Aviso de Privacidade
O texto deste documento está disponível apenas em inglês.
This notice covers processing in which apiRiver acts as controller: account data and technical logs. Processing of the content of your documents, where apiRiver acts as a processor on the customer's instructions, is not governed by this notice — it is governed by the data processing agreement (see the DPA outline) and is described in section 7 only for completeness.
1. Who processes the data
Controller: ФОП Александр Рич, a sole proprietor in Ukraine (same as in the Terms of Service, section 1). Country of registration: Ukraine. The registered address and the registration number are stated in the Imprint. Contact for data-protection matters and data-subject requests: [email protected].
- Data protection officer (DPO): [LAWYER REQUIRED: whether one is appointed; the Article 37 GDPR criteria for this processing are not assessed here].
- Representative in the EU under Article 27 GDPR: [LAWYER REQUIRED: the question arises because the controller is established outside the EU and offers services to data subjects in the EU; whether the Article applies, or one of its exceptions, is a legal question].
2. Two roles
| Data | apiRiver's role | Governed by |
|---|---|---|
| Email, sign-in metadata, API key, technical logs | Controller | this notice |
| Content of invoices submitted for generation or validation | Processor, on the customer's instructions | data processing agreement with the customer |
[LAWYER REQUIRED: the processor role for document content is decided; the controller role for registration data is a proposal awaiting confirmation]
3. What data is processed
| Data | Form |
|---|---|
| Email address | stored in plain form, normalised, unique per account; also held when a sign-in link is requested, before an account exists |
| Sign-in link token | only a keyed hash (HMAC-SHA-256 with a server-side secret) is stored; the raw value is not |
| Sign-in session | a session identifier tied to the account; the session cookie is HttpOnly, Secure, SameSite=Lax |
| API key | a public prefix in plain form plus a keyed hash of the secret; the raw secret is not stored and is shown once, when the key is issued |
| Remaining free quota | a number, at account level |
| Sign-in form rate-limit counters | kept only in the memory of the running process, keyed by email address; they do not survive a restart |
| IP address | in the reverse-proxy access log and in the application log |
| Request URL, time, response code, request identifier | in the access log and the application log |
About the IP address specifically: the rate limiter does not read the client address at all until a trusted perimeter is configured — its windows are keyed by email address, and its counters are ephemeral in-process memory, not permanent storage. The IP processing that exists from day one is logging: the client address appears in the logs, and it is for the logs that a legal basis and a retention period are needed. [LAWYER REQUIRED: treating an IP address as personal data is an agent's proposal awaiting confirmation]
Not processed: passwords (sign-in is by one-time link only).
Payment data: account code; euro balance; history of balance movements (type, amount, balance after, date, a reference — for top-ups, the PayPal transaction identifier or, if the notification carries none, its message identifier); subscription dates and allowance; subscription purchases (months, price, dates); a record of each email processed from the payment mailbox, including emails from other senders, which are rejected (message identifier, outcome, short reason; for a rejected sender, its domain); unmatched payments (amount, currency, reference, message identifier). Unmatched payments are also reported to the operator by email (amount, message identifier, reference, reason). The text of a PayPal notification email, which may include the payer's name and PayPal email address, is not stored in the database and is not included in that report. Original PayPal notification emails remain in the operator's mailbox. [AUTHOR/LAWYER REQUIRED: retention period of the mailbox holding PayPal notification emails, and whether they count as accounting records under tax law]
A usage log of API calls is not kept at this time; when one is introduced, this notice will be extended with a line about it and its retention period.
