Tablemere — Privacy Policy
Version: 2026-09-19-draft
Effective: [effective date]
Controller: Tablemere SL (in formation), [registered address], Spain, CIF [CIF/NIF] Privacy contact: [privacy@ address] Data Protection Officer: [DPO contact or "no DPO appointed"]
DRAFT for lawyer review. Not yet in force. See
legal/README.md.
This policy explains what personal data Tablemere SL processes as controller: data about the people who open accounts, visit the website or write to us. For personal data that customers store inside the Service (in their tables and files), Tablemere is a processor acting on the customer's instructions; that is governed by the Data Processing Agreement, not by this policy.
1. Two roles, in one sentence each
- Account and website data (this policy): we decide why and how it is processed; we are the controller.
- Customer content (the DPA): the customer decides; we store and serve it as instructed; we are the processor.
2. What we collect, why, and on what legal basis
2.1 Account holders (humans)
| data | where it comes from | why | legal basis (Art. 6 GDPR) | kept |
|---|---|---|---|---|
| email address | you, at signup or through the sign-in service | to create and identify the account, send one-time codes, invitations and service notices, place you in your organisation by verified domain | contract (6.1.b) | life of the account + 30 days after deletion, then in backups for up to 14 more days |
| display name / workspace name | you | to label the account and its organisation | contract (6.1.b) | same |
| organisation membership and role (owner, admin, member), claimed email domains, invitations (invited address, role, who invited) | you or your organisation's admins | to run organisations and access control | contract (6.1.b) | same; an unaccepted invitation expires after a set time and can no longer be used (its record is removed with the organisation, see the decisions file) |
identity-provider link (issuer, subject identifier, last login time) — only if you sign in through auth.tablemere.eu |
the sign-in service | to recognise you on later logins | contract (6.1.b) | same |
sign-in service account (email, password hash or passkey, sessions) — only if you use auth.tablemere.eu |
you | to authenticate you | contract (6.1.b) | same |
| API keys: key identifier, label, creation, last use and revocation times; the key itself only as a SHA-256 hash | generated by us on your request | to authenticate your tools and agents | contract (6.1.b) | same |
| one-time signup and recovery codes, stored as a salted hash, plus attempt counter | generated by us | to verify your address | contract (6.1.b) | 10 minutes, or until used |
| project, warehouse and table names, quota counters (bytes stored, objects, commits) | you / measured by us | to run the Service and enforce the free-tier limit | contract (6.1.b), legitimate interest in preventing abuse (6.1.f) | life of the account |
2.2 Everyone who calls the API (including automated agents)
| data | why | legal basis | kept |
|---|---|---|---|
| IP address of the caller, in memory, for rate limiting of signup (5 per hour per address) and of failed credential attempts (10 per key per 10 minutes) | to prevent abuse and credential guessing | legitimate interest (6.1.f) | at most 1 hour in memory; never written to the database |
| server logs: time, method, path, response code, error references; the caller's network address and the API key identifier (never the secret) when a request is refused for too many failed attempts; the caller's network address when a signup is rate-limited | to operate, debug and secure the Service | legitimate interest (6.1.f) | 30 days [founder to confirm; see decisions file — today logs are kept on the host without automatic rotation, which must be fixed before publication] |
2.3 Website visitors (tablemere.eu)
The website is static. It sets no cookies, runs no analytics, loads no third-party scripts or fonts (fonts are served from our own host), and its web server keeps no access log. The only data that reaches us is what your browser sends to fetch the pages, which is discarded once the page is served. The signup page sends the email address you type to our API (section 2.1) and nothing else.
2.4 People who write to us
Email to our addresses on tablemere.eu (support, privacy, security, legal) is stored in mailboxes hosted for us by Infomaniak Network SA in Switzerland, together with your name, address and whatever you write. Legal basis: legitimate interest in answering you (6.1.f), or contract (6.1.b) if you are a customer. Kept for [24 months proposed] after the last exchange, longer if needed for a legal claim.
