Privacy notice
How we handle personal data.
Noetra's eenmanszaak is still being registered. Until it exists, the person responsible for this website is a named individual, set out below. Registration changes the identification details in that section. It does not change who is responsible or how any of this works.
This notice covers the website at noetra.eu and the mail you send us. Client engagement data is a separate matter and the last section deals with it.
It describes what the site does today. Where something is planned but not switched on, it says so rather than describing it in the present tense.
Who is responsible
- Controller
- Luis Zadra, acting as Noetra. A Belgian eenmanszaak has no legal personality, so the controller is and will remain a natural person.
- Postal address
- [a Belgian postal address a rights request can be sent to]
- luis@noetra.eu
- Also involved
- Joshua Clercx maintains this website and its code. He acts on Luis's instructions, which makes him a processor for the purposes of this notice.
We have not appointed a data protection officer. Article 37 does not require one here, and with two people it would be a formality rather than a safeguard.
What happens when you open a page
Cloudflare serves this site. Their network receives your IP address, the page you asked for, your browser's user agent and the time, because a web server cannot deliver a page without them. Cloudflare keeps these in its own request logs.
Lawful basis: our legitimate interest under Article 6(1)(f) in running and securing a website. The interest is straightforward and the intrusion is minimal: we never look at these logs to identify anyone.
Audience measurement
Every page loads a small script from static.cloudflareinsights.com, which
reports to cloudflareinsights.com. It is Cloudflare Web Analytics. It tells
us how many times a page was viewed and roughly where in the world from, and nothing
that identifies you. It sets no cookie and stores nothing on your device.
Lawful basis: legitimate interest under Article 6(1)(f) in knowing whether anyone reads the site. You can object to it at any time using the contact details above, and a content blocker will stop it without our involvement.
We hold no copy of this data ourselves. Cloudflare determines how long it keeps it and publishes that in its own documentation. We can only tell you what we see, which is counts.
What happens when you email us
Mail sent to an address at noetra.eu goes to Cloudflare Email Routing, which forwards it into the founders' personal Gmail mailboxes. There is no Google Workspace account behind noetra.eu. That means Google receives your message and holds it under its own consumer terms, as a separate controller, not on our instructions.
We think you should know that before you write to us. If it matters to you, say so and we will arrange another route.
Lawful basis: Article 6(1)(f), responding to a business enquiry you started. Once the exchange is clearly about a possible engagement, Article 6(1)(b), steps taken at your request before entering a contract, applies as well.
The contact form
The form on the home page is not connected yet. It is hidden and no submission can be sent. Until it works, the site shows our email address instead.
When we do connect it, it will collect your name, your email address, your company and your message, and nothing else. It will pass through a Cloudflare program that checks the submission and hands it to an email provider for delivery. We will update this notice before that happens, not after.
There will be two automated checks: a hidden field that only automated software fills in, and a bot challenge. If either rejects your message you will be told on the spot and given our email address, so a wrong decision never loses what you wrote. Neither check produces a decision with a legal or similarly significant effect on you, so Article 22 does not apply, but you should know they exist.
Cookies
This site sets no cookies. We checked the live site on 1 September 2026 and no page
returns a Set-Cookie header, and nothing is written to local or session
storage.
There is therefore no consent banner, because there is nothing stored on or read from your device that would need consent under Article 5(3) of the ePrivacy Directive. Fonts, stylesheets and the site's own script are all served from noetra.eu. The analytics script above is the one request that leaves our domain, and it neither stores nor reads anything on your device.
If you visited noetra.eu before September 2026 you may still hold a cookie from the parking page the domain used to show. That was not ours and we cannot remove it. Your browser can.
Who else sees your data
| Who | What they do | Where | Relationship |
|---|---|---|---|
| Cloudflare | Serves the site, routes mail to noetra.eu, measures page views | Global network, US company | Processor. [Their data processing agreement has not been accepted yet. Accept it, then delete this note.] |
| Runs the personal mailboxes your message is forwarded into | Global, US company | Separate controller. Not acting on our instructions | |
| GitHub | Holds this site's source code. Receives no visitor data | US company | Not a recipient of your data |
| Porkbun | Domain registrar. Holds our registration details, not yours | United States | Not a recipient of your data |
We do not sell data, we do not share it for advertising, and we do not add anyone who writes to us to a mailing list.
Transfers outside the EEA
Cloudflare and Google are established in the United States. Both are certified under the EU-US Data Privacy Framework, and the European Commission's adequacy decision for that framework is the mechanism those transfers rely on. Cloudflare's agreement additionally carries Standard Contractual Clauses, which take over if the adequacy decision falls away. Ask us and we will point you at the current text of either.
How long anything is kept
- Your emails
- For as long as the conversation is live, and after that for as long as we may need to show what was agreed or discussed. We review the mailbox once a year and delete what is no longer needed. Deleted mail sits in Gmail's bin for a further 30 days.
- Server logs
- Held by Cloudflare under its own retention policy. We keep no copy.
- Audience measurement
- Held by Cloudflare under its own retention policy. We see counts, not records.
Your rights
You can ask us for a copy of what we hold about you, to correct it, to delete it, to restrict what we do with it, or to hand it to someone else. Because we rely on legitimate interest, you can also object at any time, and we then have to stop unless we can show compelling grounds that override your objection.
Email luis@noetra.eu or write to the postal address above. We will answer within one month. There is no charge.
Giving us your details is never a statutory or contractual requirement. Nothing on this site asks for them. If you email us and leave things out, the only consequence is that we may not be able to answer properly.
We make no decisions about you by automated means that produce legal or similarly significant effects, and we do not profile you.
If you want to complain
Tell us first, because most things are quicker to fix that way. You also have the right to complain to the Belgian Data Protection Authority, whatever we say:
- Authority
- Gegevensbeschermingsautoriteit / Autorité de protection des données
- Address
- Drukpersstraat 35, 1000 Brussel, Belgium
- Telephone
- +32 (0)2 274 48 00
- contact@apd-gba.be
- Website
- gegevensbeschermingsautoriteit.be
Client engagement data
Noetra has not run an engagement yet. This section describes what we will do, not what we have been doing. It is here so you can judge the terms before you talk to us.
When we analyse a client's quote-to-cash data, the client will be the controller and Noetra the processor under Article 28. We will act only on their documented instructions, under a signed data processing agreement naming the data, the purpose, the duration, the security measures and the deletion terms.
Most of that data describes companies, not people: contracts, invoices, subscriptions, usage. The personal data in it is narrow, mainly contact names, user records used for seat counts, and signer identities on envelopes. We will ask clients to hash or pseudonymise those before they reach us. Hashing is pseudonymisation and not anonymisation: the hash is still personal data and stays inside the agreement. What it buys is that we never hold a readable customer email.
Our preferred arrangement is to work inside the client's own infrastructure, so the row-level data never leaves their systems. Contracts and signed amendments are the exception, because we have to read them, and the engagement letter will say where those are held and when they are destroyed. Where working inside a client's systems is not possible we will use an environment dedicated to that client, never a shared one.
Joshua Clercx will be the only person on the sub-processor annex. Everything else on it will be infrastructure. Clients get notice and a right to object before that list changes.
Changes to this notice
If it changes we update the version and the date at the top. We will not make a material change quietly. This is version 2, published [date you publish it].