Privacy Policy
Effective Date: 29 July 2026
Controller: Noteastic OG, Anton-Baumgartner-StraĂe 44, C8/1504, 1230 Wien, Ăsterreich (FN 644438 d; UID ATU81638239)
Language: English (British)
1. Definitions and Interpretation
1.1 Definitions
In this Policy, capitalised expressions have the meanings set out below. Terms defined in the Terms of Service have the same meaning here unless a different meaning is given.
- âAccountâ means the user account required to access the Application.
- âAccount Dataâ has the meaning set out in Section 5.1(a).
- âApplicationâ or âNoteastic Applicationâ means the Noteastic software application for Microsoft Windows, distributed through the Microsoft Store.
- âAttribution Dataâ has the meaning set out in Section 5.1(c).
- âBilling Dataâ has the meaning set out in Section 5.1(g).
- âControllerâ has the meaning given in Article 4(7) GDPR.
- âCorrespondence Dataâ has the meaning set out in Section 5.1(d).
- âCurrency-Geolocation Dataâ has the meaning set out in Section 5.1(i).
- âData Subjectâ means an identified or identifiable natural person to whom Personal Data relates.
- âEEAâ means the European Economic Area.
- âFeedback Dataâ has the meaning set out in Section 5.1(e).
- âGDPRâ means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation).
- âMicrosoft Storeâ means the digital distribution platform operated by Microsoft Corporation.
- âNewsletterâ means Our optional email newsletter, comprising the thematic content categories described in Section 5.1(j), sent only to Users who have subscribed to it.
- âNewsletter Dataâ has the meaning set out in Section 5.1(j).
- âNoteasticâ, âWeâ, âUsâ, or âOurâ means Noteastic OG, the legal entity identified in Section 2.
- âPersonal Dataâ has the meaning given in Article 4(1) GDPR.
- âPolicyâ or âPrivacy Policyâ means this document.
- âProcessingâ (and its cognate expressions) has the meaning given in Article 4(2) GDPR.
- âServicesâ means the Application, the Website, and any related services We provide, including Subscription handling.
- âStripeâ means Stripe Payments Europe Limited, an Irish entity within the Stripe group of companies, acting as Our payment processor.
- âSub-Processorâ means any Processor engaged by Us to Process Personal Data on Our behalf.
- âSubscriptionâ means a recurring agreement to access the Pro Plan in exchange for a periodic Subscription Fee, as defined in the Terms of Service.
- âTelemetryâ has the meaning set out in Section 5.1(b).
- âTerms of Serviceâ means Our separately published Terms of Service, available at https://www.noteastic.app/en/legal/terms-of-service.
- âUserâ, âYouâ, or âYourâ means an individual who uses the Services.
- âWebsiteâ means the website located at noteastic.app and its subdomains.
- âWebsite Dataâ has the meaning set out in Section 5.1(f).
1.2 Interpretation
(a) Headings are for convenience only and do not affect interpretation.
(b) References to a Section are to a section of this Policy unless stated otherwise.
(c) The singular includes the plural and the plural includes the singular.
2. Controller Identity and Contact
The Controller of Personal Data Processed under this Policy is:
Noteastic OG
Anton-Baumgartner-StraĂe 44, C8/1504
1230 Wien, Ăsterreich
- Firmenbuch (Companies Register) Number: FN 644438 d (Handelsgericht Wien)
- UID-Nummer (VAT identification number): ATU81638239
- Privacy contact: privacy@noteastic.app
- General contact: office@noteastic.app
We have not appointed a Data Protection Officer. We are not required to do so under Article 37 GDPR given Our size, structure, and Processing activities. The privacy contact above is the designated point of contact for all data-protection matters.
3. Scope of this Policy
This Policy applies to all Processing of Personal Data by Us in connection with:
(a) the Application, including telemetry collected before and after Account creation;
(b) Your Account;
(c) the Subscription and One-Time Purchase mechanics relating to the Pro Plan, including payment processing through Stripe;
(d) the Website;
(e) Our correspondence with You; and
(f) inbound feedback through public channels (see Section 14).
