Legal
Privacy Policy
Transparent information on the processing of personal data when using the HejData platform
Version 2026-07-06-v2 · As of July 6, 2026
Note on this translation
This English translation is for informational purposes only. The German version is legally binding.
1. Controller
The controller within the meaning of Art. 4(7) and Art. 13 GDPR for the HejData platform (registration, dashboard, billing, support) is:
Lars Macario, Klingnberg 11, 25451 Quickborn, Deutschland
Email for privacy requests: hej@macario.dev
HejData is aimed at founders, solo founders, and small teams. We process personal data in a purpose-limited, data-minimizing manner and only to the extent required to operate the platform.
2. Two roles: platform users vs. your apps' end users
It is important to distinguish two processing situations:
- Platform users (you as a HejData customer): We are the controller for your account data, billing information, and dashboard usage. This privacy policy applies to that processing.
- End users of your connected projects (e.g. visitors to your website, users in your Supabase DB): You are the controller. HejData processes this data solely on your behalf under the Data Processing Agreement (DPA). Details are in the DPA and the list of sub-processors.
- If you embed the HejData tracking script on your website, you must update your own privacy policy to disclose HejData as a processor and ensure a valid legal basis.
3. Scope
This privacy policy applies to the website hejdata.app (or your production domain), registration, login, the dashboard, the platform's API interfaces, and communication with us.
It does not apply to external third-party websites or services we link to (e.g. Stripe Checkout, Supabase dashboard). Those providers' privacy policies apply.
4. Data processed, purposes, and retention
Below we describe what data we process as controller, for what purposes, and how long:
- Account data (email, display name, password hash via Supabase Auth) — registration, login, account management — for as long as the account is active, then deletion within 30 days
- Organization and project data (workspace name, project name, slug, domain, connection status) — providing the multi-project dashboard — while the account or project is active
- Waitlist data (email, language, timestamp, IP hash, founding discount status) — managing the waitlist until access is granted — until invitation or deletion on request, up to 24 months without invitation
- Invite and onboarding data (invite codes, optional email binding) — controlled activation of waitlist spots — until redemption or invite expiry
- Billing data (Stripe customer ID, subscription status, selected plan, payment history metadata) — contract fulfillment — contract term plus statutory retention (up to 10 years)
- Usage and audit data (login timestamps, security-relevant dashboard actions, e.g. project created, DPA accepted, invite generated) — security, traceability, fraud prevention — 24 months
- Technical access data (IP address, user agent, timestamps on API/dashboard access) — operation, error analysis, abuse detection — up to 90 days in server logs unless longer retention is security-relevant
- Support communication (content of your email inquiries) — handling support and privacy requests — until resolved, then up to 24 months
- Alert configuration (encrypted recipient email per project) — threshold notifications — while alerts are active; email address is not stored in plain text
5. Legal bases
Processing is based on the following legal bases (Art. 6 GDPR):
- Art. 6(1)(b) GDPR — performance of contract and pre-contractual measures (account, dashboard features, billing)
- Art. 6(1)(f) GDPR — legitimate interest in secure, stable operation (audit log, log files, abuse detection, troubleshooting); your interests do not override ours as we minimize data and restrict access
- Art. 6(1)(c) GDPR — legal obligation (e.g. tax retention of invoice data)
- Art. 6(1)(a) GDPR — consent where required (e.g. optional marketing communication, if offered)
7. Recipients and processors
We only share personal data when necessary for contract fulfillment, legally required, or with your consent.
The following service providers process data on our behalf (details and sub-processor chain at /en/subprocessors):
- Supabase Inc. — PostgreSQL database, authentication, storage of platform and analytics data — server location: Frankfurt am Main (EU)
- Hostinger International Ltd. — application hosting, cron job execution — EU (Lithuania)
- Stripe Inc. — payment processing and subscription management — USA/Ireland (see section on third-country transfers)
- Hostinger — sending alert emails to recipients you configure
8. Third-country transfers
We primarily process data in the European Union (database in Frankfurt, hosting in the EU).
When using Stripe, transfers to the USA cannot be ruled out. Stripe provides appropriate safeguards (including EU Standard Contractual Clauses and the EU-US Data Privacy Framework where applicable).
As a US company, Supabase may have access possibilities under US law despite EU server location. We select the Frankfurt EU data center and maintain a data processing agreement with Supabase.
Further information is available in the respective providers' privacy notices.
9. Data security (technical and organizational measures)
We implement appropriate technical and organizational measures (TOMs) to protect your data pursuant to Art. 32 GDPR, including in particular:
- Encrypted data transmission (TLS/HTTPS) for all connections to the platform
- Encrypted storage of sensitive connection data (Supabase service role keys, Stripe webhook secrets) with AES-256-GCM — plain-text secrets are not stored in the database
- Encrypted storage of alert recipient emails; the address is not displayed in plain text in the dashboard
- Row Level Security (RLS) in PostgreSQL — tenant isolation at database level
- Role-based access control in the dashboard (owner, admin, viewer) — write access to integrations only for authorized roles
- Service role keys and encryption keys server-side only — never exposed to the browser
- Audit logging of security-relevant actions (e.g. DPA acceptance, project changes, invite creation)
- Origin validation for analytics events — events are only accepted from the configured project domain
- Regular backups via Supabase; production system access limited to authorized personnel
- Data minimization: we only collect data necessary for each purpose
10. No automated decision-making
We do not carry out automated decision-making including profiling within the meaning of Art. 22 GDPR that produces legal effects concerning you or similarly significantly affects you.
Alert notifications are based on statistical threshold comparisons (Z-score on aggregated daily values) and do not constitute legally effective automated decisions.
11. Retention and deletion
Account data is stored while your account is active. After a deletion request or cancellation, personal data is removed within 30 days unless statutory retention obligations apply.
Project data (metrics, connections, analytics events) is deleted when you permanently remove a project in the danger zone.
Billing data is retained for up to 10 years in accordance with commercial and tax law requirements.
Audit log entries are deleted after 24 months. Server log files are rotated after a maximum of 90 days unless longer retention is security-relevant.
12. Your rights as a data subject
You have the following rights regarding your personal data:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing based on legitimate interests (Art. 21 GDPR)
- Withdrawal of consent (Art. 7(3) GDPR) — without affecting lawfulness before withdrawal
13. Exercising your rights & right to complain
To exercise your rights, send an informal message to hej@macario.dev. Please describe your request as specifically as possible so we can identify you. We typically respond within 30 days.
You have the right to lodge a complaint with a data protection supervisory authority — in particular the authority at your place of residence or our registered office:
Independent Centre for Privacy Protection Schleswig-Holstein (ULD SH), Holstenstraße 98, 24103 Kiel, Germany, https://www.datenschutzzentrum.de/
14. Children
HejData is aimed at business founders and entrepreneurs. The platform is not intended for persons under 16. We do not knowingly collect data from children.
15. Changes to this privacy policy
We update this privacy policy when legal requirements, platform features, or our processing change. The current version is always available at /en/privacy; the version date is shown at the top of this page.
For material changes, we notify registered users by email or via a notice in the dashboard.