Privacy Policy
Version 1.0 — effective 31 August 2026
In short: this website has no accounts, no forms, no cookies, no analytics and no advertising. The only personal data involved is the technical record every web server keeps of a request, plus anything you choose to put in an email to us.
1. Who is responsible for your data
LabDeck (“we”, “us”) is the controller of the personal data described in this policy. You can reach us about anything on this page at [email protected].
We are not required to appoint a Data Protection Officer, and we have not appointed one.
2. What this policy covers
This policy covers the LabDeck website at labdeck.dev only. LabDeck applications — including anything we publish to app stores — are each covered by their own privacy policy, published with that application. If you are looking for the policy for a specific app, it is linked from that app’s store listing or from within the app itself.
3. What we collect, and why
Nothing you have to hand over
These pages are static. There are no accounts, sign-up forms, comment fields, or payment flows. We set no cookies, and we run no analytics, advertising, tracking pixels, session recording, or third-party embeds. You are not profiled here, and nothing you read on this site is recorded against your identity.
Technical request data
Every website receives a request before it can return a page. Delivering these pages therefore involves processing:
| Data | Purpose | Legal basis (GDPR) |
|---|---|---|
| IP address, date and time, requested URL, HTTP status, browser user-agent, referring page | Delivering the page you asked for; keeping the service available; detecting and blocking abuse, scraping and attacks | Legitimate interests (Art. 6(1)(f)) — operating and securing a website we make publicly available |
| Network error reports (failed or interrupted requests), collected by our network provider | Diagnosing connectivity and delivery faults | Legitimate interests (Art. 6(1)(f)) |
| Your email address and the contents of your message, if you email us | Reading and replying to you | Legitimate interests (Art. 6(1)(f)), or steps prior to a contract (Art. 6(1)(b)) where you are contacting us about work |
We do not use any of this to build a profile of you, and we never sell it, rent it, or share it for anyone’s marketing.
4. Whether you have to provide anything
You are under no legal or contractual obligation to give us any personal data. Technical request data cannot be avoided while visiting any website, including this one — it is inherent to how the web works. Emailing us is entirely voluntary; if you choose not to, the only consequence is that we cannot reply to you. There is no part of this site that is withheld from you for declining to provide information.
5. Who else processes it
We keep the number of parties involved deliberately small. Personal data described above may be processed by:
- Cloudflare — provides the network, TLS termination, caching and abuse protection sitting in front of this site. It processes technical request data and network error reports on our behalf.
- Our own server — the site runs on a virtual server we operate ourselves, hosted in Frankfurt, Germany, which keeps standard access logs.
- Google (Workspace) — provides the mailbox behind our contact address, so email you send us is processed there.
These providers act on our instructions under data processing agreements. We disclose personal data to no one else, except where we are legally obliged to (for example a binding order from a competent authority), or where it is necessary to establish, exercise or defend a legal claim.
6. International transfers
We are based in Israel, this site is served from a server in Germany, and Cloudflare and Google operate global networks — so your data may be processed outside the country you are in. Israel holds an adequacy decision from the European Commission, and transfers to our providers are governed by their data processing agreements, which incorporate the European Commission’s Standard Contractual Clauses where those apply.
7. How long we keep it
Access and error logs are kept only for as long as they remain useful for operating and securing the service, and they are not archived, exported, or combined with anything else. Correspondence is kept for as long as needed to handle your enquiry and to keep a record of our dealings with you, and is deleted on request unless we are required to retain it.
8. Your rights
You can ask us to:
- confirm whether we hold personal data about you, and give you a copy of it;
- correct it if it is inaccurate or incomplete;
- delete it;
- restrict how we use it, or object to our use of it where we rely on legitimate interests;
- provide it in a portable, machine-readable form, where that right applies.
Write to [email protected] and we will respond within 30 days. Exercising any of these rights is free, and we will not treat you differently for it.
We take no automated decisions that produce legal or similarly significant effects, and we do no profiling.
If you think we have handled your data badly, please tell us first — we would rather fix it. You also have the right to complain to a regulator: in Israel, the Privacy Protection Authority; in the EEA or the UK, your local data protection authority.
9. Security
This site is served only over HTTPS, sits behind a network provider that filters hostile traffic, and runs on infrastructure we administer ourselves and keep patched. No system is perfectly secure, but because we deliberately collect so little here, there is very little to lose.
10. Children
This website is not directed at children and we do not knowingly collect personal data from them. If you believe a child has sent us personal data, email us and we will delete it.
11. Changes to this policy
If this policy changes, we will post the revised version on this page and update the version number and effective date above. Material changes will be summarised here so you can see what moved.
12. Contact
Questions, requests, or complaints about privacy: [email protected]