What data we process, for what purpose, how long we keep it, and how you can exercise your rights under the GDPR and the Data Protection Act 2018.
Parcela — land and site intelligence platform. Contact: privacy@parcela.site. Data controller within the meaning of the GDPR (Regulation (EU) 2016/679) and the Data Protection Act 2018.
Account data: email address, anonymous identifier (cookie), hashed API key.
Technical data: IP address, user agent, timestamps of API calls, response codes, response times.
Site data: site identifiers (address / Eircode), analysis results, DD PDFs. Site identifiers alone are not personal; linked to an account email they may be indirectly identifiable.
We do NOT process: payment details (handled directly by Stripe), folio extracts or other documents you upload (you control their retention).
Service delivery (GDPR Art. 6(1)(b) — contract performance): API processing, report generation, account management.
Billing and volume control (Art. 6(1)(b) and (c)): usage recording for rate limits and invoicing.
Service-initiated communication (Art. 6(1)(b)): planning-alert notifications for tracked sites.
Marketing: ONLY with consent (Art. 6(1)(a)). Opt-out anytime.
Legitimate interest (Art. 6(1)(f)): platform security, abuse detection, aggregated statistics.
Account data: until deletion + 30 days grace.
API usage logs: 30 days operational, 13 months for billing records.
DD reports: SHA-256 stamped, kept while the account is active; individually deletable.
Server logs (Vercel, Supabase): 14 days default, longer only for security incidents.
User-uploaded data (photos, extracts): you control retention; account deletion removes all linked objects.
Infrastructure providers (processors under GDPR Art. 28): Supabase (PostgreSQL + Storage, EU-Central), Vercel (hosting, eu-west), Resend (transactional email), DeepSeek / Anthropic / OpenAI (generative AI — anonymised inputs, no personal data in prompts).
We do NOT sell personal data. We do NOT share data with data brokers. Customer data is NOT used to train AI models without explicit consent.
All infrastructure is within the EEA (Frankfurt / Dublin) by default. External generative APIs may process anonymised prompts in the US under the EU Standard Contractual Clauses (Commission Decision 2021/914).
Enterprise customers may request a "Data Residency" review — certain features (e.g. the AI narrative) can be disabled if US transfer is unacceptable.
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), and objection (Art. 21).
We respond to requests within 30 days at privacy@parcela.site. Complex requests may be extended by 60 days — we will inform you.
You also have the right to lodge a complaint with the Data Protection Commission (DPC), 21 Fitzwilliam Square South, Dublin 2, D02 RD28 — dataprotection.ie.
Changes will be announced 30 days in advance via email to the account address. Previous versions are available on request at privacy@parcela.site.
For access, rectification, erasure, restriction, portability, or objection requests, please contact us at the address below. We respond within 30 days.
privacy@parcela.site