Skip to main content

GDPR data map (draft)

Status: DRAFT. Map systems before appointing a DPO / completing RoPA.

ProcessingPersonal dataLawful basis (draft)SystemsRetention (draft)
Device bindingBech32 address, pubkey, challenge metadataLegitimate interest / contractzunia-backendUntil revoke + short audit window
Push deliveryPush endpoint, device idConsent (notification permission)Backend + FCM/APNs/Web PushUntil unsubscribe
Tx history cacheAddress, tx hashes, summariesLegitimate interest (service)zunia-indexerCap per wallet; TTL TBD
Support emailEmail, message contentConsent / legitimate interestInboxOrdinary business retention
Crash / SentryDevice model, stack (scrubbed)Legitimate interestSentryPer Sentry project policy
AnalyticsPrefer none / privacy-preservingConsent if usedTBDTBD

Cross-border

Hosting regions TBD (Fly/Railway/Vercel). Document SCCs when vendors process EU data.

Data subject requests

Email [email protected]. Process access and erasure for server-side records. On-device keys are user-controlled; erasure means uninstall or wipe the device.