Privacy Policy

Last updated: July 29, 2026

BankVerter Privacy Policy

Last updated: July 27, 2026

Data Controller

Lobesoft LLC (the "Company", "we", "our", "us") operates as a data controller for personal data collected through the BankVerter service.

Registered address: Mikheil Gakhokidze 49, 0182 Tbilisi, Georgia Contact: [email protected]

What Data We Collect

DataPurposeLegal BasisRetention
Email addressAccount identification, login, password reset, verificationConsent (Art 6(1)(a))Until account deletion + 30 days
Password hash (argon2id)AuthenticationNecessary for contract (Art 6(1)(b))Until account deletion
Display name (optional)Profile personalizationConsent (Art 6(1)(a))Until account deletion
Country (optional)Analytics, feature optimizationConsent (Art 6(1)(a))Until account deletion
IP addressSecurity, rate limiting, audit loggingLegitimate interest (Art 6(1)(f))90 days in logs
Session activityService functionality, session managementNecessary for contract (Art 6(1)(b))30 days after session expiry
Parse history metadataService functionality, usage analyticsConsent (Art 6(1)(a))Until account deletion

Your Rights (GDPR Articles 15-22)

  • Right to access (Art 15): Export your data via the account settings page
  • Right to rectification (Art 16): Update your profile information in account settings
  • Right to erasure (Art 17): Delete your account — data is erased within 30 days
  • Right to restrict processing (Art 18): Contact us to restrict processing
  • Right to data portability (Art 20): Export your data in machine-readable JSON format
  • Right to object (Art 21): Object to processing for analytics at any time

Data Processing

  • PDF files you upload are processed in your browser and on our secure servers (OCR and AI parsing). Your PDF content is used only to produce your CSV and is never shared, sold, or used for any other purpose.
  • Account data (email, password hash, session activity) is stored on our server using SQLite.
  • We do not share your data with third parties for marketing or analytics.
  • Payment processing is handled by Paddle.com Inc. and Paddle Payments Ltd. as Merchant of Record. Payment data (name, billing address, payment method details) is shared with Paddle, who acts as an independent data controller. See Paddle's Privacy Policy.
  • Our server infrastructure is hosted by Hetzner Online GmbH, acting as a data processor under GDPR Art 28. We have entered into a Data Processing Agreement with Hetzner as required by GDPR Art 28.
  • We use essential session cookies only (no tracking, analytics, or advertising cookies).

Data Security

  • Passwords are hashed with argon2id (memory-hard, OWASP-recommended parameters)
  • Sessions use opaque random tokens with SHA-256 hashing in the database
  • All traffic is encrypted via HTTPS
  • The database is stored locally on the server with file-system permissions

Data Retention

  • Account data: retained until you delete your account, then erased within 30 days
  • Audit logs: retained for 3 years after account deletion (legal obligation, Art 17(3)(e))
  • Consent records: retained for 3 years after withdrawal (accountability, Art 5(2))
  • IP addresses in logs: 90 days

Changes to This Policy

We may update this privacy policy from time to time. Material changes will be notified by email at least 30 days before they take effect. Continued use of the service after the effective date constitutes acceptance of the updated policy.

Governing Law

This privacy policy is governed by the laws of Georgia, without regard to its conflict of laws provisions.

Contact

For GDPR requests: [email protected]