Privacy Policy
Effective date: 2026-09-05 · Last updated: 2026-09-05
1. Who is responsible for your data
For the purposes of the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679),[1] the data controller for this website is:
Roberto Esposito, trading as Apeirion Labs (entreprise individuelle /
micro-entrepreneur, SIREN 107392805), Lyon, France.
Contact: support@apeirionlabs.com
We are a solo-operator business. We have not appointed a Data Protection Officer, as our processing does not meet the GDPR thresholds that require one; the contact above handles all privacy requests personally.
Note on Paddle: for the billing side of your purchase, Paddle acts as its own, separate data controller — not as our processor — because it determines the purposes and means of the billing, tax and fraud processing it performs in its own name (see §2.2 and §3).[2]
2. What data we collect, and why
2.1 Visiting the site
We do not use cookies, client-side analytics scripts, or tracking pixels. The only data collected when you browse the site is standard server access logs (IP address, user-agent string, requested page, referrer, timestamp), which our web server generates. We analyse these logs server-side (with a log analyser running on our own server), not with any code running in your browser and not via any third-party analytics service.
Because we place and read no information on your device — no cookies, no local storage, no pixels — this site does not require a cookie-consent banner. French law makes consent necessary only for operations that write information to, or read information from, your terminal equipment; purely server-side analysis of our own logs is outside that requirement.[3] If that ever changes — for example, if a browser-side analytics script or cookie is added — this policy and the site will be updated, and, where required, your consent will be requested first.
Server access logs still contain personal data (an IP address is personal data),[4] so we process them lawfully and briefly: retained for approximately 14–30 days for security, abuse-prevention, and basic traffic-volume monitoring, then deleted or aggregated. Legal basis: our legitimate interest in operating and securing the site (GDPR Art. 6(1)(f)).[5]
2.2 Making a purchase
Checkout for every purchase is handled entirely by Paddle.com Market Ltd (or the relevant Paddle group entity), our payment provider and Merchant of Record. Paddle collects your name, email address, billing address, and payment details directly — we never see or store your card details.[6]
In its role as Merchant of Record, Paddle acts as an independent (separate) data controller for the billing, tax-calculation, invoicing, and fraud-prevention data associated with your transaction, because Paddle determines its own purposes and means for that processing.[2] Paddle's own Privacy Policy (at paddle.com) governs that processing.
We separately receive, from Paddle, the minimum order data needed to fulfil and support your purchase: which product you bought, the amount paid, and your email address, so we can deliver your product/entitlement and respond to support requests about that order. For that received data, we are the controller. Legal basis: performance of the sale contract with you (GDPR Art. 6(1)(b)).[7]
2.3 Contacting us
If you email support@apeirionlabs.com, we keep that correspondence to respond to you and for a reasonable support-history record. Legal basis: legitimate interest in providing support (GDPR Art. 6(1)(f)) and/or contract performance if it relates to an order.
2.4 The email we send you about an order
This store operates no waitlist and no mailing list, and no page on it collects an email address in order to sign you up to anything. There are exactly two ways your address reaches us: you buy something, or you write to us.
When you buy, Paddle passes us the address you used at checkout (see §2.2) and we send you the delivery message for that order — your download link and what you need to find your receipt — and we keep a record that the message was sent, so we can show the product was delivered and re-send it if it never arrived. We do not add that address to any other list, we do not use it to market anything to you, and we do not share it. Legal basis: performance of the sale contract with you (GDPR Art. 6(1)(b)); if you separately ask us to write to you about something else, that rests on your consent (GDPR Art. 6(1)(a)) and you can withdraw it at any time. Retention: for as long as we need it to support the order and to show it was delivered, or until you ask us to delete it — one email to support@apeirionlabs.com suffices.
Writing to us is the other route: our contact page publishes the same support address and no form, so mailing us is the only way to start that conversation. What happens to that correspondence is described in §2.3.
