Lektoria
  • 01Process
  • 02Pricing
  • 03Method
  • 04Privacy
  • 05FAQ
Sign inUpload file →
§ B

Privacy policy

Information under Art. 13, 14 GDPR and § 25 TDDDG. The German version is legally binding.

Controller

Ufuk Dumrul (sole proprietorship, brand Lektoria), Königstraße 82, 53332 Bornheim. Contact: info@lektoria.eu; data-protection requests: datenschutz@lektoria.eu.
There is no statutory obligation to appoint a data protection officer (sole proprietorship below the thresholds of Art. 37 GDPR / § 38 BDSG); the controller named above is responsible.

Categories of data processed

Name for contract handling and personalisation of report and invoice. Email address as account and login identifier and for notifications. A self-chosen password, stored exclusively as an argon2id hash (never in plain text). Uploaded files including any personal data they contain (proper names, addresses, student IDs). Payment data exclusively at Stripe (card content never reaches Lektoria). Server log data (incl. IP address, timestamp, requested resource) to secure operation.

Purposes of processing and legal bases at a glance

For each category of data we state the specific purpose and the applicable legal basis (Art. 13 (1) (c) GDPR):
• Uploaded document (incl. third-party data it contains) — delivery of the proofreading service: OCR preparation, multi-stage consensus and expert review by an AI model (Google Vertex AI), synthesis and PDF report. Legal basis: Art. 6 (1) (b) GDPR (contract performance).
• Name — creation and management of the customer account, personalisation of report and invoice. Legal basis: Art. 6 (1) (b) GDPR.
• Email address — login to the password-protected export area, provision of the report, contract communication. Legal basis: Art. 6 (1) (b) GDPR.
• Password (argon2id hash) — authentication and access protection for the export area, where document and report are held for 90 days. Legal basis: Art. 6 (1) (b) GDPR, supported by (f) (access security).
• Notification email with login link — notice that the finished report is available in the password-protected export area; we deliberately do not send the report itself by email (the transport path is not end-to-end encrypted), only the invoice is attached (small-amount invoice, without document content). Legal basis: Art. 6 (1) (a) GDPR (consent; revocable at any time, see next section).
• Payment data (via Stripe) — processing of payment. Legal basis: Art. 6 (1) (b) GDPR; for Stripe's own fraud prevention partly (c) and (f) under Stripe's own controllership.
• Invoice and billing data — compliance with commercial and tax retention obligations. Legal basis: Art. 6 (1) (c) GDPR in conjunction with § 147 AO / § 257 HGB.
• Server log data / IP address — IT security, stability and abuse prevention. Legal basis: Art. 6 (1) (f) GDPR (the specific legitimate interest is named in the next section).

Explanation of the legal bases

Contract performance (Art. 6 (1) (b) GDPR) covers upload, review, account management and delivery. The legal obligation (c) covers retention of invoice data. The legitimate interest (f) covers the server log data; the specific legitimate interest is ensuring IT security and system stability and defending against abuse and attacks (named under Art. 13 (1) (d) GDPR).
The notification email with login link is based on your consent ((a)), which you give at checkout. You can withdraw this consent at any time with effect for the future (to datenschutz@lektoria.eu); the lawfulness of processing carried out before withdrawal remains unaffected (Art. 7 (3) GDPR). After a withdrawal we no longer notify you by email — you then retrieve the report yourself in the export area.

Whether provision is required

Providing your name and email address and uploading the document to be edited are required to conclude and perform the proofreading contract. Without this data the service cannot be delivered. There is no further statutory obligation to provide data (Art. 13 (2) (e) GDPR).

