GDPR
Last updated: 2026-03-12
This page summarizes how momentake implements GDPR principles in product, security, and support.
Controller and roles
momentake acts as controller for account and billing data. For media uploaded by users, the user sets the business purpose of processing and is responsible for the lawfulness of third-party data.
Lawful basis
Processing relies on contract performance, legal obligations, legitimate interests, and consent where applicable.
DSAR process
Users can create DSAR requests directly in Settings for data export and account erasure, with status tracking from submission to completion.
Retention and deletion
Data is retained only as necessary for service operation and legal requirements. Erasure removes or anonymizes personal data according to policy.
Security and incident response
We apply transport encryption, access control, security logging, and documented incident response procedures including escalation and notifications.
Subprocessors and transfers
Subprocessors and transfer safeguards are documented on the Subprocessors page and in project documentation.