This Policy does not apply to:
(g) information You choose to publish through third-party platforms (for example, on subreddits or the Microsoft Store review surface) where We do not control the platform; or
(h) Processing performed by Stripe, Microsoft, Google, or other third parties acting as Independent Controllers in respect of their own services. Such Processing is governed by those third partiesâ privacy notices.
4. Minimum Age
4.1 Sixteen-year minimum
The Application is not directed at, and not intended for, persons under sixteen (16) years of age. You must be at least 16 to use the Services.
4.2 No knowing collection from minors
We do not knowingly collect Personal Data from persons under 16. If We become aware that We have collected Personal Data from a person below that age, We will delete it without undue delay and close any associated Account.
4.3 Higher local thresholds
Where the law in Your country of residence imposes a higher minimum age for the use of online services or for the provision of Personal Data, that higher age applies to You.
5. Personal Data We Process
5.1 Categories
We Process the following categories of Personal Data:
(a) Account Data â information You provide or generate in the course of creating and maintaining an Account: email address, given name, family name, hashed password (where applicable), unique anonymous user identifier, the identity-provider source (email/password, Google OAuth, Microsoft OAuth), email-verification status, Account creation timestamp, last-sign-in timestamp.
(b) Telemetry â data concerning the performance, stability, and use of the Application:
- crash reports and diagnostic logs;
- application-start and application-stop events;
- anonymised feature-usage events (including, with effect from the Effective Date, usage events relating to Pro Plan features);
- device metadata: device family, device form factor, operating-system version;
- network metadata: IP address (truncated where reasonably practicable for analytic Processing, retained in full where required for diagnostic purposes), language, approximate geolocation derived from IP;
- a unique anonymous user identifier (which You may, but are not required to, share with Us in connection with a support request).
(c) Attribution Data â Your responses, where You provide them, to the in-Application attribution question (âWhere did You hear about Us?â) and the in-Application student question (whether You are a student and Your field of study).
(d) Correspondence Data â the content of any communication You send to Us at office@noteastic.app or privacy@noteastic.app or another published address, together with the senderâs email address and the timestamp.
(e) Feedback Data â feedback that You voluntarily submit through the in-Application feedback mechanism, including the verbatim message and, where You provide it, an email address for Us to follow up.
(f) Website Data â data collected when You visit the Website, where You have accepted analytics cookies (Section 11), via PostHog: page visits, click events, session duration, browser metadata, IP address, language, referrer, UTM parameters (source, medium, campaign, owner).
(g) Billing Data â data generated by and necessary for the Subscription or One-Time Purchase lifecycle:
- a Stripe customer identifier stored on Your Account record;
- per-entitlement records containing: the Plan code, the entitlement kind (subscription, one-time purchase, or grant), the entitlement status (such as active, trial, or grace), the current Billing-Period end date where applicable (a One-Time Purchase is perpetual and has no Billing-Period end date), and a Stripe reference identifier (a subscription identifier for a Subscription, or a payment-intent identifier for a One-Time Purchase);
- a webhook event ledger containing the raw Stripe event payloads received by Us for idempotent Processing and audit.
(h) Statutory Records â Invoices and related billing records as retained under § 132 of the Austrian Federal Tax Code (Section 9.4).
(i) Currency-Geolocation Data â the IP address of the device from which You access the pricing or checkout interface, whether in the Application or on the Website. This IP address is Processed transiently and solely to resolve the country associated with it, so that prices may be displayed to You in the currency likely relevant to You. The IP address is resolved against a locally held, offline geolocation database queried within Our own infrastructure; it is not transmitted to any third party for this purpose. Only the country is derived (no more granular location, such as region or city, is determined), only the resulting country and currency are returned, and the IP address is not stored, logged, or associated with You in connection with this purpose. The currency so determined is a default suggestion only; You may select a different available currency at checkout.
