Your data protection rights under EU law
SnapAPI is committed to protecting your personal data and complying with the General Data Protection Regulation (GDPR). This page explains how we process personal data of individuals in the European Economic Area (EEA) and the United Kingdom.
This document supplements our Privacy Policy with specific information required by the GDPR.
For the purposes of the GDPR, SnapAPI acts as:
Contact details:
We process personal data under the following legal bases:
| Processing Activity | Legal Basis |
|---|---|
| Account creation and management | Contract performance (Article 6(1)(b)) |
| Processing API requests | Contract performance (Article 6(1)(b)) |
| Payment processing | Contract performance (Article 6(1)(b)) |
| Service-related communications | Legitimate interest (Article 6(1)(f)) |
| Analytics and service improvement | Legitimate interest (Article 6(1)(f)) |
| Marketing communications | Consent (Article 6(1)(a)) |
| Legal compliance | Legal obligation (Article 6(1)(c)) |
Under the GDPR, you have the following rights:
Request a copy of all personal data we hold about you.
Request correction of inaccurate or incomplete personal data.
Request deletion of your personal data ("right to be forgotten").
Request limitation of processing of your personal data.
Receive your data in a structured, machine-readable format.
Object to processing based on legitimate interests or for marketing.
Withdraw consent at any time where we rely on consent.
Lodge a complaint with a supervisory authority.
To exercise any of these rights, please contact us at dpo@snapapi.pics. We will respond to your request within 30 days.
You can also exercise many of these rights directly through your dashboard:
We use the following sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| LemonSqueezy | Payment processing | USA (Privacy Shield) |
| Google Cloud | Infrastructure hosting | EU (Frankfurt) |
| Cloudflare | CDN and DDoS protection | Global (EU data centers) |
When we transfer personal data outside the EEA, we ensure appropriate safeguards are in place:
You can request a copy of the relevant safeguards by contacting our DPO.
We retain personal data only as long as necessary:
| Data Type | Retention Period | Justification |
|---|---|---|
| Account data | Until account deletion + 30 days | Contract performance |
| Usage logs | 90 days | Legitimate interest (debugging) |
| Payment records | 7 years | Legal obligation (tax laws) |
| Marketing consent | Until withdrawn | Consent records |
We implement appropriate technical and organizational measures including:
For enterprise customers who need a Data Processing Agreement (DPA), we provide a GDPR-compliant DPA that includes:
Contact legal@snapapi.pics to request a DPA.
For any GDPR-related inquiries, please contact our Data Protection Officer:
You also have the right to lodge a complaint with your local supervisory authority if you believe your data protection rights have been violated.