1. Controller and roles
Controller for account, website, security and business recordsGökhan VodinaliGäbelbachstrasse 39, 3027 BernSwitzerland (CH)Legal form / registration: Individual operator; no commercial-register number providedsupport@hemelion.comWhen MandateShield processes personal data contained in authenticated API requests solely on a business Customer's documented instructions, that Customer acts as controller or business and MandateShield acts as processor or service provider under the Data Processing Addendum. The Customer decides whether and how to use every technical output.
2. Data categories and sources
- Account and contract: email and optional display name from Sign in with ChatGPT; organization name, business identifier and country; agreement versions, document and agreement digests, affirmative representations, acceptance time, locale and keyed pseudonymous request evidence.
- Service and evidence: API-key prefixes and hashes, key roles and audiences, public verification keys, mandate policies, purchase and authority metadata, findings, idempotency/replay records, receipt hashes, lifecycle states, provider-result metadata, provider evidence checked without trusting the caller report, timestamps, usage counters and the first account-scoped occurrence of defined operational milestones. Milestone evidence references are stored only as one-way digests.
- Provider configuration: optional restricted provider lookup credentials stored with authenticated encryption, provider account identifiers and connection state.
- Billing: plan, Stripe customer, Checkout Session, invoice and subscription identifiers, consent and order metadata. Stripe receives payment, billing-address and tax information. MandateShield is designed not to receive full card or bank credentials.
- Security: network addresses processed transiently, keyed rotating abuse identifiers, request headers, bounded security logs and incident records.
- Public Proof Network: subject URI, repository and exact commit references, self-reported coverage, cryptographic binding evidence and public attestation data supplied by a publisher.
- Deployment activation records: the HTTPS domain or public GitHub repository chosen by an account holder, the exact default-branch commit where applicable, bounded lifecycle identifiers, timestamps, cryptographic digests and the explicitly limited server-observation claims published in the proof and badge. Email, organization name, payment credentials and payment-provider data are not included in the public record.
Sources are the Customer and its users, ChatGPT sign-in, Stripe, Customer-directed providers or networks, public proof sources and signals generated when a request reaches the service.
3. Purposes and legal bases
Data is used to form and perform business contracts, authenticate accounts, provide requested decisions and evidence, enforce mandates, prevent replay and abuse, secure and debug the service, reconcile execution state, meter and invoice usage, comply with legal obligations, establish or defend claims and improve reliability using privacy-minimized statistics. Depending on applicable law, the bases are contract and pre-contract steps, legitimate interests in security and service operation, legal obligations, Customer's documented instructions and consent for optional browser analytics.
MandateShield does not sell personal data or use it for cross-context behavioral advertising. Optional browser activation events are not attached to an account, email, purchase envelope, merchant or receipt and are off by default. Separately, the service stores one first-occurrence record when its own control plane confirms a defined account, strict reservation, permit, terminal evidence checked without trusting the caller assertion, or Stripe subscription milestone. Those account-scoped records operate the service and are not published as global counts.
If consent is granted, an opaque per-tab identifier in session storage helps suppress duplicate events. Unverified client activation signals are retained for up to 90 days and are not proof of unique people, customers, integrations or revenue.
Optional activation analytics: denied. Global Privacy Control and Do Not Track always override a grant.
4. Automated outputs
MandateShield produces technical policy and authority results, but MandateShield itself does not take a decision that produces legal or similarly significant effects for an individual. The Customer determines whether and how to rely on an output and must assess its own automated-decision obligations. Customers must not submit data for prohibited high-risk individual decisions.
5. Recipients and international transfers
Recipient categories may include infrastructure and security hosting, identity/sign-in, billing/tax/payment administration, Customer-directed provider endpoints, professional advisers, authorities where legally required and acquirers subject to appropriate safeguards. The current operational list and role distinctions appear on the Subprocessors page.
Data may be processed outside the Customer's country. Where required, transfers are governed by an applicable adequacy decision, contractual clauses or another lawful mechanism actually in place. This notice does not claim an unexecuted transfer instrument.
6. Retention
| Record | Typical maximum |
|---|---|
| Public sandbox request body | Processed to return the response; not intentionally stored as transaction evidence |
| Rotating anonymous abuse bucket | 48 hours after creation |
| Optional activation signal | 90 days |
| Plan decision/evidence records | Sandbox 7 days; Starter 30; Growth 60; Scale 90; Machine 30, subject to unresolved execution and billing preservation |
| Replay and security evidence | Up to 400 days where required to prevent reuse or abuse |
| Usage-month records | Approximately 15 months |
| Account-scoped operational milestones | Until account deletion; first occurrence only, with a one-way evidence-reference digest |
| Deployment activation proof | Publicly retrievable for up to 180 days after issuance. The account-scoped source record remains until account deletion, subject to the limited legal, security and backup qualifications below. |
| Provider credentials | Until removed, replaced or account deletion |
| Operational account data | Until account deletion or no longer needed |
| Contract, order, invoice and legal-claim evidence | Up to 10 years after the relationship ends where necessary for accounting, contract proof or legal claims |
Account deletion removes account-scoped operational milestones, deployment activation proofs and their public availability together with the active operational account, subject to unresolved execution and billing safeguards. Minimal contract, invoice, security or claim evidence may remain for the period above. Isolated backups are not used for ordinary processing and expire under the applicable backup cycle; deletion is not described as instantaneous physical destruction.
7. Rights and choices
Depending on applicable law, individuals may request access, correction, deletion, restriction, portability, or object to processing; withdraw consent without affecting prior lawful processing; and complain to the competent supervisory authority. Signed-in users can export active account data, revoke credentials, cancel billing and delete the operational account without contacting support. Requests that cannot be completed self-service may be sent to the controller contact above. Identity verification and lawful exceptions may apply.
8. Security, children and required data boundaries
Controls include transport security, hashed API secrets, role-scoped credentials, authenticated encryption for optional provider credentials, tenant scoping, bounded input, replay protection, retention cleanup and cryptographically verifiable receipts. No security program guarantees that an incident is impossible.
The service is for business users aged 18 or older. Do not submit children's data, cardholder data, bank credentials, private keys, passwords, special-category data or unnecessary personal data.
9. Changes
Material changes are versioned and, when required, presented for renewed acceptance. The version at the top identifies this notice.