// legal

Privacy Notice

Draft — pending review

Allotment Technology Ltd · Draft version 2026-07-03 · Not yet in effect — see draft notice above

This notice explains what personal data we process when you use the Teasynaer website (teasynaer.dev) and the live demo hosted there, why we process it, how long we keep it, and the rights you have under UK data-protection law.

We've tried to keep it plain. Where the law has a name for something, we've said so.

1. What this notice covers — and what it doesn't

This notice covers only:

  • (a) the public marketing and documentation website at teasynaer.dev; and
  • (b) the live demo — the real Teasynaer application that we run on our own infrastructure so you can try it in your browser.

It does not cover the self-hosted Teasynaer software. Teasynaer is open-source software you can download and run on your own machine or server. When you self-host it, your data stays on your infrastructure — Allotment Technology Ltd does not receive, process, store, or have any access to it. That's the point of the product. Your use of the self-hosted software is governed by its MIT licence (see the LICENSE file in the repository), not by this notice. Nothing in this document creates any Allotment involvement in a self-hosted deployment.

Everything below is about the website and the demo only.

2. Who we are

Allotment Technology Ltd is the data controller for personal data collected through teasynaer.dev and the live demo.

  • Company: Allotment Technology Ltd, registered in England and Wales (company number 16925574), sole director Adam Boon.
  • Registered address: 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ.
  • ICO registration: ZC092549.
  • Contact for privacy matters: hello@allotmentology.tech.

This notice is governed by the law of England and Wales and is written to comply with the UK GDPR and the Privacy and Electronic Communications Regulations (PECR).

3. What we collect

We collect very little, and we don't ask you to sign up for anything to use the demo.

  • Server logs. When you visit the site or use the demo, our servers automatically record standard technical information — your IP address, the request made, user-agent (browser/device string), timestamps, and response/error codes. This is the ordinary by-product of running a web service securely.
  • Demo session data. The live demo runs on anonymous, shared, ephemeral sessions. There is no account and no signup, so there is no sign-in or sign-out. We hold the minimum needed to keep a demo session working (for example a strictly-necessary session cookie and the QA runs you create during the session). Because sessions are shared and anonymous, we generally cannot tie demo activity to an identifiable person.
  • Anything you upload into the demo. You can create QA runs and upload evidence — screenshots, and a screen recording — into the demo. Screen and screenshot capture is manual and gated by your browser's permission prompts; nothing is captured automatically or in the background. Whatever you choose to upload, we process so the demo can show you the feature. Please do not upload sensitive or real personal data — see the warning in section 4.
  • Product-analytics events (planned — not yet live). We plan to collect aggregate product-analytics events (for example: a page was viewed, a demo run was created) to understand how the site and demo are used. This is not yet live: until it launches, no product-analytics events are collected and no analytics cookies are set. When analytics launches it will run through PostHog (EU region, PostHog Cloud), a third-party analytics provider acting as our sub-processor (see sections 6 and 8). Because the intended analytics are cookie-based, the site will at that point show a cookie consent banner, and this notice and the Cookie Notice will be updated accordingly.
  • Enquiry emails. If you email us (for example to ask a question or to exercise a data-protection right), we receive your email address, your name if you give it, and the content of your message.

What we don't collect or do

  • We set no advertising or tracking cookies, and use no third-party advertising or cross-site tracking.
  • We do not require an account, name, or email to use the demo.
  • We do not sell personal data, and we never have.
  • The demo does not perform automatic or background capture — capture is always manual and browser-permission-gated.

4. The live demo — please read this before you upload anything

The demo is a shared sandbox, and you should treat it as public and temporary:

  • Sessions are anonymous and shared, with no signup (and therefore no sign-in or sign-out).
  • The demo is reset every night, without notice. Your runs and any evidence you uploaded are wiped nightly.
  • Teasynaer does not currently offer pixel-level redaction of captured screenshots or recordings. Anything visible on your screen when you capture it will be uploaded as-is.

Because of this, do not upload sensitive information or real personal data (yours or anyone else's) into the demo — no real customer data, credentials, health or financial information, or anything you wouldn't put on a public noticeboard. Use dummy data. If you do upload personal data, it is wiped at the next nightly reset in any event.

5. Why we process it, and our lawful basis

We process each category for a single, stated purpose, and only where we have a lawful basis under Article 6 UK GDPR.

WhatPurposeLawful basis
Server logsOperate, secure, and troubleshoot the site and demo; detect and prevent abuseLegitimate interests — Article 6(1)(f) UK GDPR
Demo session data & uploadsProvide the interactive demo you have chosen to useLegitimate interests — Article 6(1)(f) UK GDPR
Product analytics (planned — not yet live)Understand aggregate usage to improve the site and demoNot currently processed. When launched: consent for the analytics cookies under PECR, gathered via a cookie banner (see section 6); the associated processing will be set out when the feature goes live
Enquiry emailsRead and respond to the enquiry you chose to send usLegitimate interests — Article 6(1)(f) UK GDPR

We don't use your data for advertising, profiling, or automated decision-making, and we don't sell it.

