Hesperan

Draft — placeholders in [brackets] must be completed and the text reviewed before hesperan.com goes public.

(Legal)

Privacy

How we process personal data when you use hesperan.com and the Hesperan API (GDPR).

Controller

[Company legal name, address] — hello@hesperan.com. See the imprint.

Website

We set no tracking or advertising cookies. When you sign in we set one strictly necessary session cookie. Our servers log IP address, time and requested URL for security for [retention, e.g. 14 days] (Art. 6(1)(f) GDPR).

Account and sign-in

For your account we store your email address, name (if provided by GitHub) and sign-in sessions (Art. 6(1)(b) GDPR). Sign-in links are sent by email via [email provider]. If you sign in with GitHub, GitHub shares your profile name, email and avatar with us.

API requests

To answer a request we process the state and questions you send. [Retention of request content: e.g. not stored after the answer is returned.] For billing and abuse prevention we store metadata per request: time, API key, number of questions, decisions or amount charged, status and latency.

Payments

Purchases are sold through Link by Stripe (Stripe Technology Europe, Limited) as merchant of record [if Managed Payments is used; otherwise: processed by Stripe Payments Europe, Ltd.]. Stripe processes your payment and billing data under its own privacy policy. We receive the payment status and invoice data, never your full card details (Art. 6(1)(b) GDPR).

Processors and hosting

[Hosting provider and location], [email provider], Stripe. Data processing agreements are in place. [Transfers outside the EU and safeguards, if any.]

Early-access list

If you request early access we store your email, company and message to contact you (Art. 6(1)(a) GDPR). You can withdraw at any time.

Your rights

Access, rectification, erasure, restriction, portability and objection (Art. 15–21 GDPR), and the right to lodge a complaint with a supervisory authority. Write to hello@hesperan.com.