Privacy Policy
In force since 25 August 2026
Dear User,
We make every effort to ensure the security and confidentiality of your personal data. We care about your privacy both when you visit our website and when you join the early access list or contact us by email. We act in accordance with the law, including Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (the “GDPR”).
In this document we want to give you the most important information about the processing of your personal data. For simplicity we have set it out as questions and answers. All so that you know for what purpose, on what basis and for how long we process your data, as well as who may have access to it and what rights you have.
How do we obtain your personal data?
When using the noteeva.com website (the “Website”) you may be asked to provide your personal data. Providing data is voluntary, but in certain situations it may prove necessary. For example, without an email address we cannot add you to the early access list or answer a question you send us by email.
When joining the early access list you provide an email address. Optionally you may add your name, team size, industry, areas of interest and a short description of the challenge you are facing. Optional fields can be skipped and the sign-up still works.
Some data is collected automatically during your visit to the Website (e.g. IP address, browser type, operating system). It serves to administer the site, provide hosting and measure how the Website is used. Until you submit the form westore nothing on your device — neither cookies nor any other data. We write more about this below, in the section on cookies.
Who is the Controller of your personal data?
The controller of your personal data is Marcin Garus, ul. Narutowicza 49 lok. 5, 90-130 Łódź, Poland.
If you have questions or doubts, you can contact us electronically at the following email address: welcome@noteeva.com, or by post at the address given above.
For what purpose, on what legal basis and for how long do we process your data?
We process your personal data for the purpose of:
- contacting you about the launch of Noteeva and sending information about early access (the early access list):
- the legal basis is your voluntary consent (Art. 6(1)(a) GDPR) and, for sending to your email address, the prior consent required by Art. 398(1) of the Polish Electronic Communications Law of 12 July 2024,
- the data will be processed until consent is withdrawn, whereby withdrawal does not affect the lawfulness of processing carried out before the withdrawal;
- protecting the form against automated sign-ups (bots) and ensuring the correct functioning of the Website:
- the legal basis is our legitimate interest (Art. 6(1)(f) GDPR) in protecting the Website against abuse and keeping it running,
- the data will be processed until the purpose of processing is achieved;
- analysing the activity of Website users, that is, statistics on the use of its individual parts:
- for anonymous measurement, which stores nothing on your device, the legal basis is our legitimate interest (Art. 6(1)(f) GDPR) in knowing which content genuinely helps interested people; LINKING those statistics to your email address happens only on the basis of separate, voluntary consent (Art. 6(1)(a) GDPR), ticked in the form and not required to sign up,
- the data will be processed until an effective objection is raised or the purpose of processing is achieved;
- answering questions addressed to us electronically:
- the legal basis is our legitimate interest (Art. 6(1)(f) GDPR) in communicating with people interested in our products and services,
- the data will be processed until the limitation periods for claims under applicable law expire;
- establishing, pursuing and defending possible claims:
- the legal basis is our legitimate interest (Art. 6(1)(f) GDPR) in taking action to protect our rights before courts and other state authorities,
- the data will be processed until the limitation periods for claims under applicable law expire;
- fulfilling obligations in the area of personal data protection:
- the legal basis is a legal obligation incumbent on us (Art. 6(1)(c) GDPR),
- the data will be processed until the limitation periods for claims arising from breaches of data protection law expire.
REMEMBER! We process personal data for as long as is necessary to achieve the purposes indicated above, unless you submit a valid and correct request for erasure of your personal data. The processing period may also depend on applicable law, e.g. on the limitation periods for claims. Early access list data is deleted at the latest when you unsubscribe from our communication — every message we send contains an unsubscribe link.
Who may be a recipient of your personal data?
In some situations, if it proves necessary to achieve the purposes of processing, we rely on the support and assistance of external entities. In every case, however, before transferring personal data we require its recipients to guarantee its appropriate protection and confidentiality.
The recipients of your personal data may be:
- providers of the tools we use to run the Website and the early access list: the provider of the email delivery system, the provider of the tool for analysing activity on the Website, the provider of the form's bot protection and the hosting provider,
- entities whose assistance and services we use in the course of our business under separate agreements,
- state authorities entitled to it under applicable law,
- other entities whose request for the transfer of data is justified under applicable law.
Specifically, these are:
| Service | Purpose | Location |
|---|---|---|
| MailerLite | Storing sign-ups and sending email | European Union |
| PostHog | Website usage measurement | European Union (Frankfurt) |
| Cloudflare Turnstile | Protecting the form from bots | Global network |
| Vercel | Website hosting and form handling | United States / global network |
Do we transfer personal data to third countries?
