Last updated: February 24, 2026
PrivacyCache (“we”, “our”, or “us”) is the data controller responsible for your personal data. PrivacyCache is a privacy compliance management platform that helps organisations manage GDPR evidence, DSARs, and audit readiness.
Contact: contact@privacycache.com
When you create an account, we collect:
When you use our compliance features, we process:
When you use our free DSAR Deadline Calculator, we may collect your email address if you opt in to receive your results. Calculator inputs (jurisdiction, request type, dates) are processed client-side and not stored on our servers.
With your consent (via our cookie banner), we collect analytics data through PostHog:
This data is only collected if you accept analytics cookies. If you reject cookies, no analytics data is collected.
We process your personal data based on the following legal grounds:
We use the following third-party services to provide PrivacyCache. All are bound by Data Processing Agreements (DPAs):
| Service | Purpose | Location |
|---|---|---|
| Neon | PostgreSQL database hosting | EU (Frankfurt) |
| Cloudflare R2 | Evidence file storage | EU |
| Railway | Application hosting | EU |
| Anthropic | Smart Evidence Capture (AI metadata extraction) | US (no data retention) |
| Polar.sh | Subscription payments | EU |
| PostHog | Product analytics (consent-based) | EU |
| Resend | Transactional email delivery (reports, alerts) | US (SCCs in place) |
| Better Auth | Authentication | Self-hosted (EU) |
We use the following types of cookies:
Session cookies for authentication and cookie consent preference. These are required for the platform to function and cannot be disabled.
PostHog analytics cookies to understand how you use our platform. These are only set if you accept analytics cookies via our consent banner. You can change your preference at any time by clearing your browser cookies and revisiting the site.
We retain your data for as long as your account is active or as needed to provide services:
Under the GDPR, you have the following rights:
To exercise any of these rights, contact us at contact@privacycache.com. We will respond within 30 days as required by the GDPR.
We implement appropriate technical and organisational measures to protect your personal data, including:
All core data processing occurs within the EU (Frankfurt). When evidence is processed by Anthropic's Smart Evidence Capture feature, image data is sent to Anthropic's API (US) for metadata extraction. Anthropic does not retain this data after processing. This transfer is covered by Standard Contractual Clauses (SCCs) and a Data Processing Agreement.
PrivacyCache is a B2B service designed for organisations. We do not knowingly collect personal information from children under 16 years of age. If you believe a child has provided us with personal information, please contact us.
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the “Last updated” date. For significant changes, we will notify you via email.
If you believe we are processing your personal data unlawfully, you have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your habitual residence, place of work, or place of the alleged infringement.
For any questions about this Privacy Policy or to exercise your data subject rights:
Email: contact@privacycache.com