The hosted API does not intentionally retain submitted XBRL files or validation JSON. The self-hosted Docker runtime sends no customer data or telemetry to EasyBRL.

1. Scope and our roles

This Policy applies to penguinxbrl.com, customer and API-key portals, checkout, licensing and activation, support, product activity reporting, and hosted validation. EasyBRL is the controller for those business operations.

For personal data contained in an XBRL file or validation result, the customer decides why the data is processed and EasyBRL acts as its processor under the DPA. For the offline Docker product, EasyBRL receives no runtime data unless a customer chooses to send material in a support request.

2. Controller and contact

EasyBRL does not claim that the absence of an EU representative is exempt from GDPR Article 27; this position requires legal review.

The controller is EasyBRL LLC, a Wyoming limited liability company operating PenguinXBRL. Privacy, rights, and security questions may be sent to [email protected]. EasyBRL has not appointed a data protection officer or an Article 27 EU representative. You may contact us directly in English.

3. Personal data we collect

ContextData categories
Accounts and portalName, email, optional company, organization and role, account status, user ID, authentication credential and password verifier, confirmation and recovery state, session and sign-in/security records, API-key identifiers, creation and last-use times.
Purchases and licensingPlan, user count, checkout/customer/subscription identifiers, payment status, amounts and currency, invoices, acceptance evidence, activation and installation records. EasyBRL does not receive full card details.
Hosted API metadataOrganization/account ID, non-secret key ID, request ID and time, selected region, endpoint, authentication outcome, response status, billable units, source IP and security events.
Support and inquiriesName, email, optional company, message, correspondence, and files or diagnostics you deliberately provide.
Product activityOperation, outcome, taxonomy and entrypoint, software version, installation/machine label, workbook filename if reported, and exception details. Filing contents are not intentionally collected through activity reporting.
WebsiteConsent choice, page/referrer, browser or user-agent, and interaction events. Google advertising/analytics data is collected only after consent where required.
Hosted validation contentThe XBRL file, personal data it may contain, transient working data, and returned diagnostics. These are not intentionally retained after the response.
Self-hosted runtimeNone. The runtime makes no outbound connection or telemetry transmission to EasyBRL.

4. Sources of data

We receive data directly from you or your organization, from software installations acting at your direction, from Stripe concerning payment status, from security and network infrastructure, and from Google only when the relevant website consent is active. Customers are the source of data contained in submitted filings.

5. Purposes and legal bases

PurposeLegal basis where GDPR/UK GDPR applies
Provide accounts, licenses, validation, support, and billingPerformance of a contract or steps requested before a contract.
Authenticate, prevent abuse, secure systems, and investigate incidentsLegitimate interests in protecting customers and the Services; legal obligation where applicable.
Maintain tax, payment, acceptance, and corporate recordsLegal obligation and establishment, exercise, or defense of legal claims.
Operate and improve products using content-free activity and reliability dataLegitimate interests, balanced against user privacy and subject to available controls.
Respond to inquiries and manage commercial relationshipsContract steps and legitimate interests in business communications.
Google advertising and analyticsConsent where required. Consent may be withdrawn at any time.
Process personal data inside hosted XBRL filesThe customer’s documented instructions and legal basis; EasyBRL acts as processor, not controller, for this content.

6. Hosted validation: transient processing

We do not intentionally persist, log, back up, inspect, train models on, or use submitted XBRL files or validation JSON for our own purposes. They exist only in transient memory or temporary working storage required to answer the request and are destroyed when the request succeeds, fails, or times out.

Retained API metadata does not include filenames, facts, reporting-entity identifiers taken from the file, request bodies, validation diagnostics, or returned results. Personnel access to file content is not part of normal service operation.

7. Recipients and providers

We do not sell personal information. Google advertising may constitute targeted advertising, sharing, or a sale under some US state definitions; it is disabled before consent and can be rejected or withdrawn through Cookie Settings. We disclose data when legally required or necessary to protect rights and safety, using the narrowest lawful scope.

  • Supabase provides authentication and user-directory services for platform and management accounts.
  • Google Cloud provides region-selected infrastructure.
  • Cloudflare provides firewall, load-balancing, and configured regional edge services.
  • Stripe processes payments and subscription administration and acts under its own terms for payment services.
  • Google provides advertising and analytics only after the applicable consent and may act as an independent controller for those services.
  • Professional advisers, authorities, or transaction counterparties may receive limited data when lawfully necessary.

8. Regions and international transfers

Hosted validation customers select an available EU or US content-processing region. Decrypted file content is contractually confined to that region, including configured edge processing. Supabase account and authentication records are stored in the region selected for the applicable Supabase project. Limited provider support and operational metadata, central billing, and content-free security metadata may be processed in the United States or other locations under contractual safeguards.

EasyBRL is a US company. Where EEA personal data is transferred to the United States without an adequacy decision, we use the European Commission’s Standard Contractual Clauses and appropriate supplementary measures. For UK restricted transfers we use the applicable UK addendum. Provider transfer safeguards are identified in their contractual documentation.

9. Retention

We may isolate a record for longer when reasonably necessary for a legal hold, active dispute, fraud investigation, or binding legal obligation, then delete it when that need ends.

RecordRetention
Submitted XBRL and validation JSONNo intentional retention; destroyed when the request completes, fails, or times out; never included in backups.
API and security logs90 days.
Detailed content-free usage and product activity24 months.
Portal and account profileSubscription or account lifetime plus 90 days, unless needed for a dispute or law.
Inquiries and support24 months after the last substantive contact.
Website analyticsUp to 14 months; consent preferences are renewed at least every six months.
Tax, invoice, payment, and legal acceptance evidence7 years.
Encrypted backups containing otherwise retained metadataExpire within 30 days after the source record is deleted.

10. Security

We use technical and organizational safeguards appropriate to the data and risk, including encrypted transport, encryption at rest for retained metadata, non-recoverable API-key storage, least privilege, tenant separation, monitoring, patching, incident response, and secure deletion. No internet transmission or storage system is guaranteed to be completely secure.

11. Your privacy rights

Depending on your location and applicable law, you may request access, correction, deletion, restriction, portability, or a copy of personal data; object to or opt out of certain processing, targeted advertising, sharing, or sale; withdraw consent; or appeal a denied request. You will not be discriminated against for exercising a right.

Send a request to [email protected]. Describe the account or relationship involved. We may verify identity and authority using proportionate information and may ask an authorized agent for proof of authority. We generally respond within the legally required period. If EasyBRL is processing filing content for a customer, contact that customer first; we will assist it under the DPA.

12. Complaints

Please contact us first so we can address your concern. EEA and UK residents may also complain to the data-protection authority where they live or work or where an alleged infringement occurred. US residents may contact the regulator or attorney general identified by applicable state law.

13. Children and automated decisions

The Services are not directed to children under 18, and we do not knowingly collect their account data. Contact us if you believe a child supplied data directly to us. We do not make decisions producing legal or similarly significant effects about individuals using solely automated processing. Validation diagnostics concern submitted filings, not decisions about a person.

14. Policy changes

We will post changes with a new version and date. We will give at least 30 days’ notice through the account email or portal before a material change to an active paid Service, unless urgent legal or security needs require faster action. Earlier versions remain available on request.

Contact

Questions about this document can be sent through the contact form or to [email protected].

Complete purchase

Enter your details and continue to secure payment.

Enterprise XBRL package validation

Choose a service term or contact us about procurement.

Contact PenguinXBRL

Tell us who to contact and what you need.

Cookie settings

Choose whether optional advertising and analytics may run in this browser.

Necessary

Preference, security, checkout, and requested session functions.

Always on