Privacy Policy
Last updated 27 July 2026
1. Controller
The controller responsible for processing personal data on this website within the meaning of the General Data Protection Regulation (GDPR) is:
Martin Stephan Friedrich
Mähdlestraße 50a
6922 Wolfurt
Austria
Email: hello@outvero.app
Phone: +43 676 82555170
There is no statutory obligation to appoint a data protection officer for processing of this scope (Art. 37 GDPR).
2. What this website is
Outvero is a pre-launch product. This page has exactly one function: it describes what we are building and lets you put your email address on a waitlist so we can tell you when early access opens. There is no user account, no login, and no product functionality here.
3. What we store when you join the waitlist
When you submit the signup form, we store the following:
- Your email address — as entered, plus a normalised (lowercased, trimmed) copy used solely to stop the same address being added twice.
- Which form you used (hero, call-to-action, footer or modal), so we can see which part of the page persuades people.
- The referring URL your browser sent, plus any UTM campaign parameters in the address bar, so we can tell which channel brought you here.
- Your browser’s user agent string (browser and operating system), truncated — used to diagnose problems and identify automated abuse.
- An approximate country, derived by our hosting provider from your connection. Your IP address itself is not written to our database.
- The date and time of signup, and of your confirmation (see below).
Providing your email address is voluntary. Without it we cannot put you on the waitlist, but nothing else on this page requires it.
4. Confirming your signup (double opt-in)
After you submit the form we send you a single email containing a confirmation link. Your address is only added to the active waitlist once you click it. We record the time of that confirmation in order to demonstrate your consent, as required by Art. 7(1) GDPR. If you never confirm, the unconfirmed entry is deleted after 30 days.
5. Legal basis and purpose
We process this data on the basis of your consent under Art. 6(1)(a) GDPR, which you give by submitting the form and confirming it. The purpose is limited to notifying you when early access opens and understanding, in aggregate, where our signups come from. We do not use your address for unrelated marketing, and we do not sell, rent or pass it to third parties for their own purposes.
You may withdraw your consent at any time with effect for the future — every email we send contains an unsubscribe link, and you can write to hello@outvero.app. Withdrawing consent does not affect the lawfulness of processing carried out beforehand.
6. Server log data
Our hosting provider automatically records technical access data (including IP address, time of request, requested resource, referrer and user agent) in order to deliver the site securely and reliably. The legal basis is our legitimate interest in operating a functioning, attack-resistant website under Art. 6(1)(f) GDPR.
On our current plan, Vercel retains these runtime logs for one hour, after which they are discarded. Build logs, which relate to deployments of the site and not to visitors, are retained for the lifetime of the deployment. Log data is not combined with the waitlist data.
7. Cookies and tracking
This website sets no advertising or analytics cookies and runs no third-party tracking scripts, pixels or analytics. Vercel Web Analytics and Speed Insights are not enabled. For that reason, no cookie consent banner is shown.
The only cookie that can be set is a strictly necessary, httpOnly session cookie on our internal administration page, which we use to view the waitlist. It is never set for ordinary visitors.
8. Fonts and external content
The Poppins typeface is served from our own domain and bundled with the site. Your browser makes no connection to Google Fonts or any other external font service, so no data is transmitted to third parties when the page renders. All images are likewise served from our own domain.
9. Protecting the form against abuse
To stop automated signups we use a hidden decoy field, a check on how quickly the form was submitted, and a limit on how many submissions can come from one network address within a given period.
To apply that limit we briefly process your IP address. It is never stored: before it is used as a counter it is converted into an irreversible hash with a secret server-side value, so the stored key cannot be turned back into an address. The counter itself is deleted once its ten-minute window has passed. The approximate country mentioned in section 3 is derived from the same connection data by our hosting provider. The legal basis is our legitimate interest in preventing abuse under Art. 6(1)(f) GDPR.
10. Processors
We use the following providers, each engaged under a data processing agreement pursuant to Art. 28 GDPR:
- Supabase, Inc. (United States) — the PostgreSQL database holding the waitlist. Our project is hosted in the Frankfurt (eu-central-1) region, so the data is stored in Germany. Access is restricted to the project owner; every write goes through a server-side key and the table is not publicly readable.
- Vercel Inc. (United States) — hosting and content delivery for this website.
- Resend, Inc. (United States) — sending the confirmation email and, later, the early-access announcement. Our sending domain is configured in Resend’s EU region (Ireland), so messages are processed and delivery data stored within the European Union.
11. Transfers outside the EU/EEA
The waitlist database is located in Germany and outgoing email is processed in Ireland, so the data itself stays within the EU. All three providers are nevertheless US companies whose staff may access data in the course of support and operations. Those transfers are safeguarded as follows:
- Vercel is certified under the EU–U.S. Data Privacy Framework, and its Data Processing Addendum additionally incorporates the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) pursuant to Art. 46(2)(c) GDPR.
- Supabase relies on the EU Standard Contractual Clauses incorporated into its Data Processing Addendum.
- Resend relies on the EU Standard Contractual Clauses incorporated into its Data Processing Addendum.
You may request a copy of the relevant safeguards from us at hello@outvero.app.
12. How long we keep it
We keep your address until you ask us to delete it, until you unsubscribe, or until the waitlist has served its purpose and is retired — whichever comes first. It is then deleted. Unconfirmed signups are deleted after 30 days (section 4).
13. Your rights
Under the GDPR you have the right to:
- confirmation of, and access to, the data we hold (Art. 15)
- correction of inaccurate data (Art. 16)
- erasure of your data (Art. 17)
- restriction of processing (Art. 18)
- receive your data in a portable format (Art. 20)
- object to processing based on legitimate interests (Art. 21)
- withdraw consent at any time (Art. 7(3))
To exercise any of these, write to hello@outvero.app.
You also have the right to lodge a complaint with a supervisory authority. The authority competent for us is:
Österreichische Datenschutzbehörde
Barichgasse 40–42
1030 Vienna, Austria
dsb@dsb.gv.at · +43 1 52 152-0
If you are resident in another EU/EEA member state, you may also complain to the supervisory authority of your own country.
14. Changes to this policy
As the product moves from waitlist to launch, this policy will change. The date at the top always reflects the current version.