Legal Notice · GDPR
Privacy notice for EU / EEA users
Last update: 11 July 2026 · Effective date: 11 July 2026 · Version: 2026-07-11-v1
This page is written for users based in the European Union or the European Economic Area (EEA) whose personal data is protected by the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"). Users in Türkiye should consult the Turkish privacy policy, which is the legally binding version under the Turkish Personal Data Protection Law (KVKK Law No. 6698). If you are a resident of both jurisdictions, both notices apply.
1. Who is the controller
Field Notebook is a personal, non-commercial research project. The controller — the natural person who determines the purposes and means of processing your personal data — is:
- Danial Nassouhi, a natural person residing in Türkiye.
- Contact: [email protected].
Because Field Notebook is operated by a single natural person and processes personal data on a scale that does not meet the Art. 37 GDPR threshold, no separate Data Protection Officer (DPO) has been appointed. All privacy correspondence goes to the address above.
2. Whether GDPR applies to you
The controller is based in Türkiye, outside the EU. However, GDPR Art. 3(2)(a) applies to processing carried out by a controller not established in the Union where the processing relates to offering goods or services to data subjects in the Union. Field Notebook markets and offers its service in English via the public website hosted on Cloudflare Pages, and its backend runs on Fly.io's Frankfurt region — both of which imply that the service is offered to users in the EU/EEA. GDPR therefore applies in full to your data.
3. What personal data we process
- Account identifiers: your email address, and if you set one, an Argon2id-hashed password. We never store passwords in plaintext.
- Authentication artefacts: a SHA-256-hashed session token (30-day lifetime), and short-lived one-time codes (OTPs) stored as HMAC-SHA256 hashes with a server-side pepper over a per-code salt. Plaintext is never persisted.
- Observation data: the coordinates of the sites you add, the discipline-specific field values you enter, notes, timestamps, and any custom fields you configure.
- Files you upload: photos (EXIF metadata is stripped on upload), voice recordings, and any transcripts you request.
- Emergency-button events: if you press the emergency button, we record the coordinates at that moment and a timestamp — only then, never continuously.
- Consent records: the version of this privacy notice you accepted and the timestamp of acceptance, so we can prove lawful basis on request.
- Language preference: Turkish or English, used to decide which language to send OTP emails in.
Categories we do NOT process: no advertising identifiers, no third-party analytics, no browser fingerprinting, no location tracking outside the observations and emergency events you actively create, no special-category data under Art. 9 GDPR (health, biometric, political, religious, etc.) unless you voluntarily enter it as free-form text — in which case Art. 9(2)(a) explicit consent applies and you are cautioned that free-form fields are not the intended repository for such data.
4. Purposes and legal bases
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing you with access to the service you signed up for — storing your observations, serving them back, letting you export or delete them. | 6(1)(b) — performance of the contract we form with you at sign-up. |
| Authenticating your sign-in via email + one-time code and, optionally, password. | 6(1)(b) — contractual necessity. |
| Transferring your data to sub-processors (see §6) located outside the EU/EEA. | 6(1)(a) — your explicit consent given at sign-up (Standard Contractual Clauses back the transfer; see §7). |
| Transcribing audio recordings when you request it (Groq API). | 6(1)(a) — your explicit request; you can decline. |
| Sending you the OTP email and, if you use the feedback form, a receipt email. | 6(1)(b) — contractual necessity for authentication; 6(1)(f) — legitimate interest in acknowledging your message for feedback receipts. |
| Preventing abuse (rate limiting sign-in attempts, blocking obvious brute force). | 6(1)(f) — legitimate interest in keeping the service and other users safe. |
| Keeping backups of the database and uploaded files for disaster recovery. | 6(1)(f) — legitimate interest in the integrity of the service. |
| Retaining evidence of your consent to this notice. | 6(1)(c) — legal obligation under Art. 7(1) GDPR to demonstrate consent. |
5. Where the legal basis is legitimate interest
Under Art. 6(1)(f) we have identified the following as legitimate interests: (a) preventing abuse of authentication endpoints; (b) preserving service integrity via backups; (c) sending human-readable acknowledgements of your feedback. In each case, the interest is limited to what is strictly necessary for the operational activity — rate-limit counters are pruned after two hours, backups are automatically deleted after 30 days, and feedback receipts contain only your original message and no marketing content. If you want to object to processing on the basis of legitimate interest, contact us at the address above; you can also opt out of feedback receipts by not using the feedback form.
