//privacy-policy

Privacy Policy

Last updated: 15 January 2026

This policy explains what personal data 0xProgramming OÜ collects through 0xprogramming.com, why, on what legal basis, how long it is kept and what rights you have. It is written to be read, not to be survived.

1. Who is responsible

The data controller is 0xProgramming OÜ, a private limited company registered in Estonia under registry code 16634675, EU VAT EE102570771, registered office Pikk tn 14-2, 44307 Rakvere, Lääne-Viru maakond, Estonia.

We have not appointed a Data Protection Officer: we do not carry out large-scale monitoring or process special-category data, so Article 37 GDPR does not require one. Requests are handled by the address above.

2. What we collect and why

DataPurposeLegal basisRetention
Consultation request: company, name, work email, phone, website, project scope, timeline, and the load figures you entered in the estimatorTo assess your enquiry, prepare an architecture opinion and respond with a proposalArt. 6(1)(b) — steps prior to a contract; Art. 6(1)(a) — your consent, recorded with a timestamp24 months from last contact, unless it becomes a contract
Contact form: name, email, company, subject, messageTo answer your messageArt. 6(1)(a) — consent; Art. 6(1)(f) — our legitimate interest in responding to business enquiries24 months from last contact
Technical request log: endpoint, HTTP method, status code, timestamp, user agent, and a salted hash of your IP addressSecurity, abuse prevention, rate limiting and debuggingArt. 6(1)(f) — legitimate interest in keeping the service available and secure90 days, then deleted automatically
Contract data (once engaged): billing details, signatories, correspondencePerforming the contract and meeting Estonian accounting lawArt. 6(1)(b) — contract; Art. 6(1)(c) — legal obligation7 years, as required by the Estonian Accounting Act

What we deliberately do not collect

  • No advertising, analytics or social-media tracking cookies, and no third-party pixels of any kind.
  • No raw IP addresses in the database. Where an IP is needed for rate limiting it is stored as a salted SHA-256 hash, which cannot be reversed to the original address.
  • No profiling and no automated decision-making with legal or similarly significant effects (Art. 22 GDPR). The architecture estimator is a deterministic calculation you run yourself; it produces no decision about you.
  • No special-category data (Art. 9). Please do not include health, biometric, political or similar data in a message.

3. Who else sees your data

We do not sell personal data and we do not share it with advertising networks. Data is disclosed only to the processors we need to run the service, each under a written processing agreement:

  • Hosting and database provider — infrastructure inside the European Union (European Union (Estonia / Germany)).
  • Email provider — delivery of enquiry notifications and our replies to you.
  • Accountant — for contract and invoicing data only, under Estonian professional-secrecy obligations.

Beyond that, we disclose data only where a law obliges us to, or where it is necessary to establish, exercise or defend a legal claim.

International transfers

All processing takes place within the European Economic Area. If that ever changes we will rely on an adequacy decision or on Standard Contractual Clauses, and this policy will be updated before the transfer begins.

4. When you are our client

When we are engaged on your systems, any personal data in those systems is yours, not ours: you are the controller and we act as a processor under a signed Data Processing Agreement. In that role we work only on your documented instructions, use least-privilege access issued for the engagement, and give those credentials back or have them revoked at handover. We do not copy production personal data into our own environments; where test data is needed, it is anonymised or synthetic.

5. Your rights

Under the GDPR you may ask us to:

  • confirm whether we process data about you, and give you a copy (Art. 15);
  • correct data that is wrong or incomplete (Art. 16);
  • delete your data (Art. 17), where no legal retention obligation applies;
  • restrict processing while a dispute about accuracy or legitimate interest is resolved (Art. 18);
  • provide your data in a portable, machine-readable format (Art. 20);
  • object to processing based on legitimate interest (Art. 21);
  • withdraw consent at any time (Art. 7(3)) — this does not affect processing already carried out.

Write to privacy@0xprogramming.com. We answer within one month, free of charge. We may ask a question to confirm your identity, but no more than is necessary.

If you are not satisfied with our answer you can complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, Estonia — aki.ee — or to the supervisory authority in your own country of residence.

6. Security

The site is served over TLS. Form submissions are validated and rate-limited server-side. Database access uses a least-privilege account with no schema-modification rights, submissions are stored on EU infrastructure, and operational logs are written pre-redacted — free-text fields such as your message or project scope never reach them. Retention limits are enforced by scheduled database jobs rather than by anyone remembering to run a cleanup.

No system is perfect. If we ever suffer a breach likely to result in a risk to your rights, we will notify the supervisory authority within 72 hours and, where the risk is high, notify you directly.

7. Cookies and browser storage

This site sets no advertising or analytics cookies. The only browser storage it uses is a single key that remembers you dismissed the storage notice. Details are in the Cookie Policy.

8. Changes

If this policy changes materially we will update the date at the top and, where the change affects data we already hold about you, tell you directly. The current version is always the one published here.