Data Protection

Last updated: September 2026
Overview

Publize operates on a zero data retention principle. Documents uploaded for processing are automatically deleted within one hour. We do not store, analyse, or share your document content beyond what is strictly required to perform the requested operation.

Document Processing

All uploaded files are processed on secured servers within the European Union. After processing completes, the following applies.

Files are automatically deleted within one hour of upload. Scheduled maintenance routines continuously remove expired and orphaned data. No document content is retained after deletion and no backup or archive of processed files is created. Downloaded results are your responsibility. Once removed from our systems, files cannot be recovered.

Account Data

We collect the minimum information necessary to operate your account. Your email address is used for authentication and account recovery. Your password is stored as a one-way cryptographic hash and cannot be viewed or recovered by anyone, including administrators. Activity logs record feature usage, file sizes, and processing duration for operational monitoring. No document content is included in these logs.

We do not collect, store, or process payment card information. Payment processing is handled by an external payment provider.

Security

All communications are encrypted in transit and at rest. Credentials and secrets are managed through a dedicated vault service and are never stored in application code. Account protection includes rate-limited authentication, automatic lockout after failed attempts, and optional two-factor authentication. Each user account is strictly isolated and can only access its own files and activity data.

Your Rights

You may access, export, and delete your personal data at any time through your profile settings. Data export allows you to download all personal information associated with your account. Account deletion permanently removes your account and all associated data. This action is immediate and irreversible. For any additional data-related requests, contact your platform administrator.

Compliance

The platform is designed in accordance with GDPR principles including data minimisation, purpose limitation, and the right to erasure. It aligns with HIPAA requirements by ensuring no protected health information is stored beyond the active processing window. Controls consistent with ISO 27001 are applied throughout, including access management, encryption, audit logging, and automated data lifecycle governance. Zero data retention is enforced by default. Document content is not persisted beyond the one-hour processing window and no backups of uploaded content are created.

Data Residency

All platform infrastructure is hosted within the European Union. Data does not leave the EU for storage or processing by our systems.

This policy applies to the Publize platform. If you have questions about how your data is handled, contact your platform administrator.

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please reload the page.