Privacy Policy
How PageWard collects, uses and protects personal data, under the EU General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG).
Last updated: 22 July 2026
Fields marked TO FILL need real details. This policy should be reviewed by a lawyer before PageWard opens to paying customers, and updated whenever a new processor (payment, email, analytics) is added.
1. Who is responsible
The controller responsible for processing your personal data is:
Jeremy Cabaret
TO FILL — street and number, postal code, Obertrum am See, Austria
Email: privacy@pageward.dev TO FILL — confirm this mailbox exists
Full provider details are in the Impressum.
2. Scope
This policy covers two things:
- The marketing website at pageward.dev — the page you are reading.
- The PageWard application at app.pageward.dev — currently in a closed pilot with invited design partners.
3. What we collect and why
3.1 Marketing website — no data collected
The marketing website at pageward.dev has no sign-up form, no newsletter and no mailing list. We do not collect, store or process any personal data through it. The only way to contact us is a plain email link — if you choose to write to us, we simply receive and reply to your email, as with any normal correspondence.
If we later add a sign-up or early-access list, this policy will be updated — naming the provider used and the legal basis — before any address is collected.
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Email correspondence — only if you email us directly | Answering your enquiry | Legitimate interest (Art. 6(1)(f)) in responding to enquiries; pre-contractual steps (Art. 6(1)(b)) where relevant | As long as needed to handle the enquiry and any follow-up |
3.2 Server logs (both website and application)
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| IP address, browser/user agent, requested URL, timestamp | Delivering the site, security, abuse prevention, diagnosing errors | Legitimate interest (Art. 6(1)(f)) in operating a secure service | Up to 30 days, per our hosting providers' standard retention |
3.3 Application accounts and content (app.pageward.dev)
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Email address (and optional password, stored only as a secure hash) | Authentication — signing you in via magic link or password | Contract / pre-contractual measures (Art. 6(1)(b)) | Until the account is deleted |
| Uploaded HTML files and their metadata (title, description, timestamps) | Providing the core service — storing and serving your pages | Contract (Art. 6(1)(b)) | Until you delete the page. There is no self-service account deletion during the pilot — email privacy@pageward.dev and we will delete your files and records manually |
| Pilot membership — your email address and whether you hold an admin flag | Determining who is permitted to upload during the closed pilot | Contract (Art. 6(1)(b)) | Until the pilot ends or your account is deleted |
| Viewer allowlists — email addresses you authorise to view a page | Enforcing who may access a page | Contract (Art. 6(1)(b)); you are responsible for having a basis to share those addresses with us | Until removed by you or the page is deleted |
| View log — which authorised email opened which page, and when | Giving page owners a basic access record (a core, disclosed feature of the product) | Legitimate interest (Art. 6(1)(f)) in access transparency and security | Until the page or account is deleted |
A note on uploaded content: if you upload a file containing other people's personal data, you remain responsible for that data as its controller. We process it on your behalf as a processor. Please do not upload special-category data (health, biometric, political opinions, etc.) during the pilot.
What other people can see: anyone you grant access to a page will see the email address of the account that owns it.
3.4 Product metrics during the closed pilot
While PageWard is in its closed pilot, the operator can view aggregate usage metrics derived from the records above — including page titles, owner email addresses, viewer email addresses, and view counts — in order to judge whether the product actually works. The legal basis is legitimate interest (Art. 6(1)(f)) in developing and operating the service. The operator also has direct administrative access to the underlying database.
This is disclosed because it is real: it is not anonymised, and it spans all pilot participants. It ends when the closed pilot ends.
3.5 If someone shared a page with you
You may appear in our records without ever having signed up — because a PageWard user added your email address to a page's allowlist. Under Article 14 GDPR you're entitled to know:
- What we hold: your email address, which pages you were granted access to, and — if you opened one — the times you did so.
- Where it came from: the person who invited you, not from you.
- Why: so we can check you're allowed to open the page, and so its owner can see who accessed it.
- How long: until the owner removes you, or deletes the page.
- Your rights: all of those in section 8 below. Contact privacy@pageward.dev — though note that the page owner decides who may access their content, so requests about that decision are usually best directed to them.
