Zephiel API

Compliance

GDPR compliance

Last updated 27 August 2026

This is a demonstration project. The text below is a worked example of what a GDPR page should cover, not legal advice, and the platform is not currently operated as a live commercial service. Have a qualified data protection adviser review and adapt it before publishing it for a real product.

The General Data Protection Regulation gives people in the European Economic Area and the United Kingdom rights over how their personal data is handled. This page explains what Zephiel collects, why, how long it is kept, who else processes it, and how to exercise those rights.

Our role

For your Zephiel account — your name, email, keys, usage, and invoices — we act as the data controller. We decide what is collected and why.

For data you send through the gateway to a listed API, we act as a data processor. We forward the request, record only its metadata, and do not retain request or response bodies. Each listing names its provider so you can assess where that payload goes before subscribing.

If you send personal data through an API, you are the controller for that data and are responsible for having a lawful basis to do so.

Lawful bases

We rely on four bases, depending on the purpose:

  • Performance of a contractrunning your account, issuing keys, metering calls, taking payment
  • Legitimate interestssecuring the platform, preventing abuse, diagnosing faults
  • Legal obligationkeeping financial records for the statutory period
  • Consentany optional communication you opt into, withdrawable at any time

What we process

Every category of personal data the platform stores, and how long it is kept:

Personal data categories, purpose, lawful basis, and retention period
CategoryExamplesPurposeBasisRetention
Account detailsName, email address, hashed passwordCreating and securing your accountContractUntil you delete the account
API credentialsKey prefix and a SHA-256 digest of each keyAuthenticating gateway requestsContractUntil the key is revoked, then 30 days
Request metadataTimestamp, endpoint, HTTP status, latencyMetering usage and enforcing quotasContract13 months, then aggregated
Billing recordsPlan, amount, currency, payment reference, statusTaking payment and meeting accounting dutiesContract / legal obligation7 years (statutory)
Session dataOpaque session identifier, expiryKeeping you signed inContract30 days, or until sign-out
Server logsIP address, user agent, referring pageSecurity, abuse prevention, diagnosticsLegitimate interests30 days

We do not sell personal data, and we do not use it to train models.

Your rights

If you are in the EEA or UK you have the following rights. Exercise any of them by emailing info@zephiel.com — we respond within 30 days.

Access
Ask for a copy of the personal data we hold about you.
Rectification
Have inaccurate details corrected — most are editable in your dashboard.
Erasure
Ask us to delete your account and associated data, subject to records we must keep by law.
Restriction
Ask us to pause processing while a dispute about accuracy or legitimacy is resolved.
Portability
Receive your account and usage data in a structured, machine-readable format.
Objection
Object to processing carried out on the basis of legitimate interests.
Withdraw consent
Where processing relies on consent, withdraw it at any time without affecting prior processing.

You also have the right to complain to your local supervisory authority. We would appreciate the chance to resolve it with you first.

Subprocessors

These providers process personal data on our behalf under written agreements that impose equivalent obligations. We give notice before adding a new one.

Subprocessors, their role, the data they handle, and location
ProviderRoleData handledLocation
VercelApplication hosting and edge deliveryRequest metadata, IP addressesUnited States / EU regions
NeonManaged PostgreSQL databaseAll stored account, usage, and billing dataEU (London)
PaystackPayment processingEmail address, transaction amount and referenceNigeria / South Africa

Third-party API providers listed on the marketplace are not our subprocessors — when you subscribe to one you form your own relationship with that provider for the payloads you send it.

International transfers

Our primary database is hosted in the EU. Where data reaches a provider outside the EEA or UK, the transfer is covered by the European Commission's Standard Contractual Clauses together with a transfer risk assessment, or by an adequacy decision where one applies.

Cookies and logs

Zephiel sets one cookie: an opaque session identifier that keeps you signed in. It ishttpOnlyandSameSite=Lax, expires after 30 days, and is strictly necessary — so it does not require consent. Your theme preference is stored in localStorage, never sent to us.

We run no advertising, analytics, or third-party tracking scripts. Server logs record IP address, user agent, and referrer for 30 days for security and diagnostics.

Security measures

  • Passwords hashed with scrypt and a per-user salt — never stored or logged in plaintext.
  • API keys stored only as SHA-256 digests; the plaintext is shown once and cannot be recovered.
  • Sessions are opaque random identifiers checked against the database on every request, so revocation is immediate.
  • All traffic served over TLS; database connections require TLS.
  • Every database query is parameterised, eliminating SQL injection.
  • Administrative areas are role-gated and excluded from search indexing.

Children

Zephiel is a developer tool intended for people aged 16 and over. We do not knowingly collect data from children. If you believe a child has created an account, contact us and we will remove it.

Breach notification

If a personal data breach occurs that is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and tell affected customers without undue delay.

Data processing agreement

If you need a signed DPA incorporating the Standard Contractual Clauses, request one at info@zephiel.com and we will return a countersigned copy.

Questions about your data?

Write to our data protection contact and we will get back to you within 30 days.