Last updated: March 1, 2026

Privacy Policy

At Rindexa, we are committed to protecting your personal data and respecting your privacy. This policy explains how we collect, use, and safeguard your information in compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the ePrivacy Directive 2002/58/EC, and other applicable data protection laws. Please also read our Terms and Conditions.

1. Data Controller

The data controller responsible for processing your personal data is:

Rindexa

Email: privacy@rindexa.com

2. What Data We Collect

We collect and process the following categories of personal data:

  • Account information: Tenant ID, email address, and hashed password provided during registration.
  • Usage data: API usage metrics, search query volumes, and indexed document counts (aggregated, non-personal).
  • Technical data: IP addresses, browser type, device information, and access timestamps collected automatically when you visit our website.
  • Cookie data: Information collected through cookies and similar technologies as described in Section 8.

3. Purpose and Legal Basis for Processing

We process your personal data for the following purposes, under the corresponding legal bases:

Purpose Legal Basis (GDPR Art. 6)
Providing and maintaining the service Performance of a contract (Art. 6.1.b)
Account creation and authentication Performance of a contract (Art. 6.1.b)
Service monitoring and improvement Legitimate interest (Art. 6.1.f)
Analytics and website optimization Consent (Art. 6.1.a)
Sending promotional and product update emails Consent (Art. 6.1.a, ePrivacy Art. 13)
Legal compliance and fraud prevention Legal obligation (Art. 6.1.c)

4. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:

  • Account data: Retained for the duration of your account. Deleted within 30 days of account closure.
  • Search index data: Retained until you delete documents or close your account.
  • Server logs: Retained for up to 90 days for security and debugging purposes.
  • Analytics data: Retained for up to 26 months in aggregated form.

5. Your Rights under GDPR

As a data subject, you have the following rights under the GDPR:

  • Right of access (Art. 15): Obtain confirmation and a copy of your personal data.
  • Right to rectification (Art. 16): Correct inaccurate personal data.
  • Right to erasure (Art. 17): Request deletion of your personal data ("right to be forgotten").
  • Right to restriction (Art. 18): Restrict processing under certain conditions.
  • Right to data portability (Art. 20): Receive your data in a structured, machine-readable format.
  • Right to object (Art. 21): Object to processing based on legitimate interest.
  • Right to withdraw consent (Art. 7.3): Withdraw consent at any time without affecting prior processing.

To exercise any of these rights, please contact us at privacy@rindexa.com. We will respond within 30 days.

6. Data Sharing and Transfers

We do not sell your personal data. We may share data with the following categories of recipients:

  • Hosting provider: Vercel Inc. (United States) — for website and application hosting.
  • Database provider: PostgreSQL hosting services for data persistence.
  • Payment processor: Stripe Inc. — for subscription billing (if applicable).

For transfers to countries outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) as approved by the European Commission.

7. Data Security

We implement appropriate technical and organizational measures to protect your personal data, including:

  • Encryption of data in transit (TLS/HTTPS) and at rest.
  • Passwords are hashed using industry-standard algorithms (bcrypt/argon2).
  • API keys are prefixed and hashed; only the prefix is stored in plaintext.
  • Tenant isolation ensures no data leakage between customers.
  • Rate limiting and HMAC webhook signature validation to prevent abuse.

8. Cookies

Our website uses cookies and similar technologies. You can manage your cookie preferences through the cookie banner displayed on your first visit.

Type Purpose Duration
Essential Required for basic website functionality and cookie consent preferences. Session / 1 year
Analytics Help us understand how visitors interact with the website (e.g., Vercel Analytics). Up to 26 months

You can withdraw your cookie consent at any time by clearing your browser's local storage or cookies for this site.

9. Marketing Communications

During registration, you may opt in to receive product updates, tips, and promotional emails from Rindexa. This consent is freely given, specific, informed, and unambiguous, in compliance with GDPR Article 7 and the ePrivacy Directive (2002/58/EC, Article 13).

You have the right to withdraw your consent at any time, without affecting the lawfulness of processing carried out prior to withdrawal. You can do so by:

  • Clicking the unsubscribe link included in every marketing email.
  • Contacting us at privacy@rindexa.com.

Transactional emails (account confirmation, security alerts, service changes) are sent on the basis of contract performance (Art. 6.1.b) and will continue regardless of marketing preferences.

10. Third-Party Links

Our website may contain links to third-party websites. We are not responsible for the privacy practices of those sites. We encourage you to read their respective privacy policies.

11. Children's Privacy

Our services are not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have collected such data, please contact us and we will promptly delete it.

12. Changes to This Policy

We may update this privacy policy from time to time. Material changes will be communicated via the email address associated with your account at least 30 days before they take effect, and through a prominent notice on our website. The "Last updated" date at the top of this page reflects the most recent revision.

13. Supervisory Authority

If you believe that our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority in the EU Member State of your habitual residence, place of work, or place of the alleged infringement.

Contact Us

For any questions or requests regarding this privacy policy or your personal data, please contact:

privacy@rindexa.com