GDPR Compliance

InfiniUm Tools is built for EU users. Our server is hosted in Frankfurt, Germany (EU). We collect minimal data, use privacy-preserving analytics, and never sell personal data. This page explains our GDPR compliance in plain language.

Contents
  1. Data Controller
  2. GDPR Principles We Follow
  3. Lawful Basis for Processing
  4. Your Rights Under GDPR
  5. International Data Transfers
  6. Data Protection Measures
  7. Data Breach Procedure
  8. Contact & Complaints

1. Data Controller

InfiniUm Tools acts as the data controller for personal data processed through infinium.tools. As data controller, we determine the purposes and means of processing your personal data.

Contact: contact@infinium.tools

We do not currently require a Data Protection Officer (DPO) as we do not process large volumes of sensitive personal data. However, all privacy inquiries are handled directly and promptly.

2. GDPR Principles We Follow

PrincipleHow we apply it
Lawfulness, fairness, transparencyWe document all processing activities and publish this information publicly
Purpose limitationData collected for tool functionality is not used for any other purpose
Data minimisationWe collect only what is strictly necessary β€” tool inputs are not stored
AccuracyAccount data can be updated at any time from the dashboard
Storage limitationServer logs: 7 days. Rate limit counters: 24 hours. Account data: until deletion
Integrity & confidentialityTLS 1.3, bcrypt password hashing, firewall-restricted server access
AccountabilityWe maintain records of processing activities and respond to all GDPR requests

3. Lawful Basis for Processing

Processing activityLawful basisDetails
Running tool requestsContract performance (Art. 6(1)(b))Necessary to provide the service you requested
Account managementContract performance (Art. 6(1)(b))Necessary to manage your account and plan
Rate limitingLegitimate interests (Art. 6(1)(f))Preventing abuse and ensuring fair service for all users
Security loggingLegitimate interests (Art. 6(1)(f))Detecting and preventing security threats
Payment processingContract performance (Art. 6(1)(b))Processing Pro/Team subscriptions via Stripe
Payment records retentionLegal obligation (Art. 6(1)(c))Required by EU tax law (7 years)
Analytics (aggregated)Legitimate interests (Art. 6(1)(f))Privacy-preserving, cookieless Umami analytics
Transactional emailContract performance (Art. 6(1)(b))Account verification, password reset only

4. Your Rights Under GDPR

πŸ“‹ Right of Access (Art. 15)

Request a complete copy of all personal data we hold about you.

✏️ Right to Rectification (Art. 16)

Correct inaccurate or incomplete personal data. Update from your dashboard or contact us.

πŸ—‘οΈ Right to Erasure (Art. 17)

Request deletion of your personal data. Delete your account from the dashboard for immediate erasure.

⏸️ Right to Restrict Processing (Art. 18)

Request that we limit how we process your data while a dispute is resolved.

πŸ“¦ Right to Data Portability (Art. 20)

Receive your personal data in a structured, machine-readable format (JSON).

🚫 Right to Object (Art. 21)

Object to processing based on legitimate interests. We will stop unless we have compelling grounds.

↩️ Right to Withdraw Consent (Art. 7)

Withdraw consent at any time without affecting the lawfulness of prior processing.

πŸ€– Rights re: Automated Decisions (Art. 22)

We do not make automated decisions with significant effects on individuals.

To exercise any right, email contact@infinium.tools with subject "GDPR Request β€” [Right]". We respond within 30 days. No fee applies. We may ask you to verify your identity before processing the request.

5. International Data Transfers

Our primary server is located in Frankfurt, Germany (EU). However, some sub-processors are based outside the EU:

Sub-processorLocationTransfer mechanismPurpose
Anthropic (Claude AI)USAStandard Contractual Clauses (SCCs)AI tool processing
StripeUSA/EUEU-US Data Privacy FrameworkPayment processing
Google (OAuth)USAEU-US Data Privacy FrameworkOptional login method
Zoho MailEUNo transfer β€” EU-basedTransactional email
DigitalOceanEU (Frankfurt)No transfer β€” EU-basedServer hosting

All international transfers are governed by appropriate safeguards under GDPR Chapter V.

6. Data Protection Measures

Technical measures

Organisational measures

7. Data Breach Procedure

In the event of a personal data breach, we will:

If you discover or suspect a security vulnerability, please report it responsibly to contact@infinium.tools.

8. Contact & Complaints

InfiniUm Tools β€” Data Controller

πŸ“§ contact@infinium.tools

🌐 infinium.tools

We respond to all GDPR requests within 30 days.

You also have the right to lodge a complaint with your national data protection authority. In the EU, you can find your national authority at edpb.europa.eu.

For general privacy information, see our full Privacy Policy.