[{"data":1,"prerenderedAt":10},["ShallowReactive",2],{"legal:en:privacy-policy":3},{"id":4,"title":5,"version":6,"effectiveDate":7,"language":8,"html":9},"privacy-policy","Privacy Policy","1.3.0","2026-08-27","en","\u003Cp>This policy explains what personal data Postqron processes, why, and what you can do\nabout it. It is written to be read, not to be survived.\u003C\u002Fp>\n\u003Ch2>1. Who is responsible\u003C\u002Fh2>\n\u003Cp>The controller of your personal data is\nApdsoftware di Carlo Zuffetti, Via C. Colombo 15, 24047 Treviglio (BG), Italy — VAT 03835250162, REA BG 431224.\u003C\u002Fp>\n\u003Cp>You can reach us at\n\u003Ca href=\"mailto:privacy@postqron.com\">privacy@postqron.com\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>We have not appointed a Data Protection Officer: our processing does not meet the\nconditions of Art. 37 GDPR — we are not a public authority, our core activity is not\nlarge-scale systematic monitoring, and we do not process special categories of data at\nscale. Privacy requests go to the address above and are handled by us directly.\u003C\u002Fp>\n\u003Ch2>2. What we process, and why\u003C\u002Fh2>\n\u003Ch3>2.1 Account and authentication\u003C\u002Fh3>\n\u003Cp>Email address, password (stored only as an Argon2id hash — we never hold the password\nitself), preferred language, sessions and their expiry, and the tokens used to verify\nyour address or reset your password.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Why:\u003C\u002Fstrong> to provide the service you asked for. \u003Cstrong>Legal basis:\u003C\u002Fstrong> performance of a\ncontract (Art. 6(1)(b) GDPR).\u003C\u002Fp>\n\u003Ch3>2.2 Jobs and executions\u003C\u002Fh3>\n\u003Cp>The schedules you define, the destination addresses, HTTP methods, headers and bodies\nyou configure, and for every execution: the time it started and ended, its duration,\nthe outcome, the HTTP status, a truncated extract of the response and the attempt\nnumber.\u003C\u002Fp>\n\u003Cp>Two things worth stating plainly. First, \u003Cstrong>you decide what goes into a job\u003C\u002Fstrong>: if you\nput personal data in a URL, a header or a body, we will process it because you put it\nthere. Second, \u003Cstrong>response extracts are stored\u003C\u002Fstrong>, so if the system you call returns\npersonal data, that data reaches our logs.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Why:\u003C\u002Fstrong> to run the service and to let you see what happened. \u003Cstrong>Legal basis:\u003C\u002Fstrong>\nperformance of a contract.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Retention:\u003C\u002Fstrong> execution logs are kept for the period of your plan — 3, 15, 30 or 90\ndays — and then deleted.\u003C\u002Fp>\n\u003Ch3>2.3 Repository synchronisation\u003C\u002Fh3>\n\u003Cp>If you connect a GitHub repository, we process the repository identifier, the events\nGitHub sends us when you push, and the content of the \u003Ccode>cron.yaml\u003C\u002Fcode> file. We request\nread-only access to repository contents and metadata, and nothing else.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Legal basis:\u003C\u002Fstrong> performance of a contract.\u003C\u002Fp>\n\u003Ch3>2.4 Secrets and credentials\u003C\u002Fh3>\n\u003Cp>Workspace secrets, API keys and AI provider keys are encrypted at rest, never returned\nin readable form after they are saved, and never written to logs.\u003C\u002Fp>\n\u003Ch3>2.5 Billing\u003C\u002Fh3>\n\u003Cp>Payments are handled by Paddle as Merchant of Record (§4). We receive the subscription\nstatus, plan and the identifiers needed to reconcile it. \u003Cstrong>We never see your payment\ncard.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Two things you give us directly, before Paddle is involved: your \u003Cstrong>confirmation that\nyou are buying for professional use\u003C\u002Fstrong> (§3 of the Terms) and, if you have one, your\n\u003Cstrong>VAT number\u003C\u002Fstrong>. You type both into our form, so we hold them — Paddle receives them\ntoo, for the invoice.