# spun.ink — Privacy Notice

> Version 2026-08-25b · effective 2026-08-25 · supersedes version 2026-08-25, readable at  
> `spun.ink/legal/privacy/2026-08-25` · English is the contract language · content hash: the  
> SHA-256 of the served bytes, printed on the page itself and reproducible from the raw markdown at  
> `spun.ink/legal/privacy.md`.  
> Applies to: spun.ink and every service City of Code GmbH provides under that name — the platform  
> site at `spun.ink`, customer sites served at `<handle>.myspun.ink`, and customer domains served by  
> spun.ink.  
> This is **information under Articles 13 and 14 GDPR, not a contract term.** There is nothing here
> to accept. A German courtesy version may follow.  
> **What changed in this version:** our error tracker is now also sent the log lines our own software
> writes when something goes wrong — what failed and on which request, for which account and site.
> Nothing a visitor gives you travels with them: no parameters, no session data, no IP address, no
> query strings, exactly as before. Sections 5 and 7 name the new category and say how long it is
> kept — **five days**, against sixty for a crash report.

---

## Summary in plain words

- **We collect only what we need.** To run your account we need an e-mail address and a name. That is the whole of it. We take no payment data ourselves, we run no analytics anywhere, we set no advertising cookies, and we never sell personal data. We do watch our own servers for crashes — an error tracker is told what broke and where, never who was visiting (section 5).
- **We wear two hats, and the difference matters.** For your *account* we decide what happens, so we are the **controller** and this notice tells you everything. For everything a *website hosted on spun.ink* collects from its visitors, the customer who owns that site decides and we only store it for them — there we are a **processor** (section 4), with one narrow exception: the request log our own servers write (section 4.3).
- **If you filled in a form on a site hosted here, we are not your contact.** The owner of that site is. Write to us and we forward your message to them.
- **Your data stays in the European Union** — database and files in Google Cloud's EU regions, crash reports in the Netherlands, Ireland and Germany. Payments run through Stripe; our tax advisers receive the invoices the law makes us keep. Section 5 names them, section 6 the three transfers to the United States.
- **One cookie, and reading a page does not get you it.** Loading a page — ours or a customer's — stores nothing on your device. A single strictly necessary session cookie appears only when you use one of our own forms, or when a site owner opens a preview link. No banner, no tracking (section 12).
- **Your rights** — access, rectification, erasure, restriction, portability, objection — are in sections 8 and 9, and you can complain to the Austrian data protection authority (section 10).

Where this summary and a numbered section differ, the numbered section is what applies.

---

## 1. Two roles: when we are the controller, and when we are not

### 1.1 Controller — your account with us

For everything to do with **your account**, City of Code GmbH is the **controller** (Article 4(7)
GDPR): your e-mail address and name, the digest of your access token, your plan and subscription
state, your billing identifiers at Stripe, the feedback you send us, the mail we send you, and our
operational and security logs. Sections 3, 5, 6 and 7 tell you the whole of it.

### 1.2 Processor — the sites our customers publish

For everything a **customer's Site collects from its Visitors** — form submissions, uploaded assets,
published content that describes people — the **customer is the controller and we are their
processor** (Article 4(8) GDPR). We store it, serve it and hand it back to that customer on their
instruction. We do not decide what is collected, why, or for how long. The terms of that
relationship are the **Data Processing Agreement**, part of the Terms every customer accepts.

### 1.3 If you visited a site hosted on spun.ink

**Then this notice is almost certainly not the one you want.** The owner of that site is your
controller. Their own privacy notice is what applies to what they collect from you, and they are who
you address a request to. **One narrow slice is still ours:** the request log and the anti-abuse
measures that run when you load the page — section 4.3 says what that is and how to object to it.

If you cannot find the owner and you write to `support@spun.ink`, we may not answer on the merits.
We forward your message to the site owner without undue delay and, as a service commitment, within
three working days, and tell you that we have done so.

