Register of Processing Activities

GDPR Article 30 — Record of personal data processing activities.

IDPurposeData CategoriesLegal BasisRetentionRecipients
PA-001

Service Delivery

Core application operations, user account management, and feature access.

Name, Email, Profile picture, Organization membershipContract (Art. 6(1)(b))Until account deletionVercel (hosting), Neon (database)
PA-002

Billing & Payments

Processing payments, managing subscriptions, generating invoices.

Email, Name, Payment method (via Calmony Pay), Invoice historyContract (Art. 6(1)(b))7 years (financial records)Calmony Pay
PA-003

Transactional Email

Sending account notifications, team invitations, and system alerts.

Email, NameContract (Art. 6(1)(b))30 days (email logs)Resend
PA-004

Analytics

Tracking usage patterns to improve the service. Only with user consent.

Usage events, Page views, Feature interactionsConsent (Art. 6(1)(a))90 daysNone
PA-005

Security & Audit

Logging state-changing operations for security monitoring and compliance.

User ID, Action, IP address, TimestampLegitimate Interest (Art. 6(1)(f))90 daysNone
PA-006

Error Monitoring

Built-in error monitoring to maintain service reliability. PII scrubbed before storage.

Error stack traces (PII scrubbed), Browser/device metadataLegitimate Interest (Art. 6(1)(f))30 daysNone

Data Controller

SaaS FactoryUnited Kingdom

Data Protection Officer: privacy@saas-factory.ai

Privacy PolicyTerms of ServiceBack to Home