Gdpr

Preppsy

GDPR Compliance

General Data Protection Regulation compliance documentation

1. Overview

Preppsy is fully committed to GDPR (Regulation (EU) 2016/679) compliance. This page documents our compliance measures, your rights, and how to exercise them.

Data Controller

Preppsy Ltd. determines purposes/means of processing

Data Processor

We process on your behalf; subprocessors listed below

2. Lawful Basis for Processing

PurposeLawful Basis (Art. 6)Categories of Data
Account authenticationContract (b)Email, name, hashed password, OAuth tokens
Learning service deliveryContract (b)Mastery data, attempts, session logs, preferences
Analytics & improvementLegitimate Interest (f)Aggregated usage, performance metrics
Marketing communicationsConsent (a)Email, preferences (opt-in only)
Legal complianceLegal Obligation (c)Audit logs, access requests
AI processing (OpenRouter)Contract (b) + Consent (a)Uploaded content, questions, context

3. Your Rights (Articles 15-22)

Right of Access (Art. 15)

Obtain confirmation of processing and copy of your data

How to exercise: Dashboard → Compliance → Export Data

Right to Rectification (Art. 16)

Correct inaccurate or incomplete personal data

How to exercise: Dashboard → Settings → Profile

Right to Erasure (Art. 17)

Request deletion of your personal data ('Right to be Forgotten')

How to exercise: Dashboard → Compliance → Delete Account

Right to Restriction (Art. 18)

Limit processing while verifying accuracy or objection

How to exercise: Email [email protected]

Right to Portability (Art. 20)

Receive data in structured, commonly used format (JSON/CSV)

How to exercise: Dashboard → Compliance → Export Data

Right to Object (Art. 21)

Object to processing based on legitimate interest or direct marketing

How to exercise: Dashboard → Settings → Preferences

Rights re Automated Decision-Making (Art. 22)

Not subject to decisions based solely on automated processing

How to exercise: No solely automated decisions with legal effect

4. Data Processing Agreement (DPA)

For institutional customers acting as Data Controllers, we offer a standard DPA incorporating EU Standard Contractual Clauses (2021/914).

DPA Includes:

  • Subject matter, duration, nature, purpose of processing
  • Categories of personal data and data subjects
  • Controller/Processor obligations (Art. 28)
  • Subprocessor management with prior authorization
  • Data subject rights assistance
  • Security measures (Art. 32)
  • Breach notification (Art. 33-34)
  • International transfer safeguards
  • Audit rights and certifications
  • Termination and data return/deletion

Download Standard DPA (PDF) or email [email protected] for executed copy.

5. Technical & Organizational Measures (Art. 32)

Technical Measures

  • • TLS 1.3 encryption in transit
  • • AES-256 encryption at rest (PostgreSQL, Redis, S3)
  • • Row-level security for multi-tenant isolation
  • • Better Auth: secure sessions, CSRF, rate limiting
  • • Automated vulnerability scanning (GitHub Dependabot, Trivy)
  • • WAF and DDoS protection (Cloudflare)
  • • Immutable audit logs (append-only)

Organizational Measures

  • • DPO appointed (Art. 37)
  • • Data Protection Impact Assessments (Art. 35)
  • • Records of Processing Activities (Art. 30)
  • • Staff training on data protection
  • • Incident response plan (72-hr notification)
  • • Subprocessor due diligence & contracts
  • • Annual third-party penetration testing
  • • Privacy by design/default (Art. 25)

6. International Data Transfers

Our primary infrastructure is in the EU (Frankfurt). Transfers may occur to:

SubprocessorPurposeLocationSafeguard
PostgreSQL (Managed)Primary databaseEU (Frankfurt)None needed (EU)
Redis (Managed)Caching, sessionsEU (Frankfurt)None needed (EU)
OpenRouterAI inferenceUSSCCs + Supplementary Measures
CloudflareCDN, WAF, DNSGlobalSCCs + Adequacy
Better AuthAuthenticationSelf-hosted (EU)None needed (EU)

For US transfers, we implement supplementary measures: encryption in transit/at rest, zero-retention API policies where available, and contractual limitations on government access.

7. Contact & Complaints

Data Protection Officer

[email protected]

Response within 30 days (Art. 12)

Supervisory Authority

You may lodge a complaint with your local DPA:

EU Representative (Art. 27)

[EU Representative Details - to be appointed if required]