Skip to main content
Legal

Privacy policy

Last updated: 3 August 2026 Effective: 3 August 2026 Controller: LudeHQ (ludehq.com Ltd), operating WhatDoIOwe (WhatDoIOweCY), Larnaca, Cyprus. Contact: [email protected] Security contact: [email protected]

This policy explains what data WhatDoIOweCY collects, why we collect it, how long we keep it, who else touches it, and what you can do about it. We have written it in plain language. If anything is unclear, email us and we will rewrite the section.

We process personal data under the EU General Data Protection Regulation (Regulation 2016/679) and the Cyprus Law providing for the Protection of Natural Persons with regard to the Processing of Personal Data (Law 125(I)/2018).


1. What WhatDoIOweCY does

WhatDoIOweCY is a vehicle-obligations dashboard that checks supported sources for camera fines, road-tax status, MOT and insurance indicators, then provides deep links to the relevant official payment or information portals.

We never process payments for government services. We never see or touch a card number for any government payment. The initial release is free and has no in-app purchases. If we later enable paid subscriptions, Stripe will handle only our own subscription billing.

We are an independent service. We are not affiliated with the Government of Cyprus, Cyprus Police, JCC Smart, the Road Transport Department, or any municipality. We act on your explicit instruction to query supported sources on your behalf.


2. Data we collect

We deliberately collect as little as we can. The full list:

CategorySpecificallySource
Account identityName, email address, locale, timezone, marketing consent flagYou, or your chosen social sign-in provider
AuthenticationPassword hash, MFA factors, session tokens, or provider identifiersBetter Auth and, if chosen, Google, Apple, or LudeHQ SSO
VehiclePlate numberYou
National IDA salted+peppered hash. For manual checks the raw value exists only for that request. If you explicitly enable an eligible auto-check feature, it is also stored with application-level authenticated encryption until you turn auto-check offYou
Lookup resultsSnapshots of fines, road-tax status, MOT and insurance indicators retrieved from supported sources on your instructionSupported public or official sources
Billing (only if enabled and used)Plan and subscription state. Card data is held by Stripe and is not available to usStripe
SupportEmails you send us, in-app messagesYou
Operational telemetryTruncated IP (/24 IPv4, /48 IPv6), user-agent, request timestamps, error eventsYour browser / our servers
AnalyticsAggregate page views via Plausible (cookieless, no per-user profile)Your browser

We do not collect: home address, phone number, date of birth, or attributes inferred from your national ID. We do not use national IDs for profiling.


3. Why we process each category (purpose and legal basis)

PurposeData usedLegal basis (GDPR Art. 6)
Provide the service you signed up for (vehicle lookups, dashboard, notifications)Email, plate, ID hash, snapshotsArt. 6(1)(b) — performance of contract
Account creation, login, MFAEmail, password hash, MFA factorsArt. 6(1)(b) — performance of contract
Subscription billing, invoicing, refundsEmail, billing data, planArt. 6(1)(b) — performance of contract; Art. 6(1)(c) — legal obligation (tax/accounting)
Transactional email (renewal notices, receipts, security alerts)EmailArt. 6(1)(b) — performance of contract; Art. 6(1)(f) — legitimate interest
Marketing emailEmail, marketing consent flagArt. 6(1)(a) — consent (one-click opt-out)
Abuse prevention (rate limits, fraud detection, plate-enumeration controls)Truncated IP, lookup velocity, account ageArt. 6(1)(f) — legitimate interest in protecting the service and its users
Security and incident responseAudit log, error events, truncated IPArt. 6(1)(f) — legitimate interest
Tax and accounting recordsBilling data, invoicesArt. 6(1)(c) — legal obligation
Aggregate, cookieless analyticsPage viewsArt. 6(1)(f) — legitimate interest (no cookies, no profile)

We do not sell your data, ever. We do not show third-party ads.


4. How long we keep it (retention)

DataRetention
Snapshots (lookup results)30 days on Free, 24 months on paid plans. Auto-deleted by daily cron.
Encrypted national ID for opted-in auto-checkUntil you disable auto-check, delete the vehicle, or delete the account.
Unverified, unused registration7 days, then automatically deleted.
Audit log (billing events, security events)7 years — required for financial and legal records.
Account identity (email, plan, settings)For the lifetime of the account.
Deleted accounts90-day grace window for re-activation, then hard-deleted within 24 hours.
Truncated IP and operational telemetry30 days for live logs; aggregated counters retained longer with no per-user link.
Support email threads24 months after the last message.

When retention expires, the data is removed from primary storage. Encrypted backups roll over on a 35-day cycle (see §15 of our internal spec); deleted records disappear from backups within that window.


5. Your rights under GDPR

You can exercise any of these rights by emailing [email protected] or, where indicated, directly inside the app. We will respond within 30 days (target: under 5 minutes for export, under 24 hours for deletion).