(j) Newsletter Data â where You subscribe to Our optional Newsletter, data generated by and necessary for the management and delivery of that Newsletter:
- the content categories You have selected, namely one or more of: product updates, tips and tricks, technical announcements, company news, and Beta Programme communications;
- the timestamps at which You opted in and at which You last updated Your Newsletter preferences;
- a persistent, unique unsubscribe token generated for Your subscription, which enables one-click unsubscription from any Newsletter email without requiring You to sign in;
- a per-recipient delivery record generated for each Newsletter dispatch, containing a snapshot of the recipient email address and language locale taken at the time of sending, the delivery status, the number of delivery attempts, and the time of successful dispatch.
5.2 What We do NOT store
We do not store on Our own systems any of the following, all of which remain exclusively with Stripe:
(a) card numbers, the last four digits of card numbers, expiry dates, or card verification values (CVC);
(b) payment-method tokens beyond the abstract Stripe references in Section 5.1(g);
(c) billing address details beyond what is needed to render an Invoice;
(d) tax identification numbers (the Pro Plan is currently sold B2C only);
(e) bank account numbers or SEPA mandate details.
5.3 No special-category data
We do not Process any special category of Personal Data within the meaning of Article 9(1) GDPR (such as data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data, health data, or data concerning sex life or sexual orientation).
6. Purposes and Legal Bases for Processing
6.1 Mapping
For each Processing purpose, We set out below the categories of Personal Data Processed and the legal basis under Article 6(1) GDPR.
| # | Purpose | Categories of Personal Data | Legal Basis |
|---|---|---|---|
| 1 | Creation, authentication, and maintenance of Your Account | Account Data | Art. 6(1)(b) GDPR â performance of a contract |
| 2 | Provision of the Application to You | Account Data; Telemetry | Art. 6(1)(b) GDPR â performance of a contract |
| 3 | Verification of Your email address | Account Data | Art. 6(1)(b) GDPR â performance of a contract |
| 4 | Sending transactional communications relating to the Account (e.g., email verification, welcome message) | Account Data | Art. 6(1)(b) GDPR â performance of a contract |
| 5 | Diagnosis and resolution of errors and defects in the Application | Telemetry | Art. 6(1)(f) GDPR â legitimate interests (maintaining a reliable Service) |
| 6 | Statistical evaluation of feature usage for product improvement (including Pro Plan feature usage) | Telemetry; Attribution Data | Art. 6(1)(f) GDPR â legitimate interests (improving the Application) |
| 7 | Statistical evaluation of Website usage and acquisition channels where You have accepted the Website analytics banner | Website Data | Art. 6(1)(a) GDPR â consent |
| 8 | Evaluation of in-Application attribution responses | Attribution Data; Telemetry | Art. 6(1)(f) GDPR â legitimate interests (understanding how Users discover the Application) |
| 9 | Consideration and implementation of user-submitted Feedback | Feedback Data; Correspondence Data | Art. 6(1)(f) GDPR â legitimate interests (improving the Application) |
| 10 | Sending Our optional Newsletter (product updates, tips and tricks, technical announcements, company news, and Beta Programme communications) to Users who have subscribed to the relevant content categories | Account Data (email, given name); Newsletter Data | Art. 6(1)(a) GDPR â consent |
| 11 | Processing of payment and execution of the Subscription or One-Time Purchase contract (including initial purchase, Trial Period management, automatic renewal, plan changes, cancellation, and refund) | Billing Data; Account Data (email) | Art. 6(1)(b) GDPR â performance of a contract |
| 12 | Sending transactional Subscription and One-Time Purchase communications (purchase receipt, renewal receipt, Trial-Period-ending notice, renewal reminder, payment-failure notice, expiring-card notice, cancellation confirmation, refund confirmation, price-change notice) directly or through Stripe | Account Data (email); Billing Data | Art. 6(1)(b) GDPR â performance of a contract |
