PRIVACY / GRAPHMARKS
Privacy Policy
This document explains what personal data graphmarks processes, for what purpose and on what legal basis, how long it is retained and how you can exercise your rights.
Data controller
Rubén García, Spanish tax number 79005724B, address at calle Txabarri 79, 3.º B, 48910 Sestao (Bizkaia, Spain), trading as Zetesis, is the controller of the data described in this policy.
Contact address for any data protection matter: ruben@zetesis.xyz. No data protection officer has been appointed, as none of the circumstances in Article 37 GDPR apply.
Data that stays in your browser
The extension needs to read and modify browser data in order to provide its features. Installing it or using its local features does not by itself enable synchronisation with our servers. Tags and saved sessions remain local unless you are signed in with an active Sync entitlement. If Sync ends, replication stops; copies already synchronised follow the retention periods set out below.
- The browser’s native bookmark and folder tree
- Your complete browsing history
- Tabs that are currently open, unless you choose to save them in a session that is synchronised
- The content of pages you visit
- Local view preferences and configuration
Data processed on our servers
Only the following data is processed outside your device, and only when you actively use a feature that requires it:
- Identity and session data: account identifier, email address and authentication credentials, when you create an account or sign in.
- Cloud collections: the links, titles, notes and tags you choose to add to a synchronised collection, together with an identifier for the devices that sync it.
- Synchronised tags: the normalised URL and each tag you have associated with it. Changes are sent only while your account has active Sync.
- Synchronised sessions: the windows and tabs you choose to save, including their URLs, titles, order, pinned state, groups and layout. Changes are sent only while your account has active Sync.
- Technical operating data: IP address, timestamp and response code of requests to the server, logged to ensure security and detect abuse.
- Error counts: number of failures grouped by code, platform and version, only if you enable error reporting. They contain no URLs, page content or exception messages.
Purposes and legal bases
Each processing activity has a specific purpose and a legal basis under Article 6 GDPR:
- Authenticating you and protecting access to your account — performance of the contract (Art. 6(1)(b)).
- Storing and syncing the collections, tags and sessions you request across your devices — performance of the contract (Art. 6(1)(b)).
- Ensuring the security of the service, preventing abuse and rate-limiting requests — legitimate interest in keeping the service available and secure (Art. 6(1)(f)).
- Diagnosing product failures from error counts — consent (Art. 6(1)(a)). This feature is off by default, requires an explicit action to enable, and can be withdrawn at any time in the settings.
- Issuing and retaining invoices where a paid subscription exists — compliance with legal tax and accounting obligations (Art. 6(1)(c)).
Where data is processed
The infrastructure serving graphmarks (application servers and databases) is located in the European Union. No international transfers outside the European Economic Area take place.
Should a future provider involve an international transfer, this policy will be updated and the safeguards set out in Chapter V GDPR will be in place before any such transfer begins.
Recipients and processors
Personal data is not sold, disclosed to third parties for advertising purposes, or used for profiling with legal effects.
Stripe Payments Europe, Ltd. acts as a processor for payment handling and invoicing. Full card details are provided directly to Stripe and are not accessible to the controller, who retains only the subscription identifier, its status and the data required for invoicing.
The extension stores from which you install the product (Chrome Web Store, Firefox Add-ons) process their own data under their respective policies, over which the controller has no involvement.
Retention periods
- Local data stays in your browser until you delete it or uninstall the extension. It is not subject to retention periods on our side.
- Account data, cloud collections, synchronised tags and synchronised sessions are retained while the account is active. After closure or cancellation they are kept for up to two years, to allow the service to be resumed, and deleted once that period ends.
- Technical security logs are retained for a maximum of ninety days.
- Invoices and associated tax records are retained for the periods required by tax and commercial law, which extend to six years.
Your rights and how to exercise them
You may request access to your data, its rectification or erasure, the restriction of or objection to processing, and portability in a structured, commonly used format. Where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of processing carried out beforehand.
To exercise these rights, write to ruben@zetesis.xyz stating which right you wish to exercise. Requests are handled within one month of receipt.
If you believe the processing does not comply with the applicable rules, you may lodge a complaint with the Spanish Data Protection Agency (www.aepd.es) as the competent supervisory authority, or with the authority of your country of residence.
Minors
The service is not directed at children under fourteen, the age from which Article 7 of Spanish Organic Law 3/2018 allows valid consent by a minor. Any account found to have been created by a child below that age without the consent of a parent or guardian will be deleted.
Cookies and measurement
This website uses no analytics, advertising or personalisation cookies, and includes no third-party measurement tools. No consent is therefore requested for their use.
The extension uses the browser’s local storage and IndexedDB to keep preferences, tags and sessions. It does not use the browser’s sync service for tags or sessions; replication with Graphacker Server is enabled only for an account with Sync.
Limited use of data
Information obtained through Chrome APIs is used only to provide or improve graphmarks’ visible features, keep them secure and measure their reliability. It is not sold, used for personalised advertising or transferred to data brokers. This use complies with the Chrome Web Store User Data Policy, including its Limited Use requirements.
Security
Communications with the server are encrypted using TLS. Access to data is restricted by authentication, and systems are kept updated and monitored. Backups are taken regularly and their restoration is verified.
In the event of a security breach posing a risk to your rights and freedoms, the supervisory authority and, where applicable, the affected individuals will be notified within the periods set out in Articles 33 and 34 GDPR.
Changes to this policy
If graphmarks introduces new processing activities, purposes or processors, this page will be updated before the change takes effect, and consent will be obtained where required. The date shown above indicates the latest revision.