Legal Notice · GDPR

Privacy notice for EU / EEA users

Last update: 11 July 2026 · Effective date: 11 July 2026 · Version: 2026-07-11-v1

This page is written for users based in the European Union or the European Economic Area (EEA) whose personal data is protected by the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"). Users in Türkiye should consult the Turkish privacy policy, which is the legally binding version under the Turkish Personal Data Protection Law (KVKK Law No. 6698). If you are a resident of both jurisdictions, both notices apply.

1. Who is the controller

Field Notebook is a personal, non-commercial research project. The controller — the natural person who determines the purposes and means of processing your personal data — is:

Because Field Notebook is operated by a single natural person and processes personal data on a scale that does not meet the Art. 37 GDPR threshold, no separate Data Protection Officer (DPO) has been appointed. All privacy correspondence goes to the address above.

2. Whether GDPR applies to you

The controller is based in Türkiye, outside the EU. However, GDPR Art. 3(2)(a) applies to processing carried out by a controller not established in the Union where the processing relates to offering goods or services to data subjects in the Union. Field Notebook markets and offers its service in English via the public website hosted on Cloudflare Pages, and its backend runs on Fly.io's Frankfurt region — both of which imply that the service is offered to users in the EU/EEA. GDPR therefore applies in full to your data.

3. What personal data we process

Categories we do NOT process: no advertising identifiers, no third-party analytics, no browser fingerprinting, no location tracking outside the observations and emergency events you actively create, no special-category data under Art. 9 GDPR (health, biometric, political, religious, etc.) unless you voluntarily enter it as free-form text — in which case Art. 9(2)(a) explicit consent applies and you are cautioned that free-form fields are not the intended repository for such data.

4. Purposes and legal bases

PurposeLegal basis (GDPR Art. 6)
Providing you with access to the service you signed up for — storing your observations, serving them back, letting you export or delete them.6(1)(b) — performance of the contract we form with you at sign-up.
Authenticating your sign-in via email + one-time code and, optionally, password.6(1)(b) — contractual necessity.
Transferring your data to sub-processors (see §6) located outside the EU/EEA.6(1)(a) — your explicit consent given at sign-up (Standard Contractual Clauses back the transfer; see §7).
Transcribing audio recordings when you request it (Groq API).6(1)(a) — your explicit request; you can decline.
Sending you the OTP email and, if you use the feedback form, a receipt email.6(1)(b) — contractual necessity for authentication; 6(1)(f) — legitimate interest in acknowledging your message for feedback receipts.
Preventing abuse (rate limiting sign-in attempts, blocking obvious brute force).6(1)(f) — legitimate interest in keeping the service and other users safe.
Keeping backups of the database and uploaded files for disaster recovery.6(1)(f) — legitimate interest in the integrity of the service.
Retaining evidence of your consent to this notice.6(1)(c) — legal obligation under Art. 7(1) GDPR to demonstrate consent.

5. Where the legal basis is legitimate interest

Under Art. 6(1)(f) we have identified the following as legitimate interests: (a) preventing abuse of authentication endpoints; (b) preserving service integrity via backups; (c) sending human-readable acknowledgements of your feedback. In each case, the interest is limited to what is strictly necessary for the operational activity — rate-limit counters are pruned after two hours, backups are automatically deleted after 30 days, and feedback receipts contain only your original message and no marketing content. If you want to object to processing on the basis of legitimate interest, contact us at the address above; you can also opt out of feedback receipts by not using the feedback form.

6. Recipients and sub-processors

RecipientRoleLocation
Fly.io (Delaware, USA — Frankfurt EU region for our deployment)Hosts the backend API, application container, and SQLite database on encrypted volumes. TLS terminated at Fly's edge.Data at rest: EU (Frankfurt). Company: US.
Cloudflare, Inc. (California, USA)DNS, HTTPS termination for the public website, static asset delivery, DDoS filtering. Pages platform hosts the SPA build.Global CDN edges; data may transit non-EU nodes momentarily.
Cloudflare R2 (Cloudflare's object storage)Encrypted off-host backup mirror of the database and uploaded files. Bucket lifecycle: 90-day auto-expiry.EU jurisdiction bucket.
Resend, Inc. (Delaware, USA)Sends OTP sign-in codes and feedback receipt emails. Sees your email address and message content only.US-based.
Groq, Inc. (California, USA)Transcribes voice recordings on your explicit request. Groq's terms confirm it does not retain the audio after transcription completes.US-based.

