Privacy notice for this website, the waitlist and the contact form
Version of 5 October 2026 (revision 4). Applies to this website, the waitlist form and the contact form only, not to any future product.
1. Controller
PPFTEC S.R.L. (limited liability company under Romanian law), Str. Patriarh Iustinian Marina nr. 17-19B, bl. DC12, mansardă, ap. 25, 240469 Râmnicu Vâlcea, jud. Vâlcea, Romania. Trade Register (ONRC) no. J2026052999008, EUID ROONRC.J2026052999008, fiscal code (CUI) 55537142, VAT ID RO55537142. Represented by its administrator (managing director) Petre Popa. Contact for all privacy requests: [email protected], the contact form, or by post to the address above.
2. Data protection officer
We have not appointed a data protection officer because we are not required to: we are not a public body, and our core activities do not consist of large-scale, regular and systematic monitoring of people or large-scale processing of special categories of data (Article 37(1) GDPR). Please send privacy questions to [email protected].
3. What we process, why, and on which legal basis
| Data | Purpose | Legal basis (GDPR) |
|---|---|---|
| Connection data when you open a page: IP address, time, requested address, browser type (user agent) | Deliver the pages and protect the site against attacks (hosting by Cloudflare, see section 5). We do not keep access logs ourselves. | Art. 6(1)(f); our legitimate interest is a working, secure website |
| E-mail address, role, countries and the Stripe question (both optional), page language | Send the confirmation e-mail (double opt-in), keep the waitlist, send you updates about this product and, if you signed up from 5 October 2026, occasional requests for feedback (for example an invitation to a short call) | Art. 6(1)(a) consent |
| Proof of consent: time of sign-up, version of the consent text and of this notice, time of the confirmation click | Demonstrate that you consented (Art. 7(1) GDPR) | Art. 6(1)(c) with Art. 7(1) |
| Delivery state: one-time links (stored only as a cryptographic hash), number and time of confirmation e-mails | Make the confirmation and removal links work; limit repeated e-mails to the same address | Art. 6(1)(f); our legitimate interest is preventing misuse of the form against you or us |
| Bot check (Cloudflare Turnstile) on the waitlist and contact forms: Cloudflare processes your IP address, a TLS fingerprint, your browser's user agent and the page on which the check runs. We only receive whether the check passed. | Protect the form against automated abuse (fake sign-ups, e-mails to people who did not ask for them) | Art. 6(1)(f); our legitimate interest is keeping bots out of the waitlist and the contact form |
| Contact form: your name, e-mail address and message, page language, time of receipt, version of this notice | Answer your request by e-mail. The message is stored in our database and forwarded once as an e-mail to our mailbox [email protected] (see section 5, "Our mailbox"). We limit how many messages one address can send per day. | Art. 6(1)(b) where your request concerns a possible contract with us (for example the product or the waitlist); otherwise Art. 6(1)(f), our legitimate interest is answering the questions people send us |
| Counts only: daily counters of form events (for example "sign-ups per day, by page language and role") and totals of confirmed entries by role, language and the Stripe answer | Understand whether the waitlist works and who is interested | Art. 6(1)(f); our legitimate interest is evaluating demand for the product. The counts contain no e-mail address, IP address or other identifier. |
We do not store your IP address or your browser details. We store your name only if you give it in the contact form. Giving us data is neither a legal nor a contractual requirement; without an e-mail address and your consent we simply cannot put you on the waitlist, and without a name, e-mail address and message we cannot answer a contact request. We do not make decisions about you by automated means, including profiling (Article 22 GDPR).
Your consent covers only what the consent text on the form said when you signed up; we record which text that was. If you signed up before 5 October 2026, that text did not mention feedback requests, so we will not send you any unless you agree again.
4. Double opt-in
After you submit the form we send one e-mail with a confirmation link that works for 48 hours. You are only on the waitlist after you confirm. Sign-ups made before our confirmation e-mail was set up (until 4 October 2026) were stored as unconfirmed, and we said so on screen; they receive no e-mail unless you submit the form again. Unconfirmed entries expire after the periods in section 6 and are then deleted without our contacting you.
5. Recipients, processors and transfers outside the EU
Cloudflare. Hosting, form handling, bot check and database are provided by Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA, as our processor. Cloudflare's Data Processing Addendum (version 6.4, effective 3 April 2026) is part of our contract with Cloudflare. The waitlist database is a Cloudflare D1 database with EU jurisdiction, so the stored entries stay in the EU. Pages and the bot check are served from Cloudflare's worldwide network, and Cloudflare, Inc. is a US company, so connection data may be processed outside the EU/EEA. For transfers to the United States, Cloudflare is certified under the EU-U.S. Data Privacy Framework, which is covered by the European Commission's adequacy decision (EU) 2023/1795; as a fallback, the Data Processing Addendum contains the EU Standard Contractual Clauses (module 2). Cloudflare lists its sub-processors at cloudflare.com/gdpr/subprocessors. You can ask us for a copy of these safeguards at the contact address above.
