Privacy Policy

Last updated: September 10, 2026

This Privacy Policy explains how Lapseline ("Lapseline", "we", "us") collects, uses, shares, and protects personal data when you use the Lapseline application and website at lapseline.com (the "Service"). Lapseline is operated by Fidordia Software Technologies (Fidordia Yazılım Teknolojileri Anonim Şirketi), a company incorporated in Türkiye. If you have any questions, contact us at info@fidordia.com.

Data controller & data protection contact

The data controller for personal data processed through the Service is Fidordia Software Technologies (Fidordia Yazılım Teknolojileri Anonim Şirketi) (Lapseline), Kızılırmak Mah. Dumlupınar Blv. No: 3 C-1 İç Kapı No: 160, Çankaya / Ankara, Türkiye. We have not appointed a statutory Data Protection Officer, as one is not required for an operation of this size; however, all data protection matters — including the requests described below — are handled directly by our data protection contact:

Data protection contact: info@fidordia.com

Personal data we collect

  • Account data: your name, email address, and a securely hashed password.
  • Organization & team data: organization name, team members you invite, and their roles.
  • Documents & extracted data: the certificates, licenses, insurance and other documents you (or your subcontractors) upload, and the fields we extract from them (such as expiry dates, issuer, and identifiers).
  • Billing data: handled by our payment provider (see below); we receive limited subscription and card-summary information, not full card numbers.
  • Usage & technical data: log data, IP address, and basic device information generated when you use the Service.

How and why we use your data

  • To provide the Service — extraction, review, tracking, and expiry reminders.
  • To send transactional emails such as reminders, invitations, and password resets.
  • To operate billing and manage your subscription.
  • To secure the Service, prevent abuse, and maintain an audit trail.
  • To comply with our legal obligations.

Where the GDPR applies, we rely on the following legal bases: performance of a contract (providing the Service), our legitimate interests (security, service improvement), consent (where specifically requested), and compliance with legal obligations.

How your documents are processed

When you upload a document, we convert it to text on our own servers first — reading the PDF's text layer, or running optical character recognition (OCR) on a scan. The file itself, as an image or a PDF, is never sent to an AI provider.

We then redact that text before it leaves our infrastructure. Social Security and taxpayer numbers, payment card and bank account numbers, email addresses, telephone numbers, street addresses, dates of birth, driver's licence numbers, and dollar amounts are replaced with opaque placeholders such as [SSN_1]. The original values stay on our servers and are put back into the result afterwards.

The redacted text is sent to Anthropic (Claude API), which returns the certificate details we track. Anthropic processes it to serve our request and does not use API inputs or outputs to train its models.

What redaction does not cover: we do not remove names. The person or company a certificate is issued to, and the authority or insurer that issued it, are the information the product exists to extract, so they are part of the text we send. Policy, licence, permit, and certificate numbers are likewise sent, for the same reason. If a document contains sensitive information you would rather not have processed this way, please do not upload it.

Sub-processors & third parties we share data with

We do not sell your personal data. We share it only with service providers that help us run the Service, under appropriate data-processing terms:

  • Paddle — our Merchant of Record and payment processor, which handles checkout, billing, and tax.
  • Google — delivers our transactional email (reminders, invitations, password resets, document requests).
  • Anthropic — the AI provider that reads the redacted text of your documents and returns the certificate details we track. See “How your documents are processed” above for what is and is not sent.
  • Our hosting/infrastructure provider (located in the European Union, the Netherlands) — stores application data and uploaded documents.

Where your data is stored & international transfers

Your application data and uploaded documents are hosted in the European Union (the Netherlands). Some sub-processors — such as our payment and email providers — may be located in the United States or other countries. Where personal data is transferred internationally, we rely on appropriate safeguards such as the providers' standard contractual clauses.

Data retention

We retain personal data for as long as your account is active and as needed to provide the Service. When you delete a document, certificate, or your account, the associated data is removed, subject to short-lived backups and any retention required by law.

Your rights & how to exercise them

Depending on your location, you may have the right to access, correct, delete, restrict, or object to the processing of your personal data, to data portability, and to withdraw consent. You also have the right to lodge a complaint with your local data protection authority.

To make a data subject request, email info@fidordia.com with the request and the email address associated with your account. We will verify your identity and respond within the timeframe required by applicable law (generally within one month). Much of your data can also be viewed, edited, or deleted directly from your account dashboard.

Security

We protect your data with encryption in transit (HTTPS), hashed passwords, access controls, and an audit log. No system is perfectly secure, but we work to protect your data and will notify you of a breach where required by law.

Children

The Service is intended for business use and is not directed to children under 16.

Cookies

We use only essential cookies required to sign you in and keep you signed in. See our Cookie Policy for details.

Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above and, where appropriate, by notifying you.