GDPR 数据保护
英文原文 · Data protection under the GDPR
最后更新:2026年9月
目录共 14 节收起
- Our approach to data protection
- Data controller information
- What personal data we process
- Legal basis for processing
- Your rights under the GDPR
- Data processing activities
- Sub-processors
- International data transfers
- Data breach notification
- Data protection by design and default
- Automated decision-making
- Children’s data
- How to exercise your rights
- Updates to this policy
Our approach to data protection
This page explains the personal data ko.io processes, the purposes and legal bases for processing, and how to exercise your data-protection rights. Read it alongside the Privacy policy.
Data controller information
What personal data we process
We process the following categories of personal data when you use ko.io:
- Account data
Email address, display name, and hashed password (for email/password accounts). We never store passwords in plain text.
- Authentication data
JWT session tokens and Google OAuth tokens (for users who sign in with Google). Tokens are short-lived and automatically expire after 24 hours.
- API usage data
Request logs including endpoints accessed, timestamps, IP addresses, response codes, and daily usage counts tied to API keys.
- Payment data
Payment processing is handled entirely by Stripe. We do not store credit card numbers or bank details. We retain only your subscription status, plan type, and Stripe customer ID.
- Technical data
Browser user-agent string and device type, collected automatically from HTTP headers during requests to our services.
- Feedback data
When you send feedback: the message, selected category, related page URL and any screenshot you attach, processed so we can review the issue and track its status.
Legal basis for processing
We process personal data under the following legal bases as defined in Article 6(1) of the GDPR:
- Performance of contract — Art. 6(1)(b)
Providing the API service, managing your account, generating and validating API keys, processing subscription billing, and delivering the services you have signed up for.
- Legitimate interest — Art. 6(1)(f)
Security monitoring and abuse prevention, API rate limiting and quota enforcement, fraud detection, service reliability monitoring, and improving the performance and functionality of our platform. We have conducted balancing tests to ensure our interests do not override your fundamental rights.
- Consent — Art. 6(1)(a)
Marketing emails and promotional communications are sent only with your explicit opt-in consent. You can withdraw consent at any time without affecting the lawfulness of processing based on consent before withdrawal.
- Legal obligation — Art. 6(1)(c)
Retention of payment and transaction records as required by Swedish bookkeeping law (Bokfoeringslagen) and applicable EU tax regulations.
Your rights under the GDPR
As a data subject, you have the following rights under the GDPR. We are committed to facilitating the exercise of these rights promptly and free of charge.
- Right of access — Art. 15
You may request a full copy of all personal data we hold about you. We will provide this free of charge within 30 days of your request, in a commonly used electronic format.
- Right to rectification — Art. 16
You can correct inaccurate or incomplete personal data at any time through your account settings, or by contacting us at admin@ko.io.
- Right to erasure — Art. 17
You have the right to be forgotten. Account deletion removes all personal data within 30 days. Certain data may be retained longer where required by law — specifically, payment records are retained for 7 years in accordance with Swedish bookkeeping law.
- Right to data portability — Art. 20
To request your personal data in a machine-readable format, email admin@ko.io. We will explain the available scope and format for your request.
- Right to restrict processing — Art. 18
You may request that we limit how we process your data while maintaining your account. For example, you can request that we stop processing your data for analytics purposes while continuing to provide the core API service.
- Right to object — Art. 21
You may object to processing based on our legitimate interest. Upon receiving your objection, we will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
- Right to withdraw consent — Art. 7(3)
Where processing is based on consent (such as marketing emails), you may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal and has no impact on your access to the service.
- Right to lodge a complaint
You have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) at imy.se.
Data processing activities
The following table summarizes our data processing activities, the categories of data involved, the legal basis, and the retention period for each purpose.
| Purpose | Data categories | Legal basis | Retention |
|---|---|---|---|
| Account management | Email, name, password hash | Contract | Until deletion + 30 days |
| API service delivery | API keys, usage logs | Contract | Active period + 90 days |
| Billing | Stripe customer ID, plan info | Contract + Legal obligation | Active + 7 years |
| Security & abuse prevention | IP addresses, request patterns | Legitimate interest | 90 days |
| Service improvement | Anonymized usage analytics | Legitimate interest | Indefinite (anonymous) |
Sub-processors
We engage the following third-party sub-processors to deliver our services. Each has been vetted for GDPR compliance, and appropriate safeguards are in place for international transfers.