2.5 What we do not do
We do not sell personal data, do not use it for advertising, do not profile account holders, do not run marketing email lists (service notices only), and do not use any US-operated service to process it.
3. Where the data is and who else sees it
All account data, customer content, backups and logs are stored on servers in Germany (Nuremberg and Falkenstein) operated for us by our sub-processors. Our sub-processors, all of them, are:
| sub-processor | country | what they do for us | what personal data they see |
|---|---|---|---|
| Hetzner Online GmbH | Germany | compute (servers), block storage, object storage for off-host backups, DNS | everything stored in the Service, encrypted in transit; Hetzner staff do not access it in the ordinary course |
| Scaleway SAS | France (Paris region) | transactional email: signup and recovery codes, invitations, service notices | recipient email address, subject and body of the email, delivery logs |
| Infomaniak Network SA | Switzerland | mailboxes for our own company addresses (support@, privacy@, …) | the content of email you send us. Not used for customer content or account data |
Switzerland is outside the EU/EEA but is covered by a European Commission adequacy decision (Decision 2000/518/EC, confirmed in the Commission's 2024 review), so mail to our Infomaniak mailboxes is not a restricted transfer under Chapter V GDPR. No personal data is transferred to the United States or to any other third country, and no US-controlled company processes it for us.
We disclose personal data to public authorities only when a legally binding request under Spanish or EU law obliges us to, and we tell the affected customer unless the law forbids it.
4. How long we keep it
| what | how long |
|---|---|
| account data (section 2.1) | until you ask us to delete the account, or 30 days after we close it; deletion is complete within 30 days of the request |
| backups | daily; 7 copies on the host, 14 copies off-host in Hetzner Object Storage; a deleted record therefore disappears from every backup within 14 days of the deletion |
| one-time codes | 10 minutes |
| in-memory rate-limit counters | at most 1 hour |
| server logs | 30 days [confirm] |
| correspondence | [24 months proposed] |
| invoices and accounting records (paid plans, later) | as required by Spanish tax and commercial law (currently 4 years for tax, 6 years for commercial books) |
5. Your rights
You have the rights of access, rectification, erasure, restriction, portability and objection (Arts. 15–21 GDPR), and the right not to be subject to automated decisions with legal effect (we make none). Write to [privacy@ address] from the address on your account, or by post to the address above. We answer within one month, extendable by two more for complex requests, as the GDPR allows. Account holders can see and change most of their data through the API and CLI (GET /v1/orgs, GET /v1/api-keys, DELETE /v1/api-keys/{id}, organisation membership endpoints).
You may complain to the Spanish supervisory authority, the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid, www.aepd.es, or to the authority of the EU country where you live or work.
6. Security
Personal data is protected by the measures described in security-overview.md and Annex II of the Data Processing Agreement: TLS 1.2+ on every public endpoint, credentials stored only as hashes, short-lived scoped credentials for storage, per-tenant catalog isolation, a firewalled single host with key-only administrative access, daily backups with a rehearsed restore, and rotation procedures for every long-lived key. We also say there what is not yet done.
7. Children
The Service is for professional use and not directed at anyone under 18. We do not knowingly collect data from children; if we learn we have, we delete it.
8. Changes
We update this policy in place with a new version date and a change-log entry. If a change matters to you (new purpose, new sub-processor, new retention period), we email account holders before it takes effect. Sub-processor changes follow the notice procedure in the Data Processing Agreement.
9. Contact
Tablemere SL, [registered address], Spain. Privacy: [privacy@ address]. DPO: [DPO contact or "no DPO appointed"].
Change log
- 2026-09-19-draft — first draft. Data inventory taken from
platform/control_plane/app.py(tablesprincipal,api_key,identity,organization,org_member,org_domain,invitation,agent,signup_code,recovery_code; in-memorySIGNUP_RATEand_AUTH_FAILS), the website deployment (platform/deploy/web_host_setup.sh: no access log, no cookies) and the mail setup (research/21Part B). Not published.