1. Overview of processing
We process only the data needed to deliver the public website, protect the waitlist form from abuse, and manage beta waitlist registrations.
2. Server log files
When you access the website, technical server log data may be processed to keep the service secure and available. The legal basis is Art. 6(1)(f) GDPR.
- IP address
- date and time of the request
- requested URL or path
- referrer, if your browser sends one
- browser and operating-system details
- response status and transferred data volume
3. Beta waitlist
If you join the waitlist, the form sends your data to the public join-waitlist Supabase Edge Function. The submission is stored so beta invitations can be managed and duplicate signups can be avoided.
The legal basis for the signup itself is Art. 6(1)(a) GDPR. Abuse prevention and duplicate protection are based on Art. 6(1)(f) GDPR.
- email address
- optional honeypot field content, if filled
- Turnstile validation token
- timestamp and minimal request metadata needed for processing
4. Cloudflare Turnstile
To protect the waitlist form from bots, the website loads Cloudflare Turnstile when the form is displayed. Cloudflare may process IP address, browser or device data, and interaction signals to distinguish human users from bots.
The legal basis is Art. 6(1)(f) GDPR for fraud prevention, service security, and abuse protection.
5. Hosting and processors
Processing takes place only to the extent needed for secure site operation, signup handling, and abuse prevention.
- current VPS hosting for lifeautopilot.org
- Supabase for waitlist intake and secure storage
- Cloudflare Turnstile for bot protection
6. Cookies and similar technologies
The website currently does not use analytics cookies, advertising trackers, or third-party marketing pixels.
Security-related cookies or comparable browser storage may still be set by Cloudflare Turnstile where required to distinguish humans from bots.
7. Retention
Waitlist entries are retained until beta access communication is completed, you withdraw your request, or the data is no longer needed.
Server log data is retained only as long as required for technical operation, security, and troubleshooting.
8. Your rights
- access to your personal data
- rectification of inaccurate data
- erasure where legal requirements are met
- restriction of processing
- data portability where applicable
- objection to processing based on legitimate interests
- complaint to a competent supervisory authority
9. Contact for privacy requests
For privacy-related requests, contact andreasdronov@gmail.com.