GDPR Compliance
Last updated: August 22, 2026
1. Our Commitment
GetFreeToolsHub complies with GDPR for users in the EU/EEA and the UK GDPR. Controller: GetFreeToolsHub, contact dpo@getfreetoolshub.com, privacy@getfreetoolshub.com.
2. Personal Data We Process
Account data (email, name, avatar), file data (ephemeral, deleted after operation), logs (tool slug, IP SHA, success), and Stripe billing metadata. No special category data. See Privacy for file deletion flow (storage/processed/<executionId>/, 60s HMAC link).
3. Legal Bases
Contract (provide the tool you requested), Legitimate Interest (security, abuse prevention, improvement), Consent (optional analytics, withdraw anytime), Legal Obligation (tax invoices via Stripe). For India DPDP Act 2023 we also rely on consent and legitimate uses.
4. Your Rights
Access, rectification, erasure, restriction, portability, objection, and withdraw consent. Submit to dpo@getfreetoolshub.com — we reply within 30 days (GDPR Art. 12). For IN users, rights under DPDP Act available at same email.
5. Data Transfers
Data may be processed outside EU/EEA (e.g., AWS us-east-1, Stripe US). We use Standard Contractual Clauses and adequacy where required. Local Indian data may stay in ap-south-1 if STORAGE_REGION is set.
6. Retention & Deletion
Files: deleted seconds after processing. Account: until deletion request. Logs: 12 months anonymized. Backups: encrypted, 30 days. You can request full erasure — Stripe invoices are retained per legal obligation.
7. DPO & Supervisory Authority
DPO: dpo@getfreetoolshub.com. EU users may lodge a complaint with your local DPA (e.g., CNIL, BfDI). IN users may approach DPAI once constituted. We cooperate fully.