Data protection & GDPR
Generect operates in line with the GDPR. Our public legal terms:- Privacy Policy — what we collect and why, including US state privacy rights
- Terms of Service
- Legal Notices and Cookie Policy
Data Processing Agreement (DPA)
A signed DPA is available for customers processing personal data through the API — request one at support@generect.com.Infrastructure & security practices
- Hosting: production systems run in EU data centers.
- In transit: all API traffic is encrypted over HTTPS/TLS.
- Payments: processed entirely by Stripe — card data never touches Generect servers.
- API keys: scoped per token; every key can be paused, renamed, or revoked instantly from your settings, and usage and transaction history are visible via the account endpoints.
- Billing transparency: every charge is itemized (
meta.amount_charged, transactions, invoices) — see Pricing.