GDPR record
Data-protection record for Astro Notes (astronotes.eu), maintained alongside the user-facing Privacy Policy. It documents how we process personal data under the GDPR: the record of processing (Art. 30), our processors and transfers (Art. 28), retention, and breach handling (Arts. 33–34).
Record of processing (Art. 30)
| Field | Value |
|---|---|
| Controller | Marco Ferra, Av. Dom João II, 52, Piso 0, 1990-096 Lisboa, Portugal · privacy@astronotes.eu |
| Purposes | End-to-end encrypted note storage and sync; sharing; the subscriber command bridge; billing; transactional email; user feedback; and security and abuse prevention |
| Data subjects | Account holders |
| Categories | Identifiers (handle and/or email); a one-way hash of your login credential; encrypted note data (unreadable to us); who a note is shared with, and their roles; hashed session tokens; subscription state; feedback messages you send us; command bridge transmissions (ciphertext, unreadable to us) and who sent them; IP addresses in security logs; and error diagnostics (technical context only, never note content) |
| Recipients | Processors below; no other disclosure |
| Transfers | Stripe and New Relic (US) under the EU–U.S. Data Privacy Framework; all other processing, including transactional email, is EU-hosted |
| Erasure | In-app account deletion, or by the operator on request through the same database operation (immediate; bridge transmissions lose their author at once and their ciphertext within 30 days; a subscriber’s Stripe customer is deleted, retried until Stripe confirms); retention schedule below |
| Security (Art. 32) | End-to-end encryption (AES-256-GCM with client-side keys), Argon2id credential hashing, TLS with HSTS, hashed session tokens, and hardened, automatically patched infrastructure |
Processors and transfer register (Art. 28)
| Processor | Role | Region | Transfer safeguard |
|---|---|---|---|
| Hetzner Online GmbH | Hosting | EU (Germany) | EU-hosted; no transfer |
| Stripe | Payments | US | Data Privacy Framework |
| Amazon Web Services (SES) | Transactional email | EU (Germany) | EU-hosted; SCCs for support access |
| New Relic, Inc. | Service monitoring: aggregate metrics and error diagnostics, relayed through our own server and never including note content | US | Data Privacy Framework |
Each processor operates under a data processing agreement that applies via its published terms, with no separate signature required:
-
Hetzner: order-processing terms (Art. 28) form part of the Hetzner contract; EU-hosted, so no transfer occurs.
-
Stripe: the DPA forms part of the Stripe Services Agreement — https://stripe.com/legal/dpa.
-
Amazon Web Services (SES): the DPA applies via the AWS Service Terms. Sending runs in the eu-central-1 (Frankfurt) region, so message content and recipient addresses are processed in the EU; the DPA’s standard contractual clauses cover any AWS support access from outside it.
-
New Relic: the DPA, which incorporates the Data Privacy Framework, applies automatically — https://newrelic.com/termsandconditions/dataprotection.
The Data Privacy Framework listings for the US processors are Active on the EU–U.S. framework, the UK Extension, and the Swiss–U.S. framework (verified 2026-08-07 against the official DPF Participants List):
- Stripe, LLC — https://www.dataprivacyframework.gov/participant/10014 (next cert due 2027-05-11).
- New Relic, Inc. (covers New Relic CodeStream) — https://www.dataprivacyframework.gov/participant/6200 (next cert due 2026-08-13).
Retention schedule
| Data | Retention |
|---|---|
| Account, notes, and keys | Until you delete them or your account |
| Sessions | 30 minutes idle, 30 days at most |
| Deleted-note stubs (id only, for device sync) | Up to 90 days |
| Feedback messages (quota bookkeeping) | 400 days, or until account deletion |
| Command bridge transmissions (ciphertext) | 30 days; author removed on deletion |
| Security logs (IP addresses) | 30 days |
| Error diagnostics (at New Relic, no note content) | 30 days |
| Database backups | 4 days, rotating |
| Invoices (at Stripe) | As required by tax law |
A deleted account leaves every backup within 4 days by rotation, and erased accounts are never restored from backups.
Breach response (Arts. 33–34)
Because note content is end-to-end encrypted, a breach of our database exposes identifiers and the sharing graph, not your notes.
If a breach affects personal data, we notify the Portuguese supervisory authority (the CNPD) within 72 hours of becoming aware of it. Where the breach is likely to result in a high risk to you — for example, an email address exposed in a way that enables phishing — we also notify affected users directly, via the app or by email.