2.5 Using the hosted pre-flight check
The hosted Shopware Upgrade Radar pre-flight (/lp/sw67/check/) processes the
composer.lock content you paste in memory, returns the report, and does not
store your pasted content. The server keeps only anonymous counters (how many checks ran)
and the standard access logs described in §2.1. Package lists normally contain no
personal data; please do not paste files containing secrets. Legal basis for this
transient processing: performance of the service you request (GDPR Art. 6(1)(b)).
2.6 Business contact details we use for outreach (prospects)
Status: this section describes a practice we have not yet started. As of 2026-08-04 we have sent no outreach email to anyone. It is published in advance so that the information required by Article 14 GDPR is available before, not after, a first message — and so that anyone who wants to object can do so without waiting to be contacted.
Where we got your address (source). If we contact you about a pre-release tool, we obtained your business contact details from a publicly accessible source published by your own organisation — a company website's legal notice or imprint, a team or contact page, or a public professional directory listing. We do not buy, rent, scrape at scale, or receive lists from third parties, and we do not use personal addresses. Every address we hold is recorded against the specific page it was read from; if you ask, we will tell you which page and when.[15]
What we hold and why (purpose). A business email address, the organisation it belongs to, the public page it came from, and a record of what we sent and when. The purpose is narrow and single: to ask whether your agency would trial a pre-release developer tool and tell us where it breaks. We are not building a marketing database, we do not profile you, and there is no automated decision-making.
Our legal basis. Legitimate interests, GDPR Art. 6(1)(f)[5] — our interest in finding a small number of design partners for a pre-release tool, weighed against your interest in not receiving unsolicited mail. We have written that balancing test down rather than asserting it, and it is available on request from support@apeirionlabs.com. Because we did not obtain the data from you, Art. 14 requires us to give you this information at the latest when we first contact you; our first message links to this section.
How long we keep it (retention). Our proposed rule is 24 months from the last contact, after which the address and its record are deleted; if you object or ask us to delete, we act immediately and keep only the minimum needed to make sure we do not contact you again. This retention period is proposed and not yet ratified, and we say so rather than state a rule we have not adopted. It takes effect with our first prospect contact, and the figure above will be confirmed or corrected here before then.
Your right to object, and how. You may object at any time to this processing, including at the point of first contact, and we will stop — you do not have to give a reason, because the processing is for direct marketing purposes (GDPR Art. 21(2)–(3)).[16] One email to support@apeirionlabs.com saying so is enough, and a reply to any message we send counts. You also have every other right listed in §6, including access, correction, erasure and a complaint to the CNIL.
3. Who we share data with
| Recipient | GDPR role | What they process |
|---|---|---|
| Paddle.com Market Ltd | Independent controller (Merchant of Record) for billing | Payment, billing address, tax calculation, invoicing, fraud checks |
| Hetzner Online GmbH | Processor (hosting) | Server infrastructure; incidentally, the access logs described in §2.1 |
| Google (Google Workspace) | Processor (email hosting) | Support correspondence sent to support@apeirionlabs.com |
We have a data-processing agreement (Article 28 GDPR) in place with our processors (Hetzner and Google); Paddle, as a separate controller, is not our processor, so it publishes its own privacy notice rather than acting under our instructions.[8]
We do not sell personal data to anyone, and we do not share data with advertisers — we do not run any advertising or marketing-tracking technology on this site.
4. International data transfers
Some recipients may process data outside the European Economic Area. Hetzner hosts within the EU (Germany), so hosting does not involve a transfer outside the EEA. Paddle and Google may transfer data outside the EEA; where they do, those transfers are governed by their own transfer mechanisms under Chapter V GDPR — an adequacy decision (such as the EU–US Data Privacy Framework, where the recipient is certified) and/or the EU Standard Contractual Clauses.[9] Because Paddle and Google act as controllers/processors in their own right for the data they transfer, we rely on and point you to their published transfer safeguards rather than maintaining our own.
