This Privacy Policy describes how personal data is collected and processed in the context of the One Note Now project (the "Project"), in compliance with Regulation (EU) 2016/679 ("GDPR") and Italian Legislative Decree 196/2003 as amended.
The Data Controller is Alessandro Bernardini, acting as a private individual, based in Trieste, Italy. Contact: contact@onenotenow.com
Provided by the Contributor in the payment dialog (or, where none is typed, obtained from the payment processor as described in Section 2.4). Used to send the contribution receipt with the unique code identifying the moment of inclusion in the Work, and for internal operational records relating to the Work's milestones.
A short text of up to 28 characters that the Contributor may optionally leave with their contribution. The echo is stored together with the contribution and may be displayed within the Work.
The parameters of the released gesture (such as its pitch, duration, timbre and presence settings) and an anonymous technical identifier, stored together with the contribution as part of the Work. While these records remain linked to the email address used for the receipt, they constitute personal data; after the anonymisation described in Section 8 they no longer relate to an identifiable person.
The anonymous identifier is technically necessary to re-create certain sounds (it seeds the timbre of breaths and noise-based notes) and therefore appears, together with the gesture parameters, in the public data feed from which the composition is played. Each contribution receives its own randomly generated identifier at the moment of release; contributions are therefore not correlatable with one another through it, nor with a person.
Payment data (card number, expiry, CVC, cardholder name, billing country) is collected and processed directly by Stripe Payments Europe Ltd. The Administrator does not receive, see, or store payment card data. From Stripe the Administrator receives a transaction identifier and the payment status; where the Contributor does not type an email address, the receipt email address held by Stripe (for example when a saved payment method such as Link is used) may also be received and used in place of the missing address.
The Project uses browser local storage and IndexedDB to store user interface preferences and a local copy of recent contributions to the Work. This data resides exclusively on the Contributor's device and is not transmitted to the Administrator's servers.
The hosting provider (Netlify) automatically processes connection logs (IP address, timestamp, requested URL) for security and operational purposes. These logs are managed by Netlify under its own privacy policy. In addition, the Project itself briefly stores the connection IP address to enforce per-address rate limits that protect the payment and administrative endpoints from automated abuse (legal basis: legitimate interest, Article 6(1)(f) GDPR). This information is used solely for abuse prevention, not to identify or profile Contributors.
The Project itself sets no cookies. When the payment dialog is opened, Stripe's client library (Stripe.js) sets its own strictly-necessary cookies (such as __stripe_mid and __stripe_sid) for fraud prevention, governed by Stripe's own cookie policy. Because these are technical cookies necessary to provide a service the Contributor has expressly requested, no consent banner is required; they are set only if and when the Contributor chooses to open the payment dialog.
Personal data may be shared with:
These parties act as independent data controllers or data processors under their own privacy terms. No data is sold or transferred to third parties for marketing purposes.
Some recipients — notably Netlify, Inc., Resend, GitHub, Inc., and certain sub-processors used by Stripe — may be established in countries outside the European Economic Area, including the United States. In such cases, transfers are protected by appropriate safeguards under Articles 44-49 GDPR, such as Standard Contractual Clauses or adequacy decisions of the European Commission.
The Administrator may anonