GDPR — your data rights

Updated: 2026-09-23

Your data is processed under the General Data Protection Regulation. Here is what rights you have and how each of them is met.

Data controller

Dalius Dobravolskas, trading as ffff.lt, Lithuania. For anything about your data, write to info@ffff.lt.

Processors

Hetzner Online GmbH (Industriestrasse 25, 91710 Gunzenhausen, Germany). Its machine runs the application, the database files and the mail server the sign-in links come from: it is all one server. There is an Article 28 data processing agreement with them.

Google Ireland Limited, in the narrow sense that your browser fetches the site's typefaces from Google Fonts and Google therefore logs the request — your IP address and browser. Nothing about your account or your projects is sent with it.

Because the server stands in the European Union, Card-a-mon does not transfer your projects and artwork to third countries. There are no other processors: no analytics, no advertising, no mail-sending service, no backups in anybody else's cloud.

AI assistants you connect

An AI assistant you connect over MCP is not a processor of Card-a-mon's. It is a recipient you choose: when you approve it, you instruct Card-a-mon to hand it what it asks for from your projects, and from then on the company that runs it handles that data under its own terms, as a controller in its own right. That company may be outside the European Union, in which case the transfer is made at your request. Card-a-mon gives an assistant access only to the account that approved it, and only until you disconnect it.

Your rights

Legal basis

Performance of a contract: to run the editor you signed up to use, and to give an AI assistant access to your projects when you ask for it by approving the connection. Legitimate interest: to keep the service safe, which is what the cap on sign-in link requests comes from.

How long things are kept

Your data is kept until you delete the account. Inactive accounts are not deleted automatically. A sign-in link lasts fifteen minutes and works once; a session lasts 30 days, and signing out ends it at once. A connected AI assistant keeps its access until you disconnect it or leave it unused for 60 days; the token it sends with each request lasts an hour. A registration that is never approved is removed within a day.

Security

Breach notification

If data did leak and that put your rights at risk, you will be told, and so will the supervisory authority, within 72 hours, as the GDPR requires.

Supervisory authority

If you are unhappy with how your data is handled you may complain to the Lithuanian State Data Protection Inspectorate: vdai.lrv.lt.