0/5
Back to Home
GDPR Transparency & Personal Data Protection

Privacy Policy

Effective: October 2026 · Compliant with GDPR, TDDDG, and EU-U.S. Data Privacy Framework

1. Name and Address of the Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) and other national data protection laws of EU member states is:

NexaScribe

Proprietor: Mila Schorradt

Wiesengrund 3, 35091 Cölbe, Germany

Phone: +49 160 1664356

E-Mail: kontakt@nexascribe.eu

2. Processing of Handwriting Characteristics (Art. 9 GDPR)

The core functionality of NexaScribe consists of the digitization, vectorization, and typographic reconstruction of your personal handwriting.

Processed Data: When you draw characters on the drawing canvas, our engine analyzes stroke coordinates, pen pressure, stroke thickness, and slant angles.

Legal Basis: Insofar as these handwriting characteristics are classified as biometric data pursuant to Art. 4 No. 14 GDPR, processing occurs solely on the basis of your explicit consent pursuant to Art. 6 (1) lit. a in conjunction with Art. 9 (2) lit. a GDPR.

Zero AI Training with User Data: Your individual glyphs and custom fonts are NEVER used to train public AI models. The data is utilized exclusively for generating your personal typography and rendering your documents.

3. Web Hosting & Server Infrastructure (Vercel & Render)

Frontend Hosting via Vercel: Our web application is deployed across the global edge network of Vercel Inc. (440 N Barranca Ave #4133, Covina, CA 91723, USA). When accessing our pages, Vercel collects technical access data (server log files such as IP address, browser type, operating system, date and time of request) to ensure system reliability and DDoS mitigation.

Backend Hosting via Render: The backend and PDF rendering engine operate on servers hosted by Render Services, Inc. (San Francisco, CA, USA). All communication between frontend and backend takes place over secured, TLS-encrypted HTTPS connections.

Legal Basis & Data Transfers: Processing is based on Art. 6 (1) lit. f GDPR (legitimate interest in providing secure, performant, and flawless online services). Data transfers to the USA are safeguarded by Data Processing Agreements (DPAs) incorporating the European Commission's Standard Contractual Clauses (SCCs) and adherence to the EU-U.S. Data Privacy Framework.

4. Payment Processing via Stripe

For processing paid subscriptions (Plus and Premium), we utilize the payment service provider Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland (hereinafter 'Stripe').

Transmitted Data: When completing a paid subscription, your order data (selected plan, invoice amount, currency) and email address are transmitted encrypted to Stripe. The entry of your sensitive payment credentials (e.g. credit card number, CVC, bank details) takes place directly within Stripe's PCI-DSS Level 1 certified systems. We never store or have access to your full payment card details.

Legal Basis & Compliance: Data processing is performed for the fulfillment of purchase and subscription contracts pursuant to Art. 6 (1) lit. b GDPR as well as compliance with statutory tax and accounting obligations (Art. 6 (1) lit. c GDPR). For more details, consult Stripe's privacy policy: https://stripe.com/privacy.

5. AI Backend & Problem Solver (OpenAI & Google Gemini API)

For AI-assisted mathematical and textual problem analysis within 'Solve Task' mode, we connect with enterprise APIs from leading AI providers:

  • OpenAI, L.L.C., 3180 18th Street, San Francisco, CA 94110, USA
  • Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) / Google LLC (USA)

Strict Purpose Limitation & Zero Training: We exclusively utilize official enterprise/commercial APIs. Under the enterprise terms of service, submitted user inputs (prompts, task images) are strictly prohibited from being used to train or refine public foundation models. Transmitted data is processed only to return the result and is subject to strict zero-data-retention standards.

Legal Basis: Art. 6 (1) lit. b GDPR (performance of a contract to deliver the automated solution explicitly requested by the user).

6. Cookies & Web Storage (Section 25 TDDDG)

In accordance with Section 25 (2) No. 2 TDDDG (German Telecommunications-Telemedia Data Protection Act), we store only strictly necessary technical data in your browser:

  • nexascribe_token / Session-Token: For authentication and maintaining your secure session.
  • nexascribe_audio_muted: Stores your personal preference for sound effects.

We do not deploy any marketing cookies, ad networks, tracking pixels, or cross-site tracking technologies.

7. Storage Duration & Right to Erasure (Art. 17 GDPR)

We retain personal data only for as long as necessary to fulfill the respective purpose:

  • Handwriting Fonts & Glyphs: Stored securely in your private user space for the duration of your account registration.
  • Instant Self-Deletion: You can delete your custom fonts at any time in the 'Settings' panel or irrevocably erase your entire account with a single click.
  • Billing Records: Statutory fiscal and commercial retention requirements (e.g. HGB/AO) remain unaffected.

8. Your Rights as a Data Subject

As a data subject, you are entitled to comprehensive rights under Chapter III of the GDPR:

Art. 15 GDPR: Right of access to your stored personal data.
Art. 16 GDPR: Right to rectification of inaccurate data.
Art. 17 GDPR: Right to erasure ('Right to be forgotten').
Art. 20 GDPR: Right to data portability in a structured, machine-readable format.
Art. 7 (3) GDPR: Right to withdraw granted consent at any time.
Art. 77 GDPR: Right to lodge a complaint with a data protection supervisory authority.

To exercise any of your data protection rights, please contact: kontakt@nexascribe.eu.