Privacy Policy
Last updated: 10 October 2026
This policy explains what personal data Gapfile collects, why, and how it is handled.
Who is responsible
Gapfile is operated by Igor Kazazic, a sole trader (private individual, not a registered company).
Igor Kazazic · Segeparksgatan 18 · 212 50 Malmö · Sweden
Email: contact@gapfile.com
What data we collect
- Account: your email address, your name (optional), your company name and a password hash. Passwords are stored with scrypt — we never see or store your password in plain text.
- Product data and documents: the products you create, your answers, and the documents you upload (test reports, certificates, declarations, supplier details). These may contain personal data, such as names and contact details of supplier or laboratory staff.
- Payments: handled entirely by Stripe. We receive your Stripe customer ID and the status of payments and subscriptions — never your card details.
- Security: login attempts (email address, IP address, time and result) to protect against password guessing, and login sessions, stored only as a one-way hash.
- Settings: your language choice.
Why we use it
- To provide your account and the service (contract, Art. 6(1)(b) GDPR).
- To bill you and keep accounting records (legal obligation, Art. 6(1)(c) GDPR).
- To keep the service secure and prevent abuse (legitimate interest, Art. 6(1)(f) GDPR).
- To email you about your account, payments and changes to the terms (contract).
We do not sell your data, do not use it for advertising, and do not use your documents to train AI models. Gapfile does not send your documents to any AI service.
Data in your documents
For personal data contained in the product information and documents you upload, you are the controller and we process it on your behalf, only to provide the service. A data processing agreement is available on request.
Who we share data with
We use these providers to run Gapfile. Each processes data on our behalf:
- Stripe — payments and subscription billing
- Vercel — hosting of the website and application
- Neon — database hosting in the EU (Frankfurt)
- Cloudflare (R2) — storage of uploaded documents and generated technical files
Some of these providers are US companies. Where personal data is transferred outside the EU/EEA, the transfer is covered by the EU–US Data Privacy Framework or the European Commission's standard contractual clauses.
How long we keep data
- Account, product data and documents: as long as the account exists. Documents you delete in the app are removed from storage straight away. When you close your account, everything is deleted within 30 days.
- Accounting records (invoices and payments): 7 years, as required by Swedish bookkeeping law.
- Login attempts: 30 days.
- Login sessions: until you log out, at most 30 days.
- Backups: database backups may keep deleted data for up to 30 days before they are overwritten.
Cookies
Gapfile only uses cookies that are needed for the service to work:
- gpsr_session — keeps you logged in (until you log out, at most 30 days)
- gapfile_locale — remembers your language choice (1 year)
We use no analytics, advertising or tracking cookies. Stripe Checkout and the billing portal run on stripe.com and set their own cookies there, under Stripe's privacy policy.
Your rights
Under the GDPR you have the right to access, correct, delete, restrict and export your personal data, and to object to processing based on legitimate interest. Email contact@gapfile.com and we will reply within one month.
You can also complain to the Swedish Authority for Privacy Protection (IMY, imy.se) or the data protection authority in your country.
Changes to this policy
We may update this policy. The date at the top shows the latest version. Material changes are announced by email.
Questions
Questions about this policy or your data: contact@gapfile.com