Privacy Policy
Last updated: August 11, 2026 · Regulation (EU) 2016/679 (GDPR) Disclosure
Privacy-First Architecture Highlights
- Free Browser Tools: Processed entirely client-side. Your images and files never leave your device.
- Ephemeral Storage: Media uploaded to the API/Dashboard is processed ephemerally and automatically deleted post-marking.
- EU Hosting: All primary databases and application infrastructure are hosted within the European Economic Area (EEA).
1. Data Controller Information
The Data Controller responsible for processing your personal data in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation - "GDPR") and applicable national data protection legislation is:
Ildar Ibiatov (Autónomo)
Contact Email: [email protected]
Website: https://markaimedia.com
(For complete operator details and legal address, see our Imprint / Legal Notice.)
2. Categories of Data Processed & Purposes
We process personal data only to the extent necessary to provide a secure, functional, and auditable compliance service:
2.1 Unauthenticated Free Browser Tools
When using our free interactive web tools (such as the browser image marking tool or disclosure generator), file processing occurs entirely within your browser using WebAssembly, HTML Canvas, and local client-side scripts. Your uploaded media files are not transmitted to or stored on our servers.
2.2 Account & Authentication Data
If you register for an account or use our authenticated API/Dashboard (`/app`), we collect your email address, password hash, account role, and generated API keys. This data is required to manage your account, authenticate requests, and meter subscription usage (Art. 6(1)(b) GDPR).
2.3 Ephemeral Media Uploads & Compliance Audit Logs
For automated API media processing (video, audio, high-resolution images, and auditable text artifacts):
- Ephemeral Media Files: Uploaded media files are stored temporarily in isolated queue storage solely to perform watermark insertion, C2PA manifest signing, and metadata extraction. Media files are automatically deleted after job completion (or within 24 hours at maximum).
- Evidence Audit Records: We store non-sensitive cryptographic hashes (e.g. SHA-256), C2PA claim metadata, disclosure IDs, and RFC 3161 timestamps. These evidence logs do not contain raw media and are retained to allow customers to verify compliance with Article 50 (Art. 6(1)(b) & Art. 6(1)(f) GDPR).
2.4 Billing & Payment Data
Payments are processed securely via our payment service provider (e.g. Stripe or Paddle). We do not store full credit card details on our infrastructure. We store transaction IDs, subscription tier, billing address, VAT identification number, and invoice history for tax and statutory accounting compliance (Art. 6(1)(c) GDPR).
2.5 Technical Logs & Security Engineering
When accessing our website or API, server log files temporarily record your IP address, browser user-agent, access timestamp, and HTTP request headers. This data is processed strictly for network security, abuse prevention, rate-limiting, and fail2ban intrusion prevention (Art. 6(1)(f) GDPR). Logs are automatically purged after 30 days.
3. Legal Bases for Processing
- Performance of Contract (Art. 6(1)(b) GDPR): Processing necessary to render SaaS services, process API calls, and issue evidence packs.
- Legal Obligation (Art. 6(1)(c) GDPR): Compliance with tax laws, statutory accounting requirements, and regulatory bookkeeping.
- Legitimate Interests (Art. 6(1)(f) GDPR): Maintaining server infrastructure security, preventing fraud, enforcement of API usage limits, and defending legal claims.
4. Subprocessors & Data Transfers
We use trusted third-party service providers ("Subprocessors") to run our infrastructure:
| Subprocessor | Role | Location |
|---|---|---|
| Hetzner Online / EU Cloud | Primary Hosting, Database & Redis Queue | Germany / EU (EEA) |
| Stripe Payments / Paddle | Payment Processing & VAT Billing | EU / USA (SCCs / DPF) |
| RFC 3161 TSA Authority | Cryptographic Evidence Timestamping | EU (EEA) |
All data storage and server nodes are located within the European Economic Area. Where subprocessors process data outside the EEA, transfers are safeguarded by Standard Contractual Clauses (SCCs) or the EU-U.S. Data Privacy Framework.
5. Cookies & Local Storage
We prioritize user privacy and minimize data storage:
- Essential Session Cookies: Used exclusively to maintain authenticated user logins in the dashboard (`/app`).
- LocalStorage Keys: Used in your browser to remember UI preferences (e.g. selected language locale `ui_locale` and dark/light mode toggle).
- No Advertising / Tracking Cookies: We do not use third-party behavioral advertising cookies or cross-site tracking scripts.
6. Data Retention & Erasure
- Uploaded Media: Purged immediately post-processing (maximum 24h).
- Account Data: Retained for the duration of your active account subscription.
- Evidence Audit Packs: Retained as long as your account remains active or until deleted by user action to preserve tamper-evident compliance history.
- Invoices & Accounting Records: Retained for 6 to 10 years per statutory EU tax obligations.
7. Your Data Subject Rights under GDPR
Under Articles 15–22 of the GDPR, you have the following rights:
- Right of Access (Art. 15): Obtain confirmation and copy of personal data processed.
- Right to Rectification (Art. 16): Correct inaccurate or incomplete personal data.
- Right to Erasure ("Right to be Forgotten", Art. 17): Request deletion of your personal data where grounds apply.
- Right to Restriction (Art. 18): Restrict data processing under specific statutory conditions.
- Right to Data Portability (Art. 20): Receive your personal data in a structured, machine-readable format.
- Right to Object (Art. 21): Object to processing based on legitimate interests.
- Right to Lodge a Complaint (Art. 77): You have the right to lodge a complaint with a supervisory Data Protection Authority (e.g., your local EU Member State DPA).
To exercise any of these rights, please email us at [email protected].