Privacy policy
What personal data Laudiance collects, why, where it lives, and how you can see it, export it or have it deleted. Where anything is imperfect, we say so instead of rounding up.
In effect from 5 August 2026.
Who we are
Laudiance is run by SOULSOLUTIONS S.R.L., a company registered in Romania under trade register number J2026038112009, fiscal code 54876124, with its registered office at Str. Parângului nr. 9, et. 2, ap. 11, Târgu Mureș, jud. Mureș, România. In this policy, "we" means that company.
Privacy questions and requests go to contact@laudiance.com.
One platform, two roles
GDPR splits responsibility in two. A controller decides why personal data is processed. A processor handles data on the controller's instructions. Laudiance plays both roles, for different people, and this policy keeps them apart.
You hold a Laudiance account: we are your controller. We decide what the service needs from you, and we answer to you for it.
You submitted a testimonial, or a business sent you a request link: that business is your controller. It chose to collect your words, it decides where they appear, and it can delete them. We store and show your testimonial on its instructions, as its processor.
Two narrow things on our public pages happen for our own purposes rather than the business's: we compute keyed digests of IP addresses to stop spam, and our infrastructure providers keep server logs. For those two we act as controller, on our legitimate interest in keeping the platform safe.
| Your relationship to Laudiance | Controller | Where to send a request |
|---|---|---|
| You signed up for an account | SOULSOLUTIONS S.R.L., trading as Laudiance | To us: contact@laudiance.com, or the self-serve tools in Settings |
| You submitted a testimonial or received a request link | The business that asked you | To that business. If you cannot reach it, email us and we will help |
Account holders: what we collect and why
We collect what running the service takes, and nothing for advertising.
| Data | What it includes | Legal basis |
|---|---|---|
| Account | Email address and a password, stored hashed by Supabase Auth. If you use Google sign-in, Google sends us your name and email address. | Contract, Art. 6(1)(b): running the service you signed up for |
| Workspace content | Workspace names, brand colour, logo, forms and their questions, consent text versions, internal tags. | Contract, Art. 6(1)(b) |
| Billing | Your plan, subscription state, invoices, and a Stripe customer reference. Card numbers go straight to Stripe; they never touch our servers. | Contract, Art. 6(1)(b); legal obligation, Art. 6(1)(c), for tax and accounting records |
| Transactional email | A welcome email and a daily digest of new testimonials, sent through Resend. | Contract, Art. 6(1)(b) |
| Security signals | Keyed digests (HMAC) of IP addresses for rate limiting, plus spam signals such as honeypot hits. We store no raw IP addresses. | Legitimate interest, Art. 6(1)(f): keeping the platform safe |
| Support | Your email address and what you write to us. | Legitimate interest, Art. 6(1)(f): answering you |
Stripe also processes payment data for its own purposes, fraud prevention among them, under its own privacy policy.
Testimonial submitters: what we hold, and for whom
A business asked for your testimonial; Laudianceis the tool it used. On that business's behalf we hold:
- Your name, and your role or company if you gave one
- Your words: the testimonial text or your answers to the form's questions, and a star rating if you gave one
- A photo of you, if you added one
- A video, if you recorded or uploaded one
- The language you submitted in
- A consent record: the moment you ticked the consent box, plus the exact version of the consent text you saw
The consent record is strict by design. You cannot submit without ticking the consent checkbox. Consent texts are stored append-only, so if the business edits the wording later, your record still points at the words you actually agreed to.
If a business sends you a personalised request link, it typed your name, and sometimes your email address, into Laudiance first. We hold those on its behalf. We also record how far the request got — opened, started, finished — so the business can decide whether to nudge you. That works without cookies.
Businesses can also import testimonials they collected somewhere else, by hand or from a CSV file. We label those as imported, with no consent record, because we did not witness one. The importing business answers for its right to use them.
To correct or delete a testimonial, ask the business that collected it. Deletion on our side is real: the database row and the stored files go in the same routine. If you cannot reach the business, email us and we will help.
Cookies, and the lack of them
The collection form, the public Wall of Love and the embed widget set zero cookies and write nothing to localStorage or sessionStorage. They load no external fonts: our typefaces are served from our own domain. They load no third-party script, no analytics and no advertising tag. The widget is one script, and it comes from us.
The dashboard sets strictly necessary authentication cookies, nothing else. That is why there is no cookie banner: there is nothing to consent to. There are no analytics or advertising cookies anywhere, this marketing site included.
Photos and videos are the one request that leaves our own domain, and we would rather say so than let you find it in a network tab. Media lives in our file storage, which Supabase operates for us in Frankfurt, and your browser fetches it from there directly, from a host of the form <project-ref>.supabase.co. So a wall, a form or an embedded widget that shows a photo or a video makes a request to that host, and that request carries your IP address and browser user agent, as every web request does. The link identifies the file being fetched, expires within an hour, and says nothing about you. The host is a storage bucket, not an analytics or advertising service. Supabase is in the sub-processor table below.