| 13 | Issuing Invoices and retaining Invoices and other billing records | Billing Data; Statutory Records | Art. 6(1)(c) GDPR â legal obligation (§ 132 Bundesabgabenordnung) |
| 14 | Determination, collection, and reporting of value-added tax via the EU One-Stop-Shop scheme | Billing Data | Art. 6(1)(c) GDPR â legal obligation |
| 15 | Fraud prevention and risk management in respect of Subscription and One-Time Purchase payments (via Stripe Radar, Base tier) | Billing Data; transaction metadata (Stripe-side: IP address, device fingerprint, behavioural signals) | Art. 6(1)(f) GDPR â legitimate interests (preventing fraudulent transactions; safeguarding the integrity of the payment mechanism) |
| 16 | Determining the currency in which prices are displayed to You, by resolving the IP address of the device accessing the pricing or checkout interface (in the Application or on the Website) to a country against a locally held, offline geolocation database | Currency-Geolocation Data (IP address, Processed transiently) | Art. 6(1)(f) GDPR â legitimate interests (presenting prices in the currency likely relevant to You and reducing confusion at the point of sale; You may select a different available currency at checkout) |
| 17 | Compliance with other legal obligations not covered by rows 13 or 14 | As required | Art. 6(1)(c) GDPR â legal obligation |
| 18 | Establishment, exercise, or defence of legal claims | As necessary | Art. 6(1)(f) GDPR â legitimate interests |
| 19 | Keeping a record of Your Newsletter consent and of any subsequent withdrawal (unsubscription), including the persistent unsubscribe token, in order to demonstrate the lawfulness of Newsletter Processing and to give effect to Your withdrawal by suppressing further Newsletter emails | Newsletter Data (consent and withdrawal record) | Art. 6(1)(f) GDPR â legitimate interests (accountability under Article 7(1) GDPR and giving effect to Your withdrawal) |
6.2 Provision of Personal Data is voluntary but contractually required
Provision of Account Data and (in respect of the Pro Plan) Billing Data is voluntary, but without it We cannot perform the contract: an Account cannot be created without the relevant Account Data, and a Pro Subscription or One-Time Purchase cannot be concluded without the relevant Billing Data.
6.3 Telemetry before Account creation
Telemetry described in Section 5.1(b) is collected from the device on which the Application is installed before and independently of Account creation. The legitimate-interests assessment supporting this collection is available on request to privacy@noteastic.app.
6.4 Newsletter subscription is optional and separate from the contract
Subscription to the Newsletter (Section 5.1(j)) is entirely optional. It is not a condition of creating an Account, of using the Application, or of purchasing or maintaining the Pro Plan, and We do not make the performance of any contract conditional on Your consent to receive the Newsletter. You may subscribe or decline freely, and the sole legal basis on which We send the Newsletter is Your consent under Article 6(1)(a) GDPR (see also Article 7(4) GDPR on the prohibition of bundling such consent with a contract).
You may withdraw Your consent and unsubscribe at any time, with effect for the future and without affecting the lawfulness of Newsletter emails sent before the withdrawal. Every Newsletter email contains a one-click unsubscribe mechanism that operates without requiring You to sign in; You may also withdraw Your consent by adjusting Your Newsletter preferences in the Application or by contacting Us at privacy@noteastic.app. Any record We retain after You unsubscribe is limited to what is necessary to give effect to Your withdrawal and to demonstrate compliance (Section 6.1, row 19, and Section 9.2).
7. Recipients and Sub-Processors
7.1 Confidentiality and contracts
Where We share Personal Data with Sub-Processors, We do so under a written contract that requires the Sub-Processor to Process Personal Data only on Our documented instructions, to maintain confidentiality, to implement appropriate technical and organisational measures, and to comply with the Sub-Processor obligations imposed by Article 28 GDPR.
