GDPR & Data Rights

GDPR Compliance

We are committed to protecting your rights under the General Data Protection Regulation. Here's everything you need to know about how PortImg handles your data.

Effective date: June 1, 2025  ·  Last updated: April 1, 2026

GDPR compliant Data minimisation Right to erasure No data selling Respond in 30 days
Who this applies to: The GDPR formally applies to users in the European Economic Area (EEA) and the United Kingdom. However, PortImg applies GDPR-equivalent data protection principles to all users globally, regardless of location — including users of our Android app.

Your 8 GDPR Rights

👁️

Right to Access

You can request a copy of all personal data we hold about you at any time.

✏️

Right to Rectification

You can ask us to correct any inaccurate or incomplete personal data.

🗑️

Right to Erasure

You can ask us to delete your personal data — the "right to be forgotten".

⏸️

Right to Restriction

You can request that we limit how we use your data in certain circumstances.

📦

Right to Portability

Request your data in a portable, machine-readable format to transfer elsewhere.

🚫

Right to Object

Object to processing for direct marketing or legitimate interests purposes.

🤖

Automated Decisions

The right not to be subject to solely automated decisions that significantly affect you.

↩️

Right to Withdraw Consent

Where processing relies on consent, you can withdraw it at any time.

1 Who is the Data Controller?

For the purposes of the GDPR, the data controller responsible for your personal data is the PortImg team, reachable at [email protected]. We determine the purposes and means of processing any personal data collected via portimg.com and the PortImg Android app.

2 Legal Basis for Processing

We only process your personal data where we have a valid legal basis under GDPR Article 6:

  • Contract performance: Processing your uploaded files is necessary to deliver the image/PDF service you requested.
  • Legitimate interests: Collecting anonymised technical and analytics data (via GA4, Google Search Console, Bing Webmaster Tools) for security, abuse prevention, and platform performance improvement.
  • Legal obligation: Retaining certain data to comply with applicable legal or regulatory requirements.
  • Consent: For optional communications (e.g., newsletter), we rely on your explicit consent, which you can withdraw at any time by emailing [email protected].

3 Data We Collect and Why

We apply the GDPR principle of data minimisation — collecting only what is strictly necessary:

  • Uploaded files: Collected only for server-side processing tools. Automatically deleted within 1 hour via an automated cron job. Never used for profiling, analytics, or advertising.
  • Client-side processing: Many tools operate entirely in your browser. For these, your files are never transmitted to our servers.
  • Email address: Only if you voluntarily contact us or subscribe to updates. Used solely to respond to you.
  • Analytics data: Anonymised usage data collected via Google Analytics 4. IP anonymisation is enabled. Not linked to your identity.
  • Android app data: File access permissions used only to process files you explicitly select. No background data collection or tracking.

4 Data Retention

We keep personal data only for as long as strictly necessary:

  • Uploaded files (server-side): Deleted automatically within 1 hour of processing via cron job.
  • Email correspondence: Retained for up to 2 years to resolve follow-up queries, then permanently deleted.
  • Analytics logs: Retained per Google Analytics 4 default settings (up to 14 months), then automatically purged.
  • Legal obligations: Where required by applicable law, certain data may be retained for longer periods (e.g., tax records).

5 International Data Transfers

Our infrastructure and third-party tools (Google Analytics, Google Search Console, Bing Webmaster Tools) may involve servers or processors located outside the EEA. Where personal data is transferred internationally, we ensure appropriate safeguards are in place:

  • Google services use Standard Contractual Clauses (SCCs) and are subject to Google's data transfer safeguards.
  • Microsoft (Bing Webmaster Tools) uses SCCs and equivalent mechanisms under their Privacy Statement.
  • Our hosting infrastructure uses encrypted connections and access controls regardless of server location.

6 Advertising and Consent

Currently, PortImg does not display any advertisements. If we introduce advertising (e.g., Google AdSense) in the future, we will fully comply with GDPR requirements for EEA/UK users:

  • EEA/UK users will be presented with a GDPR-compliant consent mechanism before personalised ads are served.
  • If consent is not given, only non-personalised (contextual) ads will be shown.
  • Consent preferences will be recordable and changeable at any time.
  • Uploaded files will never be used for advertising targeting.
  • This Privacy Policy and Cookie Policy will be updated before any ads go live.

7 Data Security Measures

We implement appropriate technical and organisational measures to protect your personal data:

  • All data in transit is encrypted using TLS 1.2 or higher.
  • Uploaded files are stored in isolated, access-controlled environments and purged automatically.
  • Access to any personal data is restricted to personnel who need it to perform their role.
  • We regularly review security practices and update them in response to identified risks.
  • No persistent database of uploaded file contents is maintained.

Exercise Your Rights

To submit a data access, correction, deletion, or portability request, email us at [email protected] with the subject line "GDPR Request". Please include:

  • Your name and the email address associated with your request.
  • The specific right you wish to exercise (e.g., deletion, access, portability).
  • Relevant details to help us identify any data we may hold (e.g., approximate dates of use, contact email used).

We will verify your identity and respond within 30 days. In complex cases, we may extend this by an additional 60 days — we'll notify you if so.

Right to Lodge a Complaint

If you believe we have not handled your personal data in accordance with applicable law, you have the right to lodge a complaint with your local data protection authority (DPA). In the EU, find your national DPA via the European Data Protection Board. In the UK, contact the ICO.