30)
- • Staff training on data protection
- • Incident response plan (72-hr notification)
- • Subprocessor due diligence & contracts
- • Annual third-party penetration testing
- • Privacy by design/default (Art. 25)
6. International Data Transfers
Our primary infrastructure is in the EU (Frankfurt). Transfers may occur to:
| Subprocessor | Purpose | Location | Safeguard |
|---|---|---|---|
| PostgreSQL (Managed) | Primary database | EU (Frankfurt) | None needed (EU) |
| Redis (Managed) | Caching, sessions | EU (Frankfurt) | None needed (EU) |
| OpenRouter | AI inference | US | SCCs + Supplementary Measures |
| Cloudflare | CDN, WAF, DNS | Global | SCCs + Adequacy |
| Better Auth | Authentication | Self-hosted (EU) | None needed (EU) |
For US transfers, we implement supplementary measures: encryption in transit/at rest, zero-retention API policies where available, and contractual limitations on government access.
7. Contact & Complaints
EU Representative (Art. 27)
[EU Representative Details - to be appointed if required]