Privacy Policy
This policy sets out the categories of personal data processed by the Controller in connection with PipeNode, the purposes and lawful bases of that processing, the periods of retention, the recipients of the data, and the rights of the data subject.
Version 1.4 Last updated
1. Identity of the Controller
1.1 The controller for the purposes of Regulation (EU) 2016/679 (“the GDPR”) and the Data Protection Act 2018 is Brian N. Millar, an individual resident in Ireland (“the Controller”, “we”, “us” or “our”).
1.1.1 The Controller is a natural person and not a company. PipeNode is not incorporated and is operated otherwise than in the course of a trade or business. Contact details for the purposes of Article 13(1)(a) of the GDPR are those given at clause 1.2.
1.2 Correspondence in relation to this policy, including the exercise of any right under section 8, should be addressed to privacy@pipenode.app.
1.3 The Controller has not designated a Data Protection Officer, not being required to do so under Article 37 of the GDPR.
1.4 In the event of a transfer of the undertaking, the identity of the controller changes accordingly. Section 11 governs such a transfer.
2. Categories of data, purposes and lawful bases
| Category of data | Purpose of processing | Lawful basis |
|---|---|---|
| Account data — name, email address, a hash of the password, and the date of registration | Authentication of the data subject, identification within the service, and communication in relation to the service | Article 6(1)(b) — performance of a contract |
| Stored workflows — which nodes were placed, how they are connected, where they sit, and their settings. A setting is stored whether it is a choice among options the node declares or a value the data subject writes in its own words in order to configure a node, such as the strings of a find-and-replace transformation; see clause 3.4. No data supplied to a node for processing, no file name, and no output of a run; see section 3 | Retrieval of the data subject's work upon subsequent sessions and from any device | Article 6(1)(b) — performance of a contract |
| Editor feedback — the content submitted, its classification, and the name of the workflow then open | Identification of defects and of absent functionality | Article 6(1)(f) — legitimate interests in the improvement of the service |
| Contact form submissions — the name, email address and subject supplied and the content submitted. No account is required. The address supplied is not verified, no communication being sent to it for that purpose | Receipt and answer of the enquiry | Article 6(1)(f) — legitimate interests in responding to enquiries; and, where the enquiry concerns registration, Article 6(1)(b) — steps taken at the request of the data subject prior to entering a contract |
| Registered interest — an email address and the date it was given, and nothing else. Supplied by a person who is not a data subject in any other respect, through the form shown while registration is closed. No name is asked for and none is stored. The address is not verified, no communication being sent to it for that purpose | To send one message, when registration opens, to a person who asked to be told. The address is used for that and for nothing else: it is not added to any other list, is not used for marketing of any other kind, and is not combined with any other record held by the Controller | Article 6(1)(a) — consent, given by the act of submitting the form, and withdrawable at any time under section 8 |
| Authentication records — registration, sign-in, sign-out and failed sign-in events, the email address used, the originating IP address, and the reason for any failure | Security of accounts and of the service, including disclosure to the data subject of activity on the account and detection of attack. A failed attempt is recorded whether or not the address corresponds to an account | Article 6(1)(f) — legitimate interests in the security of accounts |
| IP address, transiently | Rate limitation of sign-in attempts, editor feedback and the contact form. The address is used as a counter key and is not retained beyond that use. The sole context in which an IP address is retained is the authentication records described above | Article 6(1)(f) — legitimate interests in maintaining the availability of the service |
2.1 Where processing is founded upon Article 6(1)(f), the Controller has conducted a balancing assessment against the rights and freedoms of the data subject. The right to object is set out at section 8.
3. File contents and node settings
3.1 The contents of files supplied to a workflow are not transmitted to the Controller. Upon a file being supplied to the canvas, the browser opens it from local storage and every node operating upon it executes on the data subject's own device. The Controller holds no copy of such contents and has no means of obtaining one.
3.2 The name of the file is not retained either, nor its size, type, extension, modification date or the folder it came from. Nor is any data the data subject supplies to a node for processing, whether typed or pasted, the name of any node the data subject renames, or the output of any run. All of it remains in the browser. Subject to clause 3.4, the workflow document stored by the Controller comprises the structure described at section 2 and nothing further, so a workflow reopened in a later session returns without the data it is to operate upon and the data subject supplies it again.
