Privacy Policy
Effective: July 2026
1. Controller
Frederik von der Heyden
Danzigweg 5a
59755 Arnsberg
Germany
Email: frederik@frederikvonderheyden.de
Phone: +49 172 1600313
2. Overview of processing
DSGVO Shield is an API that classifies text for personal data (PII). This policy explains which data are processed when the website and API are used.
Types of data
- Contact data (name and email submitted with a key request)
- Usage data (API calls, timestamps, and text length)
- Metadata and communication data (pseudonymized security reference and browser information)
Data subjects
- Website visitors
- API users (businesses and developers)
- People whose data occur in classified text
3. Legal bases
- Art. 6(1)(a) GDPR — consent (key request)
- Art. 6(1)(b) GDPR — performance of a contract (API use)
- Art. 6(1)(f) GDPR — legitimate interests (security and abuse prevention)
4. API data processing
The classification API (/v2/classify) processes the following data:
| Data | Purpose | Retention schedule |
|---|---|---|
| API key | Authentication | Until contract termination or revocation |
| Key/IP fingerprints | Rate limiting and abuse prevention | 7 days |
| Request ID | Traceability | 90 days |
| Classification level | Audit log | 90 days |
| Text length (bytes) | Usage statistics | 90 days |
| Response time (ms) | Performance monitoring | 90 days |
Important: Submitted text is not stored. Only classification results (level and categories) and metadata (text length and response time) are logged. Content is processed only in memory. IP and key references used for abuse prevention are pseudonymized with an installation-specific HMAC before storage.
5. Key request (contact form)
A request for an API key processes:
- Name / company
- Email address
- Use case
- Description
These data are used only to process the request and are deleted after the key is issued or declined, no later than six months after submission.
6. Hosting and server logs
Provider: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany
Data collected:
- IP address
- Browser type and version
- Operating system
- Referrer URL
- Access timestamp
Retention schedule: 30 days. Deletion is performed through log rotation and operational maintenance.
7. Privacy-friendly web analytics
DSGVO Shield uses self-hosted Umami Analytics to understand aggregate website usage. Umami is operated on our servers in Germany, sets no cookies, creates no cross-site profiles, and does not transmit analytics data to Umami Software.
We process page views, referrer, approximate device and browser information, and country derived from the IP address. The IP address is used only to process the request and is not stored in the analytics database. Session replay is disabled. Submitted API text, key request contents, form fields, URL query parameters, and URL fragments are not collected by analytics. Aggregate analytics records are retained for no more than 24 months.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is to evaluate the reach and usability of this website. You may object to this processing by enabling your browser's Do Not Track setting or by using our analytics opt-out. The opt-out is stored locally in your browser.
8. International transfers
The classification API and its content processing run on servers in Germany. Payment and email delivery use the providers named in the relevant contract and data processing terms. Their processing must be assessed separately and is not represented as free of third-country transfers.
9. Processing on behalf of customers
For business use in which text is classified on a customer's behalf, we provide a data processing agreement (DPA) on request. It defines responsibilities, instructions, technical and organizational measures, and deletion periods.
10. Retention schedules
| Data | Period |
|---|---|
| API audit logs | 90 days |
| Pseudonymized abuse fingerprints | 7 days |
| Key requests | Up to 6 months |
| Server logs | 30 days |
These are configured retention schedules. File rotation and operational maintenance perform deletion; a period is not a representation that every inactive file is erased at the exact second the period expires.
11. Your rights
You have the following rights regarding your personal data:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection (Art. 21 GDPR)
- Withdrawal of consent (Art. 7(3) GDPR)
- Complaint to a supervisory authority — LDI NRW, Kavalleriestrasse 2-4, 40213 Duesseldorf, Germany
12. SSL/TLS encryption
All website and API connections use TLS encryption (HTTPS). Unencrypted connections are redirected automatically.
13. Changes
This privacy policy may be updated when necessary. The current version is always available at this URL.