Skip to content
Privacy

Privacy notice

What this site does with data about you, under Articles 13 and 14 GDPR. It is short because the site does little: there is no analytics, no tracking, no advertising, and nothing to consent to. Last updated 21 August 2026.

Controller

Noah Pfister, Dr.-Stumpf-Straße 85a/24, 6020 Innsbruck, Österreich. hello@npaural.com, +43 677 61446810. There is no data protection officer: none of the thresholds in Art 37 GDPR is met, and saying otherwise would be decoration. Write to the address above and a person answers.

Visiting the site

What
IP address, the page requested, the time, the browser's user agent — the standard web server log.
Why
Delivering the pages and keeping the site up. Without it a request cannot be answered.
Legal basis
Art 6(1)(f) GDPR — the legitimate interest in operating a website that works.
How long
Short. Our hosting plan keeps runtime logs for about an hour and they are not copied anywhere else.

No cookie is set by looking at the site, no analytics script runs, and there is no consent banner because there is nothing that would need consent.

Buying a plugin

What
Your email address, which plugin, when, the licence issued, and — if you paid — the payment reference and the billing country your card or wallet reported.
Why
Issuing the licence, letting you sign in and get it again, and keeping the books.
Legal basis
Art 6(1)(b) GDPR for the contract itself; Art 6(1)(c) with § 132 BAO for the accounting records.
How long
The licence is perpetual, so the record of it lasts as long as it does. Records with tax relevance are kept seven years, which § 132 BAO requires and no request can shorten.
Is it optional
No. The email address is inside the signed licence and the plugin checks it. Without one there is nothing to issue.

Card details never reach this site. The payment form is Stripe's, it runs inside their own frame, and what comes back to us is a reference and a result.

Signing in

Signing in sends a one-time link to your address. The link is stored only as a hash, expires, and is spent on first use. Once you are signed in there is one cookie, holding a signed session and nothing else — no identifier that follows you anywhere. § 165 Abs 3 TKG 2021 exempts it from consent because it is exactly what you asked for by signing in. Legal basis Art 6(1)(b) GDPR; deleted when it expires or when you sign out.

Machines running your licence

What
The licence id, a random identifier the plugin generated for that installation, and two dates: first seen and last seen. Days, not times — per-launch timestamps would be a record of when you work.
What it is not
Not your name, not your hardware, nothing derived from your hardware, no fingerprint, no audio, no project data, no location beyond what any internet request reveals.
Why
Noticing when one licence is being handed around, which is the only protection these plugins have — there is no activation, no dongle and no machine lock.
Legal basis
Art 6(1)(f) GDPR. The interest is keeping paid software paid for; the counterweight is that the data is a random number and two dates, and that you can switch it off.
How long
While the licence exists. Delete a machine from your account page and the row goes.

Your Art 21 objection has a switch. One toggle on your account page stops the reporting completely, and the plugin stops sending. It also switches off the protection above — with nothing reported, nothing is detected and no machine on your licence is ever stopped. That is the consequence of the objection, not a price for making it.

The automatic part, and its limits

Art 13(2)(f) GDPR asks whether anything decides about you automatically. One thing does, so here it is in full: if an implausible number of new machines appears on a single licence, the system emails you a list and starts a 7-day clock. When it runs out, machines nobody confirmed stop working. No person reviews it in between.

The safeguards Art 22(3) asks for are built into that sequence rather than promised next to it. You are told before anything happens, not after. Machines that were already running the licence before the notice went out are never caught. Confirming a machine is one click and works at any time, including long after the deadline. You can object to the whole mechanism with the switch above, in which case it never runs. And you can write to hello@npaural.com and get a person, which is the point of Art 22(3).

Who else sees any of it

Four processors, each doing one job, each under a contract under Art 28 GDPR. Nothing is sold, and nothing is shared for anyone else's purposes.

Vercel
Hosting and the server-side functions. Functions for this site are pinned to Frankfurt, so requests are handled inside the EU. vercel.com/legal/privacy-policy
Cloudflare (D1)
The database holding accounts, licences and machines. Created with an EU jurisdiction, which restricts both where it is stored and where queries against it run. cloudflare.com/privacypolicy
Stripe
Payments. Stripe is an independent controller for its own fraud prevention and regulatory duties, and its notice covers that part. stripe.com/privacy
Resend
Sending licence, sign-in and notice emails, and receiving anything you send back. It sees the address and the message. Pinned to Resend's Irish region, and there is no open or click tracking in any message — nothing reports back that you read one. resend.com/legal/privacy-policy

Some of these are US companies or have US parents, so data can reach a third country. Where it does, the transfer runs on the European Commission's standard contractual clauses and, where the recipient is certified, on the EU–US Data Privacy Framework. You can ask for a copy of the clauses that apply.

Beyond those four: nothing on this site loads from a third party until you make it. The payment form fetches Stripe's script when you start paying, not when you open the page. If a walkthrough video is on a plugin page, its poster is served from here and nothing reaches YouTube until you press play — at which point Google receives your IP address and sets its own cookies, under its own policy.

What you can do about it

  • Access (Art 15): ask what is held and get a copy.
  • Rectification (Art 16): correct a wrong address. A licence reissued to the corrected one still works.
  • Erasure (Art 17): delete the account. The licence goes with it and the plugins fall back to demo behaviour, so this is worth meaning. Tax records stay the seven years § 132 BAO demands.
  • Restriction (Art 18) and portability (Art 20): your data, in a machine-readable file, on request.
  • Objection (Art 21): the machine reporting has a switch on your account page. For anything else, write.

Ask at hello@npaural.com. No form, no fee, and an answer within a month. If you would rather not ask us first, you do not have to.

Complaining

You can complain to a supervisory authority at any time. The Austrian one is the Österreichische Datenschutzbehörde, Barichgasse 40–42, 1030 Wien, dsb@dsb.gv.at, dsb.gv.at. If you live elsewhere in the EU, your own national authority is equally competent.

Changes

Changes here are published on this page with the date at the top. If one materially changes what happens to data already held, you get an email about it rather than a silently updated page.