trust center · data + privacy · GDPR
every system that touches your data, listed.
respira is one person and a short list of carefully picked vendors. here is exactly who they are, what they do, where they store things, and whether there is a DPA on file.
last updated Aug 5, 2026
at a glance
- data residency EU (Frankfurt) Supabase Pro · primary region
- encryption TLS 1.3 in transit AES-256 at rest
- cookie taxonomy 4 categories essentials always on · 3 opt-in
- breach notification 72 hours GDPR Art. 33
where respira stands on GDPR
respira is built and run from Brașov, Romania. that makes the EU the home jurisdiction rather than a market to comply into, and the GDPR the baseline every visitor gets, not a regional variant.
- establishment EU-established controller (Romania). GDPR applies directly, not by extension.
- residency accounts, sites, licences, telemetry and audit logs live in Supabase EU (Frankfurt). transfers outside the EEA are covered by Standard Contractual Clauses (2021/914).
- lawful basis recorded per vendor in the table below: contract performance for the ones that make the product work, consent for anything analytics or messaging, legitimate interest for error tracing.
- consent (art. 7) EU, EEA and UK visitors are geo-detected and asked before any non-essential category fires. "essentials only" carries the same visual weight as "okay". every choice is logged server-side so consent is demonstrable, and withdrawal is one click from the footer.
- rights (art. 15-22) access, rectification, erasure, portability, restriction and objection, detailed below. 30 days, usually the same week.
- breach (art. 33) 72 hours, by email to every potentially affected account and posted on this page.
- processors (art. 28) every sub-processor below has a signed DPA or accepted standard terms on file, with the date. if your organisation needs a data processing agreement with respira itself, the article 28 DPA is published in full and takes effect on one email, with a counter-signed copy on request.
one thing stated plainly, because trust pages that only say flattering things are not worth reading: "GDPR compliant" is not a certificate anyone issues. there is no audit behind that phrase the way there is behind SOC 2 or ISO 27001. what is on this page is the actual posture, vendor by vendor, with dates, so you can judge it rather than take a badge on faith.
sub-processors
15 vendors. add or swap one and this page updates from a single typed source.
| vendor | purpose | region | cookies | category | DPA |
|---|---|---|---|---|---|
| Supabase | Auth, primary Postgres, file storage, edge functions. Email, hashed password, user metadata (preferences), license records, telemetry events. No payment data (handled by LemonSqueezy / Polar). | EU (Frankfurt, eu-central-1) | sb-*-auth-token | essentials | DPA → DPA signed · Nov 14, 2025 + SCCs |
| Vercel | Hosting, edge network, serverless function execution. Request headers (IP, UA, country), routing metadata. No request bodies stored beyond function log retention (24h on the hobby tier, 7d on Pro). | EU + global | server-side only | essentials | DPA → standard terms accepted · Nov 14, 2025 + SCCs |
| Google Analytics 4 | Aggregate page-view + event analytics. Truncated IP, user agent, anonymised client id, page path, event name, optional user_id (Supabase UUID) when logged in. | Global (with EU IP truncation) | _ga, _ga_F55E0B1KNX | analytics | DPA → standard terms accepted · Nov 14, 2025 + SCCs |
| PostHog | Product analytics inside the dashboard. Distinct id = Supabase user UUID, email, plan tier, is_trial. Inputs masked in session replays. No payment data, no chat content. | EU (eu.i.posthog.com) | ph_* | analytics | DPA → DPA signed · Jan 12, 2026 + SCCs |
| Customer.io | In-app messaging and journeys. Anonymous visitor id (cookie-bound) or email when logged in. Message impressions, clicks. No content payloads beyond what is needed for delivery. | EU | _cio* | messaging | DPA → DPA signed · Dec 20, 2025 + SCCs |
| Chatwoot | Live chat support widget. Visitor identifier, chat transcript, optional email if you start a conversation. Inactive sessions purge. | EU (Chatwoot self-hosted) | cw_* | messaging | DPA → standard terms accepted · Jan 5, 2026 + SCCs |
| Resend | Transactional and broadcast email delivery. Recipient email, subject, body, delivery + open + click events. Bodies retained 14 days. | EU | server-side only | essentials | DPA → DPA signed · Nov 25, 2025 + SCCs |
| LemonSqueezy retired | Retired. Legacy payment and subscription billing. Historic records only: billing email, name, billing address, and payment method tokens from orders placed before the move to Polar. No new data is sent. Raw card numbers were never held here. | Global | server-side only | essentials | DPA → standard terms accepted · Nov 14, 2025 + SCCs |
| Polar | Payment + subscription billing. Billing email, billing address, payment method tokens. No browser cookies on respira.press. | EU | server-side only | essentials | DPA → standard terms accepted · Feb 8, 2026 + SCCs |
| Anthropic | Marketing copy generation, plus AI-assisted engineering and support. Marketing generation sends product and release text only, with no user identifiers. Support and engineering sessions see only the records needed for the ticket in hand: typically an account email, plan, site list, and error detail. No payment card data, and no content from your WordPress site unless you send it in a ticket yourself. | US (with EU SCCs) | server-side only | essentials | DPA → DPA signed · Dec 1, 2025 + SCCs |
| Google (Gemini API) | Image generation for social and marketing visuals. A text prompt describing the visual, plus brand assets. No user identifiers, no customer data. | Global (with EU SCCs) | server-side only | essentials | DPA → standard terms accepted · Nov 14, 2025 + SCCs |
| OpenAI | Fallback image generation for social and marketing visuals. A text prompt describing the visual. No user identifiers, no customer data. | US (with EU SCCs) | server-side only | essentials | DPA → standard terms accepted + SCCs |
| ElevenLabs | Sage, the support agent on the website and dashboard. On the dashboard: account email and display name, plus the page you are on and the versions you run. On public pages: no identifiers. Whatever you type into the conversation. No payment data, and no content from your WordPress site. | US (with EU SCCs) | server-side only | essentials | DPA → standard terms accepted + SCCs |
| Sentry | Error tracing and reliability monitoring. Stack traces, breadcrumbs, request metadata (path, status). Email + user_id only when explicitly attached to a captured exception. | EU (de.sentry.io) | server-side only | essentials | DPA → DPA signed · Dec 2, 2025 + SCCs |
| Frankfurter (ECB) | USD → EUR FX rate for the Earn page. None. Server-side only, requests a public exchange-rate JSON. | EU | server-side only | essentials | no DPA needed no DPA needed |
lawful basis varies per vendor (contract performance, consent, legitimate interest). per-vendor basis is documented in src/data/sub-processors.ts and surfaced via the cookie widget tune panel.
your rights
plain-english version of GDPR articles 15 through 22. response within 30 days, usually same week.
- access ask for a copy of every personal data point on file. email word@respira.press.
- rectification fix anything that is wrong about you. most fields live in /dashboard/settings; the rest is one email away.
- erasure "right to be forgotten." closes the account, drops every row, and de-identifies retained transactional logs.
- portability JSON export of your account, sites, telemetry, and billing history. file a request via email; turnaround is days, not weeks.
- restriction pause processing without deleting (useful while you decide).
- objection opt out of any processing based on legitimate interest. the cookie widget covers the consent-based categories; this is the broader sibling.
- automated decisions no automated decisions with legal effect are made about you on respira.press today. if that ever changes, you will know first.
security posture
- authentication. Supabase Auth, magic link plus OAuth.
- authorization. Postgres Row-Level Security on every table. reads scoped to
auth.uid() = user_idunless an admin gate explicitly bypasses. - secrets. never in client bundles. rotated quarterly via Vercel env vars.
- backups. Supabase daily PITR, 30-day retention.
- breach notification. 72-hour commitment per GDPR Art. 33. notified via email + posted on this page.
- error tracing. Sentry EU region, PII scrubbing on by default.
questions, requests, or just want to talk through how a workflow uses your data? word@respira.press.