merkleset
법률 문서

버전: 2026-08-12발효일: 2026-08-12동의 필요

이 문서는 영문으로만 발행됩니다. 영문본이 정본입니다. 동의는 영문 원문의 SHA-256에 대해 기록되므로, 번역문은 귀하가 동의한 본문이 될 수 없습니다.

Privacy Policy

Version 2026-08-12. Effective 2026-08-12.

This policy explains what personal data we process about you when you use merkleset, why, on what legal basis, how long we keep it, and what you can ask us to do about it.

It is short because the service collects little. We run no analytics, no advertising, no profiling and no third-party scripts, and we do not sell or share personal data.

There are two separate subjects that this policy keeps apart:

  1. Personal data about you, our customer or visitor — an email address, a login history, consent records, billing details. That is what this policy is about.
  2. Personal data inside the datasets we sell. Datasets are built to contain no personal data, screening runs in the pipeline before any published hash is computed, and the scope and known gaps of that screening are documented in clause 7 of the Data License Agreement. Section 11 below covers it.

1. Who is responsible

The controller is Andrii Sukhanov, a natural person trading as an independent professional (autónomo) registered in Spain, NIE Z2338955K, using merkleset as a trading name.

Postal address: Av. Marítima 2, puerta 05c, {{POSTAL_CODE}} Los Silos, Santa Cruz de Tenerife, Spain.

Data protection contact: privacy@merkleset.com (Andrii Sukhanov handles these requests personally).

We have not designated a Data Protection Officer. At this scale of processing — no large-scale monitoring, no special category data, no public-authority role — the GDPR does not require one. If that changes we will designate one and say so here.

Because the controller is established in Spain, the GDPR applies directly and no Article 27 representative is required.

2. What we process, why, and on what basis

DataWhere it comes fromPurposeLegal basis
Email addressYou, at sign-up and loginIdentify your account; send the one-time login codePerformance of a contract (Art. 6(1)(b))
Account timestamps: created, last loginGenerated by the serviceOperate and secure the accountPerformance of a contract (Art. 6(1)(b))
One-time login code, stored only as a SHA-256 hash, and a per-email rate-limit counterGenerated by the serviceAuthenticate you; prevent brute-force and abuse of the login endpointPerformance of a contract; legitimate interests in security (Art. 6(1)(b), (f))
Refresh tokens, stored only as SHA-256 hashes, with rotation and revocation timestampsGenerated by the serviceKeep you signed in; detect stolen tokensPerformance of a contract; legitimate interests in security (Art. 6(1)(b), (f))
Consent records: document id, version, SHA-256 hash of the exact text, acceptance timestampGenerated when you accept a documentProve which version of which document you acceptedLegal obligation (Art. 6(1)(c)); performance of a contract (Art. 6(1)(b))
Entitlements: your user id, dataset, plan, expiryGenerated when a subscription startsDecide whether you may download a releasePerformance of a contract (Art. 6(1)(b))
Application request logs: method, path, status code, durationGenerated by the serviceDiagnose faults, detect abuseLegitimate interests (Art. 6(1)(f))
Web server access logs: client IP address, timestamp, request line, status, user agentGenerated by our reverse proxySecurity, abuse investigation, fault diagnosisLegitimate interests (Art. 6(1)(f))
Contact form: your name, email, company (optional), message, plan of interest (optional)You, when you submit the formAnswer your enquiryLegitimate interests, and steps before a contract (Art. 6(1)(f), (b))
Billing data: name, email, billing address, tax identification number, transaction and payment metadataYou, through Stripe's checkoutTake payment, issue your invoice, determine and remit taxes, handle disputesPerformance of a contract; legal obligation (Art. 6(1)(b), (c)). See section 6 on Stripe's own role

That table is the complete list. We do not build profiles, we do not score you, and no decision about you is made by automated means.

Application logs are deliberately thin. The request logging interceptor records the method, path, status and duration only — never request bodies, query strings or headers. Our reverse proxy writes ordinary web server access logs, which do include the client IP address; that is the one place an IP address is recorded.

