LEGAL
Privacy Policy
Last updated: 16 August 2026
1. Controller
The data controller is Fazen Group, operator of Fazen Terminal. For any privacy request contact support@fazenterminal.com.
2. Data we process
- Account data — name, email, phone, country, hashed password and PIN. Used to create and secure your account (contract performance, GDPR art. 6.1.b).
- Billing data — subscription status, plan, invoices and payment method handled by our payment processor; we never store full card numbers (contract performance and legal obligations, art. 6.1.b–c).
- Session and device data — device identifiers, IP address and session tokens, used for login security, license enforcement and rate limiting (contract performance and legitimate interest in security, art. 6.1.b and 6.1.f).
- Support data — tickets and messages you send us (contract performance).
- Fazen AI requests — the content of research runs you submit, processed to deliver the result and meter credits (contract performance).
This website uses no analytics or advertising trackers. Server logs are kept for security and reliability.
3. Processors and recipients
We share data only with service providers that run the product on our behalf, under data-processing agreements:
- Stripe — payment and subscription processing
- Railway — API and database hosting
- Vercel — website hosting
- Resend — transactional email delivery
- AI infrastructure providers — execution of Fazen AI research runs
- GitHub — distribution of application downloads
Some providers process data outside the EEA; transfers rely on adequacy decisions or Standard Contractual Clauses.
4. Retention
We keep personal data while your account is active. When you delete your account from the application, operational records are erased and the account is irreversibly deactivated; we retain only bounded, de-identified billing and audit records required for legal, tax and anti-fraud obligations. Your former email address becomes reusable for a new registration.
5. Your rights
Under the GDPR you can request access, rectification, erasure, restriction, portability and object to processing based on legitimate interest. Account deletion is available directly inside the application. You may lodge a complaint with your supervisory authority — in Italy, the Garante per la Protezione dei Dati Personali.
6. Security
Passwords and PINs are stored only as salted hashes, transport is encrypted end to end, sessions are bound to devices, and deletion requires re-authentication. Access to production systems is restricted and audited.
7. Changes
We will announce material changes to this policy through the service or by email before they take effect.