legal

Privacy Policy

Last updated: 20 July 2026

This policy is written for users in the United Kingdom and European Economic Area. It describes practices implemented by the Convertica product. It is not a substitute for independent legal advice.

1. Who is responsible

The data controller for personal data processed through Convertica is:

GasDigital Ltd
United Kingdom
Website: https://www.convertica.app
Privacy contact: [email protected]

If you need a formal company number, registered office, or Data Protection Officer contact for contractual purposes, request it at the email above.

2. What we collect

2.1 Files you upload

Content of files you upload and files we generate are stored only to perform conversion or related tools (compress, PDF tools, etc.). A scheduled job deletes them within 24 hours. We do not sell file contents, use them to train AI models, or keep a long-term content archive.

2.2 Guest (no account) use

To enforce the free daily conversion allowance we process your IP address and a daily minutes counter. Guest jobs may also store the IP for access control to status/download for that job.

2.3 Accounts

If you register we process:

  • Email address
  • Password hash (never plaintext passwords)
  • Plan tier and remaining conversion minutes
  • Email verification and password-reset token hashes (time-limited)
  • Optional API key hash and prefix (if you create an API key)
  • PayPal payer / subscription identifiers for billing

2.4 Job metadata

For each conversion we keep status, timestamps, minutes consumed, conversion type, and original file type — not file contents after deletion.

2.5 Technical logs

Servers may produce security and error logs (IP, user agent, error stacks). If we enable optional error monitoring (e.g. Sentry), technical error data may be processed by that provider under our configuration.

2.6 Cloud import URLs

If you paste a Google Drive, Dropbox, or other share/direct link, we download the file to convert it. We process the URL and resulting file under the same retention as other uploads. Sharing settings on those platforms remain your responsibility.

3. Why we process data (legal bases)

Under the UK GDPR / EU GDPR we rely on:

  • Contract — providing conversion, account, billing, and support you request
  • Legitimate interests — securing the service, preventing abuse of free quotas, improving reliability (balanced against your rights)
  • Legal obligation — where tax, accounting, or law enforcement rules require retention of limited billing records
  • Consent — for non-essential cookies/analytics if you enable them (see Cookie Policy)

4. Who we share data with

We use processors only as needed to run the Service, for example:

  • PayPal — subscription payments (their privacy policy applies to payment data they process)
  • Resend (or similar) — transactional email (verification, password reset)
  • Hosting / infrastructure — VPS or cloud hosting for the app, database, and object storage of temporary files
  • Optional Sentry — error monitoring if configured

We do not sell personal data. We may disclose information if required by law or to protect rights, safety, and security of the Service.

5. International transfers

Some processors may process data outside the UK/EEA. Where they do, we take steps required by UK GDPR (e.g. standard contractual clauses or equivalent safeguards offered by the provider). Contact us for the current list of processors.

6. Retention

  • Uploaded & converted files: deleted within 24 hours
  • Guest IP daily counters: day-based usage records; not used as a long-term marketing profile
  • Account data: for the life of the account; deleted or anonymised on verified deletion request except where law requires retention
  • Payment records: as required for accounting and dispute handling
  • Security logs: short operational periods unless investigating abuse

7. Cookies and local storage

See our dedicated Cookie Policy and on-site consent banner. Essential storage (login token, consent choice) is required for the Service to work. We do not run third-party advertising cookies on the product.

8. Your rights (UK / EU)

Subject to applicable law, you may have the right to:

  • Access your personal data
  • Rectify inaccurate data
  • Erase data (“right to be forgotten”)
  • Restrict or object to certain processing
  • Data portability (where applicable)
  • Withdraw consent where processing is consent-based
  • Complain to a supervisory authority — in the UK, the Information Commissioner's Office (ICO)

To exercise rights, email [email protected]. We may need to verify your identity. We aim to respond within one month as required by UK GDPR.

9. Children

The Service is not directed at children under 16. If you believe a child has provided personal data, contact us and we will delete it where appropriate.

10. Automated decision-making

We do not use automated decision-making that produces legal or similarly significant effects about you beyond enforcing published quotas and security rules.

11. Security

We use technical measures appropriate to the risk (hashed passwords, JWT sessions, private upload storage, automatic file deletion). More detail: Security. No method of transmission over the Internet is 100% secure.

12. Changes

We may update this policy as the product evolves. Material changes will be reflected by the “Last updated” date. Continued use after changes means you should re-read this page.

13. Contact

Privacy: [email protected]
Support: [email protected]
Security reports: [email protected]