This notice therefore does not cover what a customer does with data collected on their own Site, nor
anything a customer injects into their own Site's head code — analytics, embeds, third-party fonts,
tracking pixels, none of which spun.ink ships.

---

## 2. Who we are, and how to reach us

spun.ink is a product and service of City of Code GmbH.

```
City of Code GmbH
Adnet 436, 5421 Adnet, Austria
E-mail: support@spun.ink
Commercial register: FN 362676y · Firmenbuchgericht: Landesgericht Salzburg
VAT identification number: ATU66573656
Managing director (Geschäftsführer): DI Norbert Egger, BSc
```

The rest of the company disclosure — chamber membership, the trade and the trade authority — is in
the **Legal notice** at `spun.ink/legal-notice`.

**For anything about personal data, write to `support@spun.ink`.** That is the single address for
this company; a person reads it. You may write in German or in English, and the postal address above
works too.

**We have no data protection officer, and none is required** under Article 37(1) GDPR: we are not a
public body, we carry out no regular and systematic monitoring of people on a large scale, and
large-scale processing of special categories of data is not a core activity of ours. We also need no
representative in the Union under Article 27 GDPR, because City of Code GmbH is established in
Austria.

## 3. What we process about you, why, and on what legal basis

This section is about **account owners** and about people who write to us. Visitors of hosted sites
are section 4 — and one part of it, **4.3, is our own controller processing** rather than the site
owner's.

We collect only what we need. There is no field on our sign-up form that exists "just in case."

### 3.1 The table

| # | What we do | What that involves | Legal basis |
|---|---|---|---|
| 1 | **Run your account and serve your sites** | E-mail address, name (which may be a company name), the digest of your access token, your plan, your account and site settings, and all the Content you or your Agent create | Article 6(1)(b) GDPR — performance of the contract |
| 2 | **Verify your address, and let you recover access** | E-mail address, when and how often we sent a verification mail, the moment you confirmed | Article 6(1)(b) |
| 3 | **Send you the mail the service needs** | Verification, recovery, deletion confirmations, sub-processor notices, breach notices, notices of changes to the Terms | Article 6(1)(b); for breach notices also Article 6(1)(c) with Articles 33–34 GDPR |
| 4 | **Bill you, invoice you, and keep the books** | E-mail address and account identifier passed to Stripe; the name, billing address and VAT identification number **you give to Stripe**, which we see as customer and invoice records; subscription state | Article 6(1)(b) for the payment; Article 6(1)(c) with § 132 BAO and the UStG for the records |
| 5 | **Comply with legal obligations and lawful orders** | Whatever a binding order or a statute actually requires, and no more | Article 6(1)(c) |
| 6 | **Keep the service up and secure** | Request logs written by the application, IP addresses read in memory by the rate limiter, error reports | Article 6(1)(f) — see 3.2 |
| 7 | **Handle abuse reports and takedowns** | The report, the address of whoever reported, the site and account concerned, what we decided and why | Article 6(1)(f) — see 3.2. Where an order or a statute compels the step, Article 6(1)(c) as well |
| 8 | **Read and act on feedback** you send us | The message, its category, the site it concerns, our triage summary and status | Article 6(1)(f) — see 3.2 |
| 9 | **Answer correspondence** you send to one of our published addresses | Your address and whatever you wrote | Article 6(1)(b) where it concerns your contract; Article 6(1)(f) where it does not |

**We do not process your data for advertising, for profiling, for scoring, or for training any
machine-learning model. We do not sell personal data, and we never have.**

### 3.2 The things we do on "legitimate interests", named

Article 6(1)(f) requires us to name the interest, not just cite the letter. There are exactly five,
in rows 6 to 9 above:

1. **Operational and security logs, and rate limiting** — keeping the service available, finding faults, stopping abuse of the infrastructure. Credentials, access tokens, e-mail addresses and every parameter of a form submission are removed before a log line is written, and the rate limiter reads an IP address in memory without storing it.
2. **The IP address in the application request log** — recognising an attack, tracing a flood back to where it came from, reconstructing an incident. Every request we serve, on spun.ink and on every site we host, writes a log line carrying the IP address it came from, and **that address is not redacted**. It is kept for **8 days**, and it is read only for faults and abuse — never combined with anything else about you, never used to profile you, never used to measure traffic.
3. **Handling abuse reports and takedowns** — not hosting illegal content, and being able to show what we did and why.
4. **Feedback** — building the product from what users tell us. Nothing is collected unless you send it.
5. **Answering correspondence that does not concern a contract with us** — replying to the person who wrote.

