Privacy Policy

Effective: July 2026

1. Controller

Frederik von der Heyden
Danzigweg 5a
59755 Arnsberg
Germany

Email: frederik@frederikvonderheyden.de
Phone: +49 172 1600313

2. Overview of processing

DSGVO Shield is an API that classifies text for personal data (PII). This policy explains which data are processed when the website and API are used.

Types of data

Data subjects

3. Legal bases

4. API data processing

The classification API (/v2/classify) processes the following data:

DataPurposeRetention schedule
API keyAuthenticationUntil contract termination or revocation
Key/IP fingerprintsRate limiting and abuse prevention7 days
Request IDTraceability90 days
Classification levelAudit log90 days
Text length (bytes)Usage statistics90 days
Response time (ms)Performance monitoring90 days

Important: Submitted text is not stored. Only classification results (level and categories) and metadata (text length and response time) are logged. Content is processed only in memory. IP and key references used for abuse prevention are pseudonymized with an installation-specific HMAC before storage.

5. Key request (contact form)

A request for an API key processes:

These data are used only to process the request and are deleted after the key is issued or declined, no later than six months after submission.

6. Hosting and server logs

Provider: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany

Data collected:

Retention schedule: 30 days. Deletion is performed through log rotation and operational maintenance.

7. Privacy-friendly web analytics

DSGVO Shield uses self-hosted Umami Analytics to understand aggregate website usage. Umami is operated on our servers in Germany, sets no cookies, creates no cross-site profiles, and does not transmit analytics data to Umami Software.

We process page views, referrer, approximate device and browser information, and country derived from the IP address. The IP address is used only to process the request and is not stored in the analytics database. Session replay is disabled. Submitted API text, key request contents, form fields, URL query parameters, and URL fragments are not collected by analytics. Aggregate analytics records are retained for no more than 24 months.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is to evaluate the reach and usability of this website. You may object to this processing by enabling your browser's Do Not Track setting or by using our analytics opt-out. The opt-out is stored locally in your browser.

8. International transfers

The classification API and its content processing run on servers in Germany. Payment and email delivery use the providers named in the relevant contract and data processing terms. Their processing must be assessed separately and is not represented as free of third-country transfers.

9. Processing on behalf of customers

For business use in which text is classified on a customer's behalf, we provide a data processing agreement (DPA) on request. It defines responsibilities, instructions, technical and organizational measures, and deletion periods.

10. Retention schedules

DataPeriod
API audit logs90 days
Pseudonymized abuse fingerprints7 days
Key requestsUp to 6 months
Server logs30 days

These are configured retention schedules. File rotation and operational maintenance perform deletion; a period is not a representation that every inactive file is erased at the exact second the period expires.

11. Your rights

You have the following rights regarding your personal data:

12. SSL/TLS encryption

All website and API connections use TLS encryption (HTTPS). Unencrypted connections are redirected automatically.

13. Changes

This privacy policy may be updated when necessary. The current version is always available at this URL.