📜 Legal
Privacy Policy, Terms of Service & GDPR Compliance
🔒 Privacy Policy
Last updated: January 2025Your documents are processed in memory and immediately discarded.
We store only the SHA-256 hash — impossible to reverse.
No analytics, no advertising, no third-party cookies.
1. Data Controller
Email: privacy@sbix.io
2. Data We Collect
| Data | Purpose | Retention |
|---|---|---|
| Email address | Account & notifications | Until deletion |
| Password (hashed) | Authentication | Until deletion |
| File hash (SHA-256) | Certification | Permanent |
| Filename | Certificate display | Until deletion |
| IP address | Security | 7 days |
3. Data We Do NOT Collect
- ❌ Your actual files or documents
- ❌ File contents in any form
- ❌ Browsing history or behavior
- ❌ Device fingerprints
- ❌ Third-party tracking data
4. Third Parties
| Service | Purpose | Data Shared |
|---|---|---|
| Stripe | Payments | Email, payment info |
| Tezos Network | Blockchain | Hash only (public) |
| Aleph.im | Decentralized storage | Hash only (public) |
| FreeTSA | Timestamp | Hash only |
5. Cookies
We use only essential cookies:
session— Authentication (session)sbix_theme— Theme preference (1 year)sbix_lang— Language preference (1 year)
No analytics, advertising, or third-party tracking cookies.
6. Security
- ✅ TLS 1.3 encryption
- ✅ Passwords hashed with bcrypt
- ✅ Ed25519 signatures
- ✅ Rate limiting & DDoS protection
📋 Terms of Service
Last updated: January 20251. Acceptance
By using SBIX Certify, you agree to these Terms of Service. If you do not agree, please do not use our service.
2. Service Description
SBIX Certify provides document certification services including:
- SHA-256 cryptographic hashing
- Merkle tree proof generation
- Ed25519 digital signatures
- RFC-3161 TSA timestamps
- Blockchain anchoring (Tezos, Aleph.im)
- PDF certificate generation
3. User Responsibilities
- Provide accurate registration information
- Maintain the security of your account
- Use the service only for lawful purposes
- Not attempt to circumvent security measures
- Not use the service for illegal document certification
4. Intellectual Property
You retain all rights to your documents. SBIX Certify does not claim ownership of any files you certify. We only store cryptographic hashes, not your actual files.
5. Service Availability
We strive for 99.9% uptime but do not guarantee uninterrupted service. Scheduled maintenance will be announced in advance when possible.
6. Pricing & Payments
- Free Plan: 5 certificates per month
- Pro Plan: €29/month, unlimited certificates
- Payments processed securely via Stripe
- Cancel anytime, no refunds for partial months
7. Limitation of Liability
SBIX Certify is provided "as is" without warranties. We are not liable for:
- Indirect or consequential damages
- Loss of data or profits
- Service interruptions
- Third-party blockchain network issues
Our maximum liability is limited to the fees you paid in the last 12 months.
8. Certificate Validity
Certificates provide cryptographic proof of document existence at a specific time. Legal validity may vary by jurisdiction. Consult legal counsel for specific legal requirements.
9. Termination
We may terminate accounts that:
- Violate these terms
- Engage in fraudulent activity
- Abuse the service
You may delete your account at any time from your dashboard.
10. Changes to Terms
We may update these terms. Continued use after changes constitutes acceptance. Material changes will be notified via email.
11. Governing Law
These terms are governed by the laws of the European Union. Disputes will be resolved in EU courts.
12. Contact
Email: legal@sbix.io
🇪🇺 GDPR Compliance
Last updated: January 2025Legal Basis (Article 6)
| Processing | Legal Basis |
|---|---|
| Account creation | Contract (Art. 6.1.b) |
| Certification | Contract (Art. 6.1.b) |
| Email notifications | Consent (Art. 6.1.a) |
| Security logging | Legitimate interest (Art. 6.1.f) |
| Payments | Contract (Art. 6.1.b) |
Your Rights
Request a copy of your data
Correct inaccurate data
Request data deletion
Limit processing
Export your data
Object to processing
Data Retention
- Account data: Until you delete your account
- Certificates: Permanent (blockchain is immutable)
- Server logs: 7 days
- Payment records: 7 years (legal requirement)
International Transfers
Your data is processed within the EU. Blockchain anchoring involves public networks (Tezos, Aleph.im) but only transmits cryptographic hashes, not personal data.
Data Protection Officer
Supervisory Authority
You have the right to lodge a complaint with your local data protection authority if you believe your rights have been violated.