1. Scope and our roles
This Policy applies to penguinxbrl.com, customer and API-key portals, checkout, licensing and activation, support, product activity reporting, and hosted validation. EasyBRL is the controller for those business operations.
For personal data contained in an XBRL file or validation result, the customer decides why the data is processed and EasyBRL acts as its processor under the DPA. For the offline Docker product, EasyBRL receives no runtime data unless a customer chooses to send material in a support request.
2. Controller and contact
The controller is EasyBRL LLC, a Wyoming limited liability company operating PenguinXBRL. Privacy, rights, and security questions may be sent to [email protected]. EasyBRL has not appointed a data protection officer or an Article 27 EU representative. You may contact us directly in English.
3. Personal data we collect
| Context | Data categories |
|---|---|
| Accounts and portal | Name, email, optional company, organization and role, account status, user ID, authentication credential and password verifier, confirmation and recovery state, session and sign-in/security records, API-key identifiers, creation and last-use times. |
| Purchases and licensing | Plan, user count, checkout/customer/subscription identifiers, payment status, amounts and currency, invoices, acceptance evidence, activation and installation records. EasyBRL does not receive full card details. |
| Hosted API metadata | Organization/account ID, non-secret key ID, request ID and time, selected region, endpoint, authentication outcome, response status, billable units, source IP and security events. |
| Support and inquiries | Name, email, optional company, message, correspondence, and files or diagnostics you deliberately provide. |
| Product activity | Operation, outcome, taxonomy and entrypoint, software version, installation/machine label, workbook filename if reported, and exception details. Filing contents are not intentionally collected through activity reporting. |
| Website | Consent choice, page/referrer, browser or user-agent, and interaction events. Google advertising/analytics data is collected only after consent where required. |
| Hosted validation content | The XBRL file, personal data it may contain, transient working data, and returned diagnostics. These are not intentionally retained after the response. |
| Self-hosted runtime | None. The runtime makes no outbound connection or telemetry transmission to EasyBRL. |
4. Sources of data
We receive data directly from you or your organization, from software installations acting at your direction, from Stripe concerning payment status, from security and network infrastructure, and from Google only when the relevant website consent is active. Customers are the source of data contained in submitted filings.
5. Purposes and legal bases
| Purpose | Legal basis where GDPR/UK GDPR applies |
|---|---|
| Provide accounts, licenses, validation, support, and billing | Performance of a contract or steps requested before a contract. |
| Authenticate, prevent abuse, secure systems, and investigate incidents | Legitimate interests in protecting customers and the Services; legal obligation where applicable. |
| Maintain tax, payment, acceptance, and corporate records | Legal obligation and establishment, exercise, or defense of legal claims. |
| Operate and improve products using content-free activity and reliability data | Legitimate interests, balanced against user privacy and subject to available controls. |
| Respond to inquiries and manage commercial relationships | Contract steps and legitimate interests in business communications. |
| Google advertising and analytics | Consent where required. Consent may be withdrawn at any time. |
| Process personal data inside hosted XBRL files | The customer’s documented instructions and legal basis; EasyBRL acts as processor, not controller, for this content. |
6. Hosted validation: transient processing
We do not intentionally persist, log, back up, inspect, train models on, or use submitted XBRL files or validation JSON for our own purposes. They exist only in transient memory or temporary working storage required to answer the request and are destroyed when the request succeeds, fails, or times out.
Retained API metadata does not include filenames, facts, reporting-entity identifiers taken from the file, request bodies, validation diagnostics, or returned results. Personnel access to file content is not part of normal service operation.
8. Regions and international transfers
Hosted validation customers select an available EU or US content-processing region. Decrypted file content is contractually confined to that region, including configured edge processing. Supabase account and authentication records are stored in the region selected for the applicable Supabase project. Limited provider support and operational metadata, central billing, and content-free security metadata may be processed in the United States or other locations under contractual safeguards.
EasyBRL is a US company. Where EEA personal data is transferred to the United States without an adequacy decision, we use the European Commission’s Standard Contractual Clauses and appropriate supplementary measures. For UK restricted transfers we use the applicable UK addendum. Provider transfer safeguards are identified in their contractual documentation.
9. Retention
We may isolate a record for longer when reasonably necessary for a legal hold, active dispute, fraud investigation, or binding legal obligation, then delete it when that need ends.
| Record | Retention |
|---|---|
| Submitted XBRL and validation JSON | No intentional retention; destroyed when the request completes, fails, or times out; never included in backups. |
| API and security logs | 90 days. |
| Detailed content-free usage and product activity | 24 months. |
| Portal and account profile | Subscription or account lifetime plus 90 days, unless needed for a dispute or law. |
| Inquiries and support | 24 months after the last substantive contact. |
| Website analytics | Up to 14 months; consent preferences are renewed at least every six months. |
| Tax, invoice, payment, and legal acceptance evidence | 7 years. |
| Encrypted backups containing otherwise retained metadata | Expire within 30 days after the source record is deleted. |
10. Security
We use technical and organizational safeguards appropriate to the data and risk, including encrypted transport, encryption at rest for retained metadata, non-recoverable API-key storage, least privilege, tenant separation, monitoring, patching, incident response, and secure deletion. No internet transmission or storage system is guaranteed to be completely secure.
11. Your privacy rights
Depending on your location and applicable law, you may request access, correction, deletion, restriction, portability, or a copy of personal data; object to or opt out of certain processing, targeted advertising, sharing, or sale; withdraw consent; or appeal a denied request. You will not be discriminated against for exercising a right.
Send a request to [email protected]. Describe the account or relationship involved. We may verify identity and authority using proportionate information and may ask an authorized agent for proof of authority. We generally respond within the legally required period. If EasyBRL is processing filing content for a customer, contact that customer first; we will assist it under the DPA.
12. Complaints
Please contact us first so we can address your concern. EEA and UK residents may also complain to the data-protection authority where they live or work or where an alleged infringement occurred. US residents may contact the regulator or attorney general identified by applicable state law.
13. Children and automated decisions
The Services are not directed to children under 18, and we do not knowingly collect their account data. Contact us if you believe a child supplied data directly to us. We do not make decisions producing legal or similarly significant effects about individuals using solely automated processing. Validation diagnostics concern submitted filings, not decisions about a person.
14. Policy changes
We will post changes with a new version and date. We will give at least 30 days’ notice through the account email or portal before a material change to an active paid Service, unless urgent legal or security needs require faster action. Earlier versions remain available on request.
Contact
Questions about this document can be sent through the contact form or to [email protected].