PrivacyPolicy

Version 1.0 · First published 21 July 2026

This Privacy Policy describes how personal data is collected and processed in the context of the One Note Now project (the "Project"), in compliance with Regulation (EU) 2016/679 ("GDPR") and Italian Legislative Decree 196/2003 as amended.

1. Data Controller

The Data Controller is Alessandro Bernardini, acting as a private individual, based in Trieste, Italy. Contact: contact@onenotenow.com

2. Data We Process

2.1. Email address

Provided by the Contributor in the payment dialog (or, where none is typed, obtained from the payment processor as described in Section 2.4). Used to send the contribution receipt with the unique code identifying the moment of inclusion in the Work, and for internal operational records relating to the Work's milestones.

2.2. Optional textual trace ("echo")

A short text of up to 28 characters that the Contributor may optionally leave with their contribution. The echo is stored together with the contribution and may be displayed within the Work.

2.3. Contribution data

The parameters of the released gesture (such as its pitch, duration, timbre and presence settings) and an anonymous technical identifier, stored together with the contribution as part of the Work. While these records remain linked to the email address used for the receipt, they constitute personal data; after the anonymisation described in Section 8 they no longer relate to an identifiable person.

The anonymous identifier is technically necessary to re-create certain sounds (it seeds the timbre of breaths and noise-based notes) and therefore appears, together with the gesture parameters, in the public data feed from which the composition is played. Each contribution receives its own randomly generated identifier at the moment of release; contributions are therefore not correlatable with one another through it, nor with a person.

2.4. Payment data

Payment data (card number, expiry, CVC, cardholder name, billing country) is collected and processed directly by Stripe Payments Europe Ltd. The Administrator does not receive, see, or store payment card data. From Stripe the Administrator receives a transaction identifier and the payment status; where the Contributor does not type an email address, the receipt email address held by Stripe (for example when a saved payment method such as Link is used) may also be received and used in place of the missing address.

2.5. Technical data stored locally on your device

The Project uses browser local storage and IndexedDB to store user interface preferences and a local copy of recent contributions to the Work. This data resides exclusively on the Contributor's device and is not transmitted to the Administrator's servers.

2.6. Server logs

The hosting provider (Netlify) automatically processes connection logs (IP address, timestamp, requested URL) for security and operational purposes. These logs are managed by Netlify under its own privacy policy. In addition, the Project itself briefly stores the connection IP address to enforce per-address rate limits that protect the payment and administrative endpoints from automated abuse (legal basis: legitimate interest, Article 6(1)(f) GDPR). This information is used solely for abuse prevention, not to identify or profile Contributors.

2.7. Cookies

The Project itself sets no cookies. When the payment dialog is opened, Stripe's client library (Stripe.js) sets its own strictly-necessary cookies (such as __stripe_mid and __stripe_sid) for fraud prevention, governed by Stripe's own cookie policy. Because these are technical cookies necessary to provide a service the Contributor has expressly requested, no consent banner is required; they are set only if and when the Contributor chooses to open the payment dialog.

3. Purposes and Legal Bases

  • Delivery of the contribution receipt and unique code: legal basis = performance of contract (Art. 6(1)(b) GDPR).
  • Execution of payment via Stripe: legal basis = performance of contract (Art. 6(1)(b) GDPR).
  • Storage of the contribution within the Work: legal basis = performance of contract and legitimate interest in the integrity of the artistic work (Art. 6(1)(b) and (f) GDPR).
  • Defence of legal claims and proof of acceptance of Terms: legal basis = legitimate interest of the Administrator (Art. 6(1)(f) GDPR).

4. Recipients

Personal data may be shared with:

  • Stripe Payments Europe Ltd, payment processor (which may rely on its own sub-processors, including in the United States, under its own terms);
  • Netlify, Inc., hosting provider and provider of the storage service for contributions;
  • Resend (the email service provider used to deliver receipts, which in turn dispatches messages through Amazon Web Services);
  • GitHub, Inc., for the storage of operational backups of the Project's data on a private repository under the Administrator's exclusive control.

These parties act as independent data controllers or data processors under their own privacy terms. No data is sold or transferred to third parties for marketing purposes.

5. International Transfers

Some recipients — notably Netlify, Inc., Resend, GitHub, Inc., and certain sub-processors used by Stripe — may be established in countries outside the European Economic Area, including the United States. In such cases, transfers are protected by appropriate safeguards under Articles 44-49 GDPR, such as Standard Contractual Clauses or adequacy decisions of the European Commission.

