Draft — pending legal review
This text describes how Annota works during the beta, but it has not been reviewed by a lawyer yet. Fields in square brackets will be filled in before public launch.
Legal · Privacy
Privacy policy
Last updated:
Annota is a visual feedback tool for web agencies: a client clicks an element on a staging site and leaves a comment, and the agency gets a task. This policy explains what personal data we process to make that work, why, for how long, and what rights you have under the GDPR (Regulation (EU) 2016/679).
01Who we are
The controller for the data described here is [Company name], registered office [Address], registration no. [Registration number]. You can reach us about anything in this policy at privacy@[domain].
For feedback that client reviewers leave on an agency's site, the agency decides why and how that feedback is collected. In that relationship the agency acts as controller and we act as its processor, processing the data only on the agency's instructions.
02What data we process, and from whom
Agencies joining the beta (waitlist). Agency name, contact name, work email, website, team size, number of active projects, the free-text description of how you want to use Annota, and the IP address the form was sent from (used for rate limiting).
Agency staff with an account. Email address, a password stored only as a PBKDF2 hash, and an audit log of actions taken in the dashboard (for example who changed a task's status, and when).
Client reviewers. The name and email the reviewer enters, their comments, screenshots of the staging page they are commenting on (form fields are masked before capture), optional voice notes of up to 60 seconds, and technical metadata such as browser, viewport size and the page URL.
We do not ask for special categories of data. Please don't include them in comments or voice notes.
03Why we process it, and on what legal basis
- Reviewing beta signups and contacting you about access: steps taken at your request before entering into a contract (Art. 6(1)(b)) and our legitimate interest in running a controlled beta (Art. 6(1)(f)).
- Providing the service (accounts, collecting feedback, turning it into tasks, sending transactional email such as invitations and deadline reminders): performance of the contract with the agency (Art. 6(1)(b)). For client reviewer data, we process it on the agency's behalf; the agency is responsible for its own legal basis.
- Security and abuse prevention (rate limiting by IP, hashed passwords, audit logs): legitimate interest in keeping the service and its users safe (Art. 6(1)(f)).
- Legal obligations, where a law requires us to keep or disclose data (Art. 6(1)(c)).
04How long we keep it
- Waitlist signups: until the request is handled, and at most [X months] afterwards if not approved.
- Staff accounts: for as long as the account is active, then deleted within [X days] of closure.
- Feedback, screenshots and voice notes: for as long as the agency keeps the project, or until the agency deletes them; deleted within [X days] after the agency's account ends.
- Audit logs: [X months], unless needed longer to investigate a security incident.
05Who else processes the data
We don't sell personal data and we don't share it for advertising. We use:
- Resend, to send transactional email (invitations, notifications, reminders).
- Hosting: the database is a self-hosted Convex instance that we operate on infrastructure provided by [Hosting provider, location].
Each provider is bound by a data processing agreement and only receives what it needs.
06International transfers
Some providers (for example the email provider) may process data outside the European Economic Area. Where that happens we rely on an adequacy decision or on the European Commission's Standard Contractual Clauses. [To be confirmed per provider.] You can ask us for a copy of the relevant safeguards.
07Your rights
You have the right to access your data, to have it corrected or deleted, to restrict or object to processing, to data portability, and to withdraw consent where processing is based on consent. Write to privacy@[domain]; we answer within one month.
If you left feedback as a client reviewer, you can also contact the agency that invited you, since it controls that data. We will help the agency answer your request.
You can also file a complaint with the Romanian data protection authority, ANSPDCP (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal), at dataprotection.ro, or with the authority in your own EU country.
09How we protect the data
- Form fields on staging pages are masked before a screenshot is taken.
- Reviewers reach a project through an access code set up by the agency.
- Staff passwords are stored only as PBKDF2 hashes, never in plain text.
- Important actions in the dashboard are written to an audit log.
- Data lives in a database we operate ourselves, with access limited to the people who need it.
10Contact and changes
Questions about this policy: privacy@[domain], or by post to [Company name], [Address].
If we change this policy in a meaningful way, we'll update the date at the top and tell account holders by email.