PageWard ← Back to site
Legal

Privacy Policy

How PageWard collects, uses and protects personal data, under the EU General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG).

Last updated: 22 July 2026

⚠ Draft — complete before relying on this

Fields marked TO FILL need real details. This policy should be reviewed by a lawyer before PageWard opens to paying customers, and updated whenever a new processor (payment, email, analytics) is added.

1. Who is responsible

The controller responsible for processing your personal data is:

Jeremy Cabaret
TO FILL — street and number, postal code, Obertrum am See, Austria
Email: privacy@pageward.dev TO FILL — confirm this mailbox exists

Full provider details are in the Impressum.

2. Scope

This policy covers two things:

3. What we collect and why

3.1 Marketing website — no data collected

Current status

The marketing website at pageward.dev has no sign-up form, no newsletter and no mailing list. We do not collect, store or process any personal data through it. The only way to contact us is a plain email link — if you choose to write to us, we simply receive and reply to your email, as with any normal correspondence.

If we later add a sign-up or early-access list, this policy will be updated — naming the provider used and the legal basis — before any address is collected.

DataPurposeLegal basisRetention
Email correspondence — only if you email us directly Answering your enquiry Legitimate interest (Art. 6(1)(f)) in responding to enquiries; pre-contractual steps (Art. 6(1)(b)) where relevant As long as needed to handle the enquiry and any follow-up

3.2 Server logs (both website and application)

DataPurposeLegal basisRetention
IP address, browser/user agent, requested URL, timestamp Delivering the site, security, abuse prevention, diagnosing errors Legitimate interest (Art. 6(1)(f)) in operating a secure service Up to 30 days, per our hosting providers' standard retention

3.3 Application accounts and content (app.pageward.dev)

DataPurposeLegal basisRetention
Email address (and optional password, stored only as a secure hash) Authentication — signing you in via magic link or password Contract / pre-contractual measures (Art. 6(1)(b)) Until the account is deleted
Uploaded HTML files and their metadata (title, description, timestamps) Providing the core service — storing and serving your pages Contract (Art. 6(1)(b)) Until you delete the page. There is no self-service account deletion during the pilot — email privacy@pageward.dev and we will delete your files and records manually
Pilot membership — your email address and whether you hold an admin flag Determining who is permitted to upload during the closed pilot Contract (Art. 6(1)(b)) Until the pilot ends or your account is deleted
Viewer allowlists — email addresses you authorise to view a page Enforcing who may access a page Contract (Art. 6(1)(b)); you are responsible for having a basis to share those addresses with us Until removed by you or the page is deleted
View log — which authorised email opened which page, and when Giving page owners a basic access record (a core, disclosed feature of the product) Legitimate interest (Art. 6(1)(f)) in access transparency and security Until the page or account is deleted

A note on uploaded content: if you upload a file containing other people's personal data, you remain responsible for that data as its controller. We process it on your behalf as a processor. Please do not upload special-category data (health, biometric, political opinions, etc.) during the pilot.

What other people can see: anyone you grant access to a page will see the email address of the account that owns it.

3.4 Product metrics during the closed pilot

While PageWard is in its closed pilot, the operator can view aggregate usage metrics derived from the records above — including page titles, owner email addresses, viewer email addresses, and view counts — in order to judge whether the product actually works. The legal basis is legitimate interest (Art. 6(1)(f)) in developing and operating the service. The operator also has direct administrative access to the underlying database.

This is disclosed because it is real: it is not anonymised, and it spans all pilot participants. It ends when the closed pilot ends.

3.5 If someone shared a page with you

You may appear in our records without ever having signed up — because a PageWard user added your email address to a page's allowlist. Under Article 14 GDPR you're entitled to know:

For page owners: a record of who opened a document, visible to you, can constitute employee monitoring. In Austria and Germany, introducing such a system may require works-council consultation (§96 ArbVG, §87 BetrVG). That obligation sits with you as the employer, not with PageWard — but you should know it exists before rolling this out to a team.

4. Cookies

The marketing website sets no cookies and uses no analytics, tracking pixels or advertising tools. It loads no external fonts or third-party scripts.

The application sets strictly necessary cookies to keep you signed in — the session and refresh tokens issued by our authentication provider, Supabase. These are essential to provide a service you have actively requested, so under §165(3) TKG 2021 (Austria's ePrivacy implementation) and the GDPR they require no consent banner. We do not use cookies for analytics, profiling or advertising anywhere.

If we add analytics in future, this policy will be updated first, and consent will be requested where legally required.

5. Who we share data with (processors)

We do not sell personal data, and we do not share it for advertising. We use the following service providers, each bound by a data processing agreement:

ProviderRoleWhere data is processed
VercelWebsite and application hostingApplication functions run in the EU (Frankfurt). Edge routing that refreshes session cookies may run globally; it does not handle page content.
SupabaseDatabase, authentication, file storageEU (Frankfurt, eu-central-1)
Email delivery providerSending sign-in (magic link) emails from login@pageward.devTO FILL — name the provider and its processing location

We will disclose any additional processors here before they are used — including a payment provider once PageWard begins accepting payment.

6. Where your data is stored

Personal data and uploaded content are stored and processed in the European Union (Frankfurt, Germany).

Transfers outside the EU do occur, and we'd rather state it than hedge. Our hosting providers are US-established companies, and the thin edge layer that refreshes your session cookie may execute outside the EU — in doing so it processes your email address. Transfers to the United States are therefore in scope. They are covered by the EU Standard Contractual Clauses and, where the provider is certified, the EU–US Data Privacy Framework. A copy of the safeguards is available on request from privacy@pageward.dev.

Do you have to give us this data?

Providing an email address is necessary to create an account — without it we cannot sign you in or provide the service. Everything else (page titles, descriptions, who you share with) is entirely up to you.

7. How we protect data

8. Your rights

Under the GDPR you have the right to:

To exercise any of these, email privacy@pageward.dev. We will respond within one month, extendable by up to two further months for complex requests — we'll tell you within the first month if that applies. We send no marketing email, so there is nothing to unsubscribe from.

Your right to object

Where we rely on legitimate interest — that is, server logs, the page view log, and pilot product metrics — you have the right to object to that processing at any time, on grounds relating to your particular situation. Email privacy@pageward.dev and we will stop unless we can show compelling legitimate grounds that override your interests.

9. Right to complain

If you believe your data has been processed unlawfully, you may lodge a complaint with the Austrian supervisory authority:

Österreichische Datenschutzbehörde
Barichgasse 40–42, 1030 Vienna, Austria
www.dsb.gv.at · dsb@dsb.gv.at

10. Automated decision-making

We do not use automated decision-making or profiling that produces legal or similarly significant effects.

11. Children

PageWard is a business tool and is not directed at children. We do not knowingly collect data from minors. (For reference, Austria sets the age of consent for information-society services at 14 under §4(4) DSG — lower than the GDPR default of 16.)

12. Changes to this policy

We may update this policy as the product develops — particularly when adding payment, email or analytics providers. The "last updated" date at the top always reflects the current version. Material changes affecting registered users will be communicated by email.