Privacy policy
Last updated: 3 August 2026 Effective: 3 August 2026 Controller: LudeHQ (ludehq.com Ltd), operating WhatDoIOwe (WhatDoIOweCY), Larnaca, Cyprus. Contact: [email protected] Security contact: [email protected]
This policy explains what data WhatDoIOweCY collects, why we collect it, how long we keep it, who else touches it, and what you can do about it. We have written it in plain language. If anything is unclear, email us and we will rewrite the section.
We process personal data under the EU General Data Protection Regulation (Regulation 2016/679) and the Cyprus Law providing for the Protection of Natural Persons with regard to the Processing of Personal Data (Law 125(I)/2018).
1. What WhatDoIOweCY does
WhatDoIOweCY is a vehicle-obligations dashboard that checks supported sources for camera fines, road-tax status, MOT and insurance indicators, then provides deep links to the relevant official payment or information portals.
We never process payments for government services. We never see or touch a card number for any government payment. The initial release is free and has no in-app purchases. If we later enable paid subscriptions, Stripe will handle only our own subscription billing.
We are an independent service. We are not affiliated with the Government of Cyprus, Cyprus Police, JCC Smart, the Road Transport Department, or any municipality. We act on your explicit instruction to query supported sources on your behalf.
2. Data we collect
We deliberately collect as little as we can. The full list:
| Category | Specifically | Source |
|---|---|---|
| Account identity | Name, email address, locale, timezone, marketing consent flag | You, or your chosen social sign-in provider |
| Authentication | Password hash, MFA factors, session tokens, or provider identifiers | Better Auth and, if chosen, Google, Apple, or LudeHQ SSO |
| Vehicle | Plate number | You |
| National ID | A salted+peppered hash. For manual checks the raw value exists only for that request. If you explicitly enable an eligible auto-check feature, it is also stored with application-level authenticated encryption until you turn auto-check off | You |
| Lookup results | Snapshots of fines, road-tax status, MOT and insurance indicators retrieved from supported sources on your instruction | Supported public or official sources |
| Billing (only if enabled and used) | Plan and subscription state. Card data is held by Stripe and is not available to us | Stripe |
| Support | Emails you send us, in-app messages | You |
| Operational telemetry | Truncated IP (/24 IPv4, /48 IPv6), user-agent, request timestamps, error events | Your browser / our servers |
| Analytics | Aggregate page views via Plausible (cookieless, no per-user profile) | Your browser |
We do not collect: home address, phone number, date of birth, or attributes inferred from your national ID. We do not use national IDs for profiling.
3. Why we process each category (purpose and legal basis)
| Purpose | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Provide the service you signed up for (vehicle lookups, dashboard, notifications) | Email, plate, ID hash, snapshots | Art. 6(1)(b) — performance of contract |
| Account creation, login, MFA | Email, password hash, MFA factors | Art. 6(1)(b) — performance of contract |
| Subscription billing, invoicing, refunds | Email, billing data, plan | Art. 6(1)(b) — performance of contract; Art. 6(1)(c) — legal obligation (tax/accounting) |
| Transactional email (renewal notices, receipts, security alerts) | Art. 6(1)(b) — performance of contract; Art. 6(1)(f) — legitimate interest | |
| Marketing email | Email, marketing consent flag | Art. 6(1)(a) — consent (one-click opt-out) |
| Abuse prevention (rate limits, fraud detection, plate-enumeration controls) | Truncated IP, lookup velocity, account age | Art. 6(1)(f) — legitimate interest in protecting the service and its users |
| Security and incident response | Audit log, error events, truncated IP | Art. 6(1)(f) — legitimate interest |
| Tax and accounting records | Billing data, invoices | Art. 6(1)(c) — legal obligation |
| Aggregate, cookieless analytics | Page views | Art. 6(1)(f) — legitimate interest (no cookies, no profile) |
We do not sell your data, ever. We do not show third-party ads.
4. How long we keep it (retention)
| Data | Retention |
|---|---|
| Snapshots (lookup results) | 30 days on Free, 24 months on paid plans. Auto-deleted by daily cron. |
| Encrypted national ID for opted-in auto-check | Until you disable auto-check, delete the vehicle, or delete the account. |
| Unverified, unused registration | 7 days, then automatically deleted. |
| Audit log (billing events, security events) | 7 years — required for financial and legal records. |
| Account identity (email, plan, settings) | For the lifetime of the account. |
| Deleted accounts | 90-day grace window for re-activation, then hard-deleted within 24 hours. |
| Truncated IP and operational telemetry | 30 days for live logs; aggregated counters retained longer with no per-user link. |
| Support email threads | 24 months after the last message. |
When retention expires, the data is removed from primary storage. Encrypted backups roll over on a 35-day cycle (see §15 of our internal spec); deleted records disappear from backups within that window.