For page owners: a record of who opened a document, visible to you, can constitute employee monitoring. In Austria and Germany, introducing such a system may require works-council consultation (§96 ArbVG, §87 BetrVG). That obligation sits with you as the employer, not with PageWard — but you should know it exists before rolling this out to a team.
4. Cookies
The marketing website sets no cookies and uses no analytics, tracking pixels or advertising tools. It loads no external fonts or third-party scripts.
The application sets strictly necessary cookies to keep you signed in — the session and refresh tokens issued by our authentication provider, Supabase. These are essential to provide a service you have actively requested, so under §165(3) TKG 2021 (Austria's ePrivacy implementation) and the GDPR they require no consent banner. We do not use cookies for analytics, profiling or advertising anywhere.
If we add analytics in future, this policy will be updated first, and consent will be requested where legally required.
5. Who we share data with (processors)
We do not sell personal data, and we do not share it for advertising. We use the following service providers, each bound by a data processing agreement:
| Provider | Role | Where data is processed |
|---|---|---|
| Vercel | Website and application hosting | Application functions run in the EU (Frankfurt). Edge routing that refreshes session cookies may run globally; it does not handle page content. |
| Supabase | Database, authentication, file storage | EU (Frankfurt, eu-central-1) |
| Email delivery provider | Sending sign-in (magic link) emails from login@pageward.dev | TO FILL — name the provider and its processing location |
We will disclose any additional processors here before they are used — including a payment provider once PageWard begins accepting payment.
6. Where your data is stored
Personal data and uploaded content are stored and processed in the European Union (Frankfurt, Germany).
Transfers outside the EU do occur, and we'd rather state it than hedge. Our hosting providers are US-established companies, and the thin edge layer that refreshes your session cookie may execute outside the EU — in doing so it processes your email address. Transfers to the United States are therefore in scope. They are covered by the EU Standard Contractual Clauses and, where the provider is certified, the EU–US Data Privacy Framework. A copy of the safeguards is available on request from privacy@pageward.dev.
Do you have to give us this data?
Providing an email address is necessary to create an account — without it we cannot sign you in or provide the service. Everything else (page titles, descriptions, who you share with) is entirely up to you.
7. How we protect data
- All traffic is encrypted in transit (HTTPS); data is encrypted at rest by our providers.
- Uploaded pages are stored in a private store and served only through an authenticated route — never from a public URL.
- Access is enforced at the database level (row-level security), so a user can only reach pages they own or have been granted access to.
- Uploaded pages run in a sandboxed frame with an isolated origin, so their code cannot read your PageWard session or reach other pages.
8. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate or incomplete data
- Erase your data ("right to be forgotten")
- Restrict or object to processing based on legitimate interest
- Data portability — receive your data in a structured, machine-readable format
- Withdraw consent at any time, without affecting processing carried out beforehand
To exercise any of these, email privacy@pageward.dev. We will respond within one month, extendable by up to two further months for complex requests — we'll tell you within the first month if that applies. We send no marketing email, so there is nothing to unsubscribe from.
Where we rely on legitimate interest — that is, server logs, the page view log, and pilot product metrics — you have the right to object to that processing at any time, on grounds relating to your particular situation. Email privacy@pageward.dev and we will stop unless we can show compelling legitimate grounds that override your interests.
9. Right to complain
If you believe your data has been processed unlawfully, you may lodge a complaint with the Austrian supervisory authority:
Österreichische Datenschutzbehörde
Barichgasse 40–42, 1030 Vienna, Austria
www.dsb.gv.at · dsb@dsb.gv.at
10. Automated decision-making
We do not use automated decision-making or profiling that produces legal or similarly significant effects.
11. Children
PageWard is a business tool and is not directed at children. We do not knowingly collect data from minors. (For reference, Austria sets the age of consent for information-society services at 14 under §4(4) DSG — lower than the GDPR default of 16.)
12. Changes to this policy
We may update this policy as the product develops — particularly when adding payment, email or analytics providers. The "last updated" date at the top always reflects the current version. Material changes affecting registered users will be communicated by email.