GDPR & Enterprise Data Privacy Architecture
MiniJudge is engineered from the ground up to eliminate third-party data processor risks. Learn how our browser-first execution ensures full compliance with EU Regulation 2016/679.
The Privacy-by-Design Paradigm (Article 25)
Under GDPR Article 25 (Data Protection by Design and by Default), organizations must implement appropriate technical and organizational measures. MiniJudge satisfies this requirement by ensuring that your raw customer datasets, CRM exports, and invoice records are processed locally inside your browser memory via client-side Web Workers, never persisting on our servers.
1. Data Controller vs. Data Processor Role
When using MiniJudge to analyze customer lists or employee datasets, you remain the sole Data Controller. Because MiniJudge does not retain, index, train on, or monetize your uploaded spreadsheets, no permanent data processing storage agreement is created.
Papa Parse runs within your browser heap. 100% of unselected columns remain in local RAM and are released immediately upon tab closure.
Your spreadsheets are never sent to public LLMs for continuous training. System 1 executes deterministic rule trees compiled in ephemeral runtime.
2. Technical & Organizational Measures (Article 32)
- TLS 1.3 Transport Encryption: Any ephemeral metadata transmission uses strict cryptographic handshakes with perfect forward secrecy.
- CWE-1236 Injection Sanitization: Pre-export neutralization prevents malicious spreadsheet formulas from executing on client machines.
- Zero Cross-Border Transfers: No personal identifiable information (PII) is transferred to third-party data brokers or scraping networks.
3. Authorized Subprocessors
To deliver the service, MiniJudge interacts exclusively with the following certified infrastructure providers:
| Subprocessor | Role | Data Handled | Compliance |
|---|---|---|---|
| Vercel Inc. | Edge Cloud Hosting | Static Assets & Proxy | SOC 2, ISO 27001 |
| Stripe Payments Europe | Payment Processing | Billing & Card Details | PCI-DSS Level 1 |
| Supabase Inc. | Lead Storage (Opt-In) | User Email (if provided) | SOC 2 Type II, GDPR |
Data Protection Inquiries
If your enterprise requires a custom Data Processing Addendum (DPA) or security audit report, reach out directly to our compliance team at privacy@prodesigner.io.