We do not sell, rent, or share your personal data with any other third party. We do not process your data for advertising, profiling, or automated decision-making within the meaning of Art. 22 GDPR.

7. International transfers

Your personal data is stored primarily inside the EU — the app database and file volumes live in Fly.io's Frankfurt region, and R2 backups target an EU jurisdiction bucket. However, the following processors are established in the United States, which the European Commission has designated as a third country without a full adequacy decision post-Schrems II:

For each of these transfers, Field Notebook relies on Standard Contractual Clauses (SCCs) as adopted by the European Commission in Implementing Decision (EU) 2021/914. Each of the three vendors publishes SCC-based Data Processing Addenda (Cloudflare's DPA, Resend's DPA, Groq's DPA), and by using their services we accept those terms on your behalf. Supplementary technical and organisational measures — TLS in transit for every hop, at-rest encryption on Fly volumes and R2 buckets, minimum-data-necessary transmission, no persistent Groq audio retention — are relied on to bring the level of protection into line with the GDPR.

You have the right to request a copy of the SCC-based clauses that govern each transfer; email us at the address in §1 and we will supply the relevant DPA references.

8. Retention

9. Whether providing data is a contractual or statutory requirement

Providing an email address is a contractual requirement: without it we cannot authenticate you and therefore cannot provide the service. Providing observation data, uploads, or free-form field values is entirely optional — you decide what to record. There is no statutory obligation to give any data to Field Notebook.

10. Your GDPR rights

You have the following rights under the GDPR. To exercise any of them, email [email protected]. We will respond within one month (Art. 12(3)) and, where possible, without charge (Art. 12(5)).

11. Right to lodge a complaint

If you believe our processing of your personal data infringes the GDPR, you may lodge a complaint with a supervisory authority (Art. 77 GDPR). The competent authority is generally the one in the EU/EEA Member State of your habitual residence, your place of work, or the place where the alleged infringement occurred:

You can also file a complaint directly with us at the contact address in §1. We will investigate and respond within one month. Filing with us first is not a precondition for lodging with an authority.

12. Security measures

Technical and organisational measures under Art. 32 GDPR include:

Personal data breach notification (Art. 33–34 GDPR). If a breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it and, without undue delay, notify affected users by email. Our incident-handling procedure is documented internally and can be provided on request from a supervisory authority.

13. Cookies and local browser storage

We use one strictly necessary session cookie set by the backend (__Host-fn_session in production; fn_session in development). Its attributes are httpOnly, Secure, SameSite=Lax, Path=/. It holds only the SHA-256-hashed session token; nothing else. Because it falls within the "strictly necessary" carve-out of the ePrivacy Directive Art. 5(3), no cookie banner is required for it.

We also use browser storage APIs to make the app work offline:

None of this is shared with any third party. You can clear it via your browser's site-data controls or by signing out.

14. Children

Field Notebook is aimed at adult researchers. We do not knowingly process personal data of anyone under 16 (the default GDPR minimum-consent age; some Member States set 13). If you believe a minor has created an account, please email us and we will delete the account and its data.

15. Changes to this notice

Material changes are posted here with a new effective date and version identifier at the top. For substantive changes (new sub-processor, new category of data, new purpose) we will re-request explicit consent through the app before continuing to process on the new basis. The full change history is preserved so you can audit the version you consented to.

16. Contact

Email [email protected] for any inquiry under this notice — access, rectification, erasure, portability, restriction, objection, consent withdrawal, or a copy of the SCC clauses governing a particular international transfer. We normally respond within one month; if the request is complex we may extend by two further months and will explain the reason.


This notice governs Field Notebook's processing of your personal data under the GDPR. The Turkish privacy policy and the KVKK enlightenment text govern processing under Turkish law. Where both apply, both are enforceable in their respective jurisdictions.