01Who we are
Poks is being built by Aidan Warriner, based in Amsterdam, The Netherlands.
Poks is not yet registered as a company with the Dutch Chamber of Commerce. Until it is, Aidan Warriner is the data controller in a personal capacity — the person who decides what data is collected and why, and the person answerable for it under the General Data Protection Regulation (GDPR). When Poks is incorporated, this policy will be updated to name the company and its registration number, and the controller will change accordingly.
You can reach us about anything in this policy at aidan@poks.app. That’s a monitored address and it’s the fastest route to a person. If you need our full postal address — to send a formal notice, for instance — email and ask, and we’ll provide it.
We are not required to appoint a Data Protection Officer, and we haven’t appointed one. Privacy questions go to the address above and are handled by us directly.
02What this policy covers
This policy covers the poks.app website, including the waitlist signup on it.
The Poks app itself is still in development. When the app launches it will process different data — host accounts, player names, buy-ins, cash-outs and settlement records — and it will have its own privacy notice, provided in the app and published before anyone can use it. Nothing in this policy should be read as describing the app, and the terms of service refer to that separate notice for anything the app does.
03What we collect and why
Not much, and only the first row is up to you. Each row gives the legal basis we rely on under Article 6 GDPR, because we’re required to tell you that. We don’t run analytics of any kind — see the cookie policy.
| What | Why | Legal basis | Kept for |
|---|---|---|---|
| Waitlist signup Your first name and email address |
To send you one email with a link to join the Poks beta when it opens | Consent Art. 6(1)(a) GDPR — you tick the box, and you can untick it any time |
Deleted within 30 days of sending your beta invitation. If the beta hasn’t opened within 12 months of your signup, we delete your details then and you’re welcome to sign up again. Immediately, if you ask |
| Server logs IP address, browser and device type, the page requested, the referring page, date and time |
To keep the site online, diagnose errors, and defend against abuse and attacks. Created automatically by our infrastructure provider — every website does this | Legitimate interest Art. 6(1)(f) GDPR — running a secure, working website |
As long as our provider retains them: [CONFIRM SUPABASE LOG RETENTION] |
| Website typefaces Your IP address and browser details, disclosed to Google when your browser fetches the fonts the site is set in |
To display the site in its intended typeface | Legitimate interest Art. 6(1)(f) GDPR — presenting our own website. We consider this a weak basis and intend to remove the dependency; see section 6 |
Not retained by us. Google’s own retention applies to what it receives |
| If you email us Your email address, your name if you give it, and whatever you write |
To answer you | Legitimate interest Art. 6(1)(f) GDPR — responding to someone who contacted us |
12 months after the conversation ends, unless it’s something we’re required to keep longer |
About the waitlist
Joining the waitlist is voluntary. You can browse the whole site without giving us anything. If you do join, we use your first name only to address the email to you, and your email address only to send that email. We will not add you to a newsletter, sell your address, or pass it to advertisers.
That email is sent on the strength of your consent, as Article 11.7 of the Dutch Telecommunications Act requires for commercial electronic messages, and it carries an unsubscribe link. You can withdraw your consent at any time — by using that link, or by emailing aidan@poks.app. Withdrawing is as easy as giving consent was, it costs you nothing, and we delete your details when you do. Withdrawing doesn’t make our earlier processing unlawful, it just stops it going forward.
Providing your name and email is not a legal or contractual requirement. The only consequence of not providing them is that we can’t tell you when the beta opens.
04What we don’t do
Stated plainly, because it’s shorter than the alternative:
- We don’t sell or rent your personal data. Not to advertisers, not to data brokers, not to anyone.
- We set no cookies at all on this site — not advertising, not analytics, not functional. See the cookie policy for the full picture.
- We run no analytics. We don’t currently measure visits to this site at all, with or without cookies.
- We don’t run ad-network pixels — no Meta pixel, no Google Ads tag, no LinkedIn or TikTok tag.
- We don’t build profiles about you and we don’t make any automated decisions about you, in the sense of Article 22 GDPR.
- We don’t collect special category data — nothing about health, beliefs, ethnicity, politics or sexuality — and we ask you not to send us any.
- We don’t process payments on this site. There’s nothing to buy here.
06Where your data is stored
Our servers are in Sweden. The website and the waitlist database both run on Supabase infrastructure in the Stockholm region (eu-north-1), so your data is stored inside the European Union. Two honest qualifications follow, because “EU servers” and “never leaves the EU” are not the same claim.
Supabase
The Stockholm region keeps your data in Sweden, but Supabase Inc. is a US company. Its support and engineering staff may, in limited circumstances, access data in order to operate the service. That access is governed by Supabase’s data processing agreement, which incorporates the European Commission’s Standard Contractual Clauses. So: stored in Sweden, with a possibility of access from outside the EEA, under contractual safeguards.
