GDPR Overview
Soonie comes with comprehensive GDPR (General Data Protection Regulation) compliance features built-in. These tools help you respect user privacy, obtain proper consent, and manage data subject rights according to EU privacy law.
Banner with accept/decline options and privacy policy link
Detailed modal with comprehensive information about data processing
Required checkbox for subscription with clear consent language
CSV and JSON export formats for data portability
Individual email deletion with GDPR confirmation
Clear information about data processing and retention
Legal Basis for Processing
Article 6(1)(a) - Consent
Soonie processes personal data based on explicit consent from data subjects:- What we collect: Email addresses for launch notifications
- Why we collect it: To send a single notification when your product launches
- Legal basis: Consent freely given by the user
- Retention period: Until launch notification is sent or upon user request for deletion
Cookie Consent Management
🍪 Cookie Banner Features
The cookie consent banner appears after 2 seconds and includes:
Configuration Options
Cookie Types Used
| Cookie | Purpose | Duration | Required |
|---|---|---|---|
theme |
Remember user's theme preference | 1 year | No |
cookieConsent |
Store consent choice | Permanent (localStorage) | Yes |
Email Collection Compliance
📧 Consent Requirements
Before email collection, users must:
- ✅ Check the consent checkbox explicitly
- ✅ Read the privacy policy (linked in checkbox text)
- ✅ Understand data usage through clear messaging
Consent Checkbox Text
Technical Implementation
Data Subject Rights Management
🗂️ User Rights Under GDPR
| Right | Article | Implementation |
|---|---|---|
| Article 15 | CSV and JSON export functions | |
| Right to Rectification | Article 16 | Delete and re-add with correct email |
| Right to Erasure | Article 17 | Individual email deletion in admin panel |
| Right to Data Portability | Article 20 | CSV and JSON export formats |
| Right to Withdraw Consent | Article 7 | Contact data controller or request deletion |
📤 Data Export Formats
CSV Export (Simple Format)
JSON Export (Complete GDPR Data)
GDPR Configuration Settings
⚙️ Basic GDPR Settings
Contact Information
Privacy Policy Modal
📜 Comprehensive Information
The privacy policy modal includes all required GDPR disclosures:
Data Collection Section
- What personal data we collect (email address)
- When we collect it (subscription signup)
- Why we collect it (launch notifications)
Data Usage Section
- How we use the data (single notification email)
- Who has access (no third-party sharing)
- Storage location (secure server storage)
User Rights Section
- Right to access personal data
- Right to rectification (correction)
- Right to erasure ("right to be forgotten")
- Right to withdraw consent
- Right to data portability
Data Protection Measures
1. File Protection
2. Input Validation
3. CSRF Protection
Organizational Measures
- Access Control: Admin panel password protection
- Data Minimization: Only collect necessary data (email)
- Purpose Limitation: Clear purpose stated (launch notifications)
- Storage Limitation: Option for automatic deletion
- Documentation: Complete audit trail of processing activities
International Compliance
🌍 Additional Privacy Laws
UK GDPR (UK DPA 2018)
- Same requirements as EU GDPR
- Covered by existing implementation
CCPA (California Consumer Privacy Act)
- Right to know: ✅ Privacy policy disclosure
- Right to delete: ✅ Admin panel deletion
- Right to opt-out: ✅ Consent withdrawal
Other Regional Laws
- PIPEDA (Canada): Consent and transparency ✅
- LGPD (Brazil): Data subject rights ✅
- PDPA (Singapore): Consent and purpose limitation ✅
Compliance Checklist
✅ Pre-Launch Checklist
- Admin password changed from default
- Privacy policy reviewed and updated
- Contact information added for data protection inquiries
- Cookie consent banner tested
- Email consent checkbox working
- Data export functions tested
- Email deletion feature tested
- HTTPS enabled for secure data transmission
- File permissions properly configured
- Records of processing documented
✅ Ongoing Compliance
- Regular backups of email data
- Monitor data requests and respond within 30 days
- Update privacy policy as needed
- Security patches applied promptly
- Staff training on data protection procedures
- Breach procedures documented and tested