Privacy and Data Processing Policy
Version 2026-09-05 · Data controller: [Operator name], [Operator postal address] · Contact: fxen@tuta.io
This policy explains what personal data Expiring Date (the "Service") collects, why, on which legal basis, how long we keep it, who we share it with, and the rights you have. It is written to satisfy the EU/UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the CPRA (CCPA), other US state privacy laws, CAN-SPAM and COPPA. Where those laws use different words for the same idea, we say so.
1. Who is responsible
[Operator name] is the data controller (under the CCPA, the "business") for the personal data processed through the Service. You can reach us at fxen@tuta.io.
2. What we collect and why
| Data | Purpose | Legal basis (GDPR) | Retention |
|---|---|---|---|
| Account data: email address, optional display name, time zone, password (stored only as an Argon2id hash), account status, acceptance timestamps and version of the Terms and this Policy, IP address at the time of consent | Create and secure your account; prove consent; deliver the Service | Art. 6(1)(b) performance of a contract; Art. 6(1)(c) legal obligation (record of consent) | Until you delete your account |
| Content data: categories, item titles, due dates, recurrence rules, notes, links, optional amounts | Provide the core Service and generate your reminders | Art. 6(1)(b) contract | Until you delete the item or your account |
| Reminder and email records: which reminders were sent when, recipient address, subject, delivery status, provider message ID, error messages | Avoid duplicate reminders; troubleshoot delivery; prove that notices were sent | Art. 6(1)(b) contract; Art. 6(1)(f) legitimate interest in reliable operation | Email log: 90 days; reminder history: until the item or account is deleted |
| Security data: login timestamps and IP addresses, failed sign-in attempts, two-factor secrets (encrypted) and recovery codes (hashed), remembered-device tokens, audit trail of account actions | Detect and block abuse, protect accounts, investigate incidents | Art. 6(1)(f) legitimate interest in security; Art. 6(1)(c) legal obligation (security of processing, Art. 32) | Failed attempts: 24 hours; audit trail: 12 months, then anonymised; tokens: until they expire (30 days) or you sign out |
| Technical logs: server error logs containing timestamps, requested URL, IP address and browser user agent | Keep the Service running and secure | Art. 6(1)(f) legitimate interest | 30 days |
| Cookies: a session cookie (essential), an optional "keep me signed in" cookie, and a CSRF protection token | Keep you signed in and protect forms against forgery | Strictly necessary; no consent banner required. No advertising or analytics cookies are used. | Session: until the browser closes or after 30 minutes of inactivity; remember-me: 30 days |
We do not collect special categories of data on purpose. The notes field is free text; please do not store health, financial account numbers or other sensitive details there beyond what you need as a reminder.
3. Emails we send
- Transactional and security emails (verification, password reset, password or two-factor changes, suspicious activity). These are necessary to operate your account and cannot be opted out of while the account exists.
- Reminder emails and the optional weekly summary. These are the Service you signed up for. You control them completely: per item, per account, or with the one-click unsubscribe link in every reminder. Turning them off is honoured immediately and does not affect your account.
- We do not send marketing email and we never share your address for others to do so.
In line with CAN-SPAM, every reminder email identifies the sender, contains our postal address and a working unsubscribe mechanism.
4. Who receives your data (processors and recipients)
- Email delivery: Brevo (Sendinblue SAS, 7 rue de Madrid, 75008 Paris, France) transmits our emails. Brevo receives your email address, name (if set), and the content of each message, acting as our processor under a data processing agreement. Brevo processes data in the EU and offers Standard Contractual Clauses for any transfer outside the EEA. Brevo's own policy: brevo.com/legal/privacypolicy.
- Hosting: the Service runs on servers operated by us or by our hosting provider, who may access data only to the extent needed to provide infrastructure and under contract.
- Authorities: we disclose data when required by a valid legal request, and only the data required.
We do not sell personal data and we do not "share" it for cross-context behavioural advertising as those terms are defined by the CCPA. We do not use your data for profiling or automated decision-making that produces legal or similarly significant effects.
5. International transfers
If we or our processors transfer personal data outside the European Economic Area, the United Kingdom or Switzerland, we rely on an adequacy decision of the European Commission, the EU-US Data Privacy Framework where the recipient is certified, or Standard Contractual Clauses supplemented by technical measures such as encryption in transit and at rest. You may request a copy of the safeguards used.
6. How we protect data
- Passwords are hashed with Argon2id; they are never stored or transmitted in clear text.
- Secrets such as API keys and two-factor seeds are encrypted at rest with authenticated encryption.
- All traffic is encrypted with TLS (HTTPS) and HTTP Strict Transport Security.
- Access to the administration area requires an administrator account with recent password confirmation, and all administrative actions are recorded in an audit log.
- Rate limiting, account lockout and optional two-factor authentication protect against credential attacks.
- Security updates for the application and its server are applied promptly.
If a personal data breach is likely to result in a risk to your rights, we will notify the competent supervisory authority within 72 hours as required by Art. 33 GDPR and inform you without undue delay, as required by GDPR and by US state breach notification laws.
7. Your rights
Under the GDPR you have the right to: access your data (Art. 15), rectify it (Art. 16), have it erased (Art. 17), restrict processing (Art. 18), receive it in a portable format (portability, Art. 20), object to processing based on legitimate interest (Art. 21), withdraw consent at any time without affecting prior processing, and lodge a complaint with a supervisory authority, in particular in the EU member state of your residence or workplace.
Under the CCPA and comparable US state laws you have the right to know what personal information we collect and how we use and disclose it, to delete it, to correct inaccurate information, to opt out of sale or sharing (we do neither), to limit use of sensitive personal information (we do not use it beyond providing the Service), and to non-discrimination for exercising your rights. You may designate an authorised agent to make a request on your behalf; we will verify the agent's authority and your identity.
How to exercise them. Most rights are self-service: the account page lets you correct your name and time zone, download a complete copy of your data as JSON, change notification settings and permanently delete your account. For anything else, email fxen@tuta.io. We respond within one month (GDPR) or 45 days (CCPA), extendable once where the law allows, and we never charge for a first request. We honour Global Privacy Control signals as an opt-out of sale/sharing, which changes nothing in practice because we do not sell or share data.
8. Retention and deletion
We keep personal data only as long as stated in section 2. When you delete your account, your profile, categories, items, reminder history and remembered devices are erased immediately; audit and email log entries are anonymised so that they can no longer be linked to you. Encrypted server backups are rotated within 30 days, after which deleted data no longer exists in backups either.
9. Children
The Service is not directed to children. We do not knowingly collect data from anyone under 16 (or under 13 in the United States, in accordance with COPPA). If you believe a child has created an account, contact us and we will delete it.
10. Do Not Track
We do not track users across third-party websites and therefore do not respond differently to "Do Not Track" signals; there is nothing to opt out of.
11. Data processing on behalf of businesses
If you use the Service on behalf of an organisation and store personal data of third parties (for example employees' document expiry dates), you are the controller of that data and we act as your processor. On request we will sign a data processing agreement under Art. 28 GDPR that covers subject matter, duration, nature and purpose of processing, our security obligations, sub-processors (listed in section 4), assistance with data subject requests, deletion at the end of the service, and audit rights.
12. Changes to this policy
We may update this policy. The version date at the top changes when we do. If a change materially affects your rights, we will notify you by email or in the Service before it takes effect and, where required, ask for renewed consent.
13. Contact
[Operator name], [Operator postal address] · fxen@tuta.io