Google Fonts
Because your browser fetches the typefaces from Google directly, your IP address reaches Google, which may process it outside the EEA under its own terms. This isn’t a transfer we make on your behalf under a contract with Google — it’s a disclosure that happens as a side effect of how the page is currently built, and we can’t paper over it with safeguards we don’t hold.
We intend to serve these fonts from our own EU server instead, which removes the disclosure entirely. Until we’ve done that, you can prevent it yourself by blocking third-party requests in your browser; the site will simply fall back to a standard typeface.
Anyone we add later
If we start using a provider outside the EEA, we’ll only do it where the European Commission has decided that country protects data adequately, or under Standard Contractual Clauses with any additional safeguards the situation requires. Email aidan@poks.app and we’ll tell you which mechanism applies to which provider, and give you the relevant documentation where we’re able to share it.
07How long we keep it
Only as long as the purpose requires. The retention column in section 3 is the full picture, in short:
- Waitlist name and email — deleted within 30 days of sending your beta invitation. If the beta hasn’t opened within 12 months of your signup, we delete your details at that point rather than sitting on them indefinitely. Sooner if you ask, or if you withdraw consent.
- Server logs — for as long as our infrastructure provider retains them: [CONFIRM SUPABASE LOG RETENTION]. We don’t copy them anywhere else.
- Emails you send us — 12 months after we finish the conversation.
Where the law obliges us to keep something longer — a tax or administrative retention obligation, for instance — we keep only what that obligation requires and nothing else.
08How we protect it
We take the measures Article 32 GDPR requires, appropriate to the fact that we hold very little: the site is served over HTTPS so traffic is encrypted in transit; the waitlist database is encrypted at rest and access is limited to the people who need it, protected by strong authentication; and we don’t copy personal data onto laptops, spreadsheets or messaging apps.
No system is perfectly secure. If a personal data breach occurs, we will report it to the Autoriteit Persoonsgegevens within 72 hours of becoming aware of it, unless it’s unlikely to result in any risk to you (Article 33 GDPR). Where a breach is likely to put your rights and freedoms at high risk, we will also tell you directly, without undue delay and in plain language (Article 34 GDPR).
09Your rights
Under the GDPR you have the following rights over your personal data. Email aidan@poks.app to use any of them. We’ll respond within one month, free of charge. If a request is unusually complex we may extend that by two months and we’ll tell you why within the first month. We may ask you to confirm your identity, but only where we genuinely can’t otherwise be sure it’s you. Only if a request were manifestly unfounded or excessive could we charge a reasonable fee or decline it, and we’d explain why if that ever came up.
If we don’t act on a request, we’ll tell you within one month, give our reasons, and remind you that you can complain to the supervisory authority or go to court.
- Access Art. 15Ask what personal data we hold about you and get a copy of it.
- Rectification Art. 16Have inaccurate data corrected and incomplete data completed.
- Erasure Art. 17Have your data deleted — for the waitlist, this is unconditional, just ask.
- Restriction Art. 18Have us pause processing while a dispute about accuracy or lawfulness is resolved.
- Objection Art. 21Object to processing we base on legitimate interest — on this site, the server logs and the font loading described above.
- Portability Art. 20Receive the data you gave us in a structured, machine-readable format, or have it sent elsewhere. This right applies to the data you provided on the basis of consent — in practice, your waitlist details.
- Withdraw consent Art. 7(3)Take back your waitlist consent at any time, with no reason needed and no penalty.
- Lodge a complaint Art. 77Complain to a data protection authority if you think we’ve got it wrong — see section 10.
10How to complain
Tell us first if you can — aidan@poks.app — and we’ll try to fix it. But you never have to go through us. You can complain directly to the Dutch supervisory authority:
Autoriteit Persoonsgegevens
Postbus 93374, 2509 AJ Den Haag, The Netherlands
Telephone: +31 70 888 8500
autoriteitpersoonsgegevens.nl
If you live in another EU or EEA country, you can also complain to your own national data protection authority. You have the right to an effective judicial remedy too.
11Age limit
This site and the Poks waitlist are for people aged 18 and over. Poks is built for home poker games, which are an adult activity. By joining the waitlist you confirm you’re 18 or older — the form says so — and we don’t knowingly collect personal data from anyone younger.
We don’t verify age beyond that declaration, because doing so would mean collecting more data about you than the waitlist justifies. Under the Dutch implementation of the GDPR (the UAVG), a child under 16 cannot validly consent to this kind of processing without a parent or guardian; our 18+ threshold sits above that line deliberately.
If you believe someone under 18 has given us their details, email aidan@poks.app and we’ll delete the record without asking why.
12Changes to this policy
We’ll update this policy when what we do changes — most likely when the app launches, or if we add a tool that handles data differently. The version number and date at the top always reflect the current text.
If a change materially affects how we handle data we already hold about you, we’ll email everyone on the waitlist before it takes effect. If a change requires your consent, we’ll ask for it rather than assume it.
13Contact
Everything — privacy questions, requests, complaints, anything else: aidan@poks.app
Aidan Warriner · Amsterdam, The Netherlands
Related: cookie policy.