7.2 Sub-Processors
The following Sub-Processors Process Personal Data on Our behalf:
| Sub-Processor | Role | Personal Data Processed | Location |
|---|---|---|---|
| Microsoft Ireland Operations Ltd (Azure App Service) | Hosting of back-end API | Account Data; Correspondence Data; Telemetry in transit; Billing Data in transit | EEA (Ireland) |
| Microsoft Ireland Operations Ltd (Azure Database for PostgreSQL) | Primary database | Account Data; Billing Data | EEA (Ireland) |
| Microsoft Ireland Operations Ltd (Azure Monitor, Application Insights) | Telemetry collection; diagnostic logging; error reporting | Telemetry | EEA (Ireland) |
| Microsoft Ireland Operations Ltd (Azure Communication Services) | Sending transactional emails (Account and Subscription) and, where You have subscribed, delivering Our optional Newsletter, via the same email relay | Account Data (email, given name); Newsletter Data | EEA (Europe region) |
| Microsoft Ireland Operations Ltd (Azure Key Vault, Entra ID, Static Web Apps, Azure DNS) | Supporting infrastructure (secrets, administrator identity, Website hosting, DNS) | Limited incidental exposure | EEA (Ireland) |
| Stripe Payments Europe Limited (Ireland) | Payment processing, Subscription billing, Stripe Tax, Customer Portal, Stripe Radar (Base), Stripe Billing, transactional billing communications | Billing Data; Account Data (email); transaction metadata; IP address; device fingerprint | EEA (Ireland); see Section 8 for any onward transfer to Stripe, Inc. (United States) |
| PostHog Inc. (via first-party reverse proxy at anal.noteastic.app) | Website analytics | Website Data | EEA (PostHog Cloud EU, Frankfurt) |
| Grafana Labs, Inc. | Observability and log aggregation | Telemetry | EEA (EU Cloud stack) |
| Google LLC (Google Workspace / Gmail) | Receipt and storage of inbound email | Correspondence Data | EEA (Google Workspace EU data-residency) |
7.3 Independent Controllers
Certain third parties Process Personal Data as Independent Controllers in respect of their own services and not on Our behalf. In particular:
(a) Stripe acts as Independent Controller for the purposes of:
(i) fraud prevention and risk scoring under Stripe Radar (in respect of the elements of that Processing that fall outside the scope of Our instructions);
(ii) regulatory compliance, including know-your-customer (KYC), anti-money-laundering, and sanctions screening obligations imposed on Stripe under European Union and Member State financial-services law; and
(iii) the sending of Stripe-direct emails to You (purchase receipt, renewal receipt, refund confirmation, payment-failure notice, renewal reminder, Trial-Period-ending notice, expiring-card notice).
In these capacities, Stripe Processes Personal Data subject to its own published privacy policy. We recommend that You review it at https://stripe.com/privacy.
(b) Microsoft Corporation acts as Independent Controller for Microsoft Store services made available to You as a Microsoft Store account-holder, including Microsoft Store reviews and Microsoft Store telemetry available to Us via Partner Center.
(c) Google LLC and Microsoft Corporation act as Independent Controllers in respect of the third-party authentication flows referenced in Section 15.
7.4 Disclosures required by law
We may disclose Personal Data to public authorities where required to do so by binding order of a competent authority or by applicable law.
7.5 Changes to the Sub-Processor list
We may add or replace Sub-Processors. Where We do so in connection with paid Subscriptions, We will update this Section 7.2 in advance of any new Processing.
8. International Transfers
8.1 EEA primary residency
Personal Data is Processed within the EEA. Our principal Sub-Processors operate from the EEA, with data residency in Ireland or another EEA Member State (see Section 7.2).
8.2 Onward transfers in respect of Stripe
Although Stripe Payments Europe Limited is Our contracting party and operates from Ireland, certain onward transfers to Stripe, Inc. (United States) or other Stripe group entities outside the EEA may occur in the course of Stripe providing the Subscription-billing service. Where such transfers occur:
(a) Stripe relies on the Standard Contractual Clauses adopted by the European Commission under Article 46(2)(c) GDPR; and, where applicable;
(b) Stripe, Inc. is certified under the EUâU.S. Data Privacy Framework or its successor instrument; further information is published by Stripe at https://stripe.com/en-at/legal/data-privacy-framework.
