PawByTech

Privacy Policy

Last updated: August 6, 2026

We collect what the service needs to work, and nothing for advertising. Your account data is ours to look after as controller; the business leads you save are yours, and we handle them only on your instructions. Everything runs on servers in Germany.

1. Who is responsible for your data

The controller for the personal data described in this policy is Dodera Software S.R.L. ("we", "us"), a company registered in Romania, registered office Str. Banat nr. 1, ap. 2, 440043 Satu Mare, jud. Satu Mare, Romania, Trade Register J30/958/2023, tax identification code 49004234. We operate the PawByTech service at https://pawbytech.com.

For anything in this policy, write to office@doderasoft.com.

We have not appointed a Data Protection Officer. We are not a public authority, our core activity is not large-scale monitoring of individuals, and we do not process special categories of data on a large scale, so Art. 37 GDPR does not require one. Requests reach a person at the address above.

2. Where your data is processed

The application server, the Postgres database and the object storage holding generated sites all run on infrastructure operated by Hetzner Online GmbH in Germany, inside the European Economic Area. Data leaves the EEA only through the providers named in section 6, and only with the safeguards listed there.

3. Two different roles — and why it matters

PawByTech handles two kinds of personal data, and our legal position differs for each.

  • Data about you, our customer. Your account, your workspace membership, your billing record, your session. Here we are the controller — we decide why and how it is processed. This policy governs it.
  • Data about the businesses you scout. The leads you search for, save, enrich, annotate and contact. You decide which businesses to look up, what to keep, and what to do with it, so you are the controller and we are your processor. We act on your instructions, which are the actions you take in the app. That relationship is governed by our Data Processing Agreement, which forms part of your contract with us.

This split is not a formality. It means you — not we — are responsible for having a lawful basis to contact the businesses you find, for telling them where you got their details when Art. 14 GDPR requires it, and for respecting their objections. The Terms of Service spell out those duties.

4. What we collect, why, and on what legal basis

We collect all of this directly from you, or generate it as you use the service. Nothing here is bought from a data broker.

PurposeDataLegal basis
Creating and running your accountName, email, password hash, email-verification status, Google account identifier and tokens if you sign in with GooglePerformance of a contract — Art. 6(1)(b) GDPR
Keeping you signed inSession token, IP address, user agent, session expiryPerformance of a contract — Art. 6(1)(b) GDPR
Running your workspaceWorkspace name, membership, roles, invitation emails, and everything you store: saved leads, board stages, notes, follow-up dates, generated sites, outreach draftsPerformance of a contract — Art. 6(1)(b) GDPR. For the lead data itself we act as your processor (see section 3)
Billing and accountingStripe customer and subscription identifiers, plan, billing period, invoices, credit balance and ledgerPerformance of a contract — Art. 6(1)(b); legal obligation for accounting and tax records — Art. 6(1)(c) GDPR
Account emailsEmail address, name, and the link being sentPerformance of a contract — Art. 6(1)(b) GDPR
Keeping the service secure and availableIP address, request path and timestamp, rate-limit counters, per-workspace usage countersLegitimate interests — Art. 6(1)(f) GDPR: preventing abuse, controlling cost, keeping the service working
Answering your messagesYour email address and whatever you write to usLegitimate interests — Art. 6(1)(f) GDPR: responding to the person who contacted us

Payment details never reach us. Card numbers are entered on Stripe's own checkout and stay with Stripe. We store only the identifiers and status Stripe returns.

We do not send marketing email unless you have separately opted in, and we do not sell, rent or share personal data for anyone else's marketing.

Our legitimate interests, weighed

Where we rely on Art. 6(1)(f), we have weighed our interest against your rights. Security and rate-limit logging uses the minimum data needed — an IP address and a timestamp — is kept briefly, is never used to profile you or to make decisions about you, and protects both you and us from account takeover and abuse. That is an interest you can reasonably expect a service like this to pursue. You can object at any time under Art. 21 GDPR; see section 8.

5. How long we keep it

DataRetention
Account and profile dataUntil you delete your account, then removed
SessionsUp to 7 days from last use; deleted immediately when you sign out
Workspace content (leads, board, notes)Until you delete it, or until the workspace is deleted
Generated mock sites and their public linksDeleted automatically 60 days after creation
InvitationsUntil accepted, revoked, or expired
Invoices and accounting records5 years from 1 July of the year following the financial year, as required by Law 82/1991 art. 25 (as amended by Law 36/2023)
Server and security logsKept in our hosting platform's rolling log storage; not archived or exported elsewhere

Deleting your account removes the account record, your sessions, your sign-in methods and your workspace memberships. A workspace is deleted separately, by its owner, from the workspace settings — and deleting it removes its leads, board, notes and generated sites with it. If you are leaving and want a workspace and its contents erased as well, delete it first or write to us and we will erase it for you.

Accounting records survive deletion because the law requires it, and are used for nothing else.

6. Who else processes it

We use a small number of providers. Each acts under a contract meeting Art. 28 GDPR, and none may use your data for their own purposes.