Data of people on the early access list is stored in the European Union, and measurement of Website usage runs on servers in the European Union (Frankfurt).
In running the Website, however, we use services and technologies offered by entities such as Vercel and Cloudflare, which are based in the United States and may partly process personal data using servers located outside the European Economic Area (EEA). Under the GDPR these are entities located in third countries, for which an adequate level of protection or a reference to appropriate safeguards must be demonstrated.
We confirm that the above entities apply compliance mechanisms provided for by the GDPR (e.g. certifications) or standard contractual clauses adopted by the European Commission (Art. 46(2)(c) GDPR). You will find more information about how these entities process data on their providers' websites.
Do we profile your personal data?
We do not profile your data for advertising purposes and we do not build marketing profiles on its basis. As part of measuring Website usage we analyse user behaviour (e.g. which parts of the page are read); this information is aggregate and auxiliary in nature.
We therefore make no automated decisions that could produce legal effects concerning natural persons or similarly significantly affect them.
Do we use cookies?
Before you submit the sign-up form we store nothing on your device: no cookies, no browser storage. Visits are counted on the measurement provider's side using a short-lived hash that cannot be traced back to you. That is why this Website shows no cookie consent dialog — there is nothing to consent to.
This changes only if you tick the separate consent in the sign-up form to link your visit with your email address. Only then is the measurement linked to that address and only then does it store cookies on your device. That consent is optional: without it the sign-up works the same and the measurement stays cookieless.
Browser settings are no substitute for consent here and cannot give it on your behalf — consent means only you ticking the separate box in the sign-up form. Regardless of that, you may block and restrict the installation of cookies using your browser settings or other (free) solutions; disabling them may cause difficulties in using websites.
How do we protect your data?
To ensure a high and consistent level of protection we apply safeguards to the IT environment appropriate to the processing, as well as technical and organisational measures, including among others:
- TLS encryption,
- creating backups,
- using data centres equipped with data protection mechanisms,
- minimising the risk of potential abuse and reacting quickly should it occur,
- ensuring the ongoing confidentiality, integrity, availability and resilience of processing systems and services,
- granting access to personal data only to authorised persons,
- creating and regularly changing passwords to systems in which personal data is processed.
What rights do the people whose data we process have?
People whose data we process have the right to:
- access their personal data;
- rectify their personal data;
- erase their personal data;
- restrict the processing of their personal data;
- object to the processing of their personal data;
- data portability;
- withdraw consent to processing (where consent is the basis for processing).
The rights listed above are not absolute, however, and in some situations, after analysis, we may lawfully refuse to fulfil them.
We also inform you that withdrawing consent to processing will not affect the lawfulness of processing carried out on the basis of the consent given before its withdrawal.
If you approach us with a request to exercise any of the above rights, we will respond without undue delay, and no later than within one month of receipt. If, due to the complex nature of the request or the number of requests, we are unable to meet your request within one month, we will meet it within the following two months. We will inform you beforehand of the intended extension.
How do you withdraw consent?
You can withdraw consent at any time, and doing so is as easy as giving it — that is what Art. 7(3) GDPR requires. Withdrawal takes effect for the future and does not affect the lawfulness of what happened before it.
- Consent to emails: use the unsubscribe link in the footer of any message we send, or write to welcome@noteeva.com. We then remove your address from the list.
- Consent to linking your visit with your email address: use the button below. The measurement then returns to cookieless mode — the same one that applies to everyone who has not signed up.
How can you complain about irregularities in the processing of personal data?
If you consider that we process your personal data contrary to applicable law, you may lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych) or with your local supervisory authority.
Does using the Website involve sending logs to the server?
Using the Website involves sending requests to the server on which the site is stored. Every request sent to the server is recorded in the server logs and stored on the server. The logs include, among others, the IP address, server date and time, and information about the browser and operating system.
Data recorded in the server logs is not associated with specific people using the site and is not used by us to identify you.
Server logs are solely auxiliary material used to administer the site, and their content is not disclosed to anyone other than persons authorised to administer the server.
Can we change our Privacy Policy?
Yes. Personal data protection is a process that we adapt to current needs and changing technology. Our Privacy Policy may therefore be supplemented or amended, of which we will inform you by posting information on the Website, and in the case of material changes we will send separate notifications by email to people on the early access list.