Compliance
GDPR compliance
Last updated 27 August 2026
This is a demonstration project. The text below is a worked example of what a GDPR page should cover, not legal advice, and the platform is not currently operated as a live commercial service. Have a qualified data protection adviser review and adapt it before publishing it for a real product.
The General Data Protection Regulation gives people in the European Economic Area and the United Kingdom rights over how their personal data is handled. This page explains what Zephiel collects, why, how long it is kept, who else processes it, and how to exercise those rights.
Our role
For your Zephiel account — your name, email, keys, usage, and invoices — we act as the data controller. We decide what is collected and why.
For data you send through the gateway to a listed API, we act as a data processor. We forward the request, record only its metadata, and do not retain request or response bodies. Each listing names its provider so you can assess where that payload goes before subscribing.
If you send personal data through an API, you are the controller for that data and are responsible for having a lawful basis to do so.
Lawful bases
We rely on four bases, depending on the purpose:
- Performance of a contract — running your account, issuing keys, metering calls, taking payment
- Legitimate interests — securing the platform, preventing abuse, diagnosing faults
- Legal obligation — keeping financial records for the statutory period
- Consent — any optional communication you opt into, withdrawable at any time
What we process
Every category of personal data the platform stores, and how long it is kept:
| Category | Examples | Purpose | Basis | Retention |
|---|---|---|---|---|
| Account details | Name, email address, hashed password | Creating and securing your account | Contract | Until you delete the account |
| API credentials | Key prefix and a SHA-256 digest of each key | Authenticating gateway requests | Contract | Until the key is revoked, then 30 days |
| Request metadata | Timestamp, endpoint, HTTP status, latency | Metering usage and enforcing quotas | Contract | 13 months, then aggregated |
| Billing records | Plan, amount, currency, payment reference, status | Taking payment and meeting accounting duties | Contract / legal obligation | 7 years (statutory) |
| Session data | Opaque session identifier, expiry | Keeping you signed in | Contract | 30 days, or until sign-out |
| Server logs | IP address, user agent, referring page | Security, abuse prevention, diagnostics | Legitimate interests | 30 days |
We do not sell personal data, and we do not use it to train models.
Your rights
If you are in the EEA or UK you have the following rights. Exercise any of them by emailing info@zephiel.com — we respond within 30 days.
- Access
- Ask for a copy of the personal data we hold about you.
- Rectification
- Have inaccurate details corrected — most are editable in your dashboard.
- Erasure
- Ask us to delete your account and associated data, subject to records we must keep by law.
- Restriction
- Ask us to pause processing while a dispute about accuracy or legitimacy is resolved.
- Portability
- Receive your account and usage data in a structured, machine-readable format.
- Objection
- Object to processing carried out on the basis of legitimate interests.
- Withdraw consent
- Where processing relies on consent, withdraw it at any time without affecting prior processing.
You also have the right to complain to your local supervisory authority. We would appreciate the chance to resolve it with you first.
Subprocessors
These providers process personal data on our behalf under written agreements that impose equivalent obligations. We give notice before adding a new one.
| Provider | Role | Data handled | Location |
|---|---|---|---|
| Vercel | Application hosting and edge delivery | Request metadata, IP addresses | United States / EU regions |
| Neon | Managed PostgreSQL database | All stored account, usage, and billing data | EU (London) |
| Paystack | Payment processing | Email address, transaction amount and reference | Nigeria / South Africa |
Third-party API providers listed on the marketplace are not our subprocessors — when you subscribe to one you form your own relationship with that provider for the payloads you send it.
International transfers
Our primary database is hosted in the EU. Where data reaches a provider outside the EEA or UK, the transfer is covered by the European Commission's Standard Contractual Clauses together with a transfer risk assessment, or by an adequacy decision where one applies.
Security measures
- Passwords hashed with scrypt and a per-user salt — never stored or logged in plaintext.
- API keys stored only as SHA-256 digests; the plaintext is shown once and cannot be recovered.
- Sessions are opaque random identifiers checked against the database on every request, so revocation is immediate.
- All traffic served over TLS; database connections require TLS.
- Every database query is parameterised, eliminating SQL injection.
- Administrative areas are role-gated and excluded from search indexing.
Children
Zephiel is a developer tool intended for people aged 16 and over. We do not knowingly collect data from children. If you believe a child has created an account, contact us and we will remove it.
Breach notification
If a personal data breach occurs that is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and tell affected customers without undue delay.
Data processing agreement
If you need a signed DPA incorporating the Standard Contractual Clauses, request one at info@zephiel.com and we will return a countersigned copy.
Questions about your data?
Write to our data protection contact and we will get back to you within 30 days.