Legal
Privacy Policy
1. Introduction
This Privacy Policy explains how [OPERATOR_LEGAL_NAME] ("we", "us", or "our") collects, uses, and protects your personal data when you use Proteus Convert ("Service").
We act as the data controller under the EU General Data Protection Regulation (GDPR — Regulation (EU) 2016/679). If you have questions, contact our data protection contact at legal@proteusconvert.com.
2. What Data We Collect
2.1 Data You Provide
- Account data: email address and password hash (when you register with email), or your OAuth provider's user ID and email (when you sign in with GitHub or Google).
- Payment data: transaction amounts and credit balances associated with your account. Payment card details are processed directly by our payment provider and are not stored by us.
2.2 Data We Collect Automatically
- Usage data: credit consumption events (which conversion type was used, timestamp, credit cost). We do not log the content of files you convert.
- Authentication tokens: a signed JWT stored in your browser's
localStoragefor session management. This token expires and is cleared on sign-out. - Server logs: standard HTTP request logs (IP address, user-agent, timestamp) retained for up to 30 days for security and abuse prevention.
2.3 Data We Do Not Collect
Because all file conversion runs locally in your browser, we never receive, store, or process the content of any file you convert. Your documents remain on your device at all times.
3. Legal Basis for Processing (GDPR Article 6)
| Processing activity | Legal basis |
|---|---|
| Creating and managing your account | Performance of a contract (Art. 6(1)(b)) |
| Processing credit purchases | Performance of a contract (Art. 6(1)(b)) |
| Sending transactional emails (password reset, receipts) | Performance of a contract (Art. 6(1)(b)) |
| Server security logs | Legitimate interests (Art. 6(1)(f)) — fraud prevention and system security |
| Compliance with legal obligations (e.g. tax records) | Legal obligation (Art. 6(1)(c)) |
4. How We Use Your Data
We use your personal data to:
- Provide, maintain, and improve the Service;
- Manage your account and authenticate your sessions;
- Process payments and maintain credit balances;
- Send transactional communications (password reset, receipts);
- Detect and prevent fraud, abuse, or illegal activity;
- Comply with applicable legal obligations.
We do not sell your personal data to third parties. We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects.
5. Data Sharing and Third Parties
We share personal data only in the following circumstances:
- OAuth providers (GitHub, Google): when you sign in via OAuth, the provider shares your email and user ID with us in accordance with their own privacy policies.
- Payment processors: credit card and payment data is handled by our third-party payment provider. We share only the minimum data required to process your transaction.
- Hosting and infrastructure: our Service runs on cloud infrastructure. Providers act as data processors under a Data Processing Agreement (DPA) compliant with GDPR Article 28.
- Legal requirements: we may disclose data if required by law, court order, or to protect the rights, property, or safety of us, our users, or others.
6. International Data Transfers
If we transfer personal data outside the European Economic Area (EEA), we ensure an adequate level of protection through one of the following mechanisms:
- An adequacy decision by the European Commission;
- Standard Contractual Clauses (SCCs) approved by the European Commission;
- Other appropriate safeguards under GDPR Chapter V.
7. Data Retention
| Data category | Retention period |
|---|---|
| Account data (email, credentials) | Until account deletion, plus up to 30 days for backup purge |
| Credit transaction records | 7 years (tax and accounting obligations) |
| Server access logs | 30 days |
| Session tokens (localStorage) | Until sign-out or token expiry |
8. Your Rights Under GDPR
As an EU/EEA resident, you have the following rights:
- Right of access (Art. 15) — request a copy of the data we hold about you.
- Right to rectification (Art. 16) — correct inaccurate or incomplete data.
- Right to erasure (Art. 17) — request deletion of your data ("right to be forgotten").
- Right to restriction (Art. 18) — restrict how we process your data in certain circumstances.
- Right to data portability (Art. 20) — receive your data in a structured, machine-readable format.
- Right to object (Art. 21) — object to processing based on legitimate interests.
- Right to withdraw consent — where processing is based on consent, you may withdraw it at any time without affecting prior processing.
To exercise any of these rights, contact us at legal@proteusconvert.com. We will respond within 30 days. You also have the right to lodge a complaint with your national data protection authority.
9. Cookies and Local Storage
We use localStorage (not cookies) to store your authentication token and theme preference. No advertising or tracking cookies are used. No third-party analytics scripts are embedded in the Service.
If you clear your browser's local storage, you will be signed out and your theme preference will be reset.
10. Children's Privacy
The Service is not directed to children under 16 years of age. We do not knowingly collect personal data from children under 16. If you believe we have inadvertently collected such data, contact us immediately and we will delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email or by a prominent notice on the Service at least 30 days before taking effect. The updated policy will be published at this URL with a new effective date.