You may object to any of these five. Section 9 says how.

### 3.3 Giving us your e-mail address is required to contract

We need an **e-mail address** to conclude and perform the contract, because it is the only channel on
which the account exists: the confirmation link, the recovery link, a sub-processor notice or a
breach notice all go there. A **name** is required by our sign-up form; it may be a personal name or
a business name.

**If you do not provide an e-mail address, we cannot create an account** and no contract comes about.
There is no other consequence — we keep no record of an attempt that never became an account.

### 3.4 Where the address came from, when an Agent typed it

spun.ink is operated by AI agents, and an account can be created by a customer's own agent calling
our sign-up tool — so **we sometimes receive an e-mail address from software rather than from the
person it belongs to.** The source of the data, in the language of Article 14(2)(f), is the account
applicant or the agent acting for them. We obtain no personal data from public sources, from data
brokers, or from anyone else.

The very first message we send to that address carries what Article 14 GDPR requires: who we are,
that the address was entered when the account was created, what we use it for, that we give it to
nobody, how to ask what we hold or have it corrected or erased, and that you may complain to the
Austrian data protection authority. **We send nothing else to that address until a human presses the
button in that mail.** If you did not ask for a spun.ink account, ignoring the mail is enough:
nothing becomes public, no contract is concluded, and the site never serves a page. Write to
`support@spun.ink` and we erase the account record.

---

## 4. Sites we host for customers — where we are the processor, and the one place we are not

### 4.1 What lives there

A customer's Site can hold **form submissions** (whatever fields that customer's form asks for),
**uploaded assets** (images, documents, and whatever they contain), and **published content** that
may describe or name people. All of it stays in the European Union (section 5).

**We do not add anything to it.** For a form submission we store the fields, the form name, the site
and account it belongs to, and the time. **We store no IP address and no browser user agent with a
submission.** Automated abuse protections run on the form itself; the only one that touches your IP
address is a rate limit, which holds it in memory and discards it.

### 4.2 Who is responsible, and what we do not do

The **customer who owns the Site is the controller**: they decide what their forms ask, what they do
with the answers and how long they keep them, and they must publish their own privacy notice on
their own site. We act only on their instruction. We do not read submissions, use them for our own
purposes, or make them available to anyone but the account they belong to — except where a binding
legal order requires it, in which case we tell the customer first unless the law forbids us to.
Isolation between accounts is structural: every record carries its account, and every query is
scoped to one account.

Submissions stay until the customer deletes them or the account is deleted. **We set no retention
ceiling of our own** — that is the controller's decision.

### 4.3 One thing on a hosted site is ours: the request log

When you load any page on a site hosted by spun.ink, our servers write an **operational request log**
and our anti-abuse measures look at your **IP address**. Those exist for *our* infrastructure, not on
the site owner's instruction — so for that narrow slice **we, not the owner, are the controller**.

- **What:** the request log entry our application writes, from which credentials, e-mail addresses and every parameter of a form submission are filtered out beforehand. On a form submission an IP address is additionally read **in memory** by the rate limiter and discarded — **it is never stored with the submission.**
- **Why and on what basis:** Article 6(1)(f) GDPR, the interests named in items 1 and 2 of section 3.2. As item 2 says, the IP address in that log line is not redacted.
- **How long:** eight days (section 7).
- **If the request crashes**, a second record is written on the same basis: the exception and its backtrace go to our error tracker (section 5), together with a log line naming what failed. **Your IP address is not part of either** — nor are the parameters you sent, the query string or any cookie. The crash report ages out within 60 days, the log line within 5.
- **Your rights reach us for this slice.** Access, erasure, restriction and **objection** (section 9) for the request log are ours to answer, at `support@spun.ink`. For everything else on the site, the owner is who to ask (section 1.3).

We set **no analytics cookie and no tracking cookie** on hosted sites. The only cookie that can
appear on one is the preview grant described in section 12, and only after a site owner opens a
preview link that was sent to them.

### 4.4 The one hop that leaves our control

**When a customer's AI agent reads a form submission, the data goes to that customer's AI model
vendor** — returned verbatim into the agent's context, under the customer's own account with that
vendor. spun.ink **makes no model calls at all** and has no contract with any model vendor. For that
step the customer is the controller, including the duty to tell their visitors about it where that
applies.

---

## 5. Who else sees the data

Four companies see personal data, and no others. There are no advertising networks, no analytics
providers, no data brokers and no marketing tools in this list, because we use none. One of the four
is an error tracker, which is not the same thing as an analytics provider: it is told about crashes
and slow requests, never about who visited what.

| Recipient | What it handles for us | Where | Role |
|---|---|---|---|
| **Google Cloud EMEA Limited**, Ireland, with **Google LLC** (United States) and Google's European group companies as authorised sub-processors for data-centre operations, maintenance and support | Our infrastructure — the application, the database, uploaded assets, operational logs, TLS certificates — and the mail relay on our own domain that carries account mail to your address. **Your e-mail address passes through it**; no Content, no submissions and no Visitor data do | Database in Belgium; assets and logs in Google's EU multi-region; support access from the United States and other Google locations | Our processor for our own controller data; our sub-processor for customers' Visitor data |
| **Stripe Payments Europe, Limited**, Ireland, with **Stripe, LLC**, United States | Everything to do with paying: checkout, the customer record, the card, invoices, receipts, dunning and the billing portal. We pass Stripe your e-mail address and account identifier; you give Stripe your name, billing address, VAT identification number and payment details directly. **Card data never touches spun.ink** | Ireland; United States | **Recipient and independent controller.** Stripe also processes this for its own purposes — fraud prevention, anti-money-laundering and know-your-customer checks, product development — under its own privacy policy at `stripe.com/privacy` |
| **AppSignal B.V.**, Netherlands, with **Worldstream B.V.** (Netherlands), **Amazon Web Services EMEA SARL** (Ireland) and **Hetzner Online GmbH** (Germany) as its own authorised sub-processors | Error tracking and performance monitoring for the platform. It is sent **diagnostic data only**: the exception and its backtrace, the controller action, the request path, the host and timings. Request parameters, session data, visitor IP addresses, cookies, the authorisation header and query strings are switched off in our deployment and never reach it. An error message can quote Content or a submission incidentally, which is why AppSignal is a sub-processor and not a mere recipient. It is also sent our **application log lines at warning level and above** and the operational events we write deliberately — an event name with the request identifier and the account and Site identifiers, and an exception class and message where there is one; the same switches apply. Samples are kept **at most 60 days**, log lines **at most 5 days** | Netherlands, Ireland and Germany — the diagnostic data never leaves the EEA | Our sub-processor for customers' Visitor data, and **our processor** for the diagnostic data itself. Separately, AppSignal is an **independent controller** for our account details with it and for service-usage data about our use of the product, which it may process in the United States (section 6) |
| **Höllermeier · Schaller & Partner Steuerberatung Salzburg GmbH**, Salzburg, Austria | Our invoices, receipts and the customer record behind them, for the statutory books and the tax returns. No Content, no submissions, no Visitor data, and no access to any of our systems | Austria — no transfer out of the Union | **Recipient and independent controller**, bound by professional secrecy under § 80 WTBG 2017. Legal basis: Article 6(1)(c) GDPR with § 132 BAO |

**No AI model vendor appears in this list.** spun.ink makes no model calls; where a customer's own
agent takes data out of spun.ink, that is the customer's processing chain (section 4.4).

