Privacy · Terms

Privacy Policy

Last updated: 2026-08-23 · Draft pending legal review
This document is an operational draft prepared by DC ESCRYPT. It describes what the service actually does today. It has not yet been reviewed by external counsel.

DC ESCRYPT ("we") operates the Raposa Aval human approval service and the signed agent infrastructure available at dcescrypt.com. This policy explains what personal data we process, why, and what rights you have under the GDPR (Regulation (EU) 2016/679).

1. Controller

DC ESCRYPT, European Union. Contact for all privacy matters: contact@dcescrypt.com. Abuse reports: abuse@dcescrypt.com.

2. What we process

CategoryExamplesLegal basis
Approval requestsAction name, free-text context supplied by the customer's agent, requester identifierArt. 6(1)(b) — performance of a contract
DecisionsApprove/reject, operator identifier, timestamp, optional commentArt. 6(1)(b); Art. 6(1)(f) — auditability
Audit logHash-chained record of every event aboveArt. 6(1)(f) — legitimate interest in tamper-evident records
API credentialsSHA-256 hashes of API keys and panel passwords — never the values themselvesArt. 6(1)(b)
CorrespondenceEmail you send to contact@ or abuse@Art. 6(1)(b) / Art. 6(1)(f)
Server logsIP address, user agent, request line, timestampArt. 6(1)(f) — security and abuse prevention

We do not run advertising or behavioural profiling on customer approval data, and we do not sell personal data.

3. Content you send us

The context field of an approval request is free text controlled by the customer. Customers decide what goes into it and remain the controller for that content; DC ESCRYPT acts as processor for it. Do not place special-category data (Art. 9 GDPR) in that field.

4. Where data is processed

Application servers and the approval database are hosted in Germany (OVH). Transactional email is delivered through Resend in the EU (eu-west-1); inbound mail for our published addresses is routed by Cloudflare. DNS and edge proxying are provided by Cloudflare.

5. Retention

The audit log is append-only and hash-chained by design. Deleting an individual entry would break the chain; erasure requests are therefore satisfied by removing or pseudonymising the underlying personal data while retaining the hash.

6. Your rights

You have the right of access, rectification, erasure, restriction, portability and objection, and the right to lodge a complaint with your supervisory authority. Write to contact@dcescrypt.com; we answer within 30 days.

7. Processors

ProcessorPurposeLocation
OVHApplication hosting, databaseGermany
CloudflareDNS, edge proxy, inbound email routingEU edge
Resend (Amazon SES)Outbound transactional emailEU (eu-west-1)

8. Cookies and analytics

The public pages set no cookies of their own. Web fonts are loaded from Google Fonts, which receives the visitor's IP address as part of the request. If measurement or advertising tags are added later, this section and a consent banner will be updated before they go live.

9. Security

API keys and panel passwords are stored only as SHA-256 hashes. The agent signing key is Ed25519, generated on the server, permissions 0600, and has never left it. All traffic is served over TLS. The approval service listens only on loopback behind nginx.

10. Changes

Material changes are announced at this URL with a new "last updated" date.