1. 1. Subject matter and scope
This agreement implements Article 28 GDPR for personal data you store as controller in your Geckify cloud workspace or have processed through Geckify. It forms part of a paid business plan and continues through completion of return and erasure. No separate signature is required; a signed copy is available from support@geckify.dev.
2. 2. Nature, purpose, duration, data, data subjects
Nature and purpose: storing, displaying, versioning and exporting the projects you create, and passing project content to the model provider you connect, in each case on your instruction. Duration: for the term of the plan plus the deletion periods in section 8.
- Types of data: project text, image files, structure and layout data, prompts, usage timestamps, email addresses of team members you invite
- Categories of data subjects: your team members and everyone whose data you store in project content
- Special categories under Art. 9 GDPR are not intended; do not store such data in projects
3. 3. Instructions
We process entrusted data only on your documented instructions arising from this agreement, the agreed service and your application settings. Your authorised persons may send additional instructions in text form to support@geckify.dev; we document them. If Union or Member State law requires processing, we inform you of that legal requirement beforehand unless prohibited on important grounds of public interest. If an instruction appears to infringe data protection law, we inform you promptly and suspend the affected processing until clarified.
4. 4. Confidentiality
Only the owner of the sole proprietorship has access. Further people are engaged only after a written confidentiality undertaking and instruction; this page is updated accordingly when that happens.
5. 5. Technical and organisational measures (Art. 32 GDPR)
We apply the following measures and keep them at the state of the art:
- TLS for every connection; encryption at rest at Cloudflare
- Sign-in with one-time codes only, no passwords, httpOnly session cookies
- Provider API keys stored encrypted and used only for runs you approve
- Tenant separation per workspace at database level, authorisation enforced server side
- Request rate limits, server-side authorisation checks and signature verification for incoming payment webhooks
- Logging of security-relevant events; server logs deleted after 30 days at the latest
- Recoverability through versioned project states and export available at any time
6. 6. Sub-processors
You give general authorisation for the listed sub-processors. We impose at least equivalent data protection obligations on them by contract and remain responsible for their performance. We notify you of new or replacement sub-processors, their role and processing locations by email at least 30 days before use. You may object on substantiated data protection grounds. We investigate and seek an appropriate alternative; affected data is not disclosed to the new provider while the objection remains unresolved. If no solution is possible, you may terminate the affected service at the change date without an additional termination fee; unused advance payments are refunded. Payment providers process payment data under their own responsibility and are not sub-processors for your project content in that capacity.
- Cloudflare, Inc. — hosting, database (D1), file storage (R2), network security and the Turnstile bot check (USA / EU)
- netcup GmbH, Emmy-Noether-Straße 10, 76131 Karlsruhe, Germany — build server for publishing with Geckify hosting (data centre in Nuremberg, Germany)
- Plus Five Five, Inc. (Resend) — delivery of sign-in codes and other transactional emails (USA)
- Stripe / Sold through Link, LLC — payments and invoices as independent controllers, outside processing of entrusted project content (Ireland / United States)
- The model provider you connect is not our sub-processor; it receives data on your own instruction under its own terms
7. 7. Assistance, data subject rights and notifications
We assist you, as far as reasonable, with access, rectification, erasure, restriction and portability, with data protection impact assessments and with consultations of the supervisory authority. If a data subject approaches us directly we refer them to you without delay. We notify you of a personal data breach without delay and at the latest within 48 hours of becoming aware, with all information available to us under Art. 33 (3) GDPR.
8. 8. Deletion and return
At the end of entrusted processing, data is returned or erased at your choice; remaining copies are erased unless retention is required by law. You can export project archives yourself; we assist with return of other entrusted personal data. Erasure generally takes place within 30 days of your instruction and the end of the relevant processing. We confirm completion on request. Legally required remaining records are minimised, restricted and used only for their retention purpose. Backup copies are overwritten within the documented backup cycle, are not used for other purposes, and are cleared again of previously erased data if restored.
9. 9. Evidence and audits
We provide information needed to demonstrate compliance with Article 28 GDPR and enable audits by you or an independent auditor you appoint. Existing evidence and remote review are used to prepare an audit; necessary on-site inspections remain available. Routine inspections are coordinated on reasonable notice, with regard to operations, security and other customers’ rights. Incidents, substantiated concerns and supervisory orders are not subject to an annual limit. Any reasonable costs are agreed beforehand and must not prevent effective exercise of audit rights.
10. 10. International transfers
Third-country transfers take place only on documented instructions and a basis under Chapter V GDPR. Before a transfer we document an applicable adequacy decision or appropriate safeguards, particularly standard contractual clauses, together with the necessary transfer assessment and supplementary measures. EU-US Data Privacy Framework certification is relied on only where it currently covers the recipient and processing concerned. If adequate protection cannot be ensured, the affected transfer is suspended. Information and a copy of the applicable safeguards are available from support@geckify.dev.