Register of Processing Activities

GDPR Article 30 — Record of personal data processing activities.

IDPurposeData CategoriesLegal BasisRetentionRecipients
PA-001

Service Delivery

Core application operations, user account management, and feature access.

Name, Email, Profile picture, Organization membershipContract (Art. 6(1)(b))Until account deletionVercel (hosting), Neon (database)
PA-002

Billing & Payments

Processing payments, managing subscriptions, generating invoices.

Email, Name, Payment method (via Calmony Pay), Invoice historyContract (Art. 6(1)(b))7 years (financial records)Calmony Pay
PA-003

Transactional Email

Sending account notifications, team invitations, and system alerts.

Email, NameContract (Art. 6(1)(b))30 days (email logs)Resend
PA-004

Analytics

Tracking usage patterns to improve the service. Only with user consent.

Usage events, Page views, Feature interactionsConsent (Art. 6(1)(a))90 daysNone
PA-005

Security & Audit

Logging state-changing operations for security monitoring and compliance.

User ID, Action, IP address, TimestampLegitimate Interest (Art. 6(1)(f))90 daysNone
PA-006

Error Monitoring

Tracking application errors to maintain service reliability. PII scrubbed before transmission.

Error stack traces (PII scrubbed), Browser/device metadataLegitimate Interest (Art. 6(1)(f))30 daysSentry (if configured)

Data Controller

{{COMPANY_NAME}}{{COMPANY_ADDRESS}}

Data Protection Officer: {{DPO_EMAIL}}

Privacy PolicyTerms of ServiceBack to Home