Apart from fetching that media, the widget talks only to the Laudiance API, where it asks for the published testimonials and nothing else. We set nothing in your browser and keep no profile of you. Your IP address is handled as described under Security signals and Server logs.
Server logs and IP addresses
Laudiancenever stores raw IP addresses. For rate limiting we keep HMAC digests computed with a key that rotates daily, so yesterday's digest is useless today. A scheduled job deletes expired entries.
Vercel and Supabase do keep client IP addresses in their own infrastructure logs, for their operational purposes and under their own retention policies. We say this plainly because "no IPs anywhere" would be an overclaim.
Sub-processors
Four companies help us run Laudiance. Each processes personal data only to provide its service to us, under a data processing agreement.
| Sub-processor | Role | Company and data location |
|---|---|---|
| Supabase | Database, file storage and authentication. Also serves photos and videos directly to visitors' browsers, so it sees their IP addresses. | US company. Our project runs in the EU (eu-central-1, Frankfurt); data at rest stays in the EU. |
| Vercel | Hosting: serves the application | US company. Runs the application code and sees request traffic, including IP addresses, in its infrastructure logs. |
| Stripe | Payments and subscription billing | US company with EU infrastructure and EU entities for European billing. |
| Resend | Transactional email (welcome email, daily digest) | US company with EU sending infrastructure. |
All four are US companies operating EU infrastructure. If your compliance bar requires EU-owned vendors end to end, Laudiance is not there yet. We would rather tell you that than pretend otherwise.
Before any new sub-processor touches personal data, we will update this list and email account holders.
Where data lives, and transfers out of the EU
The database, uploaded files (videos, photos, logos) and authentication run in Supabase's eu-central-1 region in Frankfurt. Data at rest stays in the EU.
Because our providers are US companies, some data can still reach the US: provider staff can access systems for support, Stripe routes payments through its global network, and infrastructure logs sit with each provider. Those transfers rest on the European Commission's Standard Contractual Clauses or, where the provider holds a live certification, on the EU-US Data Privacy Framework. Each provider's data processing agreement names its mechanism.
How long we keep things
| Data | Kept until |
|---|---|
| Your account and everything in it | You delete it. Deletion cancels any subscription first, then removes workspaces, testimonials, files and the account itself. The live system keeps no soft-delete copy. |
| A single testimonial | The business deletes it. The database row and its stored files go in the same routine. |
| Already-issued media links | Media is served through signed links that expire after at most one hour. A link issued just before a deletion can work until its signature lapses. The wall and widget stop showing deleted content immediately. |
| Invoices and accounting records | The period Romanian tax and accounting law requires. Account deletion does not remove these. |
| Rate-limit digests | Hours. Entries expire with their window and the signing key rotates daily. |
| Provider infrastructure logs | Vercel's and Supabase's own retention policies. |
| Database backups | Our database provider keeps automated backups for disaster recovery. Deleted data leaves them as they rotate out of that window. We do not use backups to resurrect deleted content. |
Your rights
GDPR gives you rights against the controller. For account data that is us. For a testimonial it is the business that collected it, and we assist that business in honouring them:
- Access: see the personal data held about you
- Rectification: have mistakes corrected
- Erasure: have your data deleted
- Restriction: have processing paused while a dispute is resolved
- Portability: receive your data in a machine-readable format
- Objection: object to processing based on legitimate interest
Account holders can do the two big ones without asking. Settings, Privacy and data, Export downloads a JSON file with your workspace, forms, every testimonial in every status including original and edited text and the consent records, tags, and links to media files. The same page deletes a single testimonial or the whole account — hard, files included.
For everything else, email contact@laudiance.com. We answer within a month, free of charge. If a request is complex the law lets us take up to two months more, and we will tell you if we need them.
We build no profiles and make no automated decisions with legal or similar effects.
Complaints and the supervisory authority
You can complain to us first, and we would like the chance to fix things. You do not have to start there.
Our supervisory authority is the Romanian one: Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336 București, România, dataprotection.ro.
If you live or work in another EU or EEA country, its authority can take your complaint too. Courts stay open to you either way.
How we protect it
Every database table enforces row-level security, so one customer's session cannot read another customer's rows. Media sits in private storage buckets, reachable only through signed links that expire within an hour. Testimonial content renders as text, never as HTML. TLS encrypts traffic in transit.
Consent records resist tampering. Consent texts are append-only, and a business can fix typos in a submitted testimonial only in a separate field; the original words stay stored unchanged.
If a breach ever puts your data at risk, we notify the supervisory authority within 72 hours and tell the people affected without stalling.
What we do not do
We do not:
- sell or rent personal data, or share it for advertising
- run analytics or advertising trackers, anywhere
- profile you, or use testimonials for anything beyond storing and showing them for the business that collected them
- send marketing email — the welcome email and daily digest are part of the service, and if we ever want to send more we will ask first
- aim the service at children or knowingly collect their data; Laudiance is a tool for businesses
Changes to this policy
This version applies from 5 August 2026. When the policy changes, the date changes with it. Material changes reach account holders by email before they take effect.