Processing Activities Registry
Record of processing activities pursuant to Art. 30 of Regulation (EU) 2016/679 (GDPR).
Data Controller
IDCERT S.r.l. Benefit Corporation
Pursuant to Art. 37 GDPR, the appointment of a DPO is not currently mandatory. This section will be updated if circumstances change.
Technical operation of the portal
Purpose (Art. 30.1.b)
Provision of web service, routing, page rendering
Legal Basis
Art. 6.1.f
Data Subjects (Art. 30.1.c)
Website visitors
Data Categories (Art. 30.1.c)
Navigation data (anonymized IP, user agent, URL)
Recipients (Art. 30.1.d)
Vercel Inc. (hosting), Supabase Inc. (database)
Extra-EU Transfers (Art. 30.1.e)
USA (Vercel) with SCCs; EU (Supabase eu-central-1)
Retention (Art. 30.1.f)
Duration of session
Art. 32 Measures (Art. 30.1.g)
HTTPS/TLS, CSP, HSTS, X-Frame-Options DENY, anonymized IP
Cookie consent management
Purpose (Art. 30.1.b)
Collection and recording of consent for GDPR accountability
Legal Basis
Art. 6.1.c
Data Subjects (Art. 30.1.c)
Website visitors
Data Categories (Art. 30.1.c)
Anonymous session ID, IP hash (SHA-256 + rotating salt), cookie preferences, policy version, user agent
Recipients (Art. 30.1.d)
Supabase Inc. (database, EU region)
Extra-EU Transfers (Art. 30.1.e)
EU (Supabase eu-central-1)
Retention (Art. 30.1.f)
5 years (GDPR Art. 5.2 accountability obligations)
Art. 32 Measures (Art. 30.1.g)
Supabase RLS, SHA-256 anonymized IP, CSRF protection, rate limiting
Contact request management
Purpose (Art. 30.1.b)
Responding to user requests sent through the contact form
Legal Basis
Art. 6.1.b
Data Subjects (Art. 30.1.c)
Users who fill out the contact form
Data Categories (Art. 30.1.c)
Name, email, subject, message, IP hash, language
Recipients (Art. 30.1.d)
Supabase Inc. (database, EU region)
Extra-EU Transfers (Art. 30.1.e)
EU (Supabase eu-central-1)
Retention (Art. 30.1.f)
12 months from request
Art. 32 Measures (Art. 30.1.g)
Supabase RLS, anti-bot honeypot, CSRF, rate limiting (3 req/10 min), anonymized IP
Google Analytics (consent-gated)
Purpose (Art. 30.1.b)
Anonymous statistical traffic analysis to improve the service
Legal Basis
Art. 6.1.a
Data Subjects (Art. 30.1.c)
Visitors who consent to analytics cookies
Data Categories (Art. 30.1.c)
Aggregated navigation data, IP anonymized by Google, _ga cookie
Recipients (Art. 30.1.d)
Google LLC
Extra-EU Transfers (Art. 30.1.e)
USA (Google) with EU-US Data Privacy Framework
Retention (Art. 30.1.f)
26 months (GA4 setting)
Art. 32 Measures (Art. 30.1.g)
Activated ONLY after explicit consent, anonymize_ip: true, SameSite=Lax;Secure cookies
User interface preferences
Purpose (Art. 30.1.b)
Storing language and theme preferences (light/dark)
Legal Basis
Art. 6.1.f
Data Subjects (Art. 30.1.c)
All visitors
Data Categories (Art. 30.1.c)
Language code (NEXT_LOCALE), theme (localStorage 'theme')
Recipients (Art. 30.1.d)
None (local data only)
Extra-EU Transfers (Art. 30.1.e)
None
Retention (Art. 30.1.f)
NEXT_LOCALE: 12 months; theme: until manual deletion
Art. 32 Measures (Art. 30.1.g)
Non-personal technical data, no transfer
User authentication
Purpose (Art. 30.1.b)
Registration, login, and user session management via Supabase Auth
Legal Basis
Art. 6.1.b
Data Subjects (Art. 30.1.c)
Registered users
Data Categories (Art. 30.1.c)
Email, password (hash), name, avatar URL, role, preferred locale, creation date
Recipients (Art. 30.1.d)
Supabase (sub-processor, EU/EEA infrastructure)
Extra-EU Transfers (Art. 30.1.e)
Supabase: EU servers (aws-eu-central-1). Standard Contractual Clauses (SCCs) in place.
Retention (Art. 30.1.f)
Until account deletion (ON DELETE CASCADE on all user data)
Art. 32 Measures (Art. 30.1.g)
Password hashed (bcrypt), HttpOnly/Secure/SameSite=Lax cookies, PKCE flow, RLS on all tables, session refresh via proxy
User data management (bookmarks, search history, preferences)
Purpose (Art. 30.1.b)
Saving bookmarks, search history, and personalized preferences for authenticated users
Legal Basis
Art. 6.1.b
Data Subjects (Art. 30.1.c)
Registered users
Data Categories (Art. 30.1.c)
Saved resource URIs, type (occupation/skill/qualification), title, search timestamps, theme/language preferences
Recipients (Art. 30.1.d)
Supabase (sub-processor, EU/EEA infrastructure)
Extra-EU Transfers (Art. 30.1.e)
Supabase: EU servers (aws-eu-central-1)
Retention (Art. 30.1.f)
Until account deletion (ON DELETE CASCADE). Bookmarks and history can be individually deleted by user.
