Processing Activities Registry

GDPR Art. 30

Record of processing activities pursuant to Art. 30 of Regulation (EU) 2016/679 (GDPR).

Data Controller

IDCERT S.r.l. Benefit Corporation

privacy@idcert.io

Pursuant to Art. 37 GDPR, the appointment of a DPO is not currently mandatory. This section will be updated if circumstances change.

T-01

Technical operation of the portal

Purpose (Art. 30.1.b)

Provision of web service, routing, page rendering

Legal Basis

Art. 6.1.f

Data Subjects (Art. 30.1.c)

Website visitors

Data Categories (Art. 30.1.c)

Navigation data (anonymized IP, user agent, URL)

Recipients (Art. 30.1.d)

Vercel Inc. (hosting), Supabase Inc. (database)

Extra-EU Transfers (Art. 30.1.e)

USA (Vercel) with SCCs; EU (Supabase eu-central-1)

Retention (Art. 30.1.f)

Duration of session

Art. 32 Measures (Art. 30.1.g)

HTTPS/TLS, CSP, HSTS, X-Frame-Options DENY, anonymized IP

T-02

Cookie consent management

Purpose (Art. 30.1.b)

Collection and recording of consent for GDPR accountability

Legal Basis

Art. 6.1.c

Data Subjects (Art. 30.1.c)

Website visitors

Data Categories (Art. 30.1.c)

Anonymous session ID, IP hash (SHA-256 + rotating salt), cookie preferences, policy version, user agent

Recipients (Art. 30.1.d)

Supabase Inc. (database, EU region)

Extra-EU Transfers (Art. 30.1.e)

EU (Supabase eu-central-1)

Retention (Art. 30.1.f)

5 years (GDPR Art. 5.2 accountability obligations)

Art. 32 Measures (Art. 30.1.g)

Supabase RLS, SHA-256 anonymized IP, CSRF protection, rate limiting

T-03

Contact request management

Purpose (Art. 30.1.b)

Responding to user requests sent through the contact form

Legal Basis

Art. 6.1.b

Data Subjects (Art. 30.1.c)

Users who fill out the contact form

Data Categories (Art. 30.1.c)

Name, email, subject, message, IP hash, language

Recipients (Art. 30.1.d)

Supabase Inc. (database, EU region)

Extra-EU Transfers (Art. 30.1.e)

EU (Supabase eu-central-1)

Retention (Art. 30.1.f)

12 months from request

Art. 32 Measures (Art. 30.1.g)

Supabase RLS, anti-bot honeypot, CSRF, rate limiting (3 req/10 min), anonymized IP

T-04

Google Analytics (consent-gated)

Purpose (Art. 30.1.b)

Anonymous statistical traffic analysis to improve the service

Legal Basis

Art. 6.1.a

Data Subjects (Art. 30.1.c)

Visitors who consent to analytics cookies

Data Categories (Art. 30.1.c)

Aggregated navigation data, IP anonymized by Google, _ga cookie

Recipients (Art. 30.1.d)

Google LLC

Extra-EU Transfers (Art. 30.1.e)

USA (Google) with EU-US Data Privacy Framework

Retention (Art. 30.1.f)

26 months (GA4 setting)

Art. 32 Measures (Art. 30.1.g)

Activated ONLY after explicit consent, anonymize_ip: true, SameSite=Lax;Secure cookies

T-05

User interface preferences

Purpose (Art. 30.1.b)

Storing language and theme preferences (light/dark)

Legal Basis

Art. 6.1.f

Data Subjects (Art. 30.1.c)

All visitors

Data Categories (Art. 30.1.c)

Language code (NEXT_LOCALE), theme (localStorage 'theme')

Recipients (Art. 30.1.d)

None (local data only)

Extra-EU Transfers (Art. 30.1.e)

None

Retention (Art. 30.1.f)

NEXT_LOCALE: 12 months; theme: until manual deletion

Art. 32 Measures (Art. 30.1.g)

Non-personal technical data, no transfer

T-06

User authentication

Purpose (Art. 30.1.b)

Registration, login, and user session management via Supabase Auth

Legal Basis

Art. 6.1.b

Data Subjects (Art. 30.1.c)

Registered users

Data Categories (Art. 30.1.c)

Email, password (hash), name, avatar URL, role, preferred locale, creation date

Recipients (Art. 30.1.d)

Supabase (sub-processor, EU/EEA infrastructure)

Extra-EU Transfers (Art. 30.1.e)

Supabase: EU servers (aws-eu-central-1). Standard Contractual Clauses (SCCs) in place.

Retention (Art. 30.1.f)

Until account deletion (ON DELETE CASCADE on all user data)

Art. 32 Measures (Art. 30.1.g)

Password hashed (bcrypt), HttpOnly/Secure/SameSite=Lax cookies, PKCE flow, RLS on all tables, session refresh via proxy

T-07

User data management (bookmarks, search history, preferences)

Purpose (Art. 30.1.b)

Saving bookmarks, search history, and personalized preferences for authenticated users

Legal Basis

Art. 6.1.b

Data Subjects (Art. 30.1.c)

Registered users

Data Categories (Art. 30.1.c)

Saved resource URIs, type (occupation/skill/qualification), title, search timestamps, theme/language preferences

Recipients (Art. 30.1.d)

Supabase (sub-processor, EU/EEA infrastructure)

Extra-EU Transfers (Art. 30.1.e)

Supabase: EU servers (aws-eu-central-1)

Retention (Art. 30.1.f)

Until account deletion (ON DELETE CASCADE). Bookmarks and history can be individually deleted by user.

