GDPR & Your Data

Last updated: 2026-07-31Your rights under the GDPR, the legal bases we rely on, and exactly what happens — and does not happen — when you use them.

GDPR & Your Data

The General Data Protection Regulation (EU) 2016/679 gives you specific rights over your personal data. This page explains who is responsible for your data at APERTURESyndicate, what we rely on to process it, and how to exercise each right.

For the detail of what we collect and why, see the Privacy Policy. For how long we keep it, see Data Retention. For who else touches it, see Data Processing & Sub-processors.

Who is responsible

The data controller is:

APERTURESyndicate OÜ Registry code 17384111 Priisle tee 8, Lasnamäe linnaosa, Tallinn, Harju maakond, 13914, Estonia

Full registration details are on the Company Registration & Imprint page. We have not appointed a Data Protection Officer — the GDPR does not require one for an organisation of our size and activity — so data-protection requests go to our support address below and are handled by the company directly. We are a micro-enterprise of two people, which is why requests are answered by a human in business hours rather than by a department.

Where your data lives

Personal data is stored on servers located in the European Union (Finland and Germany). Where a sub-processor operates outside the EU, the transfer is covered by the safeguards described in Data Processing & Sub-processors.

What we processWhyLegal basis (Art. 6)
Account data — email, nickname, password hash, sessionsTo create and operate your account, sign you in, keep it securePerformance of a contract
Profile content — avatar, banner, bio, links, postsTo provide the parts of the product you chose to usePerformance of a contract
Payment and subscription recordsTo take payment, issue invoices, meet accounting dutiesContract, and legal obligation
Security logs, rate-limit and abuse signalsTo protect accounts and the platform from attack and misuseLegitimate interests
Product analytics in aggregateTo understand which features are used and fix what is brokenLegitimate interests
AI training on your contentOnly if you switch it on — see AI Data & TrainingConsent
Marketing emailOnly if you subscribeConsent

Where we rely on consent, you can withdraw it at any time, and withdrawing it is as easy as giving it. Withdrawal does not affect processing that already happened.

Where we rely on legitimate interests, you have the right to object — see below.

Your rights

Right of access. You can ask for a copy of the personal data we hold about you, together with an explanation of how it is used.

Right to data portability. You can ask for an export of the data you provided to us, in a structured, commonly used, machine-readable format. Be aware of how this works in practice: there is no self-service export button in the product yet. We assemble the export by hand when you ask, which is why it takes days rather than seconds, and why the format is a set of files rather than a polished archive. The right is real and we honour it; the automation is not built yet, and we would rather say so than imply a feature that does not exist.

Right to rectification. Most of it you can fix yourself in account settings — nickname, avatar, banner, bio, links, email. Anything you cannot edit there, we correct on request.

Right to erasure. You can ask us to delete your account and your personal data. This is a genuine deletion, not a hidden profile: account records, profile content and uploaded media are removed, and the request is now carried through every service that held a copy — including chat, where your messages and uploads are erased, and Lysicon Quanture, which holds its own copy of subscriber records.

Two things deliberately survive an erasure, and you should know about both:

  • Invoices and accounting records, which Estonian law requires us to keep for 7 years. We cannot delete these, and no request can shorten the period.
  • The administrative security log. Which roles and permissions an account held, and which administrator granted them, stays in our access-control service. We keep it because an audit trail that can be erased on request is not an audit trail — it is exactly what someone who abused an administrative permission would want deleted. What is stripped from those entries is the technical session data (IP address and User-Agent, removed after 30 days), and after erasure the internal identifier left in the log no longer resolves to anything: the account, the email and the profile it pointed to are gone. We also keep a minimal record that an erasure took place, so we can prove we honoured it.

Right to restriction. You can ask us to pause processing while a dispute about accuracy or legitimate interests is resolved.

Right to object. You can object to processing based on legitimate interests, including profiling. Objections to marketing are always honoured, without exception.

Rights related to automated decision-making. Some of our protective measures are automated, and it would be misleading to claim otherwise:

  • rate limits and temporary blocks on sign-in, registration, password reset and uploads trigger automatically when activity looks abnormal;
  • automated checks flag content and behaviour for review, and can restrict a feature before a human has looked;
  • our payment provider runs its own automated fraud checks on transactions.

None of these is intended to produce a legal effect on you, and account-level enforcement — suspension, termination, removal of published content — is reviewed by a person before it stands. If an automated measure has affected you, you can ask for a human to review it, put your point of view, and contest the outcome: write to [email protected] and say what was blocked and when. Content decisions have their own appeal route with a 6-month window, described in DSA Notice & Action.

How to exercise them

Write to [email protected] from the email address registered to your account, and say which right you want to exercise. If we cannot tie the request to an account, we may ask for something further to confirm it is yours — we ask for the minimum needed and do not keep it afterwards.

We answer within 30 days of receiving the request, as the GDPR requires. If the request is unusually complex we may extend this by up to 2 further months, and we will tell you within the first month if that happens. Exercising your rights is free; we may charge a reasonable fee, or refuse, only where a request is manifestly unfounded or excessive, and we will explain why.

If you are not satisfied

You can complain to the Estonian supervisory authority:

Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate) Tatari 39, 10134 Tallinn, Estonia https://www.aki.ee/en · [email protected]

You may also complain to the supervisory authority of the EU member state where you live or work. Nothing here limits your right to a judicial remedy.

We would rather hear from you first, though — most complaints turn out to be something we can simply fix.

GDPR & Your Data | AS Docs