Privacy Policy
Last updated: February 16, 2026
1. Data Controller
Cloonar Technologies GmbH
Address: Vienna, Austria
Email: legal@docfast.dev
Data Protection Contact: privacy@docfast.dev
2. Data We Collect
2.1 Account Information
- Email address - Required for account creation and API key delivery
- API key - Automatically generated unique identifier
2.2 API Usage Data
- Request logs - API endpoint accessed, timestamp, response status
- Usage metrics - Number of API calls, data volume processed
- IP address - For rate limiting and abuse prevention
2.3 Payment Information
- Stripe Customer ID - For Pro subscription billing
- Payment metadata - Subscription status, billing period
3. Legal Basis for Processing
- Contract fulfillment (Art. 6(1)(b) GDPR) - Account creation, API service provision
- Legitimate interest (Art. 6(1)(f) GDPR) - Service monitoring, abuse prevention, performance optimization
- Legal obligation (Art. 6(1)(c) GDPR) - Tax records, payment processing compliance
4. Data Retention
- Account data: Retained while account is active + 30 days after deletion request
- API usage logs: 90 days for operational monitoring
- Payment records: 7 years for tax compliance (Austrian law)
- PDF processing data: Not stored (processed in memory only)
5. Third-Party Processors
5.1 Stripe (Payment Processing)
Purpose: Payment processing for Pro subscriptions
Data: Email, payment information
Location: EU (GDPR compliant)
Privacy Policy: https://stripe.com/privacy
5.2 Hetzner (Hosting)
Purpose: Server hosting and infrastructure
Data: All data processed by DocFast
Location: Germany (Nuremberg)
Privacy Policy: https://www.hetzner.com/legal/privacy-policy
6. Your Rights Under GDPR
- Right of access - Request information about your personal data
- Right to rectification - Correct inaccurate data (e.g., email changes)
- Right to erasure - Delete your account and associated data
- Right to data portability - Receive your data in machine-readable format
- Right to object - Object to processing based on legitimate interest
- Right to lodge a complaint - Contact your data protection authority
To exercise your rights: Email privacy@docfast.dev
7. Cookies and Tracking
DocFast uses minimal technical cookies:
- Session cookies - For login state (if applicable)
- No tracking cookies - We do not use analytics, advertising, or third-party tracking
8. Data Security
- Encryption: All data transmission via HTTPS/TLS
- Access control: Limited employee access with logging
- Infrastructure: EU-based servers with enterprise security
- API keys: Securely hashed and stored
9. International Transfers
Your personal data does not leave the European Union. Our infrastructure is hosted exclusively by Hetzner in Germany.
10. Contact for Data Protection
For questions about data processing or to exercise your rights:
Email: privacy@docfast.dev
Subject: Include "GDPR" in the subject line for priority handling
11. Changes to This Policy
We will notify users of material changes via email. Continued use of the service constitutes acceptance of updated terms.