GDPR Compliance
HEIC.dev GDPR compliance information. Learn about your rights and how we handle data in compliance with EU regulations.
General Data Protection Regulation (GDPR)
The GDPR is a regulation in EU law on data protection and privacy for all individuals within the European Union and the European Economic Area. HEIC.dev is designed with full compliance as a core technical requirement.
Data Processing Role
Under GDPR definitions, HEIC.dev acts as a facilitator for data processing. However, because all processing occurs on the user's local hardware (Client-Side), we do not act as a traditional "Data Processor" as defined in Art. 4(8) GDPR, because we never gain possession of or access to your personal image data.
Compliance Through "Privacy by Design"
We fulfill our obligations under Article 25 (Privacy by Design and by Default) through our technical architecture:
- Data Minimization: We do not collect, store, or transmit your images.
- Purpose Limitation: The only data processing that occurs is the specific conversion or view action initiated by you.
- Storage Limitation: Your image data exists in volatile memory only for the duration of the conversion task.
Data Subject Rights
As an EU citizen, you have rights regarding your personal data. Because our service does not store your data, our fulfillment of these rights is as follows:
- Right of Access & Portability: Since we do not have your data, we cannot provide an export. You already possess the data on your device.
- Right to Erasure (Right to be Forgotten): Your data is automatically "erased" from our system's memory as soon as you close the browser tab.
- Right to Rectification: You maintain full control over your files on your local machine.
Sub-processors
We utilize minimal third-party sub-processors for site infrastructure and advertising:
- Hosting: For serving the website files (not for processing data).
- Google AdSense: For monetizing the free service (subject to your consent).
- Google Analytics: For anonymous usage statistics.
If you have specific GDPR-related inquiries or require a Data Processing Agreement (DPA) for enterprise use, please contact us at: [email protected]