3.3 Where the data subject's browser supports the renaming of files in place, that browser requests permission upon first use. Such permission subsists between the data subject and the browser; the Controller neither observes nor records it.
3.4 Settings which configure a node
3.4.1 Clauses 3.1 and 3.2 are subject to the following exception. Certain nodes are configured not by a choice among options which the node declares but by a value which the data subject writes in its own words. A find-and-replace transformation is configured by the string which is to be found and the string which is to replace it; other nodes are configured in the same manner by a pattern, an expression, a separator, a delimiter, a template, a formula, or the name of a column or field. Such a value is a setting of the workflow and not data upon which the workflow operates. It is stored by the Controller as part of the stored workflow described at section 2, because a saved workflow which lost its settings could not be reopened in a working state.
3.4.2 A value written into such a setting is not private to the data subject's device, and the data subject should not write into one anything which it requires the Controller not to hold. The distinction drawn by this clause is between the instruction given to a node and the data upon which the node acts. It is not a distinction between what is sensitive and what is not, and the value is stored irrespective of what the data subject has chosen to write there. Where a particular value is not to be stored, it should be supplied to the workflow at the time of the run rather than saved into a setting, or the workflow should be kept as a scratch workflow, which is not stored by the Controller at any time.
3.4.3 Where such a value constitutes personal data, whether of the data subject or of another person, it is processed upon the basis stated for stored workflows in section 2, is retained for the period stated for stored workflows in section 6, is subject without distinction to the undertakings in section 5 against sale and against use in the training of machine-learning models, and is comprised in the rights of access, erasure and portability set out at section 8. A data subject who supplies to such a setting personal data relating to another person is itself a controller in respect of that processing.
4. Cookies and tracking technologies
4.1 The service sets a single cookie, being a session cookie. It is strictly necessary for the operation of the service, is not used for tracking, is not disclosed to any third party, and expires at the end of the session.
4.2 In an authenticated session the cookie maintains authentication. The cookie is additionally set upon the front page prior to registration, the contact form bearing a token which prevents submission by a third-party site on the data subject's behalf and that token being held in the session. A first visit to the front page therefore sets the cookie. It contains the session identifier only. It falls within the exemption for cookies strictly necessary to provide a service explicitly requested by the user, and accordingly no consent banner is presented.
4.3 The editor uses the browser's local storage to record the width of the sidebar. That data does not leave the data subject's device.
4.4 The service employs no analytics, no advertising, and no tracking technology of any description. Page-level visitor information is not available to the Controller otherwise than through server logs.
5. Recipients and categories of recipient
5.1 Personal data is disclosed to the following recipients and to no others:
- The hosting provider, DigitalOcean, LLC, which stores the database and operates the application on the Controller's behalf as a processor under a written processing agreement. The relevant infrastructure is situated in Amsterdam, the Netherlands, as to which see section 10.
- The provider through which the announcement described in section 2 is sent, Resend. An address given as a registered interest is disclosed to that provider at the time that one message is sent, and for no other purpose. No other category of data in this policy passes through it, the service sending no email of any other kind.
- Any person to whom disclosure is required by law, including a court or a regulator acting within its powers. The Controller shall notify the data subject of such disclosure save where prohibited from doing so.
- A transferee of the undertaking and its professional advisers, in accordance with section 11.
5.2 The Controller does not sell, rent or licence personal data to advertisers, data brokers, list purchasers or any other person for that person's own purposes, does not disclose it to advertisers, and does not use it to train machine-learning models. This undertaking binds any transferee of the undertaking.
5.3 Clause 5.2 is to be distinguished from a transfer of the undertaking itself, which is governed by section 11. The Controller shall not separate the data subject from the service and dispose of the data independently of it.
6. Retention periods
- Account and workflows — until deletion of the account by the data subject. Deletion takes immediate effect and removes both.
- Scratch workflows — not stored by the Controller at any time. They subsist in the page and are discarded upon reload.
- Editor feedback — 12 months following disposal of the matter.
- Contact form submissions — 12 months following the answer of the enquiry. Earlier erasure may be requested, no other record being associated with it.