Art. 32 Measures (Art. 30.1.g)
RLS: each user can only access their own data. Admin: read-only. Role escalation prevention via RLS.
Error monitoring and stability (Sentry)
Purpose (Art. 30.1.b)
Detection and diagnosis of application errors to ensure service stability. Session Replay (session recording) activated only after analytics consent.
Legal Basis
Art. 6.1.f / Art. 6.1.a
Data Subjects (Art. 30.1.c)
Website visitors and registered users
Data Categories (Art. 30.1.c)
Error stack traces, URL, user agent, browser. With analytics consent: IP, cookies, HTTP headers, interaction recordings (Session Replay)
Recipients (Art. 30.1.d)
Functional Software Inc. (Sentry), San Francisco, CA, USA
Extra-EU Transfers (Art. 30.1.e)
USA (Sentry) with Standard Contractual Clauses (SCCs)
Retention (Art. 30.1.f)
90 days (Sentry default setting)
Art. 32 Measures (Art. 30.1.g)
Basic mode without PII (legitimate interest). PII and Session Replay activated ONLY after explicit analytics consent. Tunnel route /monitoring for ad-blocker bypass. Source maps hidden from client.
Anti-bot protection (Cloudflare Turnstile)
Purpose (Art. 30.1.b)
Automated anti-bot verification on contact, registration and login forms to prevent abuse and spam
Legal Basis
Art. 6.1.f
Data Subjects (Art. 30.1.c)
Users who interact with protected forms (contact, registration, login, email change)
Data Categories (Art. 30.1.c)
IP address, browser fingerprint, widget interaction data, verification token
Recipients (Art. 30.1.d)
Cloudflare Inc., San Francisco, CA, USA
Extra-EU Transfers (Art. 30.1.e)
USA (Cloudflare) with Standard Contractual Clauses (SCCs)
Retention (Art. 30.1.f)
Duration of verification (data is not retained after token validation)
Art. 32 Measures (Art. 30.1.g)
No tracking cookies. Non-invasive widget ('managed' mode). No consent required — legitimate interest for service security.
MCP service (programmatic access to the frameworks)
Purpose (Art. 30.1.b)
Provision of the API-key MCP server: authentication, enforcement of the subscribed tier's limits, per-key usage measurement, abuse prevention
Legal Basis
Art. 6.1.b / 6.1.f
Data Subjects (Art. 30.1.c)
Registered users who create an API key in the account area
Data Categories (Art. 30.1.c)
API key (SHA-256 fingerprint and prefix only), key name, tier, accepted terms version; call log: tool, framework, request parameters, IP hash (SHA-256 + daily salt), user agent, outcome, duration; rate-limit counters: IP address in clear (requests without a valid key) or key identifier, for the 60-second window only; monthly quota counters: account identifier, for the calendar month; administrative measures on keys (suspension, reactivation, revocation): date, reason, note, administrator identifier, outcome of the email notice
Recipients (Art. 30.1.d)
Supabase Inc. (database, EU region), Vercel Inc. (hosting), Upstash, Inc. (Redis: rate-limit counters, ephemeral)
Extra-EU Transfers (Art. 30.1.e)
EU (Supabase eu-central-1); USA (Vercel Inc., Upstash, Inc.) under the EU-US Data Privacy Framework and, as a fallback, SCCs
Retention (Art. 30.1.f)
Keys: until revocation or account deletion; revoked key: hash only, for 12 months after revocation, then deleted; call log: 12 months, daily automatic purge; rate-limit counters: 60 seconds; monthly quota counters: until the first day of the following month; administrative measures on keys: 12 months, daily automatic purge
Art. 32 Measures (Art. 30.1.g)
Key stored only as SHA-256 hash; RLS enabled with no policies (server-side access only); IP never stored in clear in the log, in clear only in the rate-limit counter for 60 seconds; rate limits per IP and per key; HTTPS/TLS
MCP service Pro subscription (Stripe)
Purpose (Art. 30.1.b)
Activation, renewal and management of the paid Pro tier subscription; invoicing
Legal Basis
Art. 6.1.b / 6.1.c
Data Subjects (Art. 30.1.c)
Registered users who subscribe to the Pro tier
Data Categories (Art. 30.1.c)
At ExplorerHub: Stripe customer identifier, subscription identifier and status, plan, period end; events notified by Stripe (identifier and type only). At Stripe: email, payment data, billing address, invoices
Recipients (Art. 30.1.d)
Stripe Payments Europe, Ltd. (Dublin, Ireland) — processor for payments and invoicing; Supabase Inc. (database, EU region)
Extra-EU Transfers (Art. 30.1.e)
EU (Stripe Payments Europe, Supabase); possible transfers to Stripe, LLC (USA) under the EU-US Data Privacy Framework and SCCs
Retention (Art. 30.1.f)
Subscription data (Stripe identifiers, status, plan, period end): until account deletion, which cancels the subscription at Stripe; Stripe events (identifier and type): 12 months, daily automatic purge; invoices and tax documents at Stripe and in IDCERT's accounting records: 10 years (legal obligation, Art. 6.1.c)
Art. 32 Measures (Art. 30.1.g)
Payment on Stripe pages (PCI DSS): no card data on ExplorerHub servers; webhook with verified signature, idempotent, also handling customer.deleted to align the status when the customer is deleted at Stripe; RLS with no policies
Last updated: September 2026