This is a skeleton, not a policy. Replace this body with the text counsel drafts, then set
reviewed: true— that is what removes the notice and the noindex.Scope note: this policy covers this website only. How client data is handled inside the product belongs in the DPA, not here.
Background:
docs/legal-brief.md§10, which records what the site actually does — measured, not assumed.
1. Who we are
Controller identity: company name, IČO, registered address, contact e-mail.
2. What we collect
Measured on the live build:
- An e-mail address, when submitted through a “Get early access” form.
- Server logs from the hosting provider, in the ordinary course of serving the site.
- A theme preference stored in the browser’s localStorage under
trackin-theme. Functional only — it records light or dark mode and is never sent to us.
No cookies are set. There is no analytics, no tag manager, and no third-party embed. The site makes no third-party requests at all.
3. Why, and on what legal basis
E-mail addresses: to respond to an early-access enquiry. Legitimate interest or pre-contractual steps — counsel to confirm which.
4. How long we keep it
5. Who else sees it
Hosting provider (Cloudflare Pages) and the form endpoint, once one is configured. Name them and state where they process data.
6. International transfers
Address whether any processor places data outside the EEA, and on what basis.
7. Your rights
Access, rectification, erasure, restriction, portability, objection. How to exercise them, and the right to complain to the Úřad pro ochranu osobních údajů.
8. Cookies
As the site stands there is nothing to consent to: no cookies, and the single localStorage entry is strictly functional. This section must be revisited the moment any analytics or marketing tool is added — that would require a consent banner.