Legal
How Partikl collects, uses, and protects your information
Last updated: April 5, 2026
Effective April 5, 2026
·
Governed by Georgia law
Plain English Summary
We collect only what we need to run the Service. We do not sell your data. We do not use your content to train AI. Your content is encrypted and only you can access it. You can export or delete everything at any time from the dashboard. We do not use cookies — authentication uses a local storage token only.
Plain English Summary
Key points — full legal text below governs
We do not sell or rent your data to anyone
§4.4
We do not use your content to train AI models
§4.5
No cookies — auth token in local storage only
§6
You can export or delete all your data from the dashboard
§9
We collect account, billing, and usage data to operate the service
§3
Billing data retained per legal requirements (up to 7 years)
§10.2
Data stored in EU by default (Netherlands region)
§7
"Partikl" means the Partikl platform operated by [Aleksei Umanchenko] I/E (Individual Entrepreneur, Registration No: 346991687), registered in Georgia.
For the purposes of EU data protection law (GDPR), Partikl is the data controller for Account data and the data processor for Customer Content you upload and process through the Service.
Contact for privacy matters: privacy@partikl.io
This Privacy Policy applies to:
This Policy does not apply to Customer Content that you process through Partikl Pipelines. You are the controller of that data. Our obligations as processor are described in the Data Processing Agreement (DPA) at partikl.io/legal/dpa.
What: Name, email address, company name (optional), country.
Why: To create and manage your Account, communicate with you about the Service, and comply with legal obligations.
Legal basis: Contract (necessary to provide the Service); Legitimate interest (communications and security).
What: Billing address, payment method type (card last 4 digits only), invoice history, subscription status.
Note: Full payment card data is processed directly by our payment processor and is never stored on Partikl infrastructure.
Why: To process payments, manage subscriptions, and comply with tax and accounting obligations.
Legal basis: Contract; Legal obligation.
What: Aggregated and anonymized metrics including: API request counts, Processing task counts, storage consumption, bandwidth consumption, error rates, and feature usage patterns.
What we do NOT collect: Individual request content, per-user behavioral profiles, browsing history, or any data that identifies individual usage patterns.
Why: To operate the Service, enforce plan limits, calculate billing, and understand aggregate Service performance.
Legal basis: Contract; Legitimate interest.
What: IP address (for security and fraud prevention), User-Agent string, API client version, session token identifiers (not content).
Why: To detect unauthorized access, prevent abuse, enforce rate limits, and maintain security.
Retention: IP addresses are retained for 90 days for security purposes, then deleted or anonymized.
Legal basis: Legitimate interest (security and fraud prevention).
What: Emails and messages you send us, support ticket content, feedback you submit.
Why: To respond to your requests and improve the Service.
Legal basis: Legitimate interest; Contract.
We do not collect:
We use your data to:
We use aggregated, anonymized usage data to:
This analysis is performed on aggregated data and does not involve profiling of individual users.
We use Technical Data to:
We do not sell, rent, or trade your personal data to any third party for their independent marketing or commercial purposes. Ever.
We do not use your personal data or Customer Content to train, fine-tune, benchmark, or evaluate any machine learning model, whether operated by us or by any third party.
We may send you product updates, feature announcements, and occasional promotional communications. You can unsubscribe from marketing emails at any time using the link in any such email.
Transactional emails (billing, security, account status) cannot be unsubscribed as they are necessary for the Service.
For users in the European Economic Area (EEA), we process personal data on the following legal bases:
| Purpose | Legal Basis |
|---|---|
| Account creation and service delivery | Art. 6(1)(b) — Contract |
| Payment processing | Art. 6(1)(b) — Contract |
| Security and fraud prevention | Art. 6(1)(f) — Legitimate interest |
| Compliance with legal obligations | Art. 6(1)(c) — Legal obligation |
| Service improvement (aggregated) | Art. 6(1)(f) — Legitimate interest |
| Marketing communications | Art. 6(1)(a) — Consent (withdrawable) |
Where we rely on Legitimate interest, we have assessed that our interests do not override your fundamental rights and freedoms. You may object to processing based on Legitimate interest at any time (see §9.5).
Partikl does not use cookies of any kind — neither essential, analytical, functional, nor advertising cookies.
The Service stores a session authentication token in your browser's local storage. This token is strictly necessary to authenticate your API requests and dashboard sessions. It contains no personal data beyond a cryptographic session identifier.
Because this storage is strictly necessary for the Service to function, it does not require your consent under EU ePrivacy law.
Website and application analytics, where used, are implemented using privacy-preserving, cookieless tools (self-hosted Umami or equivalent). These tools collect aggregated, anonymized data only and do not identify individual users. No consent is required.
By default, Account data and Customer Content are stored in EU-based infrastructure (Netherlands region).
Where the Service supports configurable data residency, you may select a preferred storage region for each Namespace in your dashboard. Available regions are listed in the documentation.