ProviderWhat it doesLocationTransfer safeguard
Hetzner Online GmbHApplication server, Postgres database and object storageGermany (EEA)No transfer — data stays in the EEA
Anthropic PBCAI generation of mock sites and outreach draftsUnited StatesEU Standard Contractual Clauses (Decision 2021/914), Module 3
Stripe Payments Europe, Ltd.Payments, subscriptions and invoicesIreland (EEA), with onward transfer to Stripe, Inc.EU Standard Contractual Clauses and EU-US Data Privacy Framework
Google Ireland Ltd.Business search (Places API), performance audits (PageSpeed), Google sign-inIreland (EEA), with onward transfer to Google LLCEU Standard Contractual Clauses and EU-US Data Privacy Framework
Zoho Corporation B.V.Delivery of account emails (verification, sign-in links, invitations)Netherlands (EEA), data centres in Amsterdam and DublinNo transfer — the EU service keeps data in the EEA

Anthropic does not train its models on content sent through the API. The business brief, and any revision instruction you write, are sent in order to generate the mock site or message draft you asked for — so avoid putting personal details in them that the task does not need.

Transfers to the United States rely on the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914) and, where the provider is certified, on the EU-US Data Privacy Framework adequacy decision (Implementing Decision (EU) 2023/1795), which remains in force. You may request a copy of the safeguards in place by writing to us.

We may also disclose data to professional advisers, or to a public authority where a valid legal request obliges us to. If our business is transferred, your data may pass to the acquirer under the same terms, and we will tell you before that happens.

7. Automated processing

PawByTech scores businesses automatically — that is what the product does. Those scores are about a business's online presence, not about you, and they produce no legal or similarly significant effect on any individual. We do not carry out automated decision-making or profiling within the meaning of Art. 22 GDPR against our own users.

8. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you, and receive a copy (Art. 15);
  • have inaccurate data corrected (Art. 16);
  • have data erased where the conditions apply (Art. 17);
  • restrict processing while a dispute is resolved (Art. 18);
  • receive the data you gave us in a portable format, or have it sent to another provider (Art. 20);
  • object to processing based on our legitimate interests, on grounds relating to your situation (Art. 21);
  • withdraw any consent you have given, without affecting what was done beforehand.

Write to office@doderasoft.com. We answer within one month, and will tell you if we need the extension Art. 12(3) GDPR allows. Exercising these rights is free — we charge only for manifestly unfounded or excessive repeat requests, as Art. 12(5) permits. You can also delete your account yourself from the profile page.

If you think we have handled your data badly we would rather hear it first, but you have the right to complain to a supervisory authority — in Romania the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336 Bucharest, Romania, email anspdcp@dataprotection.ro, dataprotection.ro. If you live in another EU country you may complain to your own authority instead.

9. If your business appears in PawByTech

This section is for people who are not our customers, but whose details our customers may find through the service. It is the information Art. 14 GDPR requires when data has not been collected from you directly.

  • What we handle. Business name and address, phone number, website, opening hours, ratings and review counts, photos, and contact details published on the business's own website — typically a generic email address and social profiles. Where a business is a sole trader, or the contact details name a person, that is personal data.
  • Where it comes from. The Google Places API, Google PageSpeed Insights, and the publicly reachable pages of the business's own website, fetched by our crawler identifying itself as PawByTechBot.
  • Why. So that our customer can assess whether the business might need web or IT services, and contact it about that. The controller for this is our customer, not us; we process it on their instructions.
  • How long. Search results are transient. Anything a customer saves stays in their workspace until they delete it, or their workspace is deleted.
  • Your rights. The rights in section 8 apply, including the right to object to processing for direct marketing under Art. 21(2) GDPR — an objection we and our customers must honour without exception.

Write to office@doderasoft.com and we will remove your details from our systems and instruct the customer workspaces holding them to do the same. If you tell us who contacted you, we can identify the customer responsible so that you can exercise your rights against them directly.

10. Cookies and local storage

We use only what the service cannot work without — a session cookie and a couple of stored preferences. No analytics, no advertising, no third-party trackers, and therefore no consent banner. Each one is named and explained in the Cookie Policy.

11. Security

Traffic runs over TLS. Passwords are stored hashed, never in readable form. Session cookies are HTTP-only and secure, so page scripts cannot read them. Every request is scoped to your workspace, and rate limits sit in front of the sign-in, sign-up and password-reset endpoints. A content security policy blocks scripts from other origins. Card data never touches our servers.

No system is perfectly secure. If a breach is likely to result in a high risk to your rights we will tell you without undue delay, and we will notify the supervisory authority within 72 hours, as Art. 33 GDPR requires.

12. Children

PawByTech is a tool for businesses and is not directed at children. We do not knowingly create accounts for anyone under 16. If you believe a child has registered, tell us and we will remove the account.

13. Changes to this policy

We may update this policy as the service changes. The date at the top always reflects the current version. If a change materially affects your rights we will tell you by email or in the app before it takes effect.