Cloudflare as its own controller for Turnstile. According to Cloudflare's Turnstile Privacy Addendum (last updated 18 June 2025), Cloudflare also uses the bot-check signals as an independent controller to improve its bot detection. That use is Cloudflare's responsibility; its privacy policy applies. By embedding the bot check we make it possible for Cloudflare to collect these signals; our legal basis for that is Art. 6(1)(f), as in section 3.
E-mail delivery. We send the confirmation e-mail and the contact-form notification with Cloudflare Email Service, from the address [email protected]. Cloudflare, Inc. acts as our processor under the same Data Processing Addendum and transfer safeguards as above. Cloudflare receives the recipient address and the content of the e-mail in order to deliver it.
Our mailbox. E-mails to [email protected], including contact-form notifications and your replies to our e-mails, are forwarded by Cloudflare Email Routing to a Google (Gmail) mailbox of PPFTEC, where we read and answer them. Google provides this mailbox under its own terms, not under a data processing agreement with us, so for the e-mails stored there Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, is an independent controller and Google's privacy policy applies. Google may process the e-mails in the United States; Google LLC is certified under the EU-U.S. Data Privacy Framework (adequacy decision (EU) 2023/1795). Our legal basis for using this mailbox is Art. 6(1)(f); our legitimate interest is receiving and answering the messages people send us. If you do not want your message to reach this mailbox, write to us by post instead.
We do not sell your data or share it with anyone else.
6. How long we keep the data
- Unconfirmed entries: 7 days after sign-up when a confirmation e-mail was sent; 30 days after sign-up while no confirmation e-mail can be sent (see section 4).
- Confirmed entries, including the proof of consent: until you withdraw consent, and at the latest 12 months after the last e-mail we sent you (or after your confirmation, if we have not written since).
- When you remove your address (removal link or e-mail to us), we delete the entry and its links immediately.
- Expired entries are deleted by an automatic clean-up that runs once a day and whenever the waitlist form is used, so deletion can take up to one day longer than the periods above.
- Contact messages: deleted from our database 6 months after receipt by the same daily clean-up. If forwarding to our mailbox fails, the message is deleted at once and you see an error. We delete the copy in our mailbox once your request is settled, at the latest 6 months after receipt, unless we need it longer for a contract with you or to establish, exercise or defend legal claims.
- Counters of sending, sign-up and contact limits: deleted after 7 days. Daily event counters contain no personal data and are kept.
- Bot-check data: we keep nothing. Cloudflare's own retention is governed by its terms.
7. Your rights
You have the right to access your data, to have it corrected or erased, to restrict its processing and to receive it in a portable format (Articles 15 to 18 and 20 GDPR). You can withdraw your consent at any time with effect for the future, by e-mail to [email protected] or with the removal link in every e-mail we send; withdrawal does not affect processing that happened before it (Article 7(3) GDPR).
Right to object (Article 21 GDPR): where we rely on legitimate interests (Article 6(1)(f)), you can object at any time, on grounds relating to your particular situation, by e-mail to [email protected].
You can complain to a supervisory authority. The authority competent for us is the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral Gheorghe Magheru 28-30, sector 1, 010336 Bucharest, Romania, dataprotection.ro. You can also complain to the authority in the EU country where you live or work or where the alleged infringement took place (Article 77 GDPR); the European Data Protection Board lists all national authorities.
8. Cookies and your device
This site sets no cookies of its own and uses no analytics or tracking scripts. The only third-party script is Cloudflare Turnstile. It is not loaded when you open a page: our own script loads it only when you start using the waitlist form or the contact form (when a form field receives focus or input). It runs in a frame from challenges.cloudflare.com and reads technical characteristics of your browser to tell people from bots. Reading such information from your device is covered by Article 5(3) of the ePrivacy Directive (in Germany § 25 TDDDG, in Romania Law 506/2004). Cloudflare states that Turnstile does not use cookies to collect or store information, and in our configuration (no "pre-clearance") the widget only issues a one-time token that is sent with the form. We do not ask for consent for the bot check because it is strictly necessary to provide the forms you choose to use securely, without fake sign-ups and e-mails to people who did not ask for them (§ 25(2) no. 2 TDDDG and the corresponding Romanian rule). If you do not want the bot check to run, do not fill in the forms; you can write to us at [email protected] instead.
9. Changes
If we change this notice, we publish the new version here with a new date. We record which version applied when you signed up, and we keep every earlier version.