Where Customer Content or Account data is processed outside the EEA (for example, by a sub-processor with infrastructure in other regions), we ensure appropriate safeguards are in place, including:
We use a limited number of sub-processors to operate the Service. A current list of sub-processors, including their function, location, and DPA status, is maintained at partikl.io/legal/subprocessors.
We will provide 30 days advance notice before adding a new sub-processor that processes personal data. Notice is given via email and dashboard notification. You may object to a new sub-processor within this period.
Current categories of sub-processors include:
| Category | Purpose |
|---|---|
| Cloud infrastructure | Compute and storage hosting |
| Content delivery | CDN and edge delivery |
| Payment processing | Subscription billing and invoicing |
| Email delivery | Transactional and notification emails |
| Analytics | Aggregated, anonymized usage metrics (self-hosted) |
Customer Content is encrypted at rest using AES-256-GCM or ChaCha20-Poly1305 (configurable per Namespace). Data is encrypted in transit using TLS 1.3. Cached copies at edge locations are also encrypted.
Access to production infrastructure is restricted to authorized personnel only. Partikl personnel do not access Customer Content in plain text. Access events are logged for audit purposes.
Encryption keys are not stored in plain text at any layer of our infrastructure. Key management details are available on our Security page at partikl.io/security.
In the event of a data breach affecting your personal data, we will notify you and applicable supervisory authorities within 72 hours of becoming aware of the breach, as required by GDPR Article 33/34. Notification will describe the nature of the breach, data affected, likely consequences, and measures taken.
Depending on your location, you have the following rights regarding your personal data. We have built self-service tools in the dashboard so you can exercise most rights without contacting us.
You have the right to know what personal data we hold about you.
How to exercise: Dashboard → Account Settings → Data → Export My Data. A structured export of your Account data is generated within 24 hours.
You have the right to correct inaccurate personal data.
How to exercise: Dashboard → Account Settings → Profile. Most data can be updated directly. For billing data corrections, contact privacy@partikl.io.
You have the right to request deletion of your personal data.
How to exercise: Dashboard → Account Settings → Data → Delete Account.
Upon deletion request:
Note: deletion of Account data may make it impossible to continue using the Service.
You have the right to object to processing based on Legitimate Interest.
How to exercise: Email privacy@partikl.io with subject "Objection to Processing." We will assess your objection and respond within 30 days.
You have the right to receive your personal data in a structured, machine-readable format.
How to exercise: Same as Right of Access (§9.2). Export includes Account data in JSON format and Customer Content in original formats.
You have the right to request that we restrict processing of your data in certain circumstances (for example, while contesting accuracy).
How to exercise: Email privacy@partikl.io. We will respond within 30 days.
We do not make automated decisions about you that produce legal or similarly significant effects. Automated content moderation (§6 of the Terms of Service) is subject to human review upon appeal.
We aim to respond to all privacy requests within 30 days. In complex cases, we may extend this period by a further 60 days with notice to you.
We may need to verify your identity before processing your request. We will not charge a fee for reasonable requests.
If you are in the EEA, you also have the right to lodge a complaint with your local supervisory authority. A list of EEA supervisory authorities is available at edpb.europa.eu.
| Data Type | Retention Period |
|---|---|
| Customer Content | Until deleted by you or Account closure + 30 days |
| Account profile | Until Account closure + 30 days |
| API usage logs (aggregated) | 13 months rolling |
| Security logs (IP, access) | 90 days |
| Support communications | 2 years from last interaction |
Billing records, invoices, and transaction data are retained for the period required by applicable law — typically 7 years in EU jurisdictions. After this period, billing data is automatically and permanently deleted.
This retention applies regardless of Account status and cannot be waived as it is required by law.
Aggregated, anonymized usage statistics that cannot identify you may be retained indefinitely for Service improvement purposes.
The Service is not directed to children under 16 years of age. We do not knowingly collect personal data from children under 16. If we learn that we have collected data from a child under 16 without appropriate consent, we will delete it promptly.
If you believe we have collected data from a child under 16, please contact privacy@partikl.io.
The Service may contain links to third-party websites. We are not responsible for the privacy practices of those sites.
When you install a third-party Addon, that Addon may access Customer Content as configured in your Pipeline. Third-party Addons have their own privacy policies. We are not responsible for the data practices of third-party Addon developers. Review an Addon's declared data access scope before installation.
We may update this Privacy Policy from time to time.
Material changes (changes to what data we collect, how we use it, or who we share it with) will be notified to you at least 30 days in advance via email and dashboard notice.
Minor changes (clarifications, formatting, corrections) will be noted in the Legal Changelog at partikl.io/legal/changelog without advance notice.
The effective date at the top of this page indicates when the current version took effect.
For privacy questions and requests: privacy@partikl.io
For data breach reports: security@partikl.io
Postal address: 19 Akaki Tsereteli St, Batumi 6010, Georgia Aleksei Umanchenko I/E Individual Entrepreneur
EEA Representative (if applicable): [To be appointed upon EU entity registration]
If you are not satisfied with our response to a privacy concern, you have the right to lodge a complaint with your local data protection authority.
Version 1.0.0 — Effective April 5, 2026 See the Legal Changelog for revision history