Beyond the four above we disclose personal data only where a binding legal order requires it, and
only what the order actually requires — telling you first wherever the law lets us. The current
sub-processor list, the general written authorisation and the objection window are part of the Data
Processing Agreement.

## 6. Transfers outside the European Union

**Storage is in the European Union**, and nothing we store in our own infrastructure leaves it — the
diagnostic data at AppSignal is held in the Netherlands, Ireland and Germany, so it stays inside the
EEA too. Three transfers to the United States exist, and we name them rather than claim EU-only
processing:

| Transfer | Why | Safeguard | How to get a copy |
|---|---|---|---|
| **Google LLC (United States)** obtains access in the course of data-centre operations, maintenance and technical support for Google Cloud EMEA Limited | Google supports its infrastructure on a follow-the-sun basis; storage stays in the EU | The **EU–U.S. Data Privacy Framework**, Commission Implementing Decision (EU) 2023/1795, and the **standard contractual clauses**, Decision (EU) 2021/914 | Write to `support@spun.ink` |
| **Stripe, LLC (United States)** receives account and billing data | Stripe operates its platform from the United States | The **EU–U.S. Data Privacy Framework**, on which Stripe, LLC is self-certified, and the **standard contractual clauses**, Decision (EU) 2021/914, where the Framework does not apply | `stripe.com/legal/dpa`, or from us at `support@spun.ink` |
| **AppSignal B.V.** may process **our own account data and service-usage data** on infrastructure outside the EEA, including in the United States, as an independent controller — its own contact and billing details for us, and activity logs about how we use its product. **Nothing processed for a customer travels with it**: § 6.1 of our addendum with AppSignal confines that data to the EEA, and § 9 says in terms that it is not transferred to or processed in the United States | AppSignal runs its own business — accounting, fraud and abuse detection, product improvement — from wherever its own tooling sits | The **standard contractual clauses**, Decision (EU) 2021/914, incorporated by § 6.2 of that addendum | From us at `support@spun.ink` |

## 7. How long we keep things

| What | How long | Why that long |
|---|---|---|
| Account record — e-mail, name, token digest, plan, subscription state, verification timestamps | Until the account is deleted | It is the account |
| Your Sites, Content, templates, collections, blogs, forms, uploaded assets and revision snapshots | Until you delete them, and in any case until the account is deleted. **Revision snapshots outlive the page or template they belong to**: deleting one keeps its history so that it can be restored, and that history is erased when the Site is deleted, when the account is deleted, or when your plan's revision-retention window drops it | Article 6(1)(b); a revision snapshot exists so that an edit — or a deletion — can be undone, which is only possible if it outlives what it replaced |
| Form submissions on customers' sites | Until the customer deletes them, or the account is deleted. **We set no ceiling of our own** | Retention is the controller's decision; we are the processor and do not overrule it |
| Feedback you send us | For the life of the product, and destroyed with your account | It is the record of a product decision |
| Correspondence to `support@spun.ink` and to our postal address | **Three years** after the matter is closed | The general limitation period for claims, § 1489 ABGB |
| The application request log — **the log line carries the visitor's IP address**, so this row is how long an IP address lives with us | **8 days**, then deleted beyond recovery | Article 6(1)(f). Long enough to trace a fault or an attack across a week; short enough that a request log never becomes a history of anyone |
| Application log lines at AppSignal — what our software recorded as a warning or an error, with the request identifier and the account and Site identifiers. No parameters, no session data, no visitor IP | **At most 5 days**, then gone. **A line written before an account is deleted is not reached by that cascade** | Article 6(1)(f). Long enough to work out what happened around a fault; short enough that it never becomes a record of anyone |
| Diagnostic samples at AppSignal — an exception with its backtrace, the action, the path, the host and timings. No parameters, no session data, no visitor IP | **At most 60 days**, then only aggregate figures remain. **A sample written before an account is deleted is not reached by that cascade** | Article 6(1)(f). Long enough to see whether a crash is recurring or a one-off; short enough that it never becomes a record of anyone |
| Billing records — invoices, receipts and the customer record **at Stripe** | **Seven years from the end of the calendar year the record relates to** (§ 132 BAO). **They survive deletion of your account** | Austrian tax law requires it; Article 17(3)(b) GDPR permits it. The same seven years apply to the copies our tax advisers hold |
| Handle and released-domain records | Kept permanently, so a released address cannot be taken over immediately by someone else. They hold no Content and no Visitor data | Protecting the people who used to link to that address |

