Legal

Privacy policy

Draft — this document is pending review by counsel and is not yet in force. Bracketed items marked pending are deliberate placeholders, completed before publication. No collection happens under this document while it is a draft.

Who we are

[LEGAL ENTITY — PENDING] operates AutoETL ("we", "us"). We are the data controller for the personal data described in this policy. You can reach us about privacy at [PRIVACY CONTACT — PENDING].

This policy covers the public AutoETL website and the early-access waitlist only. It does not cover any customer product data, accounts, or uploads — those do not exist at this stage of the product, and a separate policy will govern them when they do.

What we collect and why

When you visit the site. Our site is static and served through a content delivery network. Like any website, the network our site runs on processes basic request metadata — your IP address and browser User-Agent — to deliver pages and protect the service. We do not use this to build a profile of you.

Draft note: Whether the hosting platform's optional, cookieless analytics beacon is enabled is a deployment setting confirmed before public traffic. If it is enabled, this policy will say so here; until that is confirmed, this policy makes no claim either way.

When you join the waitlist. We collect the email address you submit and basic attribution metadata (such as how you arrived at the site) so we can confirm your signup, contact you about early access, and understand which channels reach the people we are trying to help. We send you a confirmation email. You consent to this when you submit the form; the exact consent wording is versioned so we can show what you agreed to.

We do not collect special-category data, and the waitlist is not used for advertising.

Who receives your data, and where it is processed

We use a small set of service providers ("processors") to run the site and the waitlist. Each vendor publishes a data-processing agreement and offers the EU-U.S. Data Privacy Framework, with the EU Standard Contractual Clauses as a fallback, for any transfer of personal data to the United States.

Draft note: The paragraph above states what the vendors offer, not that every arrangement is confirmed in force for our account. Before publication, each vendor's data-processing agreement, account controls, and live Data Privacy Framework registration are confirmed and recorded; this policy will not publish an unconditional version of these statements until they are.
  • Cloudflare hosts and delivers the site. It processes request metadata at its global edge. On our plan tier we cannot pin a processing region, so this processing is global.
  • Render runs our application and the database that stores your waitlist signup, in a United States region.
  • Amazon Web Services (AWS) stores our encrypted database backups and manages the encryption keys, in a United States region. Your waitlist record is included in these backups in encrypted form.
  • Resend delivers our transactional emails, including your waitlist confirmation. Resend processes your email address to deliver mail; its account data is stored in the United States.
Draft note: An error-diagnostics provider (Sentry) becomes a recipient only if its software is actually running in our application with its data-processing agreement accepted. Neither holds today, so it is not listed; if that changes, it is added here — with its data-scrubbing controls stated only once configured — before it receives anything.

We do not sell your personal data, and we do not share it with anyone outside these processors except where the law requires it.

How long we keep your data

We keep your waitlist signup until you ask us to remove it or until we wind the waitlist down, and we reconcile deletions against our backups so that restoring a backup does not silently bring back a record you asked us to delete. Our providers apply their own retention windows to logs and backups — for example, our application host retains database point-in-time recovery for a limited window and logs for 7–30 days depending on plan; our email provider retains delivery logs for 30 days and stores the content of the emails it sends on our behalf.

Draft note: We are confirming with our email provider the retention duration for sent email content and for suppression records, and will state them here once confirmed.

Your rights

You can ask us to access, correct, or delete your waitlist data, or to stop contacting you. Every confirmation email includes a way to remove yourself. To exercise any right, contact [PRIVACY CONTACT — PENDING]. Depending on your location you may also have the right to complain to a data-protection authority.

Security

We store your waitlist record in a managed database and encrypt our database backups.

Draft note: Specific control claims — the database being closed to the public internet, backups encrypted with keys we manage — are stated here only once each control is configured and its evidence recorded. Until then the wording above stays general.

Changes and contact

We will update this policy as the product grows, and material changes will be noted here. Governing law is [GOVERNING LAW — PENDING]. Questions: [PRIVACY CONTACT — PENDING]. Joining the waitlist is also subject to the terms of use.