Skip to main content

Legal

PelagicLabs Website Privacy Policy

Last updated: 19 August 2026 · Effective date: 19 August 2026

This notice covers pelagiclabs.io. The mobile apps have separate notices: GILLI and NORDR. Also see the Cookie Policy.

This notice explains how PelagicLabs handles personal data when you visit pelagiclabs.io, submit a website form, join a waitlist or beta list, contact us, or choose optional website analytics. It does not govern data processed inside the GILLI or NORDR mobile apps.

This legally operative notice is currently provided in English. You may contact us to request an explanation in another European language.

1. Controller and contact

PelagicLabs has not appointed a data-protection officer because the present scale and nature of the processing do not require one. Privacy requests are handled through the contact above.

2. Personal data and sources

2.1 Data you submit

Depending on the form or communication, this can include:

  • name, email address, company, role, country, locale, and selected product;
  • contact topic, subject, message, use case, coverage request, or beta interest;
  • the page or product source associated with the submission;
  • your consent choice and the time it was recorded;
  • later correspondence and support history.

2.2 Data generated when the website is used

Hosting and security infrastructure necessarily receives network and request data, which can include IP address, request time, requested URL, HTTP method, browser or user-agent information, referrer, response status, and security or error details. The form endpoints use an IP address transiently in a short in-memory rate-limit counter to reduce spam and abuse.

2.3 Cookies and optional analytics

The website stores your privacy choice and may remember a language selected by you. Vercel Web Analytics and Speed Insights remain off until you explicitly allow analytics. After consent, they can process page, referrer, browser, device, country-level, network-performance, and Web Vitals information as described in the Cookie Policy.

2.4 Sources

We obtain data directly from you, from your browser or device during a request, from Vercel as hosting and optional analytics provider, and from service providers used to store and deliver website submissions. We do not purchase consumer profiles or enrich website visitors with third-party marketing datasets.

3. Purposes and legal bases

PurposeDataGDPR basis
Deliver pages, operate the service, diagnose failures, and secure the websiteNetwork, request, security, and error dataArticle 6(1)(f): legitimate interests in reliable and secure service operation
Answer a contact, support, partnership, or commercial inquiryContact details, message, topic, and correspondenceArticle 6(1)(b) for pre-contractual steps; otherwise Article 6(1)(f) in handling requested communications
Manage a beta list, waitlist, coverage request, or requested product updateContact details, product interest, form fields, locale, and consent recordArticle 6(1)(a): consent, withdrawable at any time
Measure aggregate page use and technical performanceVercel Analytics and Speed Insights dataArticle 6(1)(a): prior consent
Remember privacy and language choices requested by youConsent and locale storageArticle 6(1)(f) and the device-storage exemption for requested or necessary functionality
Maintain legal, tax, accounting, security, and dispute recordsRelevant correspondence, transaction, and audit informationArticle 6(1)(c) legal obligation and Article 6(1)(f) establishment or defence of claims

Our legitimate interests are operating a secure website, preventing abuse, responding to people who contact us, maintaining continuity of correspondence, and protecting legal rights. You may object to processing based on Article 6(1)(f); we will stop unless compelling legitimate grounds or legal claims justify continuation.

4. Required and optional information

Browsing does not require a name or email. Required form fields are marked in the interface and are needed to validate and answer the submission. Optional fields can be omitted. A form that relies on consent cannot be submitted until the consent box is selected. You can instead contact us directly by email, although processing your message and return address remains necessary to reply.

Analytics is optional. Refusing or withdrawing analytics consent does not reduce website functionality.

5. Recipients and processors

Personal data is disclosed only as needed to operate the relevant function:

  • Vercel: website hosting, content delivery, security, and optional consented analytics and performance measurement;
  • Google Firebase / Firestore: storage of contact, beta, and waitlist submissions;
  • Email and SMTP providers: delivery of form notifications and correspondence;
  • Professional advisers and public authorities: only where necessary for legal advice, compliance, claims, or a lawful request;
  • Business-transferee recipients: if a lawful restructuring, sale, or transfer occurs, subject to appropriate confidentiality and notice.

We do not sell website personal data, disclose it to advertising data brokers, or use form submissions for unrelated third-party marketing.

6. International transfers

Some providers or their subprocessors may process data outside the European Economic Area. Where GDPR transfer restrictions apply, transfers must rely on an adequacy decision, the European Commission's Standard Contractual Clauses with any required supplementary measures, or another lawful transfer mechanism. You may ask us for information about the relevant safeguards, subject to protection of confidential and security-sensitive terms.

7. Retention

  • Consent choice: up to 6 months, then a fresh choice is requested; withdrawal can occur earlier.
  • Language preference: up to 1 year or until you clear it.
  • Rate-limit counters: held in process memory for up to 1 hour and lost sooner when the server instance is recycled.
  • Contact and support submissions: while the request is active and thereafter only as long as reasonably needed for continuity, security, legal claims, or applicable record-keeping duties.
  • Beta and waitlist records: until the requested programme or update is completed, you withdraw, the list is closed, or the record is no longer useful for the stated purpose.
  • Email correspondence: according to the relevant mailbox retention and the purpose of the conversation.
  • Hosting and security logs: according to provider-configured operational and security retention periods.
  • Analytics: according to the limited retention configured or documented by Vercel; PelagicLabs uses it only in aggregate after consent.

We periodically review form records and delete or anonymise information that is no longer needed. Longer retention applies only where law, fraud prevention, security, an active agreement, or the establishment, exercise, or defence of legal claims requires it.

8. Automated processing

The website uses automated validation, spam controls, rate limiting, locale routing, and aggregate analytics. It does not make a decision based solely on automated processing that produces legal or similarly significant effects on you within GDPR Article 22.

9. Your rights

Subject to the conditions in applicable law, you may request:

  • access to and a copy of personal data;
  • correction of inaccurate or incomplete data;
  • erasure;
  • restriction of processing;
  • portability of data you provided where Article 20 applies;
  • objection to processing based on legitimate interests;
  • withdrawal of consent at any time.

Send requests to lukasmeerschaut@pelagiclabs.io. We may request proportionate information to verify identity. We respond without undue delay and normally within one month; the GDPR permits an extension for complex or numerous requests, with notice of the reason.

You may also complain to the Belgian Data Protection Authority at Rue de la Presse 35, 1000 Brussels, Belgium, telephone +32 (0)2 274 48 00, email contact@apd-gba.be, or through its citizen portal. You may contact the supervisory authority in the EU or EEA country where you live or work as well.

10. Security

We use HTTPS, access controls, provider security features, server-side validation, rate limiting, and restricted administrative credentials. No online system can be guaranteed completely secure. Please avoid sending sensitive personal data that is not needed for your inquiry.

11. Children

The website is intended for a general audience and is not designed to solicit personal data from children. A parent or guardian who believes a child submitted information without appropriate authority may contact us for review and deletion.

12. Changes

We update this notice when the website, providers, legal bases, or retention practices materially change. The revised date is shown above. Where required, we will request a new consent choice before introducing a new non-essential analytics or marketing technology.