**Deleting your account** erases, in one cascade: the account row, every Site, every page and post
with its blocks, every template, collection and record, every blog, every form and every submission,
every revision and revision snapshot, the search index rows, and the stored asset files.

**Deletion is not instantaneous everywhere, and we will not pretend otherwise.** It is immediate in
the live systems. Behind them our infrastructure provider keeps a short recovery window — about a
week for deleted files and for the database backups a service needs to survive a failure. Neither is
a copy anyone reads: a backup is restored only to recover the service, never to bring an erased
account back, and a restore that ever ran would be followed by re-applying the deletion. A crash
report already at AppSignal ages out on its own 60-day clock rather than in that cascade. Stripe's
tax records under § 132 BAO are the one deliberate exception.

## 8. Your rights

Where we are the controller (section 1.1), you have the right to **access** (Article 15),
**rectification** (Article 16), **erasure** (Article 17), **restriction** (Article 18) and
**portability** (Article 20), and the right to **object** — section 9, which is separate because
Article 21(4) GDPR requires it to be. Today we rely on consent for nothing described in this notice,
so there is no consent to withdraw. Where we are the **processor** (section 1.2), address the site
owner, not us (section 1.3).

**To exercise them, write to `support@spun.ink`** or to the postal address in section 2. Say what you
want; you do not have to cite an article.

- We answer **within one month**. Where a request is complex or there are many of them we may extend that by two further months, telling you within the first month that we are doing so and why (Article 12(3) GDPR).
- **It is free.** Only for a manifestly unfounded or excessive request may we charge a reasonable fee or refuse, and we would have to show why (Article 12(5)).
- If we do not act on your request we tell you why within one month, and that you may complain to the supervisory authority and go to court (Article 12(4)).
- Where we have reasonable doubts about who is asking we may ask for more information (Article 12(6)) — but where the request comes from the account address itself we will not ask you for a copy of an ID document.
- **Access and portability** run through the read tools of your own account, which return your data as structured JSON, plus a written request for anything they do not cover.
- **Changing the e-mail address or the name on an account** is a written request to `support@spun.ink`. We check that it really comes from the account holder, and complete it within the same one month.

## 9. Your right to object (Article 21 GDPR)

> **You have the right to object, at any time, on grounds relating to your particular situation, to
> processing of your personal data that is based on our legitimate interests (Article 6(1)(f) GDPR).
> If you object, we will stop processing your data for that purpose unless we can demonstrate
> compelling legitimate grounds that override your interests, rights and freedoms, or unless the
> processing serves the establishment, exercise or defence of legal claims.**
>
> **You also have the right to object at any time to processing of your personal data for direct
> marketing. If you object to that, we will stop, with no exception and no balancing.** We send no
> marketing mail today, and we would ask for your consent separately before we ever did.
>
> **To object, write to `support@spun.ink`.** A sentence is enough. You do not have to use a form or
> cite an article.

This right applies to exactly five things we do — the five named in section 3.2. Nothing else in
this notice runs on legitimate interests.

**Where we are the controller, we answer you** — your account, and the request log written when you
load any page we host (section 4.3). **Where a customer is the controller, we forward.** If your
request is about a website hosted here, we may not answer on the merits: we forward your message to
that owner without undue delay and, as a service commitment, within three working days, and we tell
you that we have done so.

We cannot run the service without any operational logging at all, and where an abuse report concerns
illegal content we may have a legal duty that overrides an objection. Where that is the case we will
tell you which ground we are relying on, in writing, so you can challenge it.

