Privacy Policy
1. Who is responsible
The data controller is the individual author of takhiOS and the UIL Platform, an independent
researcher in Norway. There is no company and no legal entity. Privacy contact: [email protected]
(or [email protected] if a DPO is appointed).
2. Scope
This policy covers personal data processed through the websites and hosted services — including account signup for the Locker, uploaded image files, and server logs. It does not cover third-party sites the project links to, or software that runs only on your own machine and sends no data anywhere.
3. What is processed and why
| Data | Purpose | Legal basis |
|---|---|---|
| Account email address | Create and manage your Locker account, authenticate you, contact you about the service | Performance of a contract (Art. 6(1)(b) GDPR); legitimate interests (Art. 6(1)(f)) |
| Uploaded image files and associated metadata | Provide the storage/testing service you asked for | Performance of a contract (Art. 6(1)(b)) |
| IP address, user agent and request metadata in server/daemon logs | Operate the service, keep it secure, debug faults, prevent abuse | Legitimate interests (Art. 6(1)(f)) |
| Donation records (if any) | Process and account for a donation | Legitimate interests / legal obligation, as applicable |
No profiling and no automated decision-making with legal effect takes place. No data is sold.
4. Cookies and tracking
The websites do not set cookies for advertising and do not track you across sites. The project’s public claim is “no tracking, no cookies, no bullshit” and this policy must match it.
Exception to be listed here if it is ever enabled: the site includes an optional Cloudflare Web Analytics beacon (cookieless, no stored IP). It is currently disabled (empty token). If it is enabled, this section must state that it is active, name Cloudflare as the processor, and describe what it collects. Any analytics, cookie, pixel or telemetry added in future must be listed in this section before it goes live.
5. Retention
Images and account records are kept until the user or the operator deletes them. There is no automatic expiry in the current service; a defined retention period will be published before any paid service. Server logs are kept under the same approach. Data is deleted or anonymised when the purpose for it ends, unless the law requires longer storage.
6. Recipients and subprocessors
Data is processed by the following service providers on the author’s instructions:
- Hosting for the Locker and related services: Interserver, Inc., United States
- Website and object storage/CDN: Cloudflare, Inc., United States
- No other subprocessors are used today. New subprocessors will be listed here before they are used.
Each must have a data processing agreement in place. A current list is kept with this policy.
7. International transfers
Some providers may store or process data outside the EEA. Where that happens, a lawful transfer mechanism is required — for example an adequacy decision by the European Commission, or the EU Standard Contractual Clauses together with any required supplementary measures. The specific mechanism for each provider is: Standard Contractual Clauses and/or the provider’s EU-U.S. Data Privacy Framework certification, verified per provider at publication.
8. Security
Reasonable technical and organisational measures are used to protect data. No system is
perfectly secure, and the software is experimental and not warranted to be secure. See
05-SECURITY-DISCLOSURE.md.
9. Your rights
Subject to the conditions in the GDPR, you have the right to:
- access the personal data held about you;
- have inaccurate data rectified;
- have data erased (“right to be forgotten”);
- restrict or object to processing;
- receive your data in a portable format;
- withdraw consent where processing is based on consent;
- lodge a complaint with the Norwegian data protection authority, Datatilsynet (https://www.datatilsynet.no).
To exercise a right, contact [email protected]. You may also complain to Datatilsynet directly.
10. Locker specifics
The Locker stores the image files you upload and an account email address. Its daemon logs may
contain IP addresses. These are covered by the purposes, bases and retention above. Locker
service rules, quotas and deletion are in 04-LOCKER-SERVICE-TERMS.md.
11. No sale of data
Personal data is not sold, rented or traded. It is not used for advertising.
12. Changes
This policy may be updated. Each update gets a new version and effective date. Each release keeps the policy it shipped with.