Card data never reaches us. The purchase transaction is processed by Stripe as merchant of record. We receive confirmation and billing metadata, never full card numbers.

3. What we do not do

  • We do not sell personal data, and we do not share it for cross-context behavioural advertising.
  • We run no analytics, no session recording, no advertising pixels and no third-party scripts.
  • We do not use your data to train models. Our datasets are built from government sources, not from customer activity.
  • We do not track you across other websites, and we serve no advertising.

4. Cookies and local storage

The site uses two client-side storage items, both strictly necessary: the login tokens in localStorage, and a NEXT_LOCALE cookie that remembers your language choice. There is no analytics or marketing storage, which is why there is no cookie consent banner. The full inventory is in the Cookie and Local Storage Policy.

5. How long we keep it

DataRetention
Account record (email, timestamps)While your account exists; deleted on request, subject to the rows below
One-time login code10 minutes, then it expires automatically
Login rate-limit counter15 minutes
Refresh tokensUp to 30 days from issue; revoked tokens are kept until expiry to detect reuse
Consent recordsFor the life of the account and then {{CONSENT_RETENTION_YEARS}} years, because they are the evidence of what you agreed to
EntitlementsFor the life of the subscription plus the period needed for billing and dispute records
Application request logsContainer logs rotate at a fixed size (10 MB × 3 files per service), so retention is bounded by volume rather than by a date
Web server access logs{{EDGE_LOG_RETENTION_DAYS}} days
Contact form emailsIn the destination mailbox, {{CONTACT_MAIL_RETENTION_MONTHS}} months
Billing and invoice records{{BILLING_RECORD_RETENTION_YEARS}} years, as required by Spanish tax and commercial law

Where a retention period above is a placeholder, the period has not been fixed yet and will be stated here before this policy is published as final.

6. Who else processes it

We use three external providers, listed with their role, data categories, location and transfer mechanism in the Subprocessor annex: DigitalOcean (hosting), Stripe (payments) and Mailgun (transactional email). We use no content delivery network and no analytics provider.

Stripe is not simply our processor. Stripe acts as merchant of record for the purchase: it invoices you, collects and remits applicable taxes, and handles payment disputes. For that billing relationship Stripe determines its own purposes and acts as an independent controller, and its own privacy notice applies to it. We remain the controller for your account and your use of the service. This matters when you exercise your rights: a request about your account comes to us, and a request about the billing relationship may need to go to Stripe as well — tell us and we will point you to the right place.

We do not otherwise disclose personal data, except where we must to comply with a legal obligation or a valid order from a competent authority, or to establish or defend a legal claim.

7. International transfers

Mailgun is used in its EU region, so login-code and contact-form email stays within the EU.

Our hosting provider, DigitalOcean, LLC, is a United States company. The datacentre region of our server is stated in the Subprocessor annex; independently of the region, a US-parent provider is capable of access, so we treat hosting as involving a potential transfer to the United States. Stripe likewise operates in both the EU and the US, in its own right as merchant of record.

For those transfers we rely on the provider's own data processing agreement together with the European Commission's Standard Contractual Clauses. The specific instrument in force for each provider is recorded in the Subprocessor annex as {{TRANSFER_MECHANISM}} until we have confirmed and published it. You can ask us for a copy of the relevant terms at privacy@merkleset.com.

8. Your rights

Under the GDPR you can ask us to:

  1. confirm whether we process personal data about you, and give you a copy (access);
  2. correct data that is inaccurate or incomplete (rectification);
  3. delete your data (erasure), subject to records we must keep for tax or evidence purposes;
  4. restrict processing while a dispute about it is resolved;
  5. port the data you gave us, in a machine-readable form;
  6. object to processing we base on legitimate interests;
  7. withdraw consent where we relied on it — which, for the processing above, we do not.

How to exercise them. Email privacy@merkleset.com from the address on your account, or tell us which account you mean. We answer within one month and will tell you if we need longer, which the GDPR permits for complex requests. We do not charge for this. We may ask you to confirm control of the account's email address, because that address is the only identifier we hold.

Deleting your account removes the account record and, by database cascade, its refresh tokens and consent records. We will tell you what we must keep and why — typically invoices and the fact that a particular document version was accepted.

Complaints. If you think we have handled your data badly, tell us first at privacy@merkleset.com. You can also complain to the Spanish supervisory authority, the Agencia Española de Protección de Datos (AEPD, www.aepd.es), or to the supervisory authority where you live or work.

9. Information for California residents

We do not sell personal information and we do not share personal information for cross-context behavioural advertising, as those terms are used in the CCPA as amended by the CPRA. We have not disclosed personal information to a third party for money or other valuable consideration in the preceding 12 months.

The categories we collect are identifiers (email address), commercial information (subscription and billing records) and internet activity limited to the log entries described in section 2. Purposes are in section 2 and retention is in section 5. You may request access, deletion, correction, and a statement of what we collect, using the route in section 8; we will not discriminate against you for asking. We do not process sensitive personal information for the purpose of inferring characteristics.

10. Security

What we actually do, rather than a list of adjectives:

  1. No passwords exist. Login is a one-time code emailed to you, so there is no password to leak, reuse or crack.
  2. Login codes and refresh tokens are stored only as SHA-256 hashes, compared in constant time. A dump of our database yields no usable credential.
  3. Short-lived access tokens (15 minutes) with rotating refresh tokens. Presenting an already-rotated token is treated as theft and revokes that whole session family.
  4. Rate limits on the login and contact endpoints, and a general request limit on the public API.
  5. Only two services are exposed to the internet — the website and the public API. Authentication, the catalogue, the databases, the message broker and object storage are reachable only on an internal network, with no public port.
  6. TLS on every public connection, with certificates renewed automatically.
  7. Minimal logging — the application never logs request bodies, query strings or headers.
  8. Download links are signed and time-limited, and are issued only after an entitlement check.

Honest limitations, because you should be able to weigh them: there is no automated backup of our databases or release artifacts today, and no automated monitoring or alerting. The service runs on a single host. We are telling you this rather than implying a resilience we do not have; it is also why the Terms of Service make no availability or recovery commitment.

11. Personal data inside the datasets

Our datasets are built from official public US federal government sources and are built to contain no personal data.

Screening runs inside the pipeline before any published hash is computed. Email addresses and telephone numbers are redacted; a value shaped like a US Social Security number with an explicit nearby cue causes the whole record to be dropped; person names are redacted where a source field declares them or where an explicit contact label introduces them. For the procurement corpus we never read the source's contact columns at all, so those values reach neither the product nor our internal storage.

The scope of that screening is deliberately narrow and we publish its gaps. It does not catch a person named in running prose without a contact label, labels separated by whitespace only, postal addresses, obfuscated contact details, or number shapes with no nearby cue. So the accurate claim is that datasets are systematically screened to a documented scope — not that they are guaranteed free of personal data.

Internal raw evidence. To make the provenance hashes checkable we keep one snapshot of each source record, exactly as fetched, in a separate internal store. Those snapshots are unscreened by design — a hash must describe the original bytes. They are never delivered to customers, never included in a release manifest, and never given a public URL. A retention period of 90 days is configured; nothing enforces it automatically yet, so expiry is currently manual. We are not going to describe that as automated deletion when it is not.

If you believe personal data about you is in a release, write to privacy@merkleset.com or follow the route in the Copyright, Takedown and Complaints Policy. We will remove it from future releases and delete it from the internal evidence store. We cannot recall a release a customer already downloaded; our licence obliges customers to remove identified records from their own copies on our reasonable request, and we will make that request.

12. Children

The service is sold to businesses and is not directed at children. We do not knowingly process data about anyone under 18. If you believe we have, write to privacy@merkleset.com and we will delete it.

13. Changes to this policy

This policy is versioned by effective date. When we publish a new version we ask you to accept it the next time you sign in, and we record the version, the acceptance time and a SHA-256 hash of the exact text you were shown. A new version applies from the date you accept it.

English is the authoritative language of this policy. Translations are for convenience only.

14. Contact

Privacy and data protection: privacy@merkleset.com Everything else: contact@merkleset.com

sha256 ae5e4febd1e2…a03829f917cc