Data Protection
Privacy & Cookie Policy
Processing transparency, purposes, retention periods, and individual rights (GDPR).
1. General Principles & Account-Free Browsing
In accordance with the GDPR (Regulation EU 2016/679), browsing rgpd.click requires neither user account creation nor personal registration.
Functional preferences (theme, language, flashcard progress) are stored strictly locally in your browser (localStorage) without external transmission.
3. AI Legal Assistant (AI Act Art. 50 & GDPR)
The platform offers an interactive documentary assistant (Lexi).
- Purpose: Methodological guidance and documentary retrieval on the GDPR.
- Legal basis: Prior and freely given consent (Art. 6.1.a GDPR) granted via the CMP or upon your first interaction with Lexi.
- Confidentiality: Server-side scrubbing of common identifiers (email addresses, phone numbers). Prompts are routed primarily to Groq with Zero Data Retention enabled at the organization level; OpenRouter may act as a fallback with data collection strictly denied (
data_collection: deny).
- Nature: Purely educational answers that do not constitute individualized legal advice or counsel.
4. Cookies & Third-Party Services
Optional third-party services are subject to your prior consent via our Consent Management Platform (CMP).
| Category | Purpose | Provider | Retention | Legal Basis |
| Necessary |
Preferences (consent, theme, learning progress). |
rgpd.click (local) |
6 months |
Legitimate Interest |
| AI Assistant |
Processing documentation queries. |
Groq (ZDR enabled); OpenRouter fallback as necessary |
Session |
Consent |
| Analytics |
Aggregated usage statistics. |
Google Analytics / Contentsquare |
Up to 13 months max |
Consent |
| Translation |
Multilingual translation module. |
Google Translate |
Session / third-party cookies per Google configuration |
Consent |
| Monetization |
Hosting support advertisements. |
Google AdSense |
Up to 13 months max |
Consent |
5. CSP Security Telemetry (Content Security Policy)
To guarantee application security and platform integrity, rgpd.click implements a technical security violation reporting mechanism (Content-Security-Policy-Report-Only).
- Purpose: Technical detection of loading failures, script injection attempts, and monitoring CSP rule compliance.
- Data minimization (Privacy-by-Design): Only strictly technical parameters are captured (directive name, blocked host, relative page URL).
- Redaction & scrubbing: URLs are automatically stripped of query strings, tokens, identifiers, and hash fragments.
- IP Addresses: IP addresses are handled transiently in memory for salted rate limiting and are never written to persistent application logs.
- Retention: Rolling 7-day maximum retention, with automated daily log deletion.
- Legal basis: Legitimate interest in cybersecurity and IT infrastructure protection (Art. 6.1.f GDPR).
- Separation: This application telemetry is distinct from hosting infrastructure-level web server access logs.
6. International Data Transfers outside the EEA
Certain optional features activated only upon your explicit consent (AI assistant, analytics, translation, ads) may entail data processing outside the European Economic Area (EEA).
- Legal Framework: All transfers outside the EEA comply strictly with Chapter V of the GDPR (Articles 44 to 50).
- Applicable Safeguards: Safeguards depend on the provider: European Commission adequacy decisions, EU-US Data Privacy Framework (for certified US recipients), and/or Standard Contractual Clauses (SCCs).
- Verification: No specific contractual guarantee is asserted without validation; mechanisms remain subject to provider compliance and updates.
- Supplementary Measures: Technical safeguards (such as pre-flight data scrubbing of emails and phone numbers) are enforced before transmission.
7. Exercising Your Rights
Under the GDPR, you have the right to access, rectify, erase, restrict, and object to the processing of your personal data. To exercise these rights, contact: matsetop@rgpd.click. For general questions: contact@rgpd.click.
You also have the right to lodge a complaint with the Belgian Data Protection Authority: Rue de la Presse 35 / Drukpersstraat 35, 1000 Brussels (dataprotectionauthority.be).