Our legitimate-interests assessment

Where we rely on legitimate interests, we've weighed our interest against your rights:

  • Purpose: running a secure, working demo and website, keeping it available and free of abuse. (Product analytics is not yet live and, when it launches, will be consent-based rather than relying on legitimate interests — see section 6.)
  • Necessity: each item we rely on legitimate interests for is the minimum needed for that purpose — technical logs to run and secure the service, and session data to make the demo function.
  • Balance: the processing is limited, expected, and not overridden by your interests, rights or freedoms. The demo is anonymous, and demo content is wiped nightly. You can object at any time (see section 10).

6. Cookies and analytics

  • Strictly-necessary cookies only, today. The only cookie we currently set is the one needed to make the demo work — a demo session cookie. It is exempt from consent under PECR because it is strictly necessary to provide a service you've asked for. Because that is the only cookie today, there is no cookie banner yet — there is nothing non-essential to consent to.
  • No tracking cookies today. We currently set no analytics, advertising, or cross-site tracking cookies, and use no third-party trackers on our pages.
  • Analytics is planned, not yet live. We intend to add product analytics via PostHog (EU region, PostHog Cloud) — a third-party sub-processor, hosted in the EU. It is not self-hosted. Until it launches, no product-analytics events are collected and no analytics cookies are set. The intended implementation follows the Allotment house approach — standard, cookie-based PostHog. Because analytics cookies are not strictly necessary, when analytics launches the site will show a cookie consent banner, analytics cookies will be set only with your consent, and the Cookie Notice will be updated to list the analytics cookies and name PostHog (EU) as a sub-processor.

7. Where it's stored

The website and the live demo run on our own servers hosted with Hetzner in the EU (data centres in Finland and/or Germany). The planned product analytics, when live, will run on PostHog Cloud (EU region) — a third-party processor located in the EU, not on our own infrastructure.

8. Recipients and sub-processors

We don't sell personal data, and we share it only with the providers we need to run the service:

  • Hetzner Online GmbH — EU cloud hosting (Finland/Germany) for the website and the demo cluster.
  • PostHog (EU region, PostHog Cloud) — planned third-party analytics sub-processor, hosted in the EU. This provider is not yet engaged: no analytics data is shared with PostHog because analytics is not yet live. When it launches, analytics events will be sent to PostHog in the EU, subject to your consent (see section 6).
  • Email handling for enquiries. Enquiries sent to hello@allotmentology.tech are handled the same way as the rest of the Allotment suite: our EU email provider Migadu, with a copy reaching the founder's Google Workspace / Gmail inbox (United States).

9. International transfers

The website, the demo, and demo content are hosted entirely within the EU (Hetzner, Finland/Germany), and the planned analytics will be hosted in the EU (PostHog Cloud, EU region). There is no international transfer of your demo data or, when live, your analytics events.

The one exception is enquiry email: if you email us, a copy of your message reaches the founder's Google Workspace inbox in the United States. That UK-to-US transfer is covered by the appropriate safeguards under UK GDPR — Standard Contractual Clauses together with the UK International Data Transfer Addendum (IDTA).

10. Retention

We keep data no longer than we need it.

  • Demo session data and anything you upload into the demo: wiped nightly, without notice, when the demo resets. We do not intentionally retain demo content beyond that reset. Like the rest of our infrastructure, the database the demo runs on is included in routine disaster-recovery backups (retained up to 30 days) — these exist solely to restore the service after an outage, not to give us, or anyone, access to past demo content; the application itself only ever shows the current, post-reset state.
  • Server logs: kept up to 30 days, unless a longer period is needed for an active security incident.
  • Product analytics (when live): none is held today because analytics is not yet live. A specific retention period will be published here before analytics launches.
  • Enquiry emails: we keep your enquiry email only as long as we need it to deal with your enquiry and any follow-up, and we delete it from our mailboxes within 12 months of the enquiry being closed.

11. Your rights

Under UK GDPR you have the right to: access the personal data we hold about you; have it corrected; have it erased; restrict how we use it; object to our use of it (including our legitimate-interests processing); and, where applicable, data portability.

To exercise any of these, email hello@allotmentology.tech. We may need to verify your identity before we act.

One honest limitation: because the demo is anonymous and shared and is wiped nightly, we usually cannot link demo activity or uploads to an identifiable individual, which limits what we can retrieve or action in response to a request about demo content — and in any event that content is deleted at the next nightly reset.

12. Complaints

You also have the right to complain to the Information Commissioner's Office (ICO), the UK's data-protection regulator, at ico.org.uk. We'd appreciate the chance to put things right first, but you can go to the ICO at any time.

13. Children

The website and demo are not directed at children. You must be 18 or over to use the demo, and if you are under 18 you should not submit personal data to us or into the demo. (This matches the age requirement in our Terms of Use.)

14. Changes

We may update this notice. Material updates will be reflected by a new version, effective date, and changelog entry. The version and date at the top of this document tell you which version you're reading.