- Registered interest — until the message it was given for has been sent, upon which the address is erased, or until erasure is requested, whichever is the earlier. It is not retained afterwards against a further announcement: the consent was given for one message and is spent by it.
- Authentication records — 12 months. Deletion of the account dissociates such records from it immediately; the entries themselves are retained for the stated period, a record of authentication activity being of no evidential value if erasable by the person to whom it relates.
- Backups — 30 days, upon the expiry of which deleted data is removed from them.
- Rate-limiting counters — a period measured in minutes and in no case exceeding one hour.
7. Technical and organisational measures
7.1 The Controller applies the following measures pursuant to Article 32 of the GDPR:
- passwords are stored as hashes only, using the algorithm recommended by the application framework, and are not recoverable by the Controller;
- every form effecting a change of state is protected against cross-site request forgery, the editor transmitting separate tokens for the saving of work and for the submission of feedback;
- the workflow editor is served under a strict Content Security Policy;
- the administration area is restricted to the operators of the instance, is gated in two independent places, and is constructed to display names and aggregate counts rather than the contents of any workflow.
7.2 No system affords absolute security. In the event of a personal data breach likely to result in a risk to the rights and freedoms of data subjects, the Controller shall notify the Data Protection Commission without undue delay and in any event within 72 hours of becoming aware of it, and shall notify affected data subjects where Article 34 so requires.
8. Rights of the data subject
8.1 The data subject has the following rights under the GDPR:
- Access (Article 15) — to obtain confirmation of processing and a copy of the personal data held.
- Rectification (Article 16) — to obtain correction of inaccurate data. Name and email address may be amended by the data subject at the settings page.
- Erasure (Article 17) — exercisable by the data subject from the settings page with immediate effect. The authentication records described in section 2 are dissociated from the account immediately but are retained for the period stated in section 6.
- Portability (Article 20) — any workflow may be exported in JSON format from the editor; the remaining data will be supplied upon request.
- Restriction and objection (Articles 18 and 21) — in respect of processing founded upon legitimate interests, including a transfer under section 11.
- Withdrawal of consent (Article 7(3)) — exercisable in respect of a registered interest, that being the one processing described in this policy which is founded upon consent. Withdrawal is as easy to give as the consent was: a message to the address at clause 8.2 asking to be taken off the list, upon which the address is erased and nothing is sent to it. No reason need be given and nothing else is affected, no other record being associated with it. There is no unsubscribe link to follow, nothing having been sent from which to follow one.
8.2 Requests should be addressed to privacy@pipenode.app. The Controller shall respond within one month of receipt in accordance with Article 12(3), without charge.
8.3 A data subject dissatisfied with the Controller's handling of personal data may lodge a complaint with the Data Protection Commission, 6 Pembroke Row, Dublin 2, D02 X963 (dataprotection.ie), or with the supervisory authority of its habitual residence.
9. Children
9.1 The service is not directed to persons under 16 years of age, that being the age of digital consent in Ireland. The Controller does not knowingly process the personal data of children. Notification of any account created by a child should be given to the Controller, upon which the account will be deleted.
10. Location of processing and international transfers
10.1 Account data and workflows are stored in Amsterdam, the Netherlands, being within the European Economic Area. There is no routine transfer of personal data outside the EEA. No resource is loaded by the browser from a third country, and the contents of files supplied to a workflow do not leave the data subject's device.
10.2 DigitalOcean, LLC is incorporated in the United States. Personal data is held upon its infrastructure in Amsterdam, the Netherlands and is not copied outside the EEA in the ordinary operation of the service. A provider incorporated in a third country may nevertheless be subject to the legal process of that country, and its personnel outside the EEA may obtain access to European systems in the course of support and infrastructure work. Such access constitutes a restricted transfer for the purposes of Chapter V of the GDPR notwithstanding that no data is moved, and is governed by the Standard Contractual Clauses incorporated into the Controller's processing agreement with that provider.
11. Transfer of the undertaking
11.1 The Service may be acquired by another person or transferred to a company formed by the Controller for the purpose of carrying it on. The provisions of this section govern the treatment of personal data upon any such event. Incorporation of the Service constitutes such a transfer and attracts the notice required by clause 11.5, the Controller and the company being distinct persons for the purposes of the GDPR.