8.3 PostHog and Grafana
PostHog Inc. and Grafana Labs, Inc. are incorporated in the United States but operate the Processing on EEA infrastructure. Standard Contractual Clauses apply to any parent-entity access that would amount to a transfer.
8.4 Schrems II awareness
We are aware of the limits imposed by the Court of Justice of the European Union in Schrems II (C-311/18) on transfers to jurisdictions affording lesser standards of protection. We rely on the Sub-Processors named above on the basis that they offer the safeguards required by Article 46 GDPR for any onward transfer.
9. Retention Periods
9.1 General principles
We retain Personal Data only for as long as necessary for the purpose for which it was Processed, unless a longer retention period is required by law or is necessary for the establishment, exercise, or defence of legal claims.
9.2 Specific retention periods
| Category | Retention Period |
|---|---|
| Account Data | For the duration of the Account; deleted on Account termination (immediate hard-delete, no grace period), subject to the carve-out in Section 9.4 |
| Telemetry and diagnostic data | 365 days from collection |
| Currency-Geolocation Data | Not stored. The IP address is Processed transiently in memory to derive the associated country and is discarded immediately thereafter; it is not retained, logged, or associated with You for this purpose |
| Website analytics data held by Sub-Processor (PostHog) | 1 year from collection |
| Feedback archives (Reddit, Microsoft Store reviews, external channels) | 3 years from the underlying communication date |
| Email correspondence at published contact addresses | 3 years from receipt |
| Newsletter subscription and consent record (selected categories, opt-in and update timestamps, unsubscribe token) | For as long as You maintain an Account. On unsubscription the record is retained, as a record of Your consent and its withdrawal (Section 6.1, row 19), and is deleted when Your Account is terminated |
| Newsletter delivery records (per-recipient dispatch log: email and locale snapshot, delivery status, delivery attempts, dispatch time) | 30 days from the dispatch of the relevant Newsletter, after which the record is deleted or anonymised |
| Billing Data (Stripe customer identifier, Subscription and One-Time Purchase records, webhook event ledger, transaction history) | 7 years from the end of the financial year in which the underlying transaction was completed, in accordance with § 132 of the Austrian Federal Tax Code; see Section 9.4 |
| Invoices | 7 years from the end of the financial year in which the Invoice was issued, in accordance with § 132 of the Austrian Federal Tax Code |
| Personal Data required to be retained by other applicable law (e.g., for tax or audit purposes) | For the period prescribed by that law |
9.3 Anonymisation as an alternative to deletion
Where Telemetry or Website Data can be effectively anonymised within the meaning of Recital 26 GDPR, We may retain the resulting non-personal data indefinitely for statistical purposes.
9.4 Carve-out for Billing Data and statutory retention
The seven-year retention requirement imposed by § 132 of the Austrian Federal Tax Code constitutes a legal obligation under Article 6(1)(c) GDPR. Notwithstanding any other provision of this Policy and notwithstanding Your exercise of the right of erasure under Article 17 GDPR, Billing Data and Invoices are retained for the statutory period, after which they are deleted or, where reasonable, fully anonymised. This carve-out is permitted under Article 17(3)(b) GDPR (Processing required for compliance with a legal obligation).
