Privacy Policy
Last updated: 14 April 2026
1. Data controller
Promnis is the data controller for personal data processed through the Service. For questions about this privacy policy, contact us at privacy@promnis.nl.
2. Data we collect
Account data
Upon registration we collect your email address and a password of your choosing (stored as a hash). Optionally: username and organization name.
Uploaded files
PDF files you upload for processing. These are temporarily stored for the duration of processing and the retention period specified in your subscription, after which they are automatically deleted.
Usage data
Number of processed files and pages, processing times, WCAG scores, and corrections you make in the editor. We use this data to improve the Service.
Payment data
Payments are processed by Stripe. Promnis does not store credit card numbers or bank account numbers. We only retain a Stripe customer ID and subscription status.
Technical data
IP addresses, browser type, and error reports via Sentry for diagnosing and resolving technical issues.
3. Legal basis
We process your personal data on the following legal grounds:
- Performance of contract: account management, PDF processing, billing.
- Legitimate interest: security, fraud prevention, service improvement, error tracking.
- Consent: where applicable, such as optional cookies or marketing communications.
- Legal obligation: tax retention requirements for invoice data.
4. Retention periods
- Account data: as long as your account is active, plus 30 days after deletion.
- PDF files: according to your subscription's retention period (default 30 days), then automatically deleted.
- Usage data: anonymized after 12 months.
- Invoice data: 7 years (legal requirement).
- Technical logs: maximum 90 days.
5. Processors and third parties
We share your data with the following processors, solely for the stated purposes:
- Stripe (US, EU Standard Contractual Clauses): payment processing.
- Sentry (US, EU Standard Contractual Clauses): error monitoring and crash reporting.
- Hosting provider (EU): server infrastructure and storage.
- Email provider (EU): transactional emails (verification, password reset).
We do not sell your personal data to third parties and do not use it for profiling or automated decision-making.
6. Security
We implement appropriate technical and organizational measures to protect your data, including:
- Encryption of data in transit (TLS) and at rest (AES-256).
- Two-factor authentication available for all users.
- Regular security audits and vulnerability scans.
- Access control based on the principle of least privilege.
7. Your rights
Under the GDPR, you have the following rights:
- Access: you can request which data we process about you.
- Rectification: you can have incorrect data corrected.
- Erasure: you can request deletion of your data.
- Restriction: you can request restriction of processing.
- Portability: you can request your data in a structured format.
- Objection: you can object to processing based on legitimate interest.
Submit requests via privacy@promnis.nl. We respond within 30 days.
8. Cookies
Promnis uses only functional cookies necessary for the operation of the Service (session, language preference). We do not use tracking or advertising cookies. Analytics data is collected server-side without third-party cookies.
9. International transfers
Your PDF files are processed and stored on servers within the European Union. For services from processors outside the EU (Stripe, Sentry), EU Standard Contractual Clauses (SCCs) apply.
10. Changes
We may amend this privacy policy. Material changes will be announced by email. The most recent version is always available on this page.
11. Complaints
If you have a complaint about the processing of your personal data, contact us at privacy@promnis.nl. You also have the right to file a complaint with the Dutch Data Protection Authority (autoriteitpersoonsgegevens.nl).
12. Contact
Promnis
Email: privacy@promnis.nl
Website: promnis.nl