6. Recipients and sub-processors
| Recipient | Role | Location |
|---|---|---|
| Fly.io (Delaware, USA — Frankfurt EU region for our deployment) | Hosts the backend API, application container, and SQLite database on encrypted volumes. TLS terminated at Fly's edge. | Data at rest: EU (Frankfurt). Company: US. |
| Cloudflare, Inc. (California, USA) | DNS, HTTPS termination for the public website, static asset delivery, DDoS filtering. Pages platform hosts the SPA build. | Global CDN edges; data may transit non-EU nodes momentarily. |
| Cloudflare R2 (Cloudflare's object storage) | Encrypted off-host backup mirror of the database and uploaded files. Bucket lifecycle: 90-day auto-expiry. | EU jurisdiction bucket. |
| Resend, Inc. (Delaware, USA) | Sends OTP sign-in codes and feedback receipt emails. Sees your email address and message content only. | US-based. |
| Groq, Inc. (California, USA) | Transcribes voice recordings on your explicit request. Groq's terms confirm it does not retain the audio after transcription completes. | US-based. |
We do not sell, rent, or share your personal data with any other third party. We do not process your data for advertising, profiling, or automated decision-making within the meaning of Art. 22 GDPR.
7. International transfers
Your personal data is stored primarily inside the EU — the app database and file volumes live in Fly.io's Frankfurt region, and R2 backups target an EU jurisdiction bucket. However, the following processors are established in the United States, which the European Commission has designated as a third country without a full adequacy decision post-Schrems II:
- Cloudflare — for TLS termination, CDN routing, and R2 storage control-plane operations.
- Resend — for sending outbound authentication and feedback emails.
- Groq — for on-demand audio transcription (only when you request it).
For each of these transfers, Field Notebook relies on Standard Contractual Clauses (SCCs) as adopted by the European Commission in Implementing Decision (EU) 2021/914. Each of the three vendors publishes SCC-based Data Processing Addenda (Cloudflare's DPA, Resend's DPA, Groq's DPA), and by using their services we accept those terms on your behalf. Supplementary technical and organisational measures — TLS in transit for every hop, at-rest encryption on Fly volumes and R2 buckets, minimum-data-necessary transmission, no persistent Groq audio retention — are relied on to bring the level of protection into line with the GDPR.
You have the right to request a copy of the SCC-based clauses that govern each transfer; email us at the address in §1 and we will supply the relevant DPA references.
8. Retention
- Account and observation data: retained for the duration of your account. On deletion the primary records are removed immediately; backups continue to hold them for up to 30 days before automatic expiry.
- Session tokens (hashed): 30 days from issue; deleted on logout or password change.
- OTP codes (hashed): 10 minutes from issue; marked as spent on use or expiry.
- Rate-limit counters: pruned after 2 hours.
- Login-attempt logs (email + IP + timestamp): pruned after 2 hours.
- Consent records (version + timestamp): retained for the lifetime of the account and for one year after account deletion, so that we can respond to any subsequent inquiry from you or from a supervisory authority.
- Backup archives: 30 days on both the primary volume and the R2 mirror.
- Emergency-button events: retained on the account so you can review your own history; deleted with the account.
9. Whether providing data is a contractual or statutory requirement
Providing an email address is a contractual requirement: without it we cannot authenticate you and therefore cannot provide the service. Providing observation data, uploads, or free-form field values is entirely optional — you decide what to record. There is no statutory obligation to give any data to Field Notebook.
10. Your GDPR rights
You have the following rights under the GDPR. To exercise any of them, email [email protected]. We will respond within one month (Art. 12(3)) and, where possible, without charge (Art. 12(5)).
- Right of access (Art. 15): obtain a copy of the personal data we hold about you. The in-app Download my data button in the user menu provides an immediate ZIP export of every record you own.
- Right to rectification (Art. 16): correct inaccurate or incomplete data. You can edit most of it directly in the app; contact us for fields you cannot edit yourself.
- Right to erasure (Art. 17): delete your personal data. The in-app Delete my account button removes every record immediately; backups roll off within 30 days.
- Right to restriction (Art. 18): ask us to freeze processing while a dispute over accuracy or lawfulness is resolved.