5. How long we keep data
| Data | Retention | Basis |
|---|---|---|
| Server access logs (§2.1) | ~14–30 days | Legitimate interest (Art. 6(1)(f)); below CNIL's 6–12-month log-retention guidance, chosen for data minimisation.[10] |
| Order / entitlement records received from Paddle | As long as needed for support and fulfilment, subject to any statutory accounting-retention below | Contract (Art. 6(1)(b)) + legitimate interest |
| Accounting records / supporting documents | Up to 10 years where a document is an accounting pièce justificative under French law | Legal obligation (Art. 6(1)(c)); Code de commerce, Art. L123-22[11] |
| Support email correspondence | A reasonable, bounded period after the matter is closed; deleted on request where not otherwise required | Legitimate interest (Art. 6(1)(f)) |
| Prospect business contact details (§2.6) | Proposed: 24 months from last contact, then deleted; immediately on objection or request. Not yet in effect — we have contacted no prospect. | Legitimate interest (Art. 6(1)(f)); see §2.6 |
6. Your rights
Under the GDPR you have the right to: access the personal data we hold about you (Art. 15); request correction of inaccurate data (Art. 16); request erasure (Art. 17); restrict or object to certain processing (Arts. 18, 21); and request portability of data you provided to us (Art. 20).[12] You also have the right to lodge a complaint with a supervisory authority — in France, the CNIL (cnil.fr).[13]
To exercise any of these rights regarding data we hold directly, contact support@apeirionlabs.com. For data held by Paddle as an independent controller (billing/payment/tax data), please contact Paddle directly using the process described in their Privacy Policy — we cannot exercise those rights on Paddle's systems on your behalf, but we will help point you to the right channel.[2]
7. Children
This site and its products are not directed at, or intended for use by, children under 16.
8. Changes to this policy
We may update this policy from time to time; the "Last updated" date above will reflect the most recent revision. Material changes affecting how we use your data will be highlighted on this page.
9. Contact
Questions about this policy or your data: support@apeirionlabs.com
Sources (footnotes)
- Regulation (EU) 2016/679 (GDPR) — eur-lex.europa.eu
- Controller/processor definitions: GDPR Art. 4(7), 4(8). Paddle determines its own purposes/means for billing/tax/fraud (remitting VAT in its own name), meeting the Art. 4(7) controller test. Paddle's asserted GDPR role to be confirmed against its current terms.
- Consent required only for operations that access or write information on the user's terminal equipment: Art. 82, Loi n° 78-17 du 6 janvier 1978; CNIL, "Cookies et traceurs : que dit la loi ?". That server-side log analysis falls outside this requirement is a reasoned inference, not an explicit CNIL statement.
- IP addresses are personal data: GDPR Recital 30; CNIL, "L'adresse IP est une donnée à caractère personnel".
- Legitimate interest as lawful basis: GDPR Art. 6(1)(f).
- Paddle as Merchant of Record collects payment/billing data directly: Paddle Buyer Terms; "How Paddle handles VAT on your behalf".
- Contract performance as lawful basis: GDPR Art. 6(1)(b).
- Requirement for an Art. 28 processing contract with processors: GDPR Art. 28; CNIL "Guide sous-traitant". Existence/version of the Hetzner AVV and Google CDPA to be confirmed.
- International-transfer framework: GDPR Arts. 44–49; EU–US Data Privacy Framework and adequacy decisions.
- CNIL recommends a rolling log-retention window of "six mois à un an" as an upper bound: CNIL "Recommandation relative aux mesures de journalisation" (2021).
- "Les documents comptables et les pièces justificatives sont conservés pendant dix ans": Code de commerce, Art. L123-22.
- Data-subject rights: GDPR Arts. 15–22.
- Right to lodge a complaint with a supervisory authority: GDPR Art. 77.
- Information to be provided where the data have not been obtained from the data subject, including the source and the categories of personal data: GDPR Art. 14(1)–(2), in particular Art. 14(2)(f). CNIL, « La prospection commerciale par courrier électronique » (B2B: a professional address may be used for a message relating to the recipient's professional function, with information and a right to object).
- Right to object to processing for direct marketing, absolutely and at any time, and the requirement to bring it to the recipient's attention explicitly and separately at the latest at the first communication: GDPR Art. 21(2)–(4).
GDPR articles cited to Regulation (EU) 2016/679; CNIL and Légifrance sources as consulted 2026-07-10. Full source URLs are available on request from support@apeirionlabs.com.