Privacy Policy

Comprehensive transparency on how RenewGuard processes, secures, and respects your personal data under the EU General Data Protection Regulation (GDPR).

Effective date: August 16, 2026

1. Data Controller & Governance

RenewGuard ("we", "our", or "us") operates the subscription management platform available at renewguard.net and renewguard.pages.dev. For the purposes of the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Data Controller responsible for your personal data is:

Panagiotis Koletsos (RenewGuard Data Governance)

Email: [email protected]

Location: Athens, Hellenic Republic (European Union)

2. Categories of Personal Data Collected

We adhere strictly to the principle of data minimization (GDPR Article 5(1)(c)). We only collect data necessary to provide and secure our subscription tracking services:

Account & Identity Data

Email address, display name, account password (stored securely as salted argon2/bcrypt hashes by Supabase Auth), and MFA TOTP secret keys.

Subscription & Financial Records

Service names, categories, costs, billing frequencies, renewal dates, payment history, and payment method aliases (e.g., "Visa •••• 4242").

Notification & User Preferences

Preferred currency, monthly budget limits, date formatting, email reminder preferences, and consent choices.

Security & Session Metadata

IP addresses (processed temporarily for rate limiting and bot mitigation via Cloudflare Turnstile), browser user-agent, and session timestamps.

3. Legal Bases for Data Processing (GDPR Art. 6)

We process your personal information only when backed by an explicit statutory legal basis:

  • Contractual Necessity (Art. 6(1)(b)): To operate your account, track subscriptions, compute analytics, and dispatch renewal reminders you configured.
  • Legitimate Interests (Art. 6(1)(f)): To maintain application security, mitigate brute-force and DDoS attacks, prevent fraud, and ensure database integrity.
  • Explicit Consent (Art. 6(1)(a)): For non-essential analytics and marketing communications, managed via our granular Cookie Consent Banner.
  • Legal Obligations (Art. 6(1)(c)): To comply with statutory data retention and legal audit requests where mandated by applicable EU laws.

4. Authorized Subprocessors & Data Transfers

We partner with enterprise infrastructure providers governed by Data Processing Agreements (DPAs) incorporating the European Commission’s Standard Contractual Clauses (SCCs):

SubprocessorPurposeLocationTransfer Mechanism
Supabase Inc.PostgreSQL Database, Auth, Edge FunctionsEU (Frankfurt) / USEU-US DPF / Standard Contractual Clauses
Cloudflare Inc.Turnstile Bot Defense, Edge CDN, DNSGlobal Edge NetworkEU-US DPF / Standard Contractual Clauses
Resend Inc.Transactional Email & Renewal RemindersUS / EU RelaysStandard Contractual Clauses

5. Your Statutory Data Subject Rights

Under GDPR Chapter III, you possess strong, actionable rights regarding your personal data:

Right of Access & Portability (Arts. 15 & 20): You can export a full, structured machine-readable JSON copy of all your records anytime from Account Settings > Export Personal Data.

Right to Erasure / To Be Forgotten (Art. 17): You can permanently delete your account and all associated subscriptions, payments, and activity records with zero residual retention via Account Settings > Danger Zone.

Right to Rectification (Art. 16): You can modify your profile name, subscription details, budget, and notification settings directly in the web app.

Right to Withdraw Consent (Art. 7(3)): You can modify or revoke cookie and telemetry consent at any time via the Cookie Policy page or consent manager.

Right to Lodge a Complaint

If you believe our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA) or your local EU supervisory authority:

Hellenic Data Protection Authority (HDPA) • Kifissias 1-3, 115 23 Athens, Greece • www.dpa.gr