4. Purposes and legal bases
[LAWYER REQUIRED: every basis below is a proposal; none should be read as established]
| Purpose | Data | Proposed legal basis |
|---|---|---|
| Create an account and let you in (sending the sign-in link email) | performance of a contract / taking steps at your request before a contract, Art. 6(1)(b) [LAWYER TO CONFIRM: this is the key qualification of the whole notice. The sign-in form has no consent checkbox because the transactional email is treated as fulfilling the user's request, not as consent. If the qualification is wrong for the author's jurisdiction, an opt-in appears in the form — a change to the product, not only to this text] | |
| Provide the API (key authentication, quota accounting) | email, key, quota | performance of a contract, Art. 6(1)(b) [LAWYER TO CONFIRM] |
| Prevent the sign-in form from being used as a mail relay (anti-abuse) | email (in memory); the address when a perimeter is configured | legitimate interest, Art. 6(1)(f) [LAWYER REQUIRED: a documented balancing test for each of the two legitimate-interest purposes in this table — this one and security and diagnostics] |
| Security and diagnostics (perimeter and application logs) | IP, URL, time, request identifier | legitimate interest, Art. 6(1)(f) (see the note in the row above) |
| Anonymised aggregated statistics about use | derived from operational metrics | further processing for statistical purposes, Art. 5(1)(b) with the safeguards of Art. 89(1); genuinely anonymous aggregates fall outside the GDPR. The right to such statistics is declared by contract (Terms of Service, section 9). |
| Balance, subscription and payment processing | [AUTHOR DECISION REQUIRED: not in the draft — added with the payment feature] | |
5. Who receives the data
| Recipient | What it receives | Why |
|---|---|---|
| Email provider — Zoho Mail | the recipient's email address and the content of the sign-in email; the messages you send to [email protected] | sending the sign-in email and receiving your messages [AUTHOR DECISION REQUIRED: the exact legal entity of the provider and its country; the same outgoing mail also carries unmatched-payment alerts to the operator — whether that belongs in this row must be decided with the payment data above] |
| Hosting provider / infrastructure | everything physically stored on the server | hosting the application and database [AUTHOR DECISION REQUIRED: provider not chosen] |
| Payment recipient — PayPal | payments are accepted as PayPal transfers; apiRiver receives PayPal's notification emails in a mailbox; what is kept from them is listed in section 3 | receiving and matching payments [LAWYER REQUIRED: PayPal's role (an independent controller or otherwise) and whether it belongs in this table as a recipient of data that apiRiver sends, or only as the source of the notifications] [AUTHOR DECISION REQUIRED: which provider hosts the mailbox that receives the PayPal notifications] |
The web fonts of this site are served from apiRiver's own server: no visitor data is transmitted to third parties for that purpose. [LAWYER REQUIRED: the draft's general statement that data is not passed to other third parties is deliberately not carried over as a blanket claim — the recipients are those in the table above, and the table is still incomplete (hosting provider, mailbox provider, payment-related recipients).] Customer data is not used for the company's own purposes.
apiRiver may change its email provider (Zoho Mail is the only one used at this time) and will update this notice when it does.
Transfers outside the EEA. [LAWYER REQUIRED IN FULL: processing is under the control of a controller established in Ukraine, i.e. outside the EEA, and sub-processors may be in third countries. On what basis such a transfer is permissible — an adequacy decision, standard contractual clauses or otherwise — is not established here. This is one of the main points of the legal review before publication.]
6. How long data is kept
The periods below are upper limits ("up to"): in practice data is usually deleted earlier.
| Item | Retention |
|---|---|
| Sign-in link token | valid for 15 minutes; the record (which holds the email address) is kept for up to 30 days after it expires, then deleted by a scheduled job. The record is also invalidated when the link is requested again. |
| Session | a sign-in lasts 30 days (the session cookie expires 30 days after sign-in and is not renewed; the expiry of the session record on the server is extended with activity); the record is kept for up to 30 days after it expires (or after you sign out, when it is deleted at once), then deleted by a scheduled job. |
| Account and email | for as long as the account exists. Inactive accounts are not deleted automatically; an account is deleted on request (section 8). |
| API key | a revoked key's record is not deleted on revocation (needed for history and for the integrity of the future usage log) and is kept for as long as the account exists. |
| Rate-limit counters | not stored: process memory, evicted when the longest window (a day) expires, lost on restart |
| Perimeter access log (including IP and URL) | up to 90 days [AUTHOR TO CONFIRM: the reverse proxy is not chosen yet; before publication its log format must be set to leave out the URL query string of the sign-in confirmation address, which carries the one-time token, and the retention period must be set on the host] |
| Application log (request identifier, client address) | up to 90 days. The application does not write URL query strings, email addresses entered in the sign-in form, API keys or cookie values into its log. The application log records the request identifier, the client address, account identifiers, and, for emails in the payment mailbox, the email's message identifier (when the email is rejected, cannot be parsed, its amount cannot be read, its processing fails, it cannot be marked as read, or the operator's report about it cannot be sent) and the sender's domain (when the email is rejected, cannot be parsed, its amount cannot be read or it has no message identifier). |
| Usage log of API calls | does not exist at this time; when it is introduced, this notice will be extended with its retention period (see section 3) |
| Balance, ledger, subscription and payment-email records | for the period required by tax and accounting rules [ACCOUNTANT/LAWYER REQUIRED: the number of years, and whether these records must be kept after an account is deleted] |
| Content of documents | not stored after the request is processed. While a PDF larger than about 10 KB is validated, the validation library writes a temporary copy to a private server directory; it is deleted when processing ends or, after an abnormal stop, by a later clean-up. |
7. The content of your documents
- The content of invoices submitted for generation or validation is not stored after the request is processed: received, processed, returned, forgotten. While a PDF larger than about 10 KB is validated, the validation library writes a temporary copy to a private server directory; it is deleted when processing ends or, after an abnormal stop, by a later clean-up.
