Privacy notice
This notice sets out what personal data we collect when you join the TasteLog waitlist, why we collect it, how long we keep it, who else receives it, and how to exercise your rights.
Who we are
TasteLog is made by Noxysoft, a one-person software studio registered in the Netherlands. Noxysoft determines the purposes and means of the processing described here, and is the controller of your personal data.
- Noxysoft
- KvK 92505481
- btw-id NL004957538B97
- contact@noxysoft.com
We have not appointed a data protection officer. Article 37 of the General Data Protection Regulation (GDPR) requires one where an organisation monitors individuals on a large scale, or processes special category data as a core activity. A waitlist does neither.
What we collect
Joining the waitlist records the following data.
- Your email address
- Used to send you updates about TasteLog while it is being built, and to notify you on the day it launches. The legal basis is your consent, under Article 6(1)(a) of the GDPR. You may withdraw it at any time.
- The date and time you signed up
- Recorded when your entry is created. The 24-month retention period below runs from this date. Kept for as long as your address is kept.
- The consent wording you accepted
- The exact text shown beneath the form, its version identifier, and the time you submitted it. This allows us to show what you were told at the time, rather than what the page says now.
- Whether your address has reached Keila
- The time your address was passed to Keila, identified below, so that it can send you the confirmation email, or the time Keila declined it. This tells the service which addresses still have to be passed on, so that none is sent twice. Kept for as long as your address is kept.
- Your IP address
- Recorded automatically when you submit the form. It serves two purposes: limiting how often the form can be submitted from one address, and forming part of the consent record above.
- Your platform and browser
- Your browser sends a user-agent string with every request, identifying itself and the operating system it runs on. We do not store that string. We reduce it to two broad categories, such as windows and firefox, and store only those. They indicate which platform to develop for first, and which browsers the site must support. A string we do not recognise, or its absence, is recorded as other.
- The page you arrived from
- The referring page, and the campaign name if the link carried one. This indicates which of our own pages are effective. It is frequently empty.
The legal basis for the last three items is legitimate interest, under Article 6(1)(f) of the GDPR. The interests are as follows. Your IP address keeps the form usable, by making automated abuse detectable while it occurs, and evidences your consent, by recording who agreed and when. Your platform and browser direct our development effort. The page you arrived from indicates which of our pages are effective. You may object to any of these. See Your rights below.
Providing your address is voluntary. No statutory or contractual requirement applies. The only consequence of not providing it is that we cannot send you updates about TasteLog or notify you when it launches.
How long we keep it
We keep your address until the first of the following occurs:
- you ask us to remove you;
- TasteLog launches and the launch email has been sent;
- 24 months have passed since you signed up.
Using the removal form deletes your address from our database. One record is retained: Keila, identified below, keeps your address marked as unsubscribed. That record prevents you from being added to the list again in error. It is retained for as long as the list exists, is used for no other purpose, and no message is sent to any address it holds. You may ask us to delete it as well.
The legal basis for that record is legitimate interest, under Article 6(1)(f) of the GDPR. The interest is ensuring that a request not to be contacted continues to be honoured. It is not your consent, which by that point you have withdrawn.
Who else receives your data
We do not sell your email address, and we do not disclose it to any party for that party's own purposes.
The processors below hold it, because they run the infrastructure behind this site. They use it only to run the site, only on our instructions, and never for themselves. Each may use sub-processors of its own, bound by the same terms.
Some of them are American companies, so some of your data leaves the European Economic Area. Each entry below says whether that happens and what covers it. For the United States, the European Commission's adequacy decision covers only companies certified under the EU-U.S. Data Privacy Framework, which can be checked on the official participant list. If a certification lapses, the standard contractual clauses, terms the Commission approved for this purpose, apply instead.
Cloudflare
Serves this page and filters malicious traffic. Every request passes through its network, so your IP address reaches it on the way to us.
Leaves the EEA: yes. Cloudflare, Inc. is an American company, certified under the Data Privacy Framework. Cloudflare's data processing addendum, which applies to every account, holds the standard contractual clauses as the fallback.
Keila
Operates the mailing list. Your address is sent to Keila when you submit the form, so that Keila can send the confirmation email and, once you confirm, hold your address on the list.
Leaves the EEA: no. Keila GmbH is a German company and hosts the list in the European Union.
Railway
Runs the site and the service behind the form, from Amsterdam.
Leaves the EEA: yes. Railway Corporation is an American company, certified under the Data Privacy Framework, and states that its primary processing takes place in the United States. Railway's data processing addendum, which we have signed, holds the standard contractual clauses as the fallback.
Neon
Runs the database that stores your address, in Frankfurt, on machines it rents from Amazon Web Services.
Leaves the EEA: yes. Neon, LLC is part of Databricks, Inc., an American company whose staff can access the database in order to operate it. Databricks is certified under the Data Privacy Framework; on the participant list it appears under Databricks, not under Neon. The Databricks data processing addendum, which Neon's terms incorporate, holds the standard contractual clauses as the fallback.
Cookies
This site sets no cookies. It loads no analytics, trackers, embedded video, maps or fonts. Every file this page loads is served from tastelog.net. We store nothing about you on your device, although your browser retains copies of the page's own files for a period, as it does on any site. No data about you reaches our database unless you complete the form and submit it.
Requests are a separate matter. Every page you request passes through Cloudflare and then Railway, and both retain request logs recording what was requested, when, and the IP address and browser it was requested from. That is how the page is served, and how malicious traffic is filtered. Cloudflare also asks your browser to report failed requests back to it; successful requests are not reported. We read those logs in order to operate the site, and nothing in them is copied into our database.
If this changes, this page is updated on the same day.
Profiling and automated decisions
We carry out no profiling, and no automated decision-making within the meaning of Article 22 of the GDPR. Your address is held in a list until we send an email to it. Nothing scores, sorts or ranks you against anyone else.
One process is automatic. If the same IP address submits the form repeatedly within a few minutes, the form rejects the later submissions until the rate falls. It reads how many requests arrived and from which address, not your identity or the content of your submission, and the only outcome it determines is whether that submission is accepted.
Your rights
Two requests are commonly confused. Their effects differ.
To stop receiving email, use the removal form. It requires your address only, and takes effect immediately.
To have your data erased, including the unsubscribed record described above, write to contact@noxysoft.com. Erasure requests are carried out manually and are not immediate. Once completed, neither we nor Keila retain any record of you.
Writing to the same address, you may also ask us to:
- confirm what personal data we hold about you, and provide a copy of it;
- correct it, if it is inaccurate;
- restrict our use of it without deleting it;
- stop relying on legitimate interest for your IP address, your platform and browser, or the page you arrived from;
- provide your data in a portable format, or transmit it to another controller.
You need not give a reason, and no fee applies. Withdrawing your consent does not affect the lawfulness of email sent before you withdrew it. We respond within one month, which is the period set by Article 12(3) of the GDPR.
How to complain
You may raise a concern with us directly, using the contact details above. You also have the right to lodge a complaint with a supervisory authority. In the Netherlands this is the Autoriteit Persoonsgegevens.
Changes to this notice
We update this page when our processing changes. The date below is the date of the last change.
Last updated 7 September 2026.
Back to the front page