5. Your rights under GDPR
You can exercise any of these rights by emailing [email protected] or, where indicated, directly inside the app. We will respond within 30 days (target: under 5 minutes for export, under 24 hours for deletion).
| Right | How to use it |
|---|---|
| Access (Art. 15) | Settings → Privacy → "Export my data". You get a JSON file with every record we hold about you, plus a README explaining each field. |
| Rectification (Art. 16) | In-app for fields you can edit yourself (email, locale, marketing consent). For fields you cannot edit (e.g. a wrongly-attributed snapshot), email support. |
| Erasure / "right to be forgotten" (Art. 17) | Settings → Privacy → "Delete my account". 90-day grace, then hard delete. Audit log entries required by tax law are retained per §4 above. |
| Restriction (Art. 18) | Email [email protected] — we will pause processing while a dispute is resolved. |
| Portability (Art. 20) | Same export as Access, in machine-readable JSON. |
| Object (Art. 21) | Marketing email is one-click opt-out from any email or in Settings. Transactional email cannot be opted out while the subscription is active (we have to be able to tell you we charged you). For other processing based on legitimate interest, email us. |
| Automated decisions (Art. 22) | We do not make automated decisions with legal or similarly significant effect. Abuse-prevention flags trigger human review before any account action. |
| Withdraw consent (Art. 7(3)) | Wherever processing is based on consent (currently: marketing email), withdrawal is one click and takes effect immediately. |
| Complain (Art. 77) | You can lodge a complaint with the Cyprus Office of the Commissioner for Personal Data Protection (dataprotection.gov.cy). We would prefer you tell us first so we can fix it. |
6. Cookies and similar technologies
We use only first-party essential cookies and storage:
| Item | Purpose | Lifetime |
|---|---|---|
| Better Auth session cookie | Keep you signed in | Session / configured session lifetime |
| Locale preference | Remember EN/EL choice | 1 year |
| CSRF token | Block cross-site request forgery | Session |
Plausible analytics is cookieless and does not build a per-user profile. We currently set no advertising or third-party tracking cookies.
Because we set no non-essential cookies, ePrivacy and the Cyprus implementing rules do not require us to display a consent banner. We still publish /cookies describing every cookie and storage item we set.
If we ever add non-essential tracking, we will add an opt-in banner with no pre-checked boxes, and update this policy first.
7. IP addresses
- We log IPs truncated to /24 (IPv4) or /48 (IPv6) — enough for abuse prevention, not enough to identify a household.
- The full IP exists only inside a single request and is never persisted.
- Truncated IPs are not linked to specific vehicles or fines in any logged form.
8. Sub-processors
These third parties process personal data on our behalf. We have a Data Processing Agreement (DPA) with each. The current list is also published at whatdoiowe.ludehq.com/en/privacy and is updated when it changes.
| Sub-processor | Role | Data category | Location |
|---|---|---|---|
| Vercel Inc. | Web application and serverless job hosting | App traffic and operational request logs | EU/US under Vercel's transfer safeguards |
| Supabase Inc. | Managed PostgreSQL database and backups | Account, authentication, vehicle and lookup data | EU project region |
| Cloudflare Inc. | DNS, proxying and network security | IP address and request metadata in transit | Global network under transfer safeguards |
| Upstash | Redis cache and QStash job delivery | Rate-limit counters, short-lived OAuth state and job metadata | Configured EU services |
| OVHcloud / LudeMail | EU-hosted mail infrastructure operated by LudeHQ | Email, message content, delivery metadata | EU (France) |
| Google / Apple / LudeHQ | Optional social identity providers | Identity-token claims when you choose that sign-in method | Provider-dependent; safeguards apply |
| Stripe Payments Europe | Future subscription payments, only if enabled | Email, card data held by Stripe, invoices | EU / global under Stripe safeguards |
| Sentry | Error tracking | Sanitised diagnostics and pseudonymous user identifiers | Under Sentry's configured safeguards |
| Better Stack | Uptime monitoring | Endpoint URLs and response times | EU |
| Plausible Analytics | Cookieless web analytics | Aggregate page views, no per-user profile | EU (Germany) |
For non-EEA transfers by providers such as Vercel, Google, Apple, Sentry, or Stripe where applicable, we rely on an adequacy decision or the European Commission's Standard Contractual Clauses (SCCs, 2021/914) plus supplementary measures where required.
We give 30 days' notice before adding a sub-processor. If you object, you can cancel and request a refund of unused time.
9. Security
We treat security as a product feature. Highlights:
- TLS 1.3 in transit, HSTS preloaded.
- Encryption at rest for the Supabase PostgreSQL database and backups.
- Application-level authenticated encryption for a national ID only when an eligible user explicitly enables auto-check; disabling it deletes the ciphertext.
- Every national ID is represented by a salted+peppered one-way hash for matching; plaintext values are never logged.
- Postgres Row-Level Security enforces tenant isolation at the database level.
- MFA available on all plans, required on Pro and above.
- Quarterly secret rotation; documented runbook.
- Suspected vulnerabilities to [email protected] — 90-day coordinated disclosure window.
In the event of a personal data breach, we notify the Cyprus Office of the Commissioner for Personal Data Protection within 72 hours (GDPR Art. 33) and affected users without undue delay (Art. 34) where the breach is likely to result in a high risk to their rights.
10. International transfers
Where data is transferred outside the EEA (see §8), we rely on:
- The European Commission's Standard Contractual Clauses (2021/914);
- Adequacy decisions where they exist;
- Supplementary technical measures (encryption in transit and at rest, access controls).
A copy of the relevant SCCs is available on request.
11. Children
WhatDoIOweCY is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has signed up, email [email protected] and we will delete the account.
12. Changes to this policy
We will email every active account at least 30 days before any material change takes effect. Non-material changes (typos, clarifications, new sub-processors with the 30-day notice above) are published with a new "Last updated" date.
A versioned diff of this document is kept in our public repository.
13. How to reach us
- General privacy: [email protected]
- Security and vulnerability reports: [email protected]
- Postal: ludehq.com Ltd, Larnaca, Cyprus
If you are not satisfied with our response, you can complain to the Cyprus Office of the Commissioner for Personal Data Protection: dataprotection.gov.cy, +357 22 818 456, [email protected].
End of policy.