Art. 32 Measures (Art. 30.1.g)

RLS: each user can only access their own data. Admin: read-only. Role escalation prevention via RLS.

T-08

Error monitoring and stability (Sentry)

Purpose (Art. 30.1.b)

Detection and diagnosis of application errors to ensure service stability. Session Replay (session recording) activated only after analytics consent.

Legal Basis

Art. 6.1.f / Art. 6.1.a

Data Subjects (Art. 30.1.c)

Website visitors and registered users

Data Categories (Art. 30.1.c)

Error stack traces, URL, user agent, browser. With analytics consent: IP, cookies, HTTP headers, interaction recordings (Session Replay)

Recipients (Art. 30.1.d)

Functional Software Inc. (Sentry), San Francisco, CA, USA

Extra-EU Transfers (Art. 30.1.e)

USA (Sentry) with Standard Contractual Clauses (SCCs)

Retention (Art. 30.1.f)

90 days (Sentry default setting)

Art. 32 Measures (Art. 30.1.g)

Basic mode without PII (legitimate interest). PII and Session Replay activated ONLY after explicit analytics consent. Tunnel route /monitoring for ad-blocker bypass. Source maps hidden from client.

T-09

Anti-bot protection (Cloudflare Turnstile)

Purpose (Art. 30.1.b)

Automated anti-bot verification on contact, registration and login forms to prevent abuse and spam

Legal Basis

Art. 6.1.f

Data Subjects (Art. 30.1.c)

Users who interact with protected forms (contact, registration, login, email change)

Data Categories (Art. 30.1.c)

IP address, browser fingerprint, widget interaction data, verification token

Recipients (Art. 30.1.d)

Cloudflare Inc., San Francisco, CA, USA

Extra-EU Transfers (Art. 30.1.e)

USA (Cloudflare) with Standard Contractual Clauses (SCCs)

Retention (Art. 30.1.f)

Duration of verification (data is not retained after token validation)

Art. 32 Measures (Art. 30.1.g)

No tracking cookies. Non-invasive widget ('managed' mode). No consent required — legitimate interest for service security.

T-10

MCP service (programmatic access to the frameworks)

Purpose (Art. 30.1.b)

Provision of the API-key MCP server: authentication, enforcement of the subscribed tier's limits, per-key usage measurement, abuse prevention

Legal Basis

Art. 6.1.b / 6.1.f

Data Subjects (Art. 30.1.c)

Registered users who create an API key in the account area

Data Categories (Art. 30.1.c)

API key (SHA-256 fingerprint and prefix only), key name, tier, accepted terms version; call log: tool, framework, request parameters, IP hash (SHA-256 + daily salt), user agent, outcome, duration; rate-limit counters: IP address in clear (requests without a valid key) or key identifier, for the 60-second window only; monthly quota counters: account identifier, for the calendar month; administrative measures on keys (suspension, reactivation, revocation): date, reason, note, administrator identifier, outcome of the email notice

Recipients (Art. 30.1.d)

Supabase Inc. (database, EU region), Vercel Inc. (hosting), Upstash, Inc. (Redis: rate-limit counters, ephemeral)

Extra-EU Transfers (Art. 30.1.e)

EU (Supabase eu-central-1); USA (Vercel Inc., Upstash, Inc.) under the EU-US Data Privacy Framework and, as a fallback, SCCs

Retention (Art. 30.1.f)

Keys: until revocation or account deletion; revoked key: hash only, for 12 months after revocation, then deleted; call log: 12 months, daily automatic purge; rate-limit counters: 60 seconds; monthly quota counters: until the first day of the following month; administrative measures on keys: 12 months, daily automatic purge

Art. 32 Measures (Art. 30.1.g)

Key stored only as SHA-256 hash; RLS enabled with no policies (server-side access only); IP never stored in clear in the log, in clear only in the rate-limit counter for 60 seconds; rate limits per IP and per key; HTTPS/TLS

T-11

MCP service Pro subscription (Stripe)

Purpose (Art. 30.1.b)

Activation, renewal and management of the paid Pro tier subscription; invoicing

Legal Basis

Art. 6.1.b / 6.1.c

Data Subjects (Art. 30.1.c)

Registered users who subscribe to the Pro tier

Data Categories (Art. 30.1.c)

At ExplorerHub: Stripe customer identifier, subscription identifier and status, plan, period end; events notified by Stripe (identifier and type only). At Stripe: email, payment data, billing address, invoices

Recipients (Art. 30.1.d)

Stripe Payments Europe, Ltd. (Dublin, Ireland) — processor for payments and invoicing; Supabase Inc. (database, EU region)

Extra-EU Transfers (Art. 30.1.e)

EU (Stripe Payments Europe, Supabase); possible transfers to Stripe, LLC (USA) under the EU-US Data Privacy Framework and SCCs

Retention (Art. 30.1.f)

Subscription data (Stripe identifiers, status, plan, period end): until account deletion, which cancels the subscription at Stripe; Stripe events (identifier and type): 12 months, daily automatic purge; invoices and tax documents at Stripe and in IDCERT's accounting records: 10 years (legal obligation, Art. 6.1.c)

Art. 32 Measures (Art. 30.1.g)

Payment on Stripe pages (PCI DSS): no card data on ExplorerHub servers; webhook with verified signature, idempotent, also handling customer.deleted to align the status when the customer is deleted at Stripe; RLS with no policies

Last updated: September 2026