Skip to main content

GDPR Compliance

OptropicGlobal GmbH is committed to protecting personal data in accordance with the General Data Protection Regulation (GDPR).

Data Controller

OptropicGlobal GmbH Musterstraße 1 10115 Berlin, Germany

Data Protection Officer: privacy@optropic.com

Personal Data We Process

API Customers (B2B)

Data TypePurposeLegal Basis
Company nameAccount managementContract
Contact emailService communicationsContract
API key metadataAuthenticationContract
Usage logsBilling, fraud preventionLegitimate interest

End Users (via Customer Apps)

Data TypePurposeLegal Basis
IP address (hashed)Fraud detectionLegitimate interest
Device fingerprint (hashed)Fraud detectionLegitimate interest
Scan location (country only)Fraud detectionLegitimate interest
No Images Stored

Camera images captured during verification are processed entirely on-device. Optropic servers never receive or store photographs.

Privacy by Design

Our architecture implements privacy principles at every level:

1. Data Minimization

  • We only collect data necessary for the service
  • No personal identifiers in verification requests
  • Aggregate statistics over individual tracking

2. Pseudonymization

  • IP addresses hashed before storage
  • Device fingerprints are one-way hashes
  • No correlation between scans and individuals

3. Local Processing

  • Physical features analyzed on-device
  • Feature vectors converted to cryptographic hashes
  • Original images never leave the device

4. Purpose Limitation

  • Data used only for stated purposes
  • No profiling or behavioral tracking
  • No data sold to third parties

Your Rights

Under GDPR, you have the right to:

RightHow to Exercise
AccessEmail privacy@optropic.com
RectificationUpdate via Studio dashboard
ErasureEmail privacy@optropic.com
Data PortabilityExport from Studio dashboard
ObjectEmail privacy@optropic.com
Restrict ProcessingEmail privacy@optropic.com

We respond to all requests within 30 days.

Data Retention

Data TypeRetention Period
Account dataDuration of contract + 7 years
API logs90 days
Verification logs2 years
Billing records10 years (legal requirement)

International Transfers

Data is processed within the EU. If transfers outside the EEA are necessary, we use:

  • EU Standard Contractual Clauses (SCCs)
  • Adequacy decisions where applicable

Sub-Processors

ProcessorPurposeLocation
Vercel Inc.HostingEU (Frankfurt)
Supabase Inc.DatabaseEU (Frankfurt)
Stripe Inc.Payment processingEU

Data Processing Agreement

Enterprise customers receive a Data Processing Agreement (DPA) as part of their contract.

Download DPA Template →

Security Measures

Technical and organizational measures protecting personal data:

  • Encryption at rest (AES-256) and in transit (TLS 1.3)
  • Access control and authentication
  • Regular security assessments
  • Employee security training
  • Incident response procedures

See our Security Policy for details.

Breach Notification

In the event of a personal data breach:

  1. We will notify the supervisory authority within 72 hours
  2. We will notify affected individuals if high risk
  3. We will document the breach and remediation

Contact

For GDPR inquiries or to exercise your rights:

Data Protection Officer privacy@optropic.com

Postal Address: OptropicGlobal GmbH Attn: Data Protection Officer Musterstraße 1 10115 Berlin, Germany

Supervisory Authority

You have the right to lodge a complaint with:

Berliner Beauftragte für Datenschutz und Informationsfreiheit Friedrichstraße 219 10969 Berlin mailbox@datenschutz-berlin.de