*This section is deliberately separate from section 8, because Article 21(4) GDPR requires the
objection right to be presented clearly and separately from any other information.*

## 10. Complaining to the data protection authority

If you think our processing of your data breaches the GDPR or the Austrian Data Protection Act, you
may complain to a supervisory authority — in particular in the Member State of your habitual
residence, of your place of work, or of the alleged infringement (Article 77 GDPR). For City of Code
GmbH the competent authority is:

```
Österreichische Datenschutzbehörde
Barichgasse 40–42, 1030 Wien, Austria
E-mail: dsb@dsb.gv.at   ·   Web: dsb.gv.at
```

The authority's work is **free of charge for you** (Article 57(3) GDPR). You need no lawyer, and you
may also go to court. Complaining does not stop you from writing to us first, and we would rather you
did — but it is your choice, not a step you owe us.

---

## 11. No automated decision-making

**We make no decisions about you by automated means, and we do no profiling** within the meaning of
Article 22 GDPR. Nothing about your account, your plan, your price or your access is decided by an
algorithm without a person. Because spun.ink is an agent-operated platform, one clarification
matters: **the AI agent is the customer's, not ours.** It acts on the customer's instruction, under
the customer's own account with their own model vendor. We make no model calls at all.

---

## 12. Cookies

spun.ink sets **a single cookie**, `_spun_session`, the session cookie of the application. It is
strictly necessary, it carries no identifier we track you with, and there is **no advertising,
analytics, measurement or consent cookie anywhere on spun.ink or on any site we host.**

**Reading a page stores nothing on your device.** An anonymous page view sets no cookie at all — not
on a customer's site, not on spun.ink's own pages, not on an error page. The cookie appears in two
situations only: when you use one of the platform's own forms, and when a site owner opens a preview
link that was sent to them.

| Cookie | When it is set | Lifetime | Attributes |
|---|---|---|---|
| `_spun_session` | On the platform's own form pages — sign-up, account recovery, account deletion, the token-reveal page, the e-mail-verification page — and on the preview step, after a site owner opens the signed preview link they were sent. **Never on an ordinary page view** | **Session** — no expiry date is set, so your browser deletes it when you close it | Host-only: never set with a `Domain=` attribute, so never shared between spun.ink and a customer site, or between two customer sites. `Path=/`, `Secure`, `HttpOnly`, `SameSite=Lax` |

Article 5(3) of the ePrivacy Directive and § 165(3) TKG 2021 allow storage without consent where it
is strictly necessary for a service you explicitly asked for, and require that you be informed
either way. Rather than claim that as a blanket, here is what the cookie holds:

- **A session identifier**, whenever the cookie is present — without it the server cannot connect the request you are making now to the one you made a moment ago.
- **A cross-site-request-forgery token**, on the platform's own form pages, so that a third-party site cannot make your browser submit one of our forms in your name. Forms on hosted customer sites do not use it: those posts are anonymous, and are protected by automated abuse checks instead (section 4.1).
- **A preview grant**, only after a site owner opens the signed, time-limited preview link they were sent — which site the preview is for and when it expires, so an unpublished draft is visible to the invited person and to nobody else.

**Legal basis: Article 6(1)(b) GDPR** — each of those steps is one you asked for, and the cookie
exists to carry it out.

**There is no consent banner, because there is nothing to consent to.** Loading a page here leaves
nothing on your device: no cookie, no `localStorage`, no `sessionStorage`, no service worker. The
moment we add anything non-essential, the banner rules apply in full.

**Cookies a customer puts on their own site are the customer's, not ours.** spun.ink ships no consent
tooling; a customer who injects analytics, embeds, maps, third-party fonts or tracking pixels into
their own Site is the controller for those cookies and owes their visitors the information and, where
the law requires it, the consent mechanism.