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Legal basis:\u003C\u002Fstrong> performance of a contract and legal obligation for tax records.\u003C\u002Fp>\n\u003Ch3>2.6 Security and audit\u003C\u002Fh3>\n\u003Cp>Records of sensitive events: sign-ins, changes of plan, key revocation, administrative\nimpersonation. Technical logs are structured to exclude secrets and personal data that\nis not necessary.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Legal basis:\u003C\u002Fstrong> legitimate interest in operating a secure service (Art. 6(1)(f)),\nand legal obligation where applicable.\u003C\u002Fp>\n\u003Ch3>2.7 Transactional email\u003C\u002Fh3>\n\u003Cp>We send email you need in order to use the service: welcome, failed-job alerts, plan\nchanges, security events. These are not marketing and you cannot unsubscribe from them\nwithout closing your account, because they are how the service tells you things.\u003C\u002Fp>\n\u003Ch3>2.8 Marketing email\u003C\u002Fh3>\n\u003Cp>If you agree to it, we send you email about the product: new features, changes worth\nknowing about, occasionally something we have written.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>This is separate from the email above in every respect.\u003C\u002Fstrong> The legal basis is your\n\u003Cstrong>consent\u003C\u002Fstrong> (Art. 6(1)(a)), asked for on its own and never bundled with accepting the\nterms or creating an account. Refusing costs you nothing: the service works the same.\u003C\u002Fp>\n\u003Cp>Every marketing message carries an unsubscribe link that works with one click and\nwithout signing in. Unsubscribing stops marketing email only — you keep receiving the\ntransactional email the service needs to send you, because that is not marketing.\u003C\u002Fp>\n\u003Cp>We keep a record of when you consented and when you withdrew, which is how we can show\nthat we had the right to write to you.\u003C\u002Fp>\n\u003Ch3>2.9 Consent records\u003C\u002Fh3>\n\u003Cp>When you accept our Terms, Privacy Policy, Acceptable Use Policy or Cookie Policy, we\nrecord \u003Cstrong>which version you accepted, when, and in which language you read it\u003C\u002Fstrong>. When a\ndocument changes and you accept the new version, that is a new record; the earlier one\nstays.\u003C\u002Fp>\n\u003Cp>This is not the same as the marketing consent in §2.8, which you can withdraw. This one\nis the evidence that you agreed to the terms under which we provide the service, and\nwhat exactly those terms said at the time — including the language, because a\ntranslation you never read would be poor evidence of what you agreed to.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Legal basis:\u003C\u002Fstrong> legal obligation and our legitimate interest in being able to show what\nwas agreed (Art. 6(1)(c) and (f)).\u003C\u002Fp>\n\u003Ch3>2.10 Website analytics\u003C\u002Fh3>\n\u003Cp>If you agree to it, we measure how our website is used: the pages opened, the site you\narrived from, and the country, browser and device type derived from the request. This\nruns through \u003Cstrong>Cloudflare Web Analytics\u003C\u002Fstrong> (§4), which writes nothing to your device,\nbuilds no identifier that follows you between visits or between sites, and produces\ncounts rather than profiles. We do not use it to recognise you, and it is not connected\nto your account.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Why:\u003C\u002Fstrong> to know which parts of the site are read and which are not, so that what we\npublish gets better. \u003Cstrong>Legal basis:\u003C\u002Fstrong> your \u003Cstrong>consent\u003C\u002Fstrong> (Art. 6(1)(a) GDPR), asked for\nbefore anything loads and refusable with a single click. Refusing costs you nothing: the\nsite works exactly the same, and you can withdraw at any time from the link in the\nfooter.