//privacy-policy

Privacy Policy

Last updated: 22 August 2026

This policy explains what personal data 0xProgramming OÜ collects through 0xprogramming.com, why, on what legal basis, how long it is kept and what rights you have. It is written to be read, not to be survived.

1. Who is responsible

The data controller is 0xProgramming OÜ, a private limited company registered in Estonia under registry code 16634675, EU VAT EE102570771, registered office Pikk tn 14-2, 44307 Rakvere, Lääne-Viru maakond, Estonia.

We have not appointed a Data Protection Officer: we do not carry out large-scale monitoring or process special-category data, so Article 37 GDPR does not require one. Requests are handled by the address above.

2. What we collect and why

DataPurposeLegal basisRetention
Consultation request: company, name, work email, project scope, timeline, and the load figures you entered in the estimatorTo assess your enquiry, prepare an architecture opinion and respond with a proposalArt. 6(1)(b) — steps taken at your request before entering into a contract24 months from last contact, unless it becomes a contract
Contact form: name, email, company, subject, messageTo answer your messageArt. 6(1)(f) — our legitimate interest in responding to business enquiries addressed to us24 months from last contact
Technical request log: endpoint, HTTP method, status code, timestamp, user agent, and a salted hash of your IP addressSecurity, abuse prevention, rate limiting and debuggingArt. 6(1)(f) — legitimate interest in keeping the service available and secure90 days, then deleted automatically
Contract data (once engaged): billing details, signatories, correspondencePerforming the contract and meeting Estonian accounting lawArt. 6(1)(b) — contract; Art. 6(1)(c) — legal obligation7 years, as required by the Estonian Accounting Act

Field by field: why each one is there

Article 6(1)(b) only covers data that is necessary for the step you asked us to take, so we went through the forms field by field and removed everything that could not pass that test. The consultation form used to ask for a phone number and a company website; both were optional, an optional field cannot be necessary, and neither was worth inventing a second legal basis for. They are gone — from the form, from the API and from the database.

This is the complete inventory. It matches the live forms and the database schema exactly; if a row is missing here, the field is not collected.

FieldFormWhy it is necessaryBasis
CompanyConsultationScoping and the proposal are addressed to a company, not a person6(1)(b)
Your nameConsultationTo address the reply to the person who asked6(1)(b)
Work emailConsultationThe only channel we have to send the answer to6(1)(b)
Project scopeConsultationThe substance of the request — no scope, no architecture opinion6(1)(b)
TimelineConsultationDetermines whether we can take the work on and in what order6(1)(b)
Load figures (RPS, data volume, workload, availability)ConsultationThe inputs the sizing is computed from; not personal data on their own6(1)(b)
Name, email, messageContactTo read and answer the message6(1)(f)
Company, subjectContactOptional. Helps route and answer accurately; leaving them empty changes nothing6(1)(f)

Retention for every row above is the one stated in the table in this section: 24 months from last contact, or longer only if the enquiry becomes a contract and Estonian accounting law requires it.

Why our forms do not ask you to tick a consent box

Because consent is not the basis we rely on, and asking for it anyway would be misleading. If you send us a project brief, handling it is a step taken at your own request before a possible contract — Article 6(1)(b). If you send a general message, answering it is our legitimate interest under Article 6(1)(f). Neither needs your consent, and consent that you must give before a form will submit is not freely given within the meaning of Article 7(4).

So the forms show you a short notice of what happens to your data instead of a required tick-box. This does not reduce your rights: you can object to the legitimate-interest processing at any time under Article 21, and ask for deletion under Article 17, using the address in section 5 below. We will stop unless we have a compelling reason that overrides your objection, which for an ordinary business enquiry we will not.

We would only ask for consent for something genuinely optional and separate — a newsletter, for example. We do not currently run one. If that changes, consent will be a separate, unticked, optional box, and this policy will say so before it appears.

What we deliberately do not collect

  • No advertising, analytics or social-media tracking cookies, and no third-party pixels of any kind.
  • No raw IP addresses in the database. Where an IP-derived value is needed for rate limiting or request security, it is stored as a salted SHA-256 pseudonymized identifier. It is used to correlate requests for abuse prevention and debugging, retained for 90 days in technical logs, and is still treated as personal data rather than as anonymous data.
  • No profiling and no automated decision-making with legal or similarly significant effects (Art. 22 GDPR). The architecture estimator is a deterministic calculation you run yourself; it produces no decision about you.
  • No special-category data (Art. 9). Please do not include health, biometric, political or similar data in a message.

