Privacy
Last updated 3 August 2026
The short version: this site sets no cookies, runs no analytics, and loads nothing from any other server. The demo has no accounts and no uploads. The only personal data involved is what any web request unavoidably creates — an IP address in a server log. This page exists because that alone is enough to require one.
This policy covers plotlas.com (this site) and app.plotlas.com (the public demo) as they exist today: no accounts, no logins, no uploads. It will be replaced before any of that changes.
Who is responsible
Wahl Analytics, an eenmanszaak (sole proprietorship) registered
in the Netherlands.
KvK 81012004 · BTW NL003520400B68
All privacy matters: [email protected]
No Data Protection Officer has been appointed, and none is required here: the processing is small-scale, involves no special-category data, and involves none of the regular, systematic monitoring of individuals that triggers Article 37 GDPR.
What is processed, and why
plotlas.com
A static page. No cookies, no analytics, no fonts or scripts from another origin, no tracking of any kind. The only interactive elements are mailto: links, which hand off to your own email program — nothing reaches us unless you choose to send a message.
app.plotlas.com
You can browse the demo collection without an account, a login, or any upload facility. No analytics scripts run and no tracking cookies are set.
Nothing is stored on your device during anonymous browsing. The software does use your browser's local storage in two situations — to keep you signed in, and to track your own in-progress uploads — but neither exists on the public demo, which has no accounts and no uploads. Anything so stored would in any case stay on your device and never be transmitted to us.
Server and access logs
Any web request necessarily passes through Cloudflare's network and, for the demo, our own server. That produces ordinary technical logs containing an IP address, timestamp, requested path, HTTP method and status, user-agent string and referrer.
IP addresses are personal data under Article 4(1) GDPR. The EU Court of Justice settled this for website operators in Breyer v Bundesrepublik Deutschland (C-582/14): even a dynamic IP address counts where some legal means, reasonably likely to be used, could link it to a person. That is why this page exists despite the absence of cookies — a cookie banner and a privacy notice are two different legal requirements, and only one of them depends on cookies.
If you write to us, we process your address and message for as long as it takes to deal with your query.
Legal basis
- Access logs — Article 6(1)(f) GDPR, our legitimate interest in operating, securing and troubleshooting the service. Recital 49 expressly recognises processing that is strictly necessary and proportionate for network and information security. Log data is not used for profiling or advertising, and is not combined with any other dataset about you.
- Email — Article 6(1)(f) for answering your query, or Article 6(1)(b) where it concerns a prospective contract, such as a commercial licence.
Cloudflare
Cloudflare, Inc. provides our CDN, DNS and edge security, and sits in front of the demo's origin server. It necessarily processes the IP addresses and request metadata above in order to deliver the service, acting as our data processor. Its Data Processing Addendum is automatically part of the subscription agreement governing every Cloudflare account including free ones — there is nothing separate to negotiate — and it incorporates the EU Standard Contractual Clauses for transfers outside the EEA.
Cloudflare separately uses aggregated network and security data for its own threat intelligence, acting there as an independent controller. Its policy: cloudflare.com/privacypolicy.
What we can actually see: on Cloudflare's free plan we have no access to raw per-request logs — those require a paid plan. We see only aggregate traffic figures such as request counts and bandwidth. We cannot look up an individual visitor's IP address through Cloudflare.
How long it is kept
- Cloudflare edge data — governed by Cloudflare's own retention practices, linked above. We do not export, copy or extend it.
- Our own server logs for the demo — retained 30 days, then rotated out automatically.
- Email — kept while your query is live, then deleted within 12 months.
GDPR sets no fixed period; Article 5(1)(e) simply requires that data not be kept longer than necessary. For reference, the Dutch data protection authority keeps its own security-purpose web logs for 90 days. Our shorter window is a judgement about proportionality for a small demo, not a legal threshold.
What we do not do
- No selling or renting of data, ever.
- No advertising, retargeting or marketing use of logs.
- No combining logs with anything else to build a profile of you.
- No attempt to work out who is looking at which images.
Your rights
Under Articles 15–22 GDPR you may request access to, correction of, erasure of, or restriction on our processing of your personal data; a copy in a portable format where technically applicable; and you may object to processing based on legitimate interest.
Because there are no accounts, we usually have no way to connect a log entry to you. Exercising some of these rights may therefore depend on your help in locating the entry — roughly when you visited, and the IP address you were using.
Write to [email protected]. We will respond within one month, as Article 12(3) requires.
You may also complain to a supervisory authority. In the Netherlands that is the Autoriteit Persoonsgegevens; elsewhere in the EU or EEA, your own country's authority.
Children
Plotlas is not directed at children, and we do not knowingly collect data identifying one.
Changes
The date at the top changes when this does. We hold no contact list, so we have no way to notify you directly — please check back if it matters to you.