RightHow to use it
Access (Art. 15)Settings → Privacy → "Export my data". You get a JSON file with every record we hold about you, plus a README explaining each field.
Rectification (Art. 16)In-app for fields you can edit yourself (email, locale, marketing consent). For fields you cannot edit (e.g. a wrongly-attributed snapshot), email support.
Erasure / "right to be forgotten" (Art. 17)Settings → Privacy → "Delete my account". 90-day grace, then hard delete. Audit log entries required by tax law are retained per §4 above.
Restriction (Art. 18)Email [email protected] — we will pause processing while a dispute is resolved.
Portability (Art. 20)Same export as Access, in machine-readable JSON.
Object (Art. 21)Marketing email is one-click opt-out from any email or in Settings. Transactional email cannot be opted out while the subscription is active (we have to be able to tell you we charged you). For other processing based on legitimate interest, email us.
Automated decisions (Art. 22)We do not make automated decisions with legal or similarly significant effect. Abuse-prevention flags trigger human review before any account action.
Withdraw consent (Art. 7(3))Wherever processing is based on consent (currently: marketing email), withdrawal is one click and takes effect immediately.
Complain (Art. 77)You can lodge a complaint with the Cyprus Office of the Commissioner for Personal Data Protection (dataprotection.gov.cy). We would prefer you tell us first so we can fix it.

6. Cookies and similar technologies

We use only first-party essential cookies and storage:

ItemPurposeLifetime
Better Auth session cookieKeep you signed inSession / configured session lifetime
Locale preferenceRemember EN/EL choice1 year
CSRF tokenBlock cross-site request forgerySession

Plausible analytics is cookieless and does not build a per-user profile. We currently set no advertising or third-party tracking cookies.

Because we set no non-essential cookies, ePrivacy and the Cyprus implementing rules do not require us to display a consent banner. We still publish /cookies describing every cookie and storage item we set.

If we ever add non-essential tracking, we will add an opt-in banner with no pre-checked boxes, and update this policy first.


7. IP addresses

  • We log IPs truncated to /24 (IPv4) or /48 (IPv6) — enough for abuse prevention, not enough to identify a household.
  • The full IP exists only inside a single request and is never persisted.
  • Truncated IPs are not linked to specific vehicles or fines in any logged form.

8. Sub-processors

These third parties process personal data on our behalf. We have a Data Processing Agreement (DPA) with each. The current list is also published at whatdoiowe.ludehq.com/en/privacy and is updated when it changes.

Sub-processorRoleData categoryLocation
Vercel Inc.Web application and serverless job hostingApp traffic and operational request logsEU/US under Vercel's transfer safeguards
Supabase Inc.Managed PostgreSQL database and backupsAccount, authentication, vehicle and lookup dataEU project region
Cloudflare Inc.DNS, proxying and network securityIP address and request metadata in transitGlobal network under transfer safeguards
UpstashRedis cache and QStash job deliveryRate-limit counters, short-lived OAuth state and job metadataConfigured EU services
OVHcloud / LudeMailEU-hosted mail infrastructure operated by LudeHQEmail, message content, delivery metadataEU (France)
Google / Apple / LudeHQOptional social identity providersIdentity-token claims when you choose that sign-in methodProvider-dependent; safeguards apply
Stripe Payments EuropeFuture subscription payments, only if enabledEmail, card data held by Stripe, invoicesEU / global under Stripe safeguards
SentryError trackingSanitised diagnostics and pseudonymous user identifiersUnder Sentry's configured safeguards
Better StackUptime monitoringEndpoint URLs and response timesEU
Plausible AnalyticsCookieless web analyticsAggregate page views, no per-user profileEU (Germany)

For non-EEA transfers by providers such as Vercel, Google, Apple, Sentry, or Stripe where applicable, we rely on an adequacy decision or the European Commission's Standard Contractual Clauses (SCCs, 2021/914) plus supplementary measures where required.

We give 30 days' notice before adding a sub-processor. If you object, you can cancel and request a refund of unused time.


9. Security

We treat security as a product feature. Highlights:

  • TLS 1.3 in transit, HSTS preloaded.
  • Encryption at rest for the Supabase PostgreSQL database and backups.
  • Application-level authenticated encryption for a national ID only when an eligible user explicitly enables auto-check; disabling it deletes the ciphertext.
  • Every national ID is represented by a salted+peppered one-way hash for matching; plaintext values are never logged.
  • Postgres Row-Level Security enforces tenant isolation at the database level.
  • MFA available on all plans, required on Pro and above.
  • Quarterly secret rotation; documented runbook.
  • Suspected vulnerabilities to [email protected] — 90-day coordinated disclosure window.

In the event of a personal data breach, we notify the Cyprus Office of the Commissioner for Personal Data Protection within 72 hours (GDPR Art. 33) and affected users without undue delay (Art. 34) where the breach is likely to result in a high risk to their rights.


10. International transfers

Where data is transferred outside the EEA (see §8), we rely on:

  • The European Commission's Standard Contractual Clauses (2021/914);
  • Adequacy decisions where they exist;
  • Supplementary technical measures (encryption in transit and at rest, access controls).

A copy of the relevant SCCs is available on request.


11. Children

WhatDoIOweCY is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has signed up, email [email protected] and we will delete the account.


12. Changes to this policy

We will email every active account at least 30 days before any material change takes effect. Non-material changes (typos, clarifications, new sub-processors with the 30-day notice above) are published with a new "Last updated" date.

A versioned diff of this document is kept in our public repository.


13. How to reach us

If you are not satisfied with our response, you can complain to the Cyprus Office of the Commissioner for Personal Data Protection: dataprotection.gov.cy, +357 22 818 456, [email protected].


End of policy.