GDPR information

GDPR Compliance

This page summarizes GDPR compliance practices for GXA Toolbox users in the European Economic Area and United Kingdom. It is not a claim of formal GDPR certification and should be read with the Privacy Policy.

Last updated: 14 August 2026

Roles and scope

GXA Technologies determines the purposes and means of processing personal data used to provide GXA Toolbox accounts, support, service operation, and measurement, except where a third-party provider acts independently under its own terms.

The exact GDPR role can depend on the activity and user relationship. Organizations using the tools remain responsible for determining their own obligations for files and personal data they choose to process.

Personal data that may be processed

  • Account details such as name, email, password hash, role, status, and account timestamps.
  • Support information such as name, email, message content, and related correspondence.
  • Processing-history metadata such as filenames, tool name, output name, size, status, timing, and timestamps for signed-in users.
  • Device, browser, network, referrer, page, interaction, cookie, and analytics information from hosting logs or tags configured through Google Tag Manager.
  • File contents when a selected feature genuinely requires transmission; many current tools instead process file contents locally in the browser.

Lawful bases

Depending on the activity, processing may rely on performance of a contract or steps requested by the user, legitimate interests in operating and securing the service, consent for optional cookies or measurement where required, or compliance with legal obligations.

When legitimate interests are used, GXA Technologies considers the service need, data minimization, user expectations, and potential impact. When consent is the basis, it may be withdrawn for future processing.

Data minimization and browser processing

The service is designed to keep many file-processing operations in browser memory where technically possible. Account history records metadata rather than uploaded file content under the current schema.

Users can further minimize data by using public tools without an account where available, avoiding personal data in filenames, declining remembered-email storage, limiting support-message content, and clearing browser storage.

EEA and UK data rights

Subject to the conditions and exceptions in applicable law, a person may request access to personal data, correction of inaccurate data, deletion, restriction of processing, objection to processing, and data portability for applicable data supplied in a structured form.

Where processing depends on consent, consent may be withdrawn without affecting processing that was lawful before withdrawal. Users may also have the right to complain to the data-protection authority in their country or region.

Submitting a rights request

Submit a request through Contact Support and state that it is a GDPR or privacy request. Describe the account email, information, and right involved without including a password or unnecessary identity document in the initial message.

GXA Technologies may request proportionate information to verify identity, clarify scope, protect another person's rights, or meet legal obligations. A request may be limited or refused when applicable law permits, with an explanation where required.

Providers and international transfers

GXA Toolbox uses providers for hosting, functions, database connectivity, fonts, tag management, analytics when configured, and content delivery. These currently include Netlify, Google services, unpkg, cdnjs, and jsDelivr for relevant functions or resources.

Providers may process data in countries outside the user's location. Where GDPR transfer rules apply, transfers should rely on an applicable adequacy decision, contractual safeguards, provider mechanism, or other lawful basis appropriate to the relationship.

Retention and security practices

Personal data is retained according to service, account, support, security, dispute, and legal needs rather than one unsupported universal period. Browser storage remains until cleared, the production session cookie has a seven-day maximum age, and providers apply configured retention to logs and analytics.

Current safeguards include HTTPS, bcrypt password hashing, signed session cookies, same-origin checks, response headers, authenticated history isolation, and browser-local processing where appropriate. These measures reduce risk but cannot guarantee absolute security.

Updates and contact

These practices may change as the service, provider configuration, or applicable law changes. Updates will be published on this route and reflected in the Privacy Policy.

Use Contact Support for GDPR questions, rights requests, consent concerns, or questions about an international transfer.

Contact

Submit a privacy-rights request

Use Contact Support and identify the request as GDPR or privacy-related.

Start a Privacy Request