10. Your Rights as a Data Subject
10.1 Rights enumerated
Subject to the conditions and exceptions set out in the GDPR, You have the following rights in respect of Your Personal Data:
(a) the right of access, pursuant to Article 15 GDPR;
(b) the right to rectification, pursuant to Article 16 GDPR;
(c) the right to erasure (âthe right to be forgottenâ), pursuant to Article 17 GDPR, subject to Section 9.4;
(d) the right to restriction of Processing, pursuant to Article 18 GDPR;
(e) the right to data portability, pursuant to Article 20 GDPR;
(f) the right to object to Processing based on legitimate interests or direct marketing, pursuant to Article 21 GDPR;
(g) the right to withdraw consent at any time, pursuant to Article 7(3) GDPR, without affecting the lawfulness of Processing carried out before the withdrawal; and
(h) the right to lodge a complaint with a supervisory authority, as further described in Section 19.
10.2 Exercise
To exercise any of these rights, please contact Us at privacy@noteastic.app. We will respond within the time limits set by Article 12(3) GDPR. We may request information reasonably necessary to confirm Your identity before responding.
10.3 No fee
We do not charge a fee for the exercise of Data Subject rights unless a request is manifestly unfounded or excessive, in which case We may charge a reasonable fee or refuse the request in accordance with Article 12(5) GDPR.
10.4 Erasure and statutory retention
The right of erasure under Article 17 GDPR is qualified by Article 17(3)(b), which preserves Processing required for compliance with a legal obligation to which the Controller is subject. Accordingly, where You exercise the right of erasure:
(a) Account Data, Telemetry, Correspondence Data, Feedback Data, Attribution Data, and Website Data attributable to You are deleted (or anonymised) in accordance with Section 9;
(b) Billing Data and Invoices are retained for the period prescribed by § 132 of the Austrian Federal Tax Code (see Section 9.4) and deleted thereafter.
11. Cookies and Similar Technologies
11.1 Application
The Application does not use cookies. Telemetry is collected through native operating-system mechanisms and is governed by Section 5.1(b) and Section 6.1.
11.2 Website
The Website uses cookies and similar technologies categorised as follows:
(a) Strictly necessary cookies â required for the technical operation of the Website. Used without consent on the legal basis of Article 6(1)(f) GDPR and the corresponding exception under the ePrivacy Directive.
(b) Analytics cookies â used to collect Website Data through PostHog (Section 5.1(f)). Set only after You have accepted them through the Website cookie banner. The legal basis is Article 6(1)(a) GDPR (consent) and the corresponding consent requirement under the ePrivacy Directive.
11.3 No advertising tracking or email tracking pixels
The Website does not use marketing or retargeting cookies, advertising pixels, or comparable identifiers. Our Newsletter emails likewise contain no tracking pixel, no open-tracking mechanism, and no click-tracking or link-rewriting: We do not measure whether You open a Newsletter email or which links You follow. The Newsletter is delivered through the same email relay used for transactional mail (Section 7.2), with no engagement-tracking feature of that relay enabled.
11.4 Subscription checkout
Stripe Checkout, used in the course of subscribing to the Pro Plan, may set cookies on its hosted-checkout domain in accordance with Stripeâs own published cookie notice. Those cookies are not set by Us and are not under Our control.
11.5 Withdrawal of consent
You may withdraw cookie consent at any time by clearing cookies through Your browser settings and revisiting the Website to make a fresh choice.
12. Automated Decision-Making and Profiling
12.1 No Article 22 decisions made by Us
We do not make decisions concerning You based solely on automated Processing, including profiling, that produce legal effects concerning You or similarly significantly affect You within the meaning of Article 22(1) GDPR.
12.2 Stripe Radar
In the course of payment processing, Stripe operates the Stripe Radar fraud-prevention system, which assigns a risk score to each transaction. Stripe may decline transactions on the basis of that score. We do not control the score and do not make payment-acceptance decisions solely on its basis; where Stripe declines a transaction, We may, in appropriate circumstances, review the decline and reinstate the transaction following manual review. The role of Stripe Radar is further described in Section 7.3.
