Privacy Policy

Last updated: July 15, 2026

This Privacy Policy explains how Lapseline ("Lapseline", "we", "us") collects, uses, shares, and protects personal data when you use the Lapseline application and website at lapseline.com (the "Service"). Lapseline is operated by Serdar Torun as a sole proprietor. If you have any questions, contact us at privacy@lapseline.com.

Data controller & data protection contact

The data controller for personal data processed through the Service is Serdar Torun (Lapseline). We have not appointed a statutory Data Protection Officer, as one is not required for an operation of this size; however, all data protection matters — including the requests described below — are handled directly by our data protection contact:

Data protection contact: privacy@lapseline.com

Personal data we collect

  • Account data: your name, email address, and a securely hashed password.
  • Organization & team data: organization name, team members you invite, and their roles.
  • Documents & extracted data: the certificates, licenses, insurance and other documents you (or your subcontractors) upload, and the fields we extract from them (such as expiry dates, issuer, and identifiers).
  • Billing data: handled by our payment provider (see below); we receive limited subscription and card-summary information, not full card numbers.
  • Usage & technical data: log data, IP address, and basic device information generated when you use the Service.

How and why we use your data

  • To provide the Service — extraction, review, tracking, and expiry reminders.
  • To send transactional emails such as reminders, invitations, and password resets.
  • To operate billing and manage your subscription.
  • To secure the Service, prevent abuse, and maintain an audit trail.
  • To comply with our legal obligations.

Where the GDPR applies, we rely on the following legal bases: performance of a contract (providing the Service), our legitimate interests (security, service improvement), consent (where specifically requested), and compliance with legal obligations.

How your documents are processed

Extraction is performed by a self-hosted AI model that runs on our own infrastructure. The contents of the documents you upload are not sent to any third-party AI provider for this purpose — they are processed within our environment.

Sub-processors & third parties we share data with

We do not sell your personal data. We share it only with service providers that help us run the Service, under appropriate data-processing terms:

  • Lemon Squeezy — our Merchant of Record and payment processor, which handles checkout, billing, and tax.
  • Resend — our email delivery provider for transactional messages.
  • Our hosting/infrastructure provider (located in the European Union, the Netherlands) — stores application data and uploaded documents.

Where your data is stored & international transfers

Your application data and uploaded documents are hosted in the European Union (the Netherlands). Some sub-processors — such as our payment and email providers — may be located in the United States or other countries. Where personal data is transferred internationally, we rely on appropriate safeguards such as the providers' standard contractual clauses.

Data retention

We retain personal data for as long as your account is active and as needed to provide the Service. When you delete a document, certificate, or your account, the associated data is removed, subject to short-lived backups and any retention required by law.

Your rights & how to exercise them

Depending on your location, you may have the right to access, correct, delete, restrict, or object to the processing of your personal data, to data portability, and to withdraw consent. You also have the right to lodge a complaint with your local data protection authority.

To make a data subject request, email privacy@lapseline.com with the request and the email address associated with your account. We will verify your identity and respond within the timeframe required by applicable law (generally within one month). Much of your data can also be viewed, edited, or deleted directly from your account dashboard.

Security

We protect your data with encryption in transit (HTTPS), hashed passwords, access controls, and an audit log. No system is perfectly secure, but we work to protect your data and will notify you of a breach where required by law.

Children

The Service is intended for business use and is not directed to children under 16.

Cookies

We use only essential cookies required to sign you in and keep you signed in. See our Cookie Policy for details.

Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above and, where appropriate, by notifying you.