ObjectBasin

Privacy policy

Last updated: 1 September 2026 · ObjectBasin GmbH, Frankfurt am Main

1. What we process

Account data (name, work email, company, billing address), operational data (API request logs, byte and request counters, caller IP addresses) and support correspondence. Stored objects are processed on your instruction: we act as a processor, you as the controller.

2. Why

To deliver the Service, meter usage, issue invoices, secure the platform against abuse and answer support requests. Legal bases are contract performance and our legitimate interest in operating a secure service.

3. Retention

Request logs 30 days; aggregated usage counters 24 months; invoices as required by German tax law (10 years); support tickets 36 months.

4. Sub-processors

We use colocation and network providers inside the EU for compute, storage and transit. A current sub-processor list, including purpose and location, is available from legal@objectbasin.com and is updated 30 days before any change.

5. International transfers

Data is stored in the region you choose. Transfers outside the EEA happen only for the us-east region, under standard contractual clauses.

6. Your rights

You may request access, correction, export, restriction or deletion of account data, and object to processing based on legitimate interest. Object data belongs to you and can be exported at any time over the API.

7. Security

Encryption in transit for all endpoints, encryption at rest on every storage node, per-bucket keys, least-privilege internal access with audit logging, and annual penetration testing.

8. Contact

Data protection enquiries: privacy@objectbasin.com