Privacy policy
Last updated: 23 July 2026
This privacy policy explains which personal data we process on this website and for what purposes.
Controller
The controller is Amyla · Noël Sabosch, Stadtweg 87, 24837 Schleswig, Germany. Contact: info@amyla.net.
Hosting and server logs
We operate the application, public load balancing, and database with UpCloud Oy, Aleksanterinkatu 15 B, 7th floor, 00100 Helsinki, Finland, in UpCloud data centre DE-FRA1 in Frankfurt am Main, Germany. UpCloud processes this data as our processor.
When you access the website, we process technically necessary data to deliver the site, keep it secure, and investigate errors. This includes in particular:
- IP address
- date and time of access
- requested URL or page/file
- referrer URL
- user agent / browser and system information
- response status and transferred data volumes
Server and proxy logs on our hosting infrastructure are generally deleted or overwritten after no more than 30 days. If a specific security incident or error occurs, affected log data may be retained for longer until the investigation and any necessary legal enforcement have been completed. It is then deleted unless a statutory obligation requires further retention. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in operating a secure and stable website).
Contact requests and email
If you contact us via the contact form or email, we process the data you provide, for example:
- name
- email address
- message / project context
- optional: budget range
The contact form creates an email that is sent through the European SMTP endpoint of AhaSend B.V., Willem Fenengastraat 16, 1096 BN Amsterdam, the Netherlands. AhaSend processes sender and recipient details, message content, and delivery metadata. Complete message content is not retained by AhaSend beyond the processing required for immediate transmission. Technical delivery metadata is retained for seven days. The message is delivered to our mailbox provided through Google Workspace by Google Cloud EMEA Limited, Velasco, Clanwilliam Place, Dublin 2, Ireland. Google Workspace is not loaded directly in your browser, but it stores the contact request received by us.
Processing is necessary to respond to your enquiry and take steps prior to entering into a contract under Art. 6(1)(b) GDPR. Where an enquiry does not concern a potential contract, processing is based on our legitimate interest in handling business communications under Art. 6(1)(f) GDPR.
Your name, email address, and message are required for processing a request submitted through the contact form; providing a budget range is voluntary. Without the required details, we cannot process the request through the form.
Protection against automated submissions
To protect the form against automated abuse, we use the self-hosted open-source software ALTCHA. The web component and computational logic are delivered exclusively from our servers. Our server at UpCloud creates a signed computational challenge that your browser solves locally as proof of work. The solution is then verified exclusively by our Laravel application.
In this configuration, ALTCHA does not set a cookie, use local browser storage, evaluate interaction signals, or send a request to an ALTCHA Sentinel, SaaS, or CDN service. Only the connection data technically required for delivery and verification and the computed solution are processed. To prevent reuse, a one-way value derived from the challenge signature is stored in our cache until the challenge expires, for no longer than ten minutes. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in preventing abuse and spam).
Error analysis with Laravel Nightwatch
We use Laravel Nightwatch, provided by Laravel Holdings Inc., 60 Broad Street, 24th Floor, #1559, New York, NY 10004, USA, to identify technical errors and performance problems. Monitoring data is stored in the EU data region selected by us.
In captured execution contexts, Nightwatch may process the request method, full URL including query parameters, IP address, technical request headers, response status, data volumes and timings, as well as exception, stack-trace, and log data. SQL query text and, for outgoing HTTP requests, the method, URL, status, and data volume may also be captured. For sent emails, the installed Nightwatch module captures the mailable class, subject, number of recipients and attachments, duration, and technical status, but neither the message content nor recipient addresses. Request content capture is disabled; sensitive headers such as cookies and authorisation data are redacted.
The legal basis is Art. 6(1)(f) GDPR (legitimate interest in error analysis, IT security, and reliable operation).
Retention period
- Server and proxy logs: generally no more than 30 days; in the event of a specific security incident or error, where necessary until the investigation and any required legal enforcement have been completed
- ALTCHA replay prevention: no longer than ten minutes
- Nightwatch monitoring data: generally no more than 30 days
- Pirsch analytics data: until deleted from the Pirsch account; separately stored user-agent data for no longer than three months according to the provider
- AhaSend: technical delivery metadata for seven days; complete message content is not retained beyond the processing required for immediate transmission
- Contact requests in Google Workspace: until final processing; beyond that only where statutory retention obligations or the establishment, exercise, or defence of legal claims require it
Recipients and processors
We use processors only where necessary for hosting, web analytics, email delivery, mailbox operation, or technical monitoring. These include UpCloud Oy, Emvi Software GmbH, AhaSend B.V., Google Cloud EMEA Limited, and Laravel Holdings Inc. ALTCHA runs exclusively on our UpCloud infrastructure and is not an external recipient.
UpCloud processes our application data in Frankfurt, Pirsch is operated in Germany, and AhaSend uses its European SMTP endpoint in Germany for our mail delivery. With Google Workspace and Laravel Nightwatch, processing by US companies or access from the USA cannot be completely excluded. Where a provider or subprocessor processes data in a third country, we rely, depending on the provider, on an adequacy decision, in particular the EU-US Data Privacy Framework, and/or on European Commission Standard Contractual Clauses under Art. 44 et seq. GDPR.
For more information, see the UpCloud Privacy Notice, the Pirsch Privacy Policy, the AhaSend Privacy Notice, the Google Privacy Policy, and the Laravel Nightwatch Privacy Policy.
Your rights
- access (Art. 15 GDPR)
- rectification (Art. 16 GDPR)
- erasure (Art. 17 GDPR)
- restriction (Art. 18 GDPR)
- data portability (Art. 20 GDPR)
- objection to processing based on legitimate interests (Art. 21 GDPR)
- withdrawal of consent with effect for the future where processing is based on consent (Art. 7(3) GDPR)
To exercise your rights, an informal message to info@amyla.net is sufficient. We do not use solely automated decision-making, including profiling, within the meaning of Art. 22 GDPR.
You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR), in particular the Independent State Centre for Data Protection Schleswig-Holstein (ULD), Holstenstraße 98, 24103 Kiel, Germany.
Email: info@amyla.net