Privacy Policy
Placeholder content — replace before this site goes live. A real GDPR- compliant privacy policy needs, at minimum: identity of the controller, what personal data is collected and why (waitlist email + IP/user-agent at signup, scan content sent to the analysis model), legal basis for each processing purpose, retention periods, sub-processors (the newsletter worker, the model provider used for analysis, Cloudflare), and the visitor's rights under Art. 15–22 GDPR including how to exercise them.
Controller
[Same identity as the Legal Notice page]
Waitlist signup
When you join the waitlist we store your email address, IP address, and user agent at signup, plus a record of the confirmation email sent, to demonstrate consent (double opt-in). [State the retention period and legal basis — likely Art. 6(1)(a) GDPR, consent.]
Scan analysis
[Describe what site content is sent for analysis, which AI provider(s) process it, whether that provider retains the content, and where processing takes place — this depends on the final backend decision (Anthropic direct / AWS Bedrock / Google Vertex / Cloudflare Gateway) and must be kept in sync with whichever is actually live.]
Your rights
[Access, rectification, erasure, restriction, portability, objection — Art. 15–22 GDPR — plus the right to lodge a complaint with a supervisory authority.]
Contact
[Same contact details as the Legal Notice page]