Draft — placeholders in [brackets] must be completed and the text reviewed before hesperan.com goes public.
(Legal)
Privacy
Controller
[Company legal name, address] — hello@hesperan.com. See the imprint.
Website
We set no tracking or advertising cookies. When you sign in we set one strictly necessary session cookie. Our servers log IP address, time and requested URL for security for [retention, e.g. 14 days] (Art. 6(1)(f) GDPR).
Account and sign-in
For your account we store your email address, name (if provided by GitHub) and sign-in sessions (Art. 6(1)(b) GDPR). Sign-in links are sent by email via [email provider]. If you sign in with GitHub, GitHub shares your profile name, email and avatar with us.
API requests
To answer a request we process the state and questions you send. [Retention of request content: e.g. not stored after the answer is returned.] For billing and abuse prevention we store metadata per request: time, API key, number of questions, decisions or amount charged, status and latency.
Payments
Purchases are sold through Link by Stripe (Stripe Technology Europe, Limited) as merchant of record [if Managed Payments is used; otherwise: processed by Stripe Payments Europe, Ltd.]. Stripe processes your payment and billing data under its own privacy policy. We receive the payment status and invoice data, never your full card details (Art. 6(1)(b) GDPR).
Processors and hosting
[Hosting provider and location], [email provider], Stripe. Data processing agreements are in place. [Transfers outside the EU and safeguards, if any.]
Early-access list
If you request early access we store your email, company and message to contact you (Art. 6(1)(a) GDPR). You can withdraw at any time.
Your rights
Access, rectification, erasure, restriction, portability and objection (Art. 15–21 GDPR), and the right to lodge a complaint with a supervisory authority. Write to hello@hesperan.com.