11.2 Data comprised in a transfer
All data described in section 2, comprising account data, stored workflows, editor feedback, contact form submissions, registered interests and authentication records. The contents of files supplied to a workflow are not held by the Controller and are incapable of transfer.
A registered interest transfers solely for the purpose of sending the one message it was given for. A transferee shall not incorporate the address into a marketing list, send anything to it other than that message, or treat possession of the address as authority for its use. Consent given to the Controller for one announcement is not consent given to a transferee for anything else.
A contact form submission transfers solely for the purpose of answering the enquiry to which it relates. A transferee shall not incorporate the address into a marketing list, communicate with the data subject in respect of any matter not raised by the enquiry, or treat possession of the address as authority for its use.
11.3 Restriction upon transfer
Personal data shall transfer only as part of the service itself and only to a transferee continuing to operate it. The Controller shall not dispose of its user base as a separate asset, shall not transfer personal data to a person acquiring other assets and not intending to operate the service, and shall not sever the data from the service for the purpose of disposing of it independently.
That restriction is also the basis upon which the transfer is lawful. Processing for the purpose for which the data was provided is permitted; a transferee continuing to operate the service pursues that purpose, whereas a person acquiring the data otherwise than with the service does not.
11.4 Lawful basis for the transfer
The transfer is founded upon Article 6(1)(f), the legitimate interests of the Controller in being able to dispose of the Service or to place it upon a corporate footing, balanced against the interest of the data subject in the destination of its personal data. The notice period, the right of objection and the restrictions in this section constitute that balance. Following the transfer, the transferee processes the data upon the same bases as the Controller, principally Article 6(1)(b).
11.5 Notice
- Notice shall be given by email not less than 30 days before any transfer takes effect.
- The notice shall identify the transferee, state its place of establishment, state its intentions in respect of the service, and state whether it intends to amend this policy.
- The data subject may within that period export its workflows and delete its account. Deletion takes immediate effect and data deleted before the transfer is not transferred. The data subject may alternatively object to the transfer alone under section 8 without closing its account.
- The transferee is bound by this policy as it stands at the date of transfer in respect of the data it acquires, until such time as it gives notice of amendment. Any such amendment constitutes a material change requiring 30 days' notice under section 12, that obligation passing to the transferee.
- The rights set out in section 8 are exercisable against the transferee as against the Controller, and the right to complain to a supervisory authority subsists in respect of both.
11.6 Due diligence prior to a transfer
- Only counts and aggregate figures are disclosed to a prospective transferee, and not the underlying records.
- Where a prospective transferee's advisers require sight of the structure of the data, the schema and a pseudonymised or synthetic sample are disclosed, and not the account data or workflows of any data subject.
- Every recipient is subject to a written confidentiality agreement restricting use to the evaluation of the transaction and requiring destruction of the material disclosed in the event that the transaction does not proceed.
- The database is not disclosed to a prospective transferee, and no bulk transfer occurs before the expiry of the notice period specified at clause 11.5.
11.7 Insolvency, incapacity and death of the Controller
The Controller being a natural person, the events which may remove the service from the Controller's hands are not those of a corporate insolvency. Upon the bankruptcy of the Controller, or the making of a personal insolvency arrangement, control of the Controller's assets may pass to an Official Assignee or personal insolvency practitioner. Upon the death or incapacity of the Controller, control may pass to a personal representative or attorney.
In each of those events the undertakings in this section cease to be within the Controller's power to perform. A person so appointed acts under duties imposed by law and by the court, which are not the duties of the Controller. No arrangement is in place for the continued operation of the service in any of those events, and a data subject should proceed on the basis that the service may cease without the notice provided for at clause 11.5.
A data subject may export its workflows at any time and should retain its own copy. That facility is the only protection which does not depend upon the Controller remaining able to act.
12. Amendment of this policy
12.1 Where this policy is amended, the date stated at the head of it shall be updated. Where an amendment materially affects the processing of personal data, notice shall be given by email not less than 30 days before it takes effect, in the manner provided by section 12 of the Terms of Service.
12.2 Enquiries in respect of this policy should be addressed to privacy@pipenode.app.