- Cloudflare Inc. — United States
CDN, edge compute, D1 database (user accounts and API keys), KV storage (caching), and Pages (static site hosting). EU-US Data Privacy Framework certified. Standard Contractual Clauses (SCCs) in place.
- Stripe Inc. — United States
Payment processing for API subscriptions. PCI DSS Level 1 certified. Standard Contractual Clauses (SCCs) in place. Stripe processes payment card data directly and ko.io never receives or stores card details.
- Oracle Corporation — United States / EU
Cloud infrastructure hosting our API servers and databases. Primary processing occurs in the European Union. A secondary replica operates in Asia-Pacific for API latency optimization.
- Google LLC — United States
OAuth authentication provider, used only when you choose to sign in with Google. We receive only your email address and display name. Standard Contractual Clauses (SCCs) in place.
International data transfers
- Primary processing: European Union (EU/EEA)
- Secondary processing: Asia-Pacific (API latency optimization)
- Transfer mechanisms: Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR for all transfers to countries outside the EEA that lack an adequacy decision
- Cloudflare: EU-US Data Privacy Framework certified, with SCCs as supplementary safeguard
We ensure that all personal data transferred outside the European Economic Area receives an adequate level of protection through appropriate contractual and technical safeguards.
Data breach notification
We maintain comprehensive incident response procedures to detect, investigate, and respond to personal data breaches.
- The supervisory authority (IMY) will be notified within 72 hours of discovering a breach that is likely to result in a risk to individuals' rights and freedoms, as required by Art. 33.
- Affected users will be notified without undue delay if the breach is likely to result in a high risk to their rights and freedoms, as required by Art. 34.
- We maintain a record of all personal data breaches, including the facts, effects, and remedial actions taken, in accordance with Art. 33(5).
Data protection by design and default
We embed data protection principles into every aspect of our platform:
- Minimal data collection — we only collect personal data that is strictly necessary for providing the service.
- Password hashing and transport encryption — passwords are hashed using PBKDF2-SHA-512 with 100,000 iterations. All data in transit is encrypted via TLS.
- No tracking cookies — we do not use tracking cookies or advertising trackers. Website analytics is Cloudflare Web Analytics, which is cookieless and reports aggregate page views only.
- Key management — create replacement API keys and revoke existing keys in Console → API keys.
- Self-service deletion — account deletion is available through your settings and results in permanent removal of all personal data, subject to legal retention requirements.
Automated decision-making
- API rate limiting is applied automatically based on your subscription plan tier. This is a technical measure and does not involve profiling or decisions with legal effects.
- We do not engage in automated decision-making that produces legal effects or similarly significant effects on data subjects as described in Art. 22.
- Automated abuse detection may temporarily restrict API access if anomalous patterns are detected. If your access is restricted, you can appeal by contacting admin@ko.io, and a human review will be conducted promptly.
Children’s data
Our services are intended for users aged 18 and older, particularly software developers and financial professionals. We do not knowingly collect or process personal data from children. If we become aware that we have inadvertently collected data from a child under 18, we will delete it immediately and terminate the associated account.
How to exercise your rights
- Self-service: Update your display name or delete your account in Settings. Email admin@ko.io for a copy of your personal data or other data-rights requests.
- Email: Send your request to admin@ko.io. Please include sufficient detail so we can identify your account and understand your request.
- Response time: We will respond within 30 days. For particularly complex requests, this may be extended by up to 60 additional days, in which case we will notify you of the extension and the reasons for the delay.
- Identity verification: We may need to verify your identity before processing your request to protect against unauthorized access to personal data.
- No fee: Standard requests are processed free of charge. We reserve the right to charge a reasonable fee for manifestly unfounded or excessive requests.
- Supervisory authority: your local data protection authority. imy.se
Updates to this policy
- Material changes:We will provide at least 30 days' advance notice via email before material changes take effect.
- Non-material changes:Updates will be reflected on this page with a revised “Last updated” date.
- Previous versions: Prior versions of this policy are available upon request by contacting admin@ko.io.