13. Security
13.1 Technical and organisational measures
We implement appropriate technical and organisational measures to protect Personal Data against unauthorised or unlawful Processing, accidental loss, destruction, or damage, taking into account the nature, scope, context, and purposes of Processing and the risks to natural persons. These measures include:
(a) hashing of Personal Data used for Telemetry attribution where reasonably practicable;
(b) encryption in transit (TLS) for all data flows between the Application, the back-end API, and Sub-Processors;
(c) encryption at rest for the primary database and for backups;
(d) restriction of administrator access to production systems through Microsoft Entra ID and the principle of least privilege;
(e) operation of the primary database in a private network without public internet exposure;
(f) segregation of duties between Subscription / Billing Data flows and Account Data flows; and
(g) regular review of access logs and infrastructure audit events.
13.2 Breach notification
In the event of a Personal Data breach, We will notify the competent supervisory authority within 72 hours of becoming aware of the breach, as required by Article 33 GDPR, and We will notify affected Data Subjects without undue delay where the breach is likely to result in a high risk to their rights and freedoms, as required by Article 34 GDPR.
14. Feedback from External Channels
We Process Personal Data made publicly available on the following channels for the purpose of considering user-submitted feedback in the development of the Application:
(a) Reddit: usernames, post or comment content, and direct messages that express opinions, requests, or feedback about Noteastic. Legal basis: Article 6(1)(f) GDPR (legitimate interests).
(b) Email correspondence at published contact addresses: as set out in Sections 5.1(d) and 9.2.
(c) Microsoft Store reviews: review content and the reviewerâs display name where shown in Partner Center. Legal basis: Article 6(1)(f) GDPR (legitimate interests).
Feedback Data is archived in a manual spreadsheet outside of the Account environment and is not linked to a Userâs Account Data unless You expressly identify Yourself for that purpose.
15. Third-Party Authentication
Where You choose to create or sign in to Your Account using Google OAuth or Microsoft OAuth, the relevant provider transmits to Us a limited set of profile attributes (typically email address, given name, and family name) for the purpose of provisioning Your Account. We receive that data as Controller and Process it as Account Data; the provider Processes its own data flow as Independent Controller under its own privacy notice.
16. Microsoft Store
Where data flows from Microsoft Corporation to Us through Partner Center in connection with the Microsoft Store distribution of the Application (for example, aggregated acquisition data, demographic aggregates, and crash-report metadata), Microsoft acts as Independent Controller and We Process the data made available to Us as Controller for the purposes set out in Section 6.
17. Changes to this Privacy Policy
17.1 Right to amend
We may amend this Policy at any time.
17.2 Notice for material changes
(a) For material changes, We will give You no less than thirty (30) calendar daysâ prior notice by email to the address associated with Your Account and, where practicable, by in-Application notice.
(b) Where the legal basis for a new Processing activity is consent, We will obtain that consent before the new Processing commences.
17.3 Non-material changes
For non-material changes, the amended Policy takes effect on publication.
17.4 Effective date
The effective date of the current version is shown at the head of this Policy.
18. How to Contact Us
For any matter arising under this Policy, including the exercise of Data Subject rights, please contact Our privacy contact at privacy@noteastic.app or write to:
Noteastic OG, Anton-Baumgartner-StraĂe 44, C8/1504, 1230 Wien, Ăsterreich
19. Supervisory Authority
You have the right to lodge a complaint with a supervisory authority pursuant to Article 77 GDPR. The supervisory authority of the Controllerâs establishment is:
Ăsterreichische Datenschutzbehörde
Barichgasse 40â42
1030 Wien, Ăsterreich
www.dsb.gv.at
If You are resident in another Member State of the European Union or the European Economic Area, You may alternatively lodge a complaint with the supervisory authority in Your country of residence or place of work.
20. Severability and Governing Law
(a) If any provision of this Policy is held to be invalid, unenforceable, or void, the remaining provisions continue in full force and effect.
(b) This Policy is governed by the laws of the Republic of Austria, without prejudice to the application of the GDPR and other applicable European Union law, and without prejudice to the right of Data Subjects under Article 79 GDPR to seek judicial remedy in the courts of their habitual residence.
End of the Privacy Policy.