6. Retention

  • Email address and contribution metadata: retained as long as the Work is publicly available, in order to identify and handle any data-subject request relating to the Contributor's contributions (such as access, rectification or erasure) and to maintain the integrity of the Work.
  • Payment data: retained by Stripe according to its own retention policy and applicable accounting obligations.
  • Optional textual trace ("echo"): retained as part of the Work, with no defined end date.
  • Operational backups: snapshots of the Project's data are taken at every contribution (replication to a separate Netlify Blobs namespace under the Administrator's account) and at scheduled intervals (a complete daily snapshot committed to a private GitHub repository under the Administrator's exclusive control, with personal-data fields encrypted using a key held outside that repository). Backups are retained as part of the repository version history for the lifetime of the Project, and form part of the safeguards under Article 32 GDPR (security of processing).
  • Erasure-request audit rows: for each fulfilled erasure request the Administrator records a small audit row containing only the SHA-256 hash of the email address, a timestamp, and counts of affected records. These rows contain no personal data in clear text and are retained under Article 5(2) GDPR (accountability obligation).

The Administrator may anonymise data after a reasonable period while preserving the integrity of the Work.

7. Rights of the Data Subject

Under Articles 15-22 GDPR, you have the right to:

  • access your personal data;
  • request rectification of inaccurate data;
  • request erasure of your data, subject to the limitations arising from the artistic and indivisible nature of the Work (see Section 8 below);
  • request restriction of processing;
  • object to processing based on legitimate interest;
  • request data portability.

To exercise these rights, contact: contact@onenotenow.com

You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali, www.garanteprivacy.it).

8. Erasure: Anonymisation Procedure

The Work is an indivisible collective artistic composition. Upon receiving an erasure request the Administrator applies an anonymisation procedure based on Article 17(3)(a) GDPR (freedom of expression and information exception): the link between the Contributor and the sound event is severed, but the sound event itself is preserved as part of the artistic Work.

8.1. Data anonymised

  • The email address associated with each of the Contributor's contributions is stripped from every operational record (mirror namespace: per-contribution records and chronological event records, and threshold markers where applicable).
  • Upon the Contributor's explicit request, the optional textual trace ("echo") attached to their contributions is also removed or obscured — for example where it contains personal data. This affects only the displayed text: the sound event itself is preserved unaltered.
  • Each anonymised record retains an internal timestamp marker confirming when the anonymisation was performed; no personal data remains in the record.

8.2. Data preserved

  • The sound event (frequency, duration, timbre, position in the Work, the optional textual trace ("echo") unless its removal is requested under Section 8.1, and the unique code received in the receipt) is kept as part of the artistic Work. Once de-linked from the Contributor's identity, it is no longer personal data within the meaning of Article 4(1) GDPR.
  • The Stripe transaction identifier (payment_intent_id) remains in operational records because it is an identifier on the side of the payment processor. The Contributor may exercise their rights with respect to that identifier directly toward Stripe under Stripe's own privacy policy.
  • Receipts already delivered to the Contributor's mailbox at the time of the request are not retrieved or modified. Copies retained by the email service provider (Resend) fall under that provider's own retention; on request the Administrator will additionally instruct their deletion where the provider makes this possible.

8.3. Audit of compliance

To demonstrate that the erasure was carried out, a small audit row is written for each fulfilled request, containing only the SHA-256 hash of the email address, a timestamp and counts of affected records. The audit row never contains the email address in clear text. It is retained under Article 5(2) GDPR (accountability).

8.4. Backups

Personal-data fields (email addresses) inside backup snapshots are encrypted with a key held separately from the backup repository, so the repository's version history never contains readable personal data. Snapshots are retained for evidentiary purposes only insofar as required by Article 17(3)(e) GDPR (defence of legal claims); because the backup copies are encrypted, they can be rendered permanently unreadable by destroying the key.

8.5. How to exercise the right

Send a request to contact@onenotenow.com from the email address you used when contributing. To help identify your contributions you may include any unique code received in your receipts. The Administrator responds within 30 days, as provided by Article 12(3) GDPR.

9. Children

The Project is not directed to persons under 18 years of age and does not knowingly collect data from minors.

10. Changes

This Privacy Policy may be updated. The version in force at the time of each contribution applies to data collected at that time.

Contact

contact@onenotenow.com

See also the Terms of Service.

← Back to Home
Terms · Privacy · Contact · © 2026 One Note Now