Legal

Privacy Policy

Last updated: May 2026 · Effective immediately
✓ GDPR native by architecture — your data never leaves your devices

1. Who We Are

Compudenser ("we", "our", "the company") operates the browser-native P2P compute platform available at compudenser.eu. We are incorporated in the European Union and subject to EU data protection law including the General Data Protection Regulation (GDPR) and the EU Data Act 2025.

2. Our Core Privacy Principle

Compudenser is GDPR-native by architecture. When you use our P2P compute mesh, your data travels directly between the devices in your mesh via encrypted WebRTC connections. We do not see it, we do not store it, and we do not transfer it to any server. Architectural compliance is not a policy — it is how the system is built.

3. Data We Collect

We collect minimal data required to operate the service:

What we never collect: the content of your compute sessions, files, AI model inputs/outputs, or any data transmitted between devices in your mesh.

4. Legal Basis for Processing (GDPR Art. 6)

5. Data Location

All account and metadata is stored on servers located within the European Union. We do not transfer personal data to third countries. The P2P mesh data stays on your devices — it is never routed through our infrastructure.

We are fully compliant with Schrems II requirements. No data transfer agreements with US entities are required because no data leaves the EU.

6. Data Retention

7. Your Rights Under GDPR

You have the following rights regarding your personal data:

To exercise any of these rights, contact us at the address below. We respond within 30 days as required by GDPR.

8. Cookies

We use strictly necessary cookies for session management and authentication. We do not use advertising cookies, third-party tracking, or fingerprinting. Analytics, if used, are privacy-preserving and EU-hosted (no Google Analytics).

9. Third-Party Services

10. Security

All connections use TLS 1.3. P2P mesh connections use DTLS-SRTP (WebRTC standard). Account passwords are hashed using bcrypt. We conduct regular security reviews. In the event of a breach affecting personal data, we notify affected users and the relevant supervisory authority within 72 hours as required by GDPR Art. 33.

11. Children

Our service is not directed at children under 16. We do not knowingly collect data from children. If you believe we have inadvertently collected data from a minor, contact us immediately for deletion.

12. Changes to This Policy

We will notify registered users by email of material changes at least 30 days before they take effect. The latest version is always available at this URL.

13. Supervisory Authority

If you believe we have violated your data protection rights, you have the right to lodge a complaint with your national supervisory authority. For EU residents, a list of authorities is available at edpb.europa.eu.

Contact — Data Protection

Email: privacy@compudenser.eu
Data Protection Officer: Abdullah Yerebakan
Company: Compudenser · European Union

For GDPR rights requests, include your email address and the specific right you wish to exercise. We respond within 30 days.