- Right to data portability (Art. 20): receive your data in a structured, machine-readable format. The ZIP export uses UTF-8 CSVs and original file bytes.
- Right to object (Art. 21): object to processing on the basis of legitimate interest (see §5). We will stop unless we can demonstrate compelling grounds that override your interests.
- Right to withdraw consent (Art. 7(3)): withdraw your consent to international transfer at any time. Because our vendors are not currently replaceable, withdrawal typically means we must close your account; we will assist you in exporting your data before we do.
- Rights concerning automated decision-making (Art. 22): not applicable — Field Notebook makes no automated decisions with legal or similarly significant effects about you.
11. Right to lodge a complaint
If you believe our processing of your personal data infringes the GDPR, you may lodge a complaint with a supervisory authority (Art. 77 GDPR). The competent authority is generally the one in the EU/EEA Member State of your habitual residence, your place of work, or the place where the alleged infringement occurred:
- Republic of Ireland: Data Protection Commission — dataprotection.ie
- Germany: Bundesbeauftragte für den Datenschutz und die Informationsfreiheit — bfdi.bund.de
- France: Commission Nationale de l'Informatique et des Libertés (CNIL) — cnil.fr
- Other Member States: search for "[country name] data protection authority". The European Data Protection Board maintains a directory of national supervisory authorities.
You can also file a complaint directly with us at the contact address in §1. We will investigate and respond within one month. Filing with us first is not a precondition for lodging with an authority.
12. Security measures
Technical and organisational measures under Art. 32 GDPR include:
- HTTPS-only transport with HSTS enforced on the whole domain and a strict Content-Security-Policy on every response.
- Argon2id password hashing (t=2, m=64 MB, p=1) and HMAC-SHA256 OTP hashing with a server-side pepper.
- httpOnly + Secure + SameSite cookies with the
__Host-prefix for the session cookie in production. - Time-based one-time password (TOTP) two-factor authentication for the admin panel.
- Per-user rate limits on sign-in, OTP verify, TOTP challenge, and audio transcription endpoints.
- Encryption at rest on Fly.io machine volumes and on Cloudflare R2 backup buckets.
- Automatic EXIF stripping on photo uploads so GPS coordinates and device identifiers are not persisted in the pixel bundle.
- Weekly dependency vulnerability scanning via
pip-audit; the current baseline is zero known CVEs. - Non-root Docker runtime with the strict allowlist for CORS, host header, and Content-Security-Policy directives.
- Backups retained for 30 days with an R2 Bucket Lock retention rule preventing early overwrite or deletion.
Personal data breach notification (Art. 33–34 GDPR). If a breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it and, without undue delay, notify affected users by email. Our incident-handling procedure is documented internally and can be provided on request from a supervisory authority.
13. Cookies and local browser storage
We use one strictly necessary session cookie set by the backend (__Host-fn_session in production; fn_session in development). Its attributes are httpOnly, Secure, SameSite=Lax, Path=/. It holds only the SHA-256-hashed session token; nothing else. Because it falls within the "strictly necessary" carve-out of the ePrivacy Directive Art. 5(3), no cookie banner is required for it.
We also use browser storage APIs to make the app work offline:
- localStorage: your active project ID, language preference, current draft observations, and the consent-version marker.
- IndexedDB: photos and audio recordings that are queued for upload when connectivity returns.
None of this is shared with any third party. You can clear it via your browser's site-data controls or by signing out.
14. Children
Field Notebook is aimed at adult researchers. We do not knowingly process personal data of anyone under 16 (the default GDPR minimum-consent age; some Member States set 13). If you believe a minor has created an account, please email us and we will delete the account and its data.
15. Changes to this notice
Material changes are posted here with a new effective date and version identifier at the top. For substantive changes (new sub-processor, new category of data, new purpose) we will re-request explicit consent through the app before continuing to process on the new basis. The full change history is preserved so you can audit the version you consented to.
16. Contact
Email [email protected] for any inquiry under this notice — access, rectification, erasure, portability, restriction, objection, consent withdrawal, or a copy of the SCC clauses governing a particular international transfer. We normally respond within one month; if the request is complex we may extend by two further months and will explain the reason.
This notice governs Field Notebook's processing of your personal data under the GDPR. The Turkish privacy policy and the KVKK enlightenment text govern processing under Turkish law. Where both apply, both are enforceable in their respective jurisdictions.