EU GDPR & Compliance Standard

GDPR & Enterprise Data Privacy Architecture

MiniJudge is engineered from the ground up to eliminate third-party data processor risks. Learn how our browser-first execution ensures full compliance with EU Regulation 2016/679.

The Privacy-by-Design Paradigm (Article 25)

Under GDPR Article 25 (Data Protection by Design and by Default), organizations must implement appropriate technical and organizational measures. MiniJudge satisfies this requirement by ensuring that your raw customer datasets, CRM exports, and invoice records are processed locally inside your browser memory via client-side Web Workers, never persisting on our servers.

1. Data Controller vs. Data Processor Role

When using MiniJudge to analyze customer lists or employee datasets, you remain the sole Data Controller. Because MiniJudge does not retain, index, train on, or monetize your uploaded spreadsheets, no permanent data processing storage agreement is created.

Client-Side Sandbox

Papa Parse runs within your browser heap. 100% of unselected columns remain in local RAM and are released immediately upon tab closure.

Zero LLM Model Training

Your spreadsheets are never sent to public LLMs for continuous training. System 1 executes deterministic rule trees compiled in ephemeral runtime.

2. Technical & Organizational Measures (Article 32)

  • TLS 1.3 Transport Encryption: Any ephemeral metadata transmission uses strict cryptographic handshakes with perfect forward secrecy.
  • CWE-1236 Injection Sanitization: Pre-export neutralization prevents malicious spreadsheet formulas from executing on client machines.
  • Zero Cross-Border Transfers: No personal identifiable information (PII) is transferred to third-party data brokers or scraping networks.

3. Authorized Subprocessors

To deliver the service, MiniJudge interacts exclusively with the following certified infrastructure providers:

SubprocessorRoleData HandledCompliance
Vercel Inc.Edge Cloud HostingStatic Assets & ProxySOC 2, ISO 27001
Stripe Payments EuropePayment ProcessingBilling & Card DetailsPCI-DSS Level 1
Supabase Inc.Lead Storage (Opt-In)User Email (if provided)SOC 2 Type II, GDPR

Data Protection Inquiries

If your enterprise requires a custom Data Processing Addendum (DPA) or security audit report, reach out directly to our compliance team at privacy@prodesigner.io.