Legal

Privacy policy

This explains what personal data we collect on poks.app, why we collect it, how long we keep it, and what you can tell us to do with it. It’s written to be read, not to be survived.

Version 1.0 In effect from [PUBLICATION DATE] Applies to poks.app

01Who we are

Poks is being built by Aidan Warriner, based in Amsterdam, The Netherlands.

Poks is not yet registered as a company with the Dutch Chamber of Commerce. Until it is, Aidan Warriner is the data controller in a personal capacity — the person who decides what data is collected and why, and the person answerable for it under the General Data Protection Regulation (GDPR). When Poks is incorporated, this policy will be updated to name the company and its registration number, and the controller will change accordingly.

You can reach us about anything in this policy at aidan@poks.app. That’s a monitored address and it’s the fastest route to a person. If you need our full postal address — to send a formal notice, for instance — email and ask, and we’ll provide it.

We are not required to appoint a Data Protection Officer, and we haven’t appointed one. Privacy questions go to the address above and are handled by us directly.

02What this policy covers

This policy covers the poks.app website, including the waitlist signup on it.

Not covered here

The Poks app itself is still in development. When the app launches it will process different data — host accounts, player names, buy-ins, cash-outs and settlement records — and it will have its own privacy notice, provided in the app and published before anyone can use it. Nothing in this policy should be read as describing the app, and the terms of service refer to that separate notice for anything the app does.

03What we collect and why

Not much, and only the first row is up to you. Each row gives the legal basis we rely on under Article 6 GDPR, because we’re required to tell you that. We don’t run analytics of any kind — see the cookie policy.

WhatWhyLegal basisKept for
Waitlist signup
Your first name and email address
To send you one email with a link to join the Poks beta when it opens Consent
Art. 6(1)(a) GDPR — you tick the box, and you can untick it any time
Deleted within 30 days of sending your beta invitation. If the beta hasn’t opened within 12 months of your signup, we delete your details then and you’re welcome to sign up again. Immediately, if you ask
Server logs
IP address, browser and device type, the page requested, the referring page, date and time
To keep the site online, diagnose errors, and defend against abuse and attacks. Created automatically by our infrastructure provider — every website does this Legitimate interest
Art. 6(1)(f) GDPR — running a secure, working website
As long as our provider retains them: [CONFIRM SUPABASE LOG RETENTION]
Website typefaces
Your IP address and browser details, disclosed to Google when your browser fetches the fonts the site is set in
To display the site in its intended typeface Legitimate interest
Art. 6(1)(f) GDPR — presenting our own website. We consider this a weak basis and intend to remove the dependency; see section 6
Not retained by us. Google’s own retention applies to what it receives
If you email us
Your email address, your name if you give it, and whatever you write
To answer you Legitimate interest
Art. 6(1)(f) GDPR — responding to someone who contacted us
12 months after the conversation ends, unless it’s something we’re required to keep longer

About the waitlist

Joining the waitlist is voluntary. You can browse the whole site without giving us anything. If you do join, we use your first name only to address the email to you, and your email address only to send that email. We will not add you to a newsletter, sell your address, or pass it to advertisers.

That email is sent on the strength of your consent, as Article 11.7 of the Dutch Telecommunications Act requires for commercial electronic messages, and it carries an unsubscribe link. You can withdraw your consent at any time — by using that link, or by emailing aidan@poks.app. Withdrawing is as easy as giving consent was, it costs you nothing, and we delete your details when you do. Withdrawing doesn’t make our earlier processing unlawful, it just stops it going forward.

Providing your name and email is not a legal or contractual requirement. The only consequence of not providing them is that we can’t tell you when the beta opens.

04What we don’t do

Stated plainly, because it’s shorter than the alternative:

05Who we share it with

Processors working on our instructions

These providers handle data for us and only as we direct, under a data processing agreement as required by Article 28 GDPR. They may not use it for their own purposes.

ProviderWhat they do for usWhat they can seeWhere
Supabase Serves the website and stores waitlist signups Server logs including IP addresses; your first name, email address and signup timestamp Stockholm, Sweden (eu-north-1). The company itself is US-based — see section 6
[EMAIL / MAILBOX PROVIDER] Sends the beta invitation and runs the aidan@poks.app mailbox Your first name and email address; any message you send us [REGION]

A third party that isn’t working for us

Google. The site currently loads its typefaces from Google Fonts, which means your browser requests those files from Google’s servers directly and discloses your IP address and browser details in the process. Google is not our processor for this and there is no data processing agreement between us covering it — Google decides for itself what it does with what it receives, under its own privacy policy. We’re telling you plainly rather than dressing it up, and section 6 explains what we’re doing about it.

Everyone else

Beyond the above, we disclose personal data only where we’re legally obliged to — for example in response to a valid order from a court or competent authority. If that happens and we’re permitted to tell you, we will. We never disclose personal data to advertisers, data brokers or anyone buying access to it.

