# Privacy Policy — Vebit

> **DRAFT for legal review.** Final version must be reviewed by an Icelandic
> lawyer experienced in GDPR / SaaS. Replace `[BRAND]`, `[COMPANY_NAME]`,
> `[KT]`, `[ADDRESS]`, `[EMAIL]` with finalized values before publishing.

**Effective date:** [DATE]
**Last updated:** [DATE]

---

## 1. Who we are

[BRAND] (hereafter "we", "us", "the Service") is a SaaS work-management
platform for tradespeople, operated by **[COMPANY_NAME]**, kt.
**[KT]**, registered office at **[ADDRESS]**, Iceland.

For privacy-related inquiries: **[EMAIL]**

## 2. Scope

This Privacy Policy explains how [BRAND] collects, uses, stores, and shares
personal data when you use the Service (vebit.is and app.vebit.is).

We are the **data controller** for personal data of:
- Users who sign up directly (e.g. company owners creating an account)
- Visitors to our marketing site

We act as a **data processor** for personal data your company adds to the
Service about your employees, customers, suppliers, or projects. Your
company is the data controller for that data; your Data Processing Agreement
(DPA) governs that relationship.

## 3. What data we collect

### 3.1 Account data (you provide)
- Email address (used for login + transactional emails)
- Password (stored hashed — we never see it)
- Display name
- Company name and (optionally) kennitala

### 3.2 Usage data (we collect when you use the Service)
- Pages visited within the app, timestamps, app version
- Errors encountered (browser, OS, viewport size — no personal content)
- IP address (used briefly for security / rate limiting, not stored long-term)

### 3.3 Customer-content data (your company adds)
- Project names, addresses, customer details
- Time entries, task lists, photos, comments
- Receipts (nóta) and invoices
- Anything else your team enters

We treat customer-content data as belonging to your company. We don't read,
share, or use it for anything except providing the Service to you.

### 3.4 Cookies & tracking
- We use **functional cookies only** — session cookies needed to keep you
  logged in. No advertising cookies. No third-party tracking pixels.
- No Google Analytics or similar by default. If we ever add usage analytics,
  it will be privacy-preserving (e.g. Plausible) and disclosed here.

## 4. Why we collect it (legal basis under GDPR)

| Data type | Purpose | Legal basis |
|---|---|---|
| Account data | Provide the Service, account management, login | Contract (Art. 6(1)(b)) |
| Usage / error data | Detect bugs, improve reliability | Legitimate interests (Art. 6(1)(f)) |
| Customer-content data | Process on your company's behalf | Contract via DPA |
| Billing data | Charge for the Service | Contract |
| Marketing emails | Tell you about updates (only if you opted in) | Consent (Art. 6(1)(a)) |

## 5. Who we share data with

We never sell personal data. We only share with vendors strictly needed to
operate the Service:

| Vendor | Purpose | Location |
|---|---|---|
| Supabase Inc. | Database, auth, storage | EU (Frankfurt) |
| Vercel Inc. | Hosting our frontend | Global (we ensure EU edge serving where possible) |
| Resend | Transactional emails (password resets, etc.) | US — uses Standard Contractual Clauses |
| OneSignal | Push notifications | US — SCCs |
| Anthropic | AI features (voice-to-task, auto-categorize) — text data sent, deleted immediately | US — SCCs, zero-retention policy |
| Payday | If you connect your Payday account | Iceland |
| Stripe (planned) | Billing | Global — SCCs |

We maintain a Data Processing Agreement with each. Full list available on
request.

## 6. International transfers

All primary storage is in the EU (Frankfurt). Some processors operate in the
US — we rely on Standard Contractual Clauses (SCCs) approved by the European
Commission, plus supplementary measures (encryption in transit and at rest)
to ensure GDPR-equivalent protection.

## 7. How long we keep data

| Data | Retention |
|---|---|
| Account data | While your account is active. 30 days after account closure (recovery window), then anonymized. |
| Customer-content data | While your subscription is active. After cancellation: 30 days then export-or-delete. |
| Error logs | 30 days, then auto-deleted |
| Billing records | 7 years (Icelandic tax law) — minimum data only |
| Marketing emails | Until you unsubscribe |
| Backups | Daily backups retained for 30 days, encrypted |

## 8. Your rights under GDPR

You have the right to:
- **Access** — request a copy of all personal data we hold about you
- **Rectify** — correct inaccurate data
- **Erase** — delete your account and associated data
- **Restrict processing** — temporarily limit what we do with your data
- **Portability** — receive your data in a machine-readable format
- **Object** — opt out of certain processing (especially marketing)
- **Withdraw consent** — for processing that relies on consent

Submit any request to **[EMAIL]**. We respond within 30 days.

For complaints, you can contact **Persónuvernd** (Icelandic Data Protection
Authority) — [personuvernd.is](https://personuvernd.is).

## 9. How we protect data

- TLS 1.2+ for all connections (HTTPS only)
- Database encrypted at rest (AES-256 via Supabase)
- Passwords hashed with bcrypt
- Row-level security policies on every database table (one customer cannot
  see another customer's data)
- Strict access control internally — only authorized engineers can access
  production data, audited
- Annual security review by external party (planned post-launch)

## 10. Data breaches

If we discover a breach affecting your personal data, we'll notify you and
the relevant authority within 72 hours, in line with GDPR Article 33.

## 11. Children's data

The Service is not intended for use by people under 18. We do not knowingly
collect data about minors. If we discover such data, we delete it.

## 12. Changes to this policy

We'll update this policy when we make changes that affect your rights.
Material changes will be communicated by email to active users at least
30 days before they take effect.

## 13. Contact

Questions, requests, complaints:
- Email: **[EMAIL]**
- Mail: **[COMPANY_NAME], [ADDRESS], Iceland**

---

*This is a DRAFT. Get it reviewed by an Icelandic privacy lawyer before
publishing. Sections marked with [BRACKETED_VALUES] must be filled in.*