\u003C\u002Fp>\n\u003Cp>The \u003Ca href=\"\u002Fen\u002Flegal\u002Fcookie-policy\u002F\">Cookie Policy\u003C\u002Fa> §2.2 describes this in full, including why we ask\nfor your consent even though this technology sets no cookies at all.\u003C\u002Fp>\n\u003Ch2>3. AI features: a transfer you should understand\u003C\u002Fh2>\n\u003Cp>If you enable AI-assisted debugging, you supply \u003Cstrong>your own\u003C\u002Fstrong> API key for an AI provider\n(OpenAI, Anthropic or another). When you use the feature, the content of the execution\nlog you are analysing is sent to that provider under your key and their terms.\u003C\u002Fp>\n\u003Cp>This means your data leaves our infrastructure and reaches a third party \u003Cstrong>that you\nchose\u003C\u002Fstrong>, under a contract \u003Cstrong>between you and them\u003C\u002Fstrong>. We are not a party to it, we do\nnot control what they do with the content, and their retention rules apply, not ours.\u003C\u002Fp>\n\u003Cp>The feature is off unless you turn it on, and each analysis is a deliberate action. We\nask for your explicit consent before the first transfer.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Legal basis:\u003C\u002Fstrong> consent (Art. 6(1)(a)), which you can withdraw at any time by\nremoving your key. Withdrawal does not affect transfers already made.\u003C\u002Fp>\n\u003Ch2>4. Who else processes your data\u003C\u002Fh2>\n\u003Cp>We use these providers. Each processes data on our instructions, under a data\nprocessing agreement.\u003C\u002Fp>\n\u003Ctable>\n\u003Cthead>\n\u003Ctr>\n\u003Cth>Provider\u003C\u002Fth>\n\u003Cth>Role\u003C\u002Fth>\n\u003Cth>Where\u003C\u002Fth>\n\u003C\u002Ftr>\n\u003C\u002Fthead>\n\u003Ctbody>\u003Ctr>\n\u003Ctd>Hetzner\u003C\u002Ftd>\n\u003Ctd>Servers and database\u003C\u002Ftd>\n\u003Ctd>Germany\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Cloudflare\u003C\u002Ftd>\n\u003Ctd>DNS, TLS, CDN, static hosting, edge protection, website analytics (§2.10)\u003C\u002Ftd>\n\u003Ctd>Global edge network\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Paddle\u003C\u002Ftd>\n\u003Ctd>Merchant of Record: payments, invoicing, tax\u003C\u002Ftd>\n\u003Ctd>United Kingdom\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Mailronix\u003C\u002Ftd>\n\u003Ctd>Transactional email delivery\u003C\u002Ftd>\n\u003Ctd>European Union — operated by Apdsoftware, the same entity that operates Postqron\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>GitHub\u003C\u002Ftd>\n\u003Ctd>Repository synchronisation, only if you connect one\u003C\u002Ftd>\n\u003Ctd>United States\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003C\u002Ftbody>\u003C\u002Ftable>\n\u003Cp>We keep this list current. If we add or change a provider in a way that affects you,\nwe update this policy and, where the change is material, we tell you before it takes\neffect.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Transfers outside the EEA.\u003C\u002Fstrong> Some providers process data outside the European\nEconomic Area. Where that happens we rely on the safeguards in Art. 46 GDPR, primarily\nthe European Commission&#39;s Standard Contractual Clauses, together with the provider&#39;s\nown technical measures.\u003C\u002Fp>\n\u003Ch2>5. How long we keep things\u003C\u002Fh2>\n\u003Ctable>\n\u003Cthead>\n\u003Ctr>\n\u003Cth>Data\u003C\u002Fth>\n\u003Cth>Kept\u003C\u002Fth>\n\u003C\u002Ftr>\n\u003C\u002Fthead>\n\u003Ctbody>\u003Ctr>\n\u003Ctd>Account and profile\u003C\u002Ftd>\n\u003Ctd>While the account exists\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Execution logs\u003C\u002Ftd>\n\u003Ctd>3, 15, 30 or 90 days, by plan\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Audit records\u003C\u002Ftd>\n\u003Ctd>24 months\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Consent records (§2.9)\u003C\u002Ftd>\n\u003Ctd>While the account exists\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Billing and tax records\u003C\u002Ftd>\n\u003Ctd>As required by law, typically 10 