3. Who else sees your data

We do not sell personal data and we do not share it with advertising networks. Data is disclosed only to the processors we need to run the service, each under a written processing agreement:

  • Namecheap, Inc. (United States) — the virtual private server that runs this website. The application, the MySQL database holding form submissions, and the server logs all live on that one machine. It is the only processor that handles data you submit here.
  • Our accountant (Estonia) — contract and invoicing data only, once you become a client, under Estonian professional-secrecy obligations.

That is the complete list. In particular there is no content delivery network, no analytics or error- reporting service, no marketing or CRM platform, no chat widget and no third-party email service: this site makes no outbound requests to anyone while you use it, which is why the Cookie Policy can state that nothing about your visit leaves our own domain. Let’s Encrypt issues the TLS certificate, but a certificate authority sees only the domain name, never your data.

Beyond that, we disclose data only where a law obliges us to, or where it is necessary to establish, exercise or defend a legal claim.

International transfers — please read this one

The server that runs this website is located in the United States and is operated by Namecheap, Inc.. Personal data you submit through a form on this site is therefore transferred to, and stored in, a country outside the European Economic Area. We are telling you this plainly because an earlier version of this policy claimed all processing stayed within the EEA, which was not correct for this infrastructure.

The transfer is covered by the data processing terms we have with that provider, which incorporate the European Commission’s Standard Contractual Clauses — the Article 46(2)(c) GDPR safeguard for transfers to a third country. You can ask us for a copy of the relevant terms at privacy@0xprogramming.com.

What this means in practice: a form submission is one row in a database on a single server, protected by the measures in section 6, and it is deleted on the schedule in section 2 or sooner if you ask. If you would rather not have your details stored outside the EEA at all, email or telephone us instead of using a form — the contact details are in section 1 and on the contact page.

If we move this site onto EEA infrastructure, this section will be corrected before the move rather than after it, and the change will be visible in the “last updated” date above.

4. When you are our client

When we are engaged on your systems, any personal data in those systems is yours, not ours: you are the controller and we act as a processor under a signed Data Processing Agreement. In that role we work only on your documented instructions, use least-privilege access issued for the engagement, and give those credentials back or have them revoked at handover. We do not copy production personal data into our own environments; where test data is needed, it is anonymised or synthetic.

5. Your rights

Under the GDPR you may ask us to:

  • confirm whether we process data about you, and give you a copy (Art. 15);
  • correct data that is wrong or incomplete (Art. 16);
  • delete your data (Art. 17), where no legal retention obligation applies;
  • restrict processing while a dispute about accuracy or legitimate interest is resolved (Art. 18);
  • provide your data in a portable, machine-readable format (Art. 20);
  • object to processing based on legitimate interest (Art. 21) — this covers messages sent through the contact form, and one email is enough to stop it.

There is no “withdraw consent” step to describe here, because we do not rely on consent for anything on this website. We do not use advertising or analytics cookies. The only browser storage is the first-party localStorage key 0xp.notice.storage, which records that you dismissed the storage notice; it contains only a timestamp and remains until you clear this site's browser storage. See the Cookie Policy.

Write to privacy@0xprogramming.com. We answer within one month, free of charge. We may ask a question to confirm your identity, but no more than is necessary.

If you are not satisfied with our answer you can complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, Estonia — aki.ee — or to the supervisory authority in your own country of residence.

6. Security

The site is served over TLS. Form submissions are validated and rate-limited server-side. Database access uses a least-privilege account with no schema-modification rights, the database listens only on the server's own loopback interface and is not reachable from the internet, and operational logs are written pre-redacted — free-text fields such as your message or project scope never reach them. Retention limits are enforced by scheduled database jobs rather than by anyone remembering to run a cleanup.

No system is perfect. If we ever suffer a breach likely to result in a risk to your rights, we will notify the supervisory authority within 72 hours and, where the risk is high, notify you directly.

7. Cookies and browser storage

This site sets no cookies at all: in particular, no advertising, analytics, social-media or tracking cookies. It uses one first-party localStorage key, 0xp.notice.storage, to remember that you dismissed the storage notice. The value is an ISO timestamp, it contains no identifier, and it remains until you clear this site's browser storage. This strictly necessary storage is not sent to our server. The Cookie Policy lists the same key, mechanism, purpose, scope and duration and explains how to clear or reset it. Public URL: 0xprogramming.com/cookie-policy.

8. Changes

If this policy changes materially we will update the date at the top and, where the change affects data we already hold about you, tell you directly. The current version is always the one published here.