## 13. The spun.ink website itself

**The spun.ink site loads nothing from any third party.** Every stylesheet, font and image is served
from our own infrastructure, so opening one of our pages discloses your IP address to us and to
nobody else. There is no analytics script, no tag manager, no embedded video or map, no social widget
and no tracking pixel, on any page. The blog and the documentation are ordinary pages: no comments,
no reactions, no account to log into. **We run no analytics of any kind** — nobody is counted,
followed between pages or profiled, and we cannot tell you who read this page. Our error tracker
measures how long our own code takes and how often it runs (section 5); that is a throughput figure
for the software, carrying no IP address and tied to no person. What a customer's own site loads is
that customer's decision (section 12).

## 14. Personal data breaches

- **Where we are the controller** (your account data): we notify the Austrian Data Protection Authority without undue delay and, where feasible, within **72 hours** of becoming aware, unless the breach is unlikely to result in a risk to people's rights and freedoms (Article 33 GDPR). Where it is likely to result in a **high** risk to you, we tell you as well, without undue delay and in plain language (Article 34).
- **Where we are the processor** (a customer's Visitor data): we notify **the customer** without undue delay and at the latest within **48 hours**, to the account e-mail address. The 72-hour notification to the authority is then theirs, because they are the controller.

**This is why your account e-mail address must stay reachable.** It is the only channel we have.

## 15. How we protect the data

The full catalogue of technical and organisational measures, written to the headings of Article 32
GDPR, is part of the **Data Processing Agreement** and available to customers. In summary:

- **Confidentiality.** Access tokens are never stored in readable form, only as digests. Data is separated per account structurally, by the query layer itself, not by convention. Access to production is limited to the people who need it, and secrets are held in a dedicated secret store.
- **Integrity.** Everything is served over TLS and the production site is HTTPS-only. Uploaded assets live in a private store and are served through short-lived signed links, never by a public URL. Credentials, e-mail addresses and all submission parameters are filtered out of logs before they are written, and the signed links we mail you never reach a log at all.
- **Availability.** Data at rest is encrypted by our infrastructure provider, backed up daily with a point-in-time-recovery window, and stored in the EU.

## 16. Children

**You must be at least 14 years old to open a spun.ink account**, or a business with authority to
contract. That is our own rule, not a statutory threshold; we set it because an account carries
publishing duties towards the public. We do not verify age. We rely on consent for nothing in this
notice, so the special rule for a child's consent to information-society services — Article 8 GDPR,
which Austria sets at the completed fourteenth year in § 4(4) of the Data Protection Act — does not
come into play for account creation, which rests on the contract.

**We do not knowingly process the data of children below that age.** If you tell us an account was
opened by someone below it, write to `support@spun.ink` and we will close it and erase it.

---

## 17. Changes to this notice

We will change this notice when the service changes or the law does. The new version gets a new
**version date**; we keep every previous version and send it to you on request. Where a change **materially affects how we
process your personal data**, we tell you by e-mail to the address on your account before it takes
effect. Nothing about your service is switched off, suspended or degraded because of a change to this
notice — there is nothing here to accept, so there is nothing to withhold — and changes never apply
retroactively to processing that has already happened.

The mechanism for changes to the **Terms of Service** — the notice period, the objection right and
the free termination right — is different, and it is in the Terms.

---

## The other spun.ink legal documents

| Document | Where it is |
|---|---|
| **Legal notice** — imprint, disclosure, contact points, and where your data lives | Published, at `/legal/imprint` |
| **Privacy Notice** — this page | Published, at `/legal/privacy` |
| **Terms of Service** — the contract; content rules, moderation, billing, switching and export | Published, at `/legal/terms` |
| **Data Processing Agreement** — where we act as processor for a customer's Visitor data | Published, at `/legal/dpa` |
| **Acceptable Use Policy** — what may not be published or done | Published, at `/legal/acceptable-use` |
| **Right of withdrawal** — the consumer withdrawal instruction and model form | Published, at `/legal/withdrawal` |

All six are served as a web page, without a login and without JavaScript, and as plain markdown at
the same address with `.md` appended. Every version stays reachable at `/legal/<name>/<version>`, so
the exact text an account accepted can still be read back.

---
