Privacy Policy
Privacy Policy
Data controller: MSoftware & Consulting s.r.o., Jelenia 1, 811 05 Bratislava, Slovakia (IČO 48212733, VAT SK2120090544) Contact: info@jsonfabrica.com
This Privacy Policy explains what personal data JsonFabrica ("the Service") collects, why, and what rights you have over it. Because we are established in the European Union, the EU General Data Protection Regulation ("GDPR") applies to our processing of your personal data.
1. What Personal Data We Collect
- Account data: your email address, provided at signup.
- Billing/payment data: billing details and payment method information, collected and processed on our behalf by our payment processor (see "Subprocessors" below). We do not store full card numbers ourselves.
- Usage and API logs: records of API requests made to the Service (e.g. timestamps, endpoint called, tenant/account identifier, usage volume), used for billing, metering, security, and troubleshooting.
We do not intentionally collect personal data contained within the synthetic JSON documents our customers generate — that data is synthetic/fabricated by design and is not sourced from real individuals. The Service is designed to handle only synthetic, non-sensitive data, and customers must not submit real sensitive data as template inputs or seed values — see Terms of Service, Sections 4 and 8.
2. Why We Process Your Data, and Legal Basis
| Purpose | Legal basis |
|---|---|
| Creating and managing your account | Performance of a contract with you |
| Billing and payment collection | Performance of a contract with you |
| Operating, securing, and monitoring the Service | Legitimate interest |
| Responding to support requests | Performance of a contract with you |
| Fraud/abuse prevention | Legitimate interest |
3. Data Retention
We retain account, billing, and usage-log data for as long as your account is active, and for a limited period afterward as needed for legal, tax, and accounting obligations.
Account data and API/usage logs are retained for up to 1 year after account closure, after which they are deleted. Billing and invoice records are retained separately for the period required by Slovak accounting law (approximately 10 years), regardless of when the account is closed.
4. Your Rights Under GDPR
As a data subject, you have the right to:
- Access the personal data we hold about you.
- Rectification of inaccurate or incomplete personal data.
- Erasure of your personal data, subject to legal/contractual retention requirements (e.g. billing records).
- Data portability, where technically feasible.
- Object to processing based on legitimate interest.
To exercise any of these rights, contact us at info@jsonfabrica.com. You also have the right to lodge a complaint with your local data protection supervisory authority, or with Slovakia's Office for Personal Data Protection (Úrad na ochranu osobných údajov SR).
We have not appointed a Data Protection Officer, as our processing activities do not meet the GDPR Article 37 threshold requiring one (no large-scale systematic monitoring and no large-scale processing of special-category data). As an EU-established controller, we are also not required to appoint a separate EU representative under GDPR Article 27, which applies only to non-EU controllers.
5. Subprocessors / Third-Party Data Processors
We use the following third-party service providers to operate the Service. Each processes personal data only to the extent necessary to provide their respective service to us.
- Stripe — payment processing.
- MongoDB Atlas — database hosting (once migrated off local/self-hosted MongoDB; see issue #4). At the time of writing, the Service's database runs on self-hosted MongoDB rather than MongoDB Atlas.
- Fly.io — application hosting (once deployed there; see issue #11). At the time of writing, the Service is not deployed on Fly.io.
- Google Workspace — business email.
- Transactional/outbound email (e.g. signup confirmations): sent via standard SMTP delivery when configured, without a bound-in third-party email API provider at this time.
- Error tracking/monitoring: planned, not yet integrated (see issues #2 and #8).
[VERIFY: final subprocessor list and this section's wording once hosting (issue #11), database (issue #4), transactional-email, and monitoring integrations are finalized]
6. International Data Transfers
[VERIFY: whether any of the listed subprocessors transfer personal data outside the EU/EEA, and what transfer safeguard applies (e.g. Standard Contractual Clauses) — confirm with counsel per each subprocessor's current data-processing terms]
7. Contact
Questions about this Privacy Policy or your personal data can be sent to info@jsonfabrica.com.