years\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Website analytics (§2.10)\u003C\u002Ftd>\n\u003Ctd>7 days of unsampled measurements, then aggregate statistics for 6 months\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Backups\u003C\u002Ftd>\n\u003Ctd>30 days\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003C\u002Ftbody>\u003C\u002Ftable>\n\u003Cp>The consent records deserve their own sentence, because the obvious guess about them is\nwrong. They go when the account goes. They are the evidence that you agreed to the terms\nunder which we served you — not a tax record — and keeping them after you have asked us\nto delete everything would mean holding personal data about someone we told we had\nremoved. Keeping them without your name would be worse than useless: a proof of consent\nthat cannot say whose it is proves nothing.\u003C\u002Fp>\n\u003Cp>When you delete your account we stop execution and revoke keys immediately, then\nremove the data after a grace period of\n30 days,\nduring which you can change your mind. Data already written to backups disappears as\nthose backups rotate out. Records we must keep for tax or legal reasons survive\ndeletion, and only those.\u003C\u002Fp>\n\u003Cp>One thing outlives deletion without being about you any more. Where an administrator\nhas acted on your account, our security log keeps a record of what \u003Cstrong>they\u003C\u002Fstrong> did, with\nevery reference to you removed. What remains says that an action happened and who took\nit; it no longer says to whom. We keep it because otherwise closing an account would\nerase the evidence of someone else&#39;s access to it. This is not a record we keep for\ntax or legal reasons — it is a security record about another person&#39;s actions.\u003C\u002Fp>\n\u003Ch2>6. Your rights\u003C\u002Fh2>\n\u003Cp>You can ask us to give you a copy of your data, correct it, delete it, restrict or\nobject to its processing, or provide it in a portable format. You can withdraw consent\nwhere processing is based on consent.\u003C\u002Fp>\n\u003Cp>Export and deletion are available in the application without asking us. For anything\nelse, write to us and we will respond within one month.\u003C\u002Fp>\n\u003Cp>If you believe we are handling your data wrongly, you can complain to your national\nsupervisory authority. In Italy that is the \u003Cem>Garante per la protezione dei dati\npersonali\u003C\u002Fem>.\u003C\u002Fp>\n\u003Ch2>7. Security\u003C\u002Fh2>\n\u003Cp>We encrypt secrets at rest, hash passwords with Argon2id, keep logs free of\ncredentials, verify the signature of incoming webhooks, rate-limit authentication, and\nrecord sensitive events in an audit log.\u003C\u002Fp>\n\u003Cp>We should also tell you what we do not have: Postqron runs on a single server, chosen\ndeliberately so that the scheduler and the database sit next to each other. That\nchoice trades resilience for latency. We take backups and we have tested restoring\nthem, but a failure of that machine interrupts the service.\u003C\u002Fp>\n\u003Ch2>8. Automated decisions\u003C\u002Fh2>\n\u003Cp>We do not make decisions with legal or similarly significant effects about you by\nautomated means, and we do not profile you.\u003C\u002Fp>\n\u003Ch2>9. Children\u003C\u002Fh2>\n\u003Cp>Postqron is not intended for people under\n16.\nWe do not knowingly collect their data.\u003C\u002Fp>\n\u003Ch2>10. Changes\u003C\u002Fh2>\n\u003Cp>We may update this policy. The version and effective date are at the top. When a\nchange is material we tell you before it takes effect and, where the law requires it,\nask for your consent again.\u003C\u002Fp>\n\u003Chr>\n\u003Cp>\u003Cstrong>Contact:\u003C\u002Fstrong> \u003Ca href=\"mailto:privacy@postqron.com\">privacy@postqron.com\u003C\u002Fa>\n\u003Cstrong>Operated by:\u003C\u002Fstrong> Apdsoftware di Carlo Zuffetti, Via C. Colombo 15, 24047 Treviglio (BG), Italy — VAT 03835250162, REA BG 431224\u003C\u002Fp>\n",1788438713269]