- Operational metrics are counted on the fly, without storing any content. [AUTHOR TO CONFIRM: no operational metrics are collected by the service at this time; this describes how they will be counted when introduced]
- With respect to that content apiRiver is a processor acting on the customer's instructions; the terms are set by the data processing agreement.
8. Your rights
A data subject may request access to their data (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and portability (Art. 20), and may object to processing based on legitimate interest (Art. 21). If any processing turns out to be based on consent, it can be withdrawn at any time without affecting the lawfulness of the processing before withdrawal.
Send requests to [email protected]. We respond within one month of receiving a request. [LAWYER REQUIRED: confirm the wording against Art. 12(3), including the possibility of extending the period]
Complaints go to a data-protection supervisory authority [LAWYER REQUIRED: which authority to name, given that the controller is outside the EEA].
Self-service account deletion is not available at this time. To have your account deleted, write to [email protected]: deletion is done on request, by hand, in this order: first the sign-in sessions, then the API keys, then the account itself. Payment records are not deleted together with the account: they are kept for the period required by tax and accounting rules (section 6). A deletion request is carried out within one month, like other requests. [AUTHOR DECISION REQUIRED — an organisational gap, not a text one: how a deletion request is handled for an account with a non-zero balance, and what is kept of the account itself for an account that has payment records — those records refer to the account record, so it cannot be deleted while they are kept (for example, whether the email address is replaced and the record kept).]
9. Automated decisions
The service takes no automated decisions that produce legal effects concerning the user or similarly significantly affect them, within the meaning of Art. 22 GDPR. [LAWYER REQUIRED: this qualification is an agent's proposal; whether the automatic triggering of the rate limiter or the suspension of access falls under the Article needs separate assessment]
10. Changes to this notice
Material changes to this notice are sent by email to the account's address. The notice period and the date on which the current version takes effect are the same as for the Terms of Service and are shown in the Terms of Service, section 14.
11. Cookies
The site sets four cookies. All four are strictly necessary for the service you ask for; none is used for analytics or advertising.
| Cookie | Purpose | Attributes | Lifetime |
|---|---|---|---|
apiriver_session | keeps you signed in to the cabinet | HttpOnly, Secure, SameSite=Lax, Path=/ | 30 days from sign-in (the cookie is not re-issued; only the session record on the server is extended with activity); removed when you sign out |
apiriver_login_csrf | one half of a double-submit pair on the sign-in form; protects the request for a sign-in link from being triggered by another site; it authenticates nobody and gives access to nothing | HttpOnly, Secure, SameSite=Lax, Path=/login | 15 minutes |
apiriver_login_confirm_csrf | the same protection on the sign-in confirmation page, so that the confirmation of a sign-in cannot be triggered by another site | HttpOnly, Secure, SameSite=Lax, Path=/login/confirm | 15 minutes (as long as the sign-in link); removed after a successful sign-in |
apiriver_lang | remembers the interface language you chose | HttpOnly, Secure, SameSite=Lax, Path=/ | until you close the browser (a session cookie); set only when you choose a language |
No analytics, advertising or third-party cookies are used at this time, and no cookie banner is shown. If such cookies appear (web analytics, pixels, embedded widgets), this section must be rewritten in full, not extended: such cookies fall under a different consent regime.
[LAWYER REQUIRED: classifying the cookies as strictly necessary (so that no prior consent is needed, and no cookie banner is shown) is the author's decision resting on a proposal; ePrivacy is implemented differently across EU countries. If the conclusion is different for the target jurisdiction, a consent mechanism is needed — a change to the product, not only to this text.]