GDPR Compliance

Last updated: December 31, 2025

FruitMetrica is committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) for all users in the European Economic Area (EEA).

1. Our Role Under GDPR

FruitMetrica acts as a Data Controller for personal data we collect directly from you (account information, preferences, communications). We are responsible for determining the purposes and means of processing your personal data.

2. Legal Basis for Processing

We process your personal data under the following legal bases:

  • Consent: Analytics cookies and marketing communications (you can withdraw consent at any time)
  • Contract: Processing necessary to provide our services when you create an account
  • Legitimate Interests: Improving our platform, preventing fraud, ensuring security
  • Legal Obligation: Compliance with applicable laws and regulations

3. Your GDPR Rights

As a data subject in the EEA, you have the following rights:

3.1 Right of Access (Article 15)

You have the right to obtain confirmation of whether we process your personal data and, if so, access to that data along with information about how it is processed.

3.2 Right to Rectification (Article 16)

You have the right to request correction of inaccurate personal data and to have incomplete data completed.

3.3 Right to Erasure (Article 17)

Also known as the "right to be forgotten," you can request deletion of your personal data when:

  • The data is no longer necessary for its original purpose
  • You withdraw consent (where consent was the legal basis)
  • You object to processing and there are no overriding legitimate grounds
  • The data was unlawfully processed

3.4 Right to Restrict Processing (Article 18)

You can request restriction of processing in certain circumstances, such as when you contest the accuracy of the data or have objected to processing.

3.5 Right to Data Portability (Article 20)

You have the right to receive your personal data in a structured, commonly used, machine-readable format (JSON, CSV) and to transmit that data to another controller.

3.6 Right to Object (Article 21)

You have the right to object to processing based on legitimate interests or for direct marketing purposes.

3.7 Rights Related to Automated Decision-Making (Article 22)

FruitMetrica does not make decisions based solely on automated processing that produce legal effects or significantly affect you. If this changes, we will provide appropriate safeguards.

4. How to Exercise Your Rights

To exercise any of your GDPR rights, contact us at:

We will respond to your request within 30 days. In complex cases, we may extend this by an additional 60 days, but we will notify you of any extension.

5. Data Retention

We retain your personal data only as long as necessary:

  • Account data: Until account deletion plus 30 days for backup recovery
  • Analytics data: Anonymized after 26 months
  • Support communications: 3 years after resolution
  • Legal/compliance records: As required by law (typically 7 years)

6. International Data Transfers

When we transfer personal data outside the EEA, we ensure appropriate safeguards are in place:

  • Adequacy decisions: Transfers to countries with adequate data protection
  • Standard Contractual Clauses (SCCs): EU-approved contract terms with data processors
  • Data Processing Agreements: Binding agreements with all third-party processors

7. Third-Party Processors

We use the following categories of data processors:

  • Hosting: Cloud infrastructure providers (EU/US with SCCs)
  • Analytics: Seline (privacy-focused analytics)
  • Communication: Email service providers

All processors are bound by data processing agreements that comply with GDPR Article 28.

8. Cookies and Consent

In accordance with GDPR and the ePrivacy Directive, we:

  • Only set non-essential cookies after obtaining explicit consent
  • Provide clear information about each cookie category
  • Allow you to withdraw consent at any time via our cookie settings
  • Store your consent preferences securely

You can manage your cookie preferences at any time by clicking the cookie icon or visiting your browser settings.

9. Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, we will:

  • Notify the relevant supervisory authority within 72 hours
  • Communicate the breach to affected individuals without undue delay
  • Document all breaches and remediation actions taken

10. Data Protection Officer

For GDPR-related inquiries, you may contact us directly at:

11. Right to Lodge a Complaint

If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or place of the alleged infringement.

A list of EU Data Protection Authorities can be found at: European Data Protection Board

12. Changes to This Policy

We will notify you of material changes to this GDPR compliance information via email or prominent notice on our platform at least 30 days before the changes take effect.

For more information about how we handle your data, please also review our Privacy Policy and Terms of Service.