Privacy Policy

Your data.
Your rights.

We collect what we need to run Sucesio — nothing more. Here is exactly what we do with it, in plain language.

Effective: 1 January 2026 — Last updated: April 2026

30-second summary
01
Data Controller

The data controller for personal data processed through sucesio.io and app.sucesio.io is Sucesio (legal entity to be confirmed upon incorporation). Contact: hello@sucesio.io

Data Protection Officer (DPO): hello@sucesio.io — subject line: "DPO Request"

02
Data Collected

We collect only strictly necessary data. Here is the complete breakdown:

Category Data Purpose Legal basis
Account Name, email, country, language Account creation & management Art. 6(1)(b) — Contract
Succession profile Asset inventory, heir designations, instructions Core service delivery Art. 6(1)(b) — Contract
Sensitive succession data Crypto wallet locations, account details, personal messages User-initiated sensitive storage Art. 6(1)(a) — Explicit consent
Check-in data Check-in timestamps, anonymised device signal Check-in mechanism operation Art. 6(1)(b) — Contract
Payment Billing name, country, payment token (Stripe) Subscription billing Art. 6(1)(b) — Contract
Support Email correspondence, issue logs Customer support Art. 6(1)(f) — Legitimate interest
Analytics Anonymised session data (Umami — no personal data) Product improvement Art. 6(1)(f) — No consent needed
03
Data Security

Succession data is among the most sensitive personal information that exists. We treat it accordingly:

  • AES-256 encryption at rest for all data
  • TLS 1.3 encryption in transit
  • Access controls — sensitive fields are accessible only to authorised Sucesio personnel where strictly necessary for support
  • EU hosting only — Frankfurt, Germany (Supabase EU-West-1)
  • Principle of least privilege — staff access restricted to what is needed for support
  • 72-hour breach notification to the competent DPA (GDPR Art. 33); user notification if high risk (Art. 34)

For full technical details: Security page →

04
Sub-Processors

We work with three sub-processors only. All operate under GDPR-compliant Data Processing Agreements:

Sub-Processor Role Location GDPR safeguard
SupabaseDatabase — all user dataEU (Frankfurt, DE)EU DPA / SCCs
ResendTransactional emailsEU regionEU DPA
StripePayment processingEU (Ireland)EU DPA / BCR

No data is transferred to third parties for advertising, marketing, or commercial purposes. Ever.

05
Posthumous Data

Sucesio is designed to operate after your death. This section explains exactly how your data is handled in that situation.

Jurisdiction-specific rules

France (Loi pour une République Numérique, 2016): You may designate a "digital executor" (mandataire numérique) who can exercise your data rights after your death. Sucesio supports this through the designated contact feature. Absent instructions, your heirs may exercise data access and deletion rights.

Spain (LOPDGDD 2018, Art. 3): Your heirs and designated persons may request access to, rectification of, or deletion of your data after your death. We will verify the identity and standing of requestors before granting access.

Other jurisdictions: We will respond to requests from persons who can demonstrate a legitimate legal interest (executor, legal heir) in accessing a deceased user's data, subject to documentation requirements.

Upon receiving a confirmed death notification with supporting documentation:

  • The account is frozen (no new logins)
  • Designated contacts receive access per your stored instructions
  • A 12-month data hold period begins
  • All data is permanently deleted after 12 months unless subject to legal hold
06
Your Rights

Under the GDPR (Arts. 15–22) or UK GDPR, you have:

👁️
Right of access
Obtain a copy of all personal data we hold about you.
✏️
Right to rectification
Correct any inaccurate or incomplete data about you.
🗑️
Right to erasure
Request permanent deletion of all your data. We delete within 30 days.
⏸️
Right to restriction
Restrict processing of your data in certain circumstances.
📦
Right to portability
Receive your data in a structured, machine-readable format.
🚫
Right to object
Object to processing based on legitimate interest at any time.

To exercise any right: email us. We respond within 30 days (extendable to 60 for complex requests, with notice).

✉️ hello@sucesio.io

You also have the right to lodge a complaint with your local DPA:

🇫🇷 CNIL (France) 🇪🇸 AEPD (España) 🇧🇪 APD/GBA (Belgique) 🇳🇱 AP (Netherlands) 🇱🇺 CNPD (Luxembourg) 🇬🇧 ICO (United Kingdom) 🇮🇪 DPC (Ireland) 🇸🇪 IMY (Sverige) 🇩🇰 Datatilsynet (DK) 🇳🇴 Datatilsynet (NO) 🇫🇮 Tietosuoja (FI)
07
Data Retention
Data categoryRetention period
Account & succession data (active)Until deletion + 90 days
Account data (terminated)90 days post-termination, then deleted
Billing records10 years (legal requirement)
Deceased user accounts12 months post confirmed death, then deleted
Support correspondence3 years from last interaction
Security & audit logs24 months
08
Cookies

Sucesio uses only strictly necessary cookies and cookieless analytics. No advertising or tracking:

09
Changes to this Policy

We may update this Privacy Policy. For any substantial change, you will be notified by email at least 30 days before it takes effect.

The date of last update is shown at the top of this page. Questions? hello@sucesio.io

Book a call