Skip to content

GDPR record

Data-protection record for Astro Notes (astronotes.eu), maintained alongside the user-facing Privacy Policy. It documents how we process personal data under the GDPR: the record of processing (Art. 30), our processors and transfers (Art. 28), retention, and breach handling (Arts. 33–34).

Record of processing (Art. 30)

Field Value
Controller Marco Ferra, Av. Dom João II, 52, Piso 0, 1990-096 Lisboa, Portugal · privacy@astronotes.eu
Purposes End-to-end encrypted note storage and sync; sharing; the subscriber command bridge; billing; transactional email; user feedback; and security and abuse prevention
Data subjects Account holders
Categories Identifiers (handle and/or email); a one-way hash of your login credential; encrypted note data (unreadable to us); who a note is shared with, and their roles; hashed session tokens; subscription state; feedback messages you send us; command bridge transmissions (ciphertext, unreadable to us) and who sent them; IP addresses in security logs; and error diagnostics (technical context only, never note content)
Recipients Processors below; no other disclosure
Transfers Stripe and New Relic (US) under the EU–U.S. Data Privacy Framework; all other processing, including transactional email, is EU-hosted
Erasure In-app account deletion, or by the operator on request through the same database operation (immediate; bridge transmissions lose their author at once and their ciphertext within 30 days; a subscriber’s Stripe customer is deleted, retried until Stripe confirms); retention schedule below
Security (Art. 32) End-to-end encryption (AES-256-GCM with client-side keys), Argon2id credential hashing, TLS with HSTS, hashed session tokens, and hardened, automatically patched infrastructure

Processors and transfer register (Art. 28)

Processor Role Region Transfer safeguard
Hetzner Online GmbH Hosting EU (Germany) EU-hosted; no transfer
Stripe Payments US Data Privacy Framework
Amazon Web Services (SES) Transactional email EU (Germany) EU-hosted; SCCs for support access
New Relic, Inc. Service monitoring: aggregate metrics and error diagnostics, relayed through our own server and never including note content US Data Privacy Framework

Each processor operates under a data processing agreement that applies via its published terms, with no separate signature required:

  • Hetzner: order-processing terms (Art. 28) form part of the Hetzner contract; EU-hosted, so no transfer occurs.

  • Stripe: the DPA forms part of the Stripe Services Agreement — https://stripe.com/legal/dpa.

  • Amazon Web Services (SES): the DPA applies via the AWS Service Terms. Sending runs in the eu-central-1 (Frankfurt) region, so message content and recipient addresses are processed in the EU; the DPA’s standard contractual clauses cover any AWS support access from outside it.

  • New Relic: the DPA, which incorporates the Data Privacy Framework, applies automatically — https://newrelic.com/termsandconditions/dataprotection.

The Data Privacy Framework listings for the US processors are Active on the EU–U.S. framework, the UK Extension, and the Swiss–U.S. framework (verified 2026-08-07 against the official DPF Participants List):

Retention schedule

Data Retention
Account, notes, and keys Until you delete them or your account
Sessions 30 minutes idle, 30 days at most
Deleted-note stubs (id only, for device sync) Up to 90 days
Feedback messages (quota bookkeeping) 400 days, or until account deletion
Command bridge transmissions (ciphertext) 30 days; author removed on deletion
Security logs (IP addresses) 30 days
Error diagnostics (at New Relic, no note content) 30 days
Database backups 4 days, rotating
Invoices (at Stripe) As required by tax law

A deleted account leaves every backup within 4 days by rotation, and erased accounts are never restored from backups.

Breach response (Arts. 33–34)

Because note content is end-to-end encrypted, a breach of our database exposes identifiers and the sharing graph, not your notes.

If a breach affects personal data, we notify the Portuguese supervisory authority (the CNPD) within 72 hours of becoming aware of it. Where the breach is likely to result in a high risk to you — for example, an email address exposed in a way that enables phishing — we also notify affected users directly, via the app or by email.