Legal
Privacy Policy
Last updated June 2025 · A standing reference statement
- Last revised
- June 2025
- Status
- In force
Note
Template wording — review with qualified counsel before launch.
Who We Are
Epidaurus is operated by [legal entity — complete before launch] ("we", "us", "our"). We are the data controller for the personal data described in this policy. Contact details are on our Imprint page.
Data We Collect
- Account data: your name and email address when you register or sign in.
- Payment data: payments are processed entirely by Stripe, Inc. We receive a confirmation token and basic billing information (e.g. last four card digits, billing country) but never your full card number. See Stripe's Privacy Policy for how they handle payment data.
- Usage and error data: anonymised error logs are collected by Sentry to help us diagnose and fix bugs. These may include browser type, OS, and the URL where an error occurred, but are not used for advertising.
- Analytics data: we collect basic, privacy-respecting analytics (page views, referrer, approximate geography) to understand how the Site is used. See our Cookie Policy for details.
Purposes and Legal Bases (GDPR)
- Contract performance (Art. 6(1)(b) GDPR): processing your account and purchase data to fulfil orders and deliver content you have purchased.
- Legitimate interests (Art. 6(1)(f) GDPR): fraud prevention, site security, error monitoring, and product improvement.
- Consent (Art. 6(1)(a) GDPR): optional analytics cookies, where your consent is obtained separately.
- Legal obligation (Art. 6(1)(c) GDPR): keeping financial records as required by applicable law.
Processors and Sub-Processors
- Stripe, Inc. — payment processing (USA; EU SCCs in place).
- Sentry (Functional Software, Inc.) — error monitoring (USA; EU SCCs in place).
- [Hosting provider — complete before launch] — server infrastructure.
- [Email provider — complete before launch] — transactional email.
International Transfers
Some of our processors are based outside the European Economic Area (EEA). Where personal data is transferred outside the EEA, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission to ensure adequate protection.
Cookies
We use cookies and similar technologies. For a full description of the cookies we set and how to control them, see our Cookie Policy.
Retention
We retain account data for as long as your account is active, plus a reasonable period thereafter for legal and accounting purposes. Payment records are kept for seven years as required by financial regulations. Error logs are retained for 90 days. Analytics data is aggregated and anonymised.
Your Rights
Under the GDPR and applicable data-protection law, you have the right to:
- Access a copy of the personal data we hold about you.
- Correct inaccurate data.
- Request erasure of your data ("right to be forgotten").
- Restrict or object to certain processing.
- Data portability — receive your data in a machine-readable format.
- Withdraw consent at any time (where processing is based on consent).
- Lodge a complaint with your national supervisory authority.
To exercise your rights, visit your account page where you can export or delete your data, or contact us directly.
Contact and DPO
For privacy enquiries, contact us at the address on our Imprint page. We aim to respond within 30 days.
Last revised June 2025 — this edition supersedes all prior editions of the privacy policy.