Privacy Policy
Last updated: 12 July 2026
1. Controller
The controller of the personal data described in this policy is Héctor Cruz Aranda, sole trader (autónomo), Spain, operating under the trade name TerraSov. Contact: support@terrasov.dev. The registered address is published in the imprint once registration formalities are completed.
2. What we process, why, and on what legal basis
| Data | Source | Purpose | Legal basis (GDPR) |
|---|---|---|---|
| Checkout email address and subscription status | Paddle (merchant of record) | Provisioning and managing your subscription and repository access | Art. 6(1)(b) — performance of a contract |
| Billing and transaction records held on our side | Paddle | Accounting and tax obligations | Art. 6(1)(c) — legal obligation (Spanish tax law) |
| GitHub username(s) assigned as engineer accounts | You, via the activation form | Granting, counting and revoking repository access | Art. 6(1)(b) — performance of a contract |
| Support correspondence | You, by email | Answering questions and resolving issues | Art. 6(1)(f) — legitimate interest in providing support |
We do not see or store your payment details. Card and payment data are processed exclusively by Paddle, whose privacy policy applies to the checkout.
3. Recipients and subprocessors
| Recipient | Role | Data touched |
|---|---|---|
| Paddle.com Market Ltd / Paddle Payments Ltd | Merchant of record: checkout, billing, VAT, invoicing | Billing details, email address |
| Amazon Web Services EMEA SARL | Platform hosting in eu-central-1 (Frankfurt), records encrypted with customer-managed KMS keys | Email address, GitHub usernames |
| GitHub, Inc. | Library repository delivery and access management | GitHub usernames |
| Cloudflare, Inc. | Website and API edge delivery | Transit only (IP addresses in transient logs) |
4. International transfers
Our own infrastructure runs in the EU (AWS eu-central-1, Frankfurt). Where a recipient listed above may process data outside the EEA — for example GitHub or Cloudflare in the United States — transfers rely on a European Commission adequacy decision (including the EU–US Data Privacy Framework where the recipient is certified) or on Standard Contractual Clauses.
5. Retention
- Subscription and billing records — for the duration of the contract and afterwards for the retention periods required by Spanish tax and commercial law.
- Access records (GitHub usernames) — deleted when repository access is revoked.
- Support correspondence — kept until the issue is resolved, then deleted in routine clean-ups.
6. Your rights
Under the GDPR you have the right of access, rectification, erasure, restriction of processing, data portability, and objection to processing based on legitimate interest. To exercise any of them, email support@terrasov.dev. You also have the right to lodge a complaint with the Spanish supervisory authority, the Agencia Española de Protección de Datos (aepd.es), or with the supervisory authority of your habitual residence.
7. Security
Customer records are stored in the EU, encrypted at rest with customer-managed KMS keys, and reachable only by single-purpose serverless functions — the same controls the Library enforces. A full description of our technical and organisational measures is on the security page.
8. Cookies and tracking
This website sets no cookies and runs no analytics or advertising trackers. When you open the Paddle checkout on the pricing page, Paddle sets its own strictly-necessary cookies required to process the transaction; see Paddle's privacy policy for details.