If Poks is ever sold, merged or restructured, we won’t quietly hand your waitlist details to a new owner. We’d email you first, and your data would only move if you were content for it to — you’d be able to have it deleted instead, and you’d keep every right in section 9 either way.

Where we rely on legitimate interest, we’ve weighed our interest against your privacy before proceeding. You’re entitled to ask us for that reasoning and we’ll give it to you.

06Where your data is stored

Our servers are in Sweden. The website and the waitlist database both run on Supabase infrastructure in the Stockholm region (eu-north-1), so your data is stored inside the European Union. Two honest qualifications follow, because “EU servers” and “never leaves the EU” are not the same claim.

Supabase

The Stockholm region keeps your data in Sweden, but Supabase Inc. is a US company. Its support and engineering staff may, in limited circumstances, access data in order to operate the service. That access is governed by Supabase’s data processing agreement, which incorporates the European Commission’s Standard Contractual Clauses. So: stored in Sweden, with a possibility of access from outside the EEA, under contractual safeguards.

Google Fonts

Because your browser fetches the typefaces from Google directly, your IP address reaches Google, which may process it outside the EEA under its own terms. This isn’t a transfer we make on your behalf under a contract with Google — it’s a disclosure that happens as a side effect of how the page is currently built, and we can’t paper over it with safeguards we don’t hold.

We intend to serve these fonts from our own EU server instead, which removes the disclosure entirely. Until we’ve done that, you can prevent it yourself by blocking third-party requests in your browser; the site will simply fall back to a standard typeface.

Anyone we add later

If we start using a provider outside the EEA, we’ll only do it where the European Commission has decided that country protects data adequately, or under Standard Contractual Clauses with any additional safeguards the situation requires. Email aidan@poks.app and we’ll tell you which mechanism applies to which provider, and give you the relevant documentation where we’re able to share it.

07How long we keep it

Only as long as the purpose requires. The retention column in section 3 is the full picture, in short:

Where the law obliges us to keep something longer — a tax or administrative retention obligation, for instance — we keep only what that obligation requires and nothing else.

08How we protect it

We take the measures Article 32 GDPR requires, appropriate to the fact that we hold very little: the site is served over HTTPS so traffic is encrypted in transit; the waitlist database is encrypted at rest and access is limited to the people who need it, protected by strong authentication; and we don’t copy personal data onto laptops, spreadsheets or messaging apps.

No system is perfectly secure. If a personal data breach occurs, we will report it to the Autoriteit Persoonsgegevens within 72 hours of becoming aware of it, unless it’s unlikely to result in any risk to you (Article 33 GDPR). Where a breach is likely to put your rights and freedoms at high risk, we will also tell you directly, without undue delay and in plain language (Article 34 GDPR).

09Your rights

Under the GDPR you have the following rights over your personal data. Email aidan@poks.app to use any of them. We’ll respond within one month, free of charge. If a request is unusually complex we may extend that by two months and we’ll tell you why within the first month. We may ask you to confirm your identity, but only where we genuinely can’t otherwise be sure it’s you. Only if a request were manifestly unfounded or excessive could we charge a reasonable fee or decline it, and we’d explain why if that ever came up.

If we don’t act on a request, we’ll tell you within one month, give our reasons, and remind you that you can complain to the supervisory authority or go to court.

10How to complain

Tell us first if you can — aidan@poks.app — and we’ll try to fix it. But you never have to go through us. You can complain directly to the Dutch supervisory authority:

Supervisory authority

Autoriteit Persoonsgegevens
Postbus 93374, 2509 AJ Den Haag, The Netherlands
Telephone: +31 70 888 8500
autoriteitpersoonsgegevens.nl

If you live in another EU or EEA country, you can also complain to your own national data protection authority. You have the right to an effective judicial remedy too.

11Age limit

This site and the Poks waitlist are for people aged 18 and over. Poks is built for home poker games, which are an adult activity. By joining the waitlist you confirm you’re 18 or older — the form says so — and we don’t knowingly collect personal data from anyone younger.

We don’t verify age beyond that declaration, because doing so would mean collecting more data about you than the waitlist justifies. Under the Dutch implementation of the GDPR (the UAVG), a child under 16 cannot validly consent to this kind of processing without a parent or guardian; our 18+ threshold sits above that line deliberately.

If you believe someone under 18 has given us their details, email aidan@poks.app and we’ll delete the record without asking why.

12Changes to this policy

We’ll update this policy when what we do changes — most likely when the app launches, or if we add a tool that handles data differently. The version number and date at the top always reflect the current text.

If a change materially affects how we handle data we already hold about you, we’ll email everyone on the waitlist before it takes effect. If a change requires your consent, we’ll ask for it rather than assume it.

13Contact

Get in touch

Everything — privacy questions, requests, complaints, anything else: aidan@poks.app

Aidan Warriner · Amsterdam, The Netherlands

Related: cookie policy.