GDPR
The General Data Protection Regulation gives people in the EU and EEA a set of rights over their personal data. We extend all of them to every PocketUtils user, wherever you are.
At a glance
Extended to everyone
These rights apply to every user, not only to people inside the EU and EEA.
Export on request
Your account data, in a structured machine-readable format, whenever you ask.
Deletion means deletion
Close your account and the profile and keys go immediately, not eventually.
Who this covers
The GDPR has applied across the EU and EEA since May 2018. It governs how organisations collect, store, and use personal data, and gives individuals enforceable rights over it.
We do not check where you are before deciding which rights you get. Everything on this page is available to every user, in every country. Splitting users into privacy-haves and have-nots is not a product decision we are willing to make.
For processing carried out through PocketUtils, we are the data controller. Where you use the API to process personal data of your own users, you are the controller and we act as your processor.
Your rights
Six rights, each exercisable by email. None of them cost anything.
Access
Ask what personal data we hold about you, why we process it, how long we keep it, and who it goes to. We send a copy.
Rectification
Have inaccurate or incomplete data corrected. Most of it you can edit yourself in account settings.
Erasure
Have your data deleted when it is no longer needed, when you withdraw consent, or when it was processed unlawfully.
Portability
Receive your data in a structured, commonly used, machine-readable format and take it to another provider.
Restriction
Have processing paused while an accuracy dispute or an objection is being resolved.
Objection
Object to processing we base on legitimate interest. We stop unless we can show compelling grounds that override your rights.
Lawful basis
Every category of data we process has a basis under Article 6. We do not rely on consent for anything essential, which is why there is no banner to click.
| Data | Lawful basis | Purpose |
|---|---|---|
| Account details | Contract | Providing the service you signed up for |
| Billing details | Contract | Taking payment and issuing credits |
| Request metadata | Contract | Metering credits and reporting your usage |
| IP address | Legitimate interest | Rate limiting and abuse prevention |
| Aggregate analytics | Legitimate interest | Understanding load and improving the service |
Retention periods for each of these are listed in the Privacy Policy.
Making a request
Do it yourself
- View and edit your profile from account settings.
- Export your account data and usage history from the dashboard.
- Close your account, which deletes your profile and revokes every key.
Or ask us
Email support@pocketutils.com from the address on your account, or use the contact form. Tell us which right you are exercising. If we cannot identify you from the request we will ask for enough detail to be sure — we are not going to hand your data to someone who merely claims to be you.
We reply within 30 days, as the regulation requires, and usually far sooner. If a request is genuinely complex and needs an extension, we tell you inside the first 30 days rather than letting the deadline pass quietly.
How we comply
Data minimisation
- Using a tool page requires no personal data at all.
- An account requires a name and an email address. That is the whole list.
- Files and rendered output are processed in memory and never written to storage.
- We log that a call happened and what it cost — never what it contained.
Privacy by design
- Defaults favour privacy; nothing extra is opted into on your behalf.
- Only strictly necessary cookies are set.
- No third-party advertising or tracking is embedded anywhere on the site.
Security
- TLS in transit, encryption at rest.
- API keys stored hashed, never in plain text.
- Isolated, short-lived sandboxes for every processing job.
- Restricted, audited production access, and a documented incident response.
We are not required to appoint a Data Protection Officer at our size and processing volume. Data protection matters are handled directly by the team at support@pocketutils.com.
International transfers
Our infrastructure runs in secure data centres, and some of our processors operate outside the EEA. Where personal data crosses a border, the transfer is covered by an appropriate safeguard — Standard Contractual Clauses, or an adequacy decision of the European Commission.
Enterprise customers who need region pinning or a signed Data Processing Agreement should talk to us.
Complaints
If you think we have handled your data badly, tell us first — most problems are a misunderstanding we can fix in a day.
You also have the right to complain to your national supervisory authority, and you do not have to come to us first. You can find yours through the European Data Protection Board.
Something here unclear?
Plain-English answers beat legal text. Write to us and a human replies.