Retention

Your uploaded file and result report are available for 90 days in the password-protected export area for self-download and are then deleted automatically; the uploaded original is deleted at the latest 90 days after payment. Earlier manual deletion is possible at any time via datenschutz@lektoria.eu. As long as the report has not been retrieved, we send a reminder every 14 days stating the deletion date. Invoice-relevant data (invoice, payment record) is retained — separately from and without the document content — for 8 years under § 147 AO / § 257 HGB (reduced from 10 to 8 years by the Fourth Bureaucracy Relief Act). For an initiated payment process, a pseudonymous accounting record additionally remains (sequential transaction number, amount, payment reference, status — without name, email or document content) as well as monthly accounting journals for the duration of the statutory retention period; the payment references are then anonymised automatically. Server log data is deleted automatically after no more than 14 days.

Processors

Hetzner Online GmbH (Falkenstein, DE) for backend, object storage and local spell-checking (LanguageTool); processor under Art. 28 GDPR. Google (Google Cloud, Vertex AI; European contracting party Google Cloud EMEA Limited, Dublin, IE, parent company Google LLC, USA) for AI-assisted document preparation (OCR) and the substantive review; processing takes place exclusively in an EU region of Vertex AI. Inputs are not used to train the models; only metadata (e.g. token and timing values) is logged, no document content. Processor under the Google Cloud Data Processing Addendum (Art. 28 GDPR), supplemented by EU Standard Contractual Clauses and certification under the EU-US Data Privacy Framework. IONOS SE (Montabaur, DE) for transactional email; processor under Art. 28 GDPR. Stripe Payments Europe Ltd. (Dublin, IE) for payment processing; for the pure contract handling a processor, while for its own fraud prevention and regulatory duties Stripe acts as an independent controller — in that respect Stripe's own privacy policy applies (stripe.com/privacy). The providers in turn engage sub-processors; the current agreements and sub-processor lists are available here: Hetzner (hetzner.com/AV/DPA_de.pdf), Google Cloud (lektoria.eu/google-cloud-dpa.pdf and cloud.google.com/terms/subprocessors), IONOS (ionos.de/terms-gtc/AVV/) and Stripe (stripe.com/legal/dpa).

Google Cloud — data processing (Art. 28 GDPR)

The Google Cloud Data Processing Addendum (data-processing agreement under Art. 28 GDPR) was read and accepted on 18 June 2026 by the administrator of the project lektoria-eu (Google account udumrul63@gmail.com). The key commitments:
1. Bound by instructions: Lektoria is the controller, Google solely the processor — Google processes the data only on documented instructions (via use of the services or separate instruction).
2. No repurposing: the data is not used for advertising, not sold and not used to train Google's AI models; it stays within the isolated project tenant.
3. Security: contractually assured technical and organisational measures — encryption, data-centre protection and independent audits (ISO 27001, SOC 2/3, annually).
4. Breach notification: Google notifies without undue delay of security incidents so that Lektoria can meet its reporting duties under Art. 33/34 GDPR.
5. Deletion after termination: on deletion of resources or end of contract, the data is removed from servers and backups within the contractually defined periods (recovery period up to 30 days, final deletion within a maximum of 180 days).
The contract is the legal foundation. Full GDPR compliance is complemented technically and organisationally: processing exclusively in EU regions (region choice / resource-location policy), inclusion of Google Cloud in the record of processing activities and — in view of "Schrems II" — a transfer impact assessment; third-country transfers are secured via the EU Standard Contractual Clauses and the EU-US Data Privacy Framework. The full contract text is available as a PDF at lektoria.eu/google-cloud-dpa.pdf.

Transfer to third countries

A distinction must be drawn between the place of processing on the one hand and a possible access or transfer to a third country on the other — EU data residency does not mean that third-country access is excluded in every case. Hetzner and IONOS are German providers processing in the EU. AI processing via Google Cloud (Vertex AI) takes place exclusively in an EU region; Google, however, is a US-based group. Insofar as data is transferred to a third country or third-country access occurs, this is based on the EU Standard Contractual Clauses of 2021 and, in addition, on certification under the EU-US Data Privacy Framework (adequacy decision of 10 July 2023). Third-country transfers are not based on consent in a blanket manner.

Residual risk of government access (US authorities)

The AI processing runs exclusively in an EU region of Google Cloud (Vertex AI); inputs are not used to train the models. As a US-based group, Google is in theory subject to US legal acts (e.g. CLOUD Act, FISA 702) that in exceptional cases can give rise to government access or disclosure obligations — such access cannot be excluded 100 % despite EU processing. We deliberately disclose this residual risk rather than conceal it, and reduce it as far as possible: EU regions only, no global model deployments, short storage, EU Standard Contractual Clauses and EU-US Data Privacy Framework certification, and disclosure of only the legally required minimum. End-to-end pre-encryption is technically not feasible for AI calls because the model must process the text in plain text. Our tip: before uploading, remove personal data you don't need — in particular data of third parties and special categories under Art. 9 GDPR.

No automated individual decisions

The AI-assisted proofreading is text editing and the preparation of findings. There is no automated decision in an individual case producing legal effects or similarly significantly affecting you within the meaning of Art. 22 GDPR; no profiling takes place. Responsibility for the finished text remains with you.

Data-subject rights

Access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), objection (Art. 21), withdrawal of consent (Art. 7 (3)). Requests to datenschutz@lektoria.eu.

Right to lodge a complaint

You may lodge a complaint with a data-protection supervisory authority at any time, in particular with the authority responsible for North Rhine-Westphalia: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), 40213 Düsseldorf.

Cookies and access to end devices (§ 25 TDDDG)

Lektoria uses strictly necessary mechanisms only: a session or login cookie, or local storage, that is strictly required for the login and the password-protected export area (§ 25 (2) TDDDG). No analytics, tracking or marketing cookies and no third-party trackers are set; a consent banner is therefore not required. The legal basis for the processing associated with the necessary cookie is Art. 6 (1) (b) GDPR (provision of the service you requested).

Audience measurement (Umami, self-hosted)

For audience measurement we use the open-source software Umami — self-hosted on our own server in Falkenstein (Hetzner, Germany); the data never leaves our server and is not shared with third parties. Umami works without cookies and without accessing information on your device; § 25 TDDDG is therefore not affected and no consent is required. Only aggregated usage data is collected: pages visited, referrer source, browser and device type, country of origin, and time of visit. The IP address is used only transiently for the technical processing of the request and is not stored. To distinguish returning visits within a single day, a non-reversible identifier that changes daily is derived from technical characteristics; identifying individual persons or tracking across websites is not possible with it. The legal basis is Art. 6 (1) (f) GDPR — our legitimate interest in privacy-preserving measurement and improvement of our service.

Data security

Transport encryption via TLS (TLS 1.3 where supported, at least TLS 1.2) for all connections. Encryption of data at rest per Hetzner's storage configuration. Passwords are stored exclusively as an argon2id hash, never in plain text. Production access only via SSH key, dedicated admin account, automatic patching, backups in an EU region. No Cloudflare/tracking scripts are embedded.

Web fonts

All fonts used (Cal Sans, Inter, Lexend — each under the SIL Open Font License) are served locally from Lektoria's own server and are not fetched from Google Fonts or any third-party CDN when a page loads. No IP address is therefore transmitted to a font provider.

Version and last update

Last updated: July 2026 (version 1.1 — added audience measurement with self-hosted Umami). If processing operations or the service providers used change, we update this policy and adjust the date.

Lektoria

Lektoria — owner Ufuk Dumrul Headquarters in Germany, processing in the EU.

Product
  • Process
  • Pricing
  • Method
  • Upload file
  • Export area (sign in)
Legal
  • Imprint
  • Privacy policy
  • Terms
  • Right of withdrawal
Contact
  • info@lektoria.eu
  • datenschutz@lektoria.eu
© 2026 LEKTORIA — processing in EU regions.build 2026.05.20