Privacy · GDPR

Privacy

The same posture as the product: the less that leaves, the less there is to defend. Sorgfalt begins with restraint.

No third-party requests — fonts are self-hosted, so no cookie banner is required.
No analytics, no trackers, no advertising pixels.
Your code never reaches us — the CLI runs locally, BYOK, EU-resident.

Controller

The controller under Art. 4 (7) GDPR is a natural person:

Felix Radzanowski
Dorfwiesen 32
75031 Eppingen
Germany · legal@agetra.eu

What we collect, and why

Only what you hand us. The waitlist stores one email address, to tell you when plumb is ready. The “I have a case” form stores your email plus a few structured fields — role, sector, codebase language, regulated yes/no, urgency — each one a fixed choice. No free-text field exists, by design: nothing confidential can leak through it.

Both rest on your consent (Art. 6 (1)(a) GDPR), confirmed by double opt-in — we send one email and only store you once you click to confirm. You may withdraw that consent at any time, with effect for the future.

What the product does not see

The oracle reads your intent surface — signature and docstring — never the code body. Evidence stays local in .plumb/; only a content digest would ever cross the wire, and signing is a futur · preview capability gated to Phase 2.

Processors

Brevo (Sendinblue SAS, Paris, France — EU) handles the mailing and the contact records for the waitlist and the case form, as our processor under an Art. 28 GDPR data-processing agreement. Lawful basis: your consent, Art. 6 (1)(a).

Bunny.net (BunnyWay d.o.o., Slovenia — EU) serves this site over its CDN and writes short-lived server logs, including the requesting IP address, for secure and reliable delivery. Lawful basis: our legitimate interest, Art. 6 (1)(f). Brevo and Bunny.net keep that data within the EU.

Google Workspace (Google Ireland Limited, with Google LLC, USA, as sub-processor) hosts the mailboxes behind our contact addresses (hello@, legal@, privacy@, admin@). When you email us, Google processes that correspondence as our processor under its Art. 28 GDPR data-processing terms. On our current plan the mailbox is not pinned to the EU; any transfer to the USA relies on the EU Standard Contractual Clauses. Lawful basis: our legitimate interest in answering you, Art. 6 (1)(f).

Retention

We keep waitlist and case data until you withdraw your consent, or until plumb launches and is offered to you — whichever comes first — then we delete it. Server logs are kept only as long as needed for secure operation.

Your rights

Access, rectification, erasure, restriction, portability, objection (Art. 15–21 GDPR), and withdrawal of consent — write legal@agetra.eu and we act within the statutory time.

You may also lodge a complaint with the supervisory authority: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg.