GDPR Compliance

Last updated: July 25, 2026

This page explains how Penci.ly handles personal data for users in the EU, EEA, and UK and how you can exercise your rights under the General Data Protection Regulation.

1. Our Role

Penci.ly is the data controller for account data, board content, and other personal data processed to provide the service. Our infrastructure providers act as processors or sub-processors under their own data processing agreements.

  • Vercel provides hosting and edge-network services.
  • Convex stores account and board content.
  • Clerk provides authentication and session management.
  • Cloudinary stores and delivers uploaded media.
  • LemonSqueezy will process billing and payment data as merchant of record once billing is live.

2. Personal Data We Process

We process the personal data needed to operate Penci.ly, including:

  • Account details such as your email address, username, display name, and profile image.
  • Boards and the content you add to them, including text, images, links, tasks, and connections.
  • Sharing information, including collaborators and their roles.
  • Limited presence data used to show who is currently viewing a board.
  • Technical request data processed by our infrastructure providers for security and abuse prevention.

See our Privacy Policy for the complete description of the data we process and how we use it.

3. Legal Bases for Processing

  • Contractual necessity: We process account and board data to provide the service you signed up for.
  • Legitimate interests: We process limited data for security, abuse prevention, and service improvement, balanced against your rights and expectations.
  • Consent: Future marketing communications, if introduced, will be consent-based and include a way to opt out.
  • Legal obligations: We may process data where necessary to comply with applicable law or valid legal process.

4. Your Data Protection Rights

Subject to the conditions and exceptions in applicable law, GDPR Articles 15–21 may give you the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate or incomplete personal data.
  • Request erasure of your personal data.
  • Restrict how we process your personal data.
  • Receive your data in a portable format.
  • Object to processing based on legitimate interests.
  • Withdraw consent at any time where processing relies on consent.

Account deletion is available as a self-service action. Requests for a full data export beyond board PDF export are currently handled manually.

5. Exercising Your Rights

Send requests to privacy@penci.ly. We may need to verify your identity before completing a request so that we do not disclose or delete data for the wrong person.

We aim to respond within 30 days, as required by GDPR Article 12(3). If a request is unusually complex or numerous, the GDPR may allow an extension, in which case we will explain the delay.

6. Data Retention and Deletion

Your content is retained while your account exists. Deleting a board removes it and its child elements from our database, and deleting your account removes your owned boards and profile data. Collaboration records on boards owned by someone else may remain until that owner removes you or deletes the board.

7. International Data Transfers

Our providers may process data outside your country, including in the United States. When EU, EEA, or UK personal data is transferred internationally, we rely on safeguards offered by those providers, such as Standard Contractual Clauses or equivalent transfer mechanisms.

8. Security

Traffic is encrypted in transit using HTTPS/TLS. Convex encrypts structured account and board data at rest using AES-256, and Cloudinary encrypts uploaded media at rest. Clerk provides authentication so Penci.ly does not store your raw password.

Penci.ly does not currently provide end-to-end encryption. Our backend must be able to process board content to render and synchronize it and to provide features such as link previews and PDF export.

9. Compliance Reviews

To keep our commitments current, we plan to:

  • Review our processor and sub-processor list quarterly for changes to certifications, terms, and data processing agreements.
  • Run dependency and vulnerability reviews quarterly.
  • Review authorization controls semi-annually.
  • Review the Privacy Policy and Terms of Service annually and whenever our practices materially change.
  • Assess every suspected personal-data breach and, where required, notify the relevant supervisory authority and affected users within 72 hours of becoming aware of it.

10. Complaints and Contact

If you have a question, complaint, or data-rights request, contact privacy@penci.ly. You may also have the right to lodge a complaint with the data protection supervisory authority in your country.