Privacy Policy
Last updated: July 29, 2026
BankVerter Privacy Policy
Last updated: July 27, 2026
Data Controller
Lobesoft LLC (the "Company", "we", "our", "us") operates as a data controller for personal data collected through the BankVerter service.
Registered address: Mikheil Gakhokidze 49, 0182 Tbilisi, Georgia Contact: [email protected]
What Data We Collect
| Data | Purpose | Legal Basis | Retention |
|---|---|---|---|
| Email address | Account identification, login, password reset, verification | Consent (Art 6(1)(a)) | Until account deletion + 30 days |
| Password hash (argon2id) | Authentication | Necessary for contract (Art 6(1)(b)) | Until account deletion |
| Display name (optional) | Profile personalization | Consent (Art 6(1)(a)) | Until account deletion |
| Country (optional) | Analytics, feature optimization | Consent (Art 6(1)(a)) | Until account deletion |
| IP address | Security, rate limiting, audit logging | Legitimate interest (Art 6(1)(f)) | 90 days in logs |
| Session activity | Service functionality, session management | Necessary for contract (Art 6(1)(b)) | 30 days after session expiry |
| Parse history metadata | Service functionality, usage analytics | Consent (Art 6(1)(a)) | Until account deletion |
Your Rights (GDPR Articles 15-22)
- Right to access (Art 15): Export your data via the account settings page
- Right to rectification (Art 16): Update your profile information in account settings
- Right to erasure (Art 17): Delete your account — data is erased within 30 days
- Right to restrict processing (Art 18): Contact us to restrict processing
- Right to data portability (Art 20): Export your data in machine-readable JSON format
- Right to object (Art 21): Object to processing for analytics at any time
Data Processing
- PDF files you upload are processed in your browser and on our secure servers (OCR and AI parsing). Your PDF content is used only to produce your CSV and is never shared, sold, or used for any other purpose.
- Account data (email, password hash, session activity) is stored on our server using SQLite.
- We do not share your data with third parties for marketing or analytics.
- Payment processing is handled by Paddle.com Inc. and Paddle Payments Ltd. as Merchant of Record. Payment data (name, billing address, payment method details) is shared with Paddle, who acts as an independent data controller. See Paddle's Privacy Policy.
- Our server infrastructure is hosted by Hetzner Online GmbH, acting as a data processor under GDPR Art 28. We have entered into a Data Processing Agreement with Hetzner as required by GDPR Art 28.
- We use essential session cookies only (no tracking, analytics, or advertising cookies).
Data Security
- Passwords are hashed with argon2id (memory-hard, OWASP-recommended parameters)
- Sessions use opaque random tokens with SHA-256 hashing in the database
- All traffic is encrypted via HTTPS
- The database is stored locally on the server with file-system permissions
Data Retention
- Account data: retained until you delete your account, then erased within 30 days
- Audit logs: retained for 3 years after account deletion (legal obligation, Art 17(3)(e))
- Consent records: retained for 3 years after withdrawal (accountability, Art 5(2))
- IP addresses in logs: 90 days
Changes to This Policy
We may update this privacy policy from time to time. Material changes will be notified by email at least 30 days before they take effect. Continued use of the service after the effective date constitutes acceptance of the updated policy.
Governing Law
This privacy policy is governed by the laws of Georgia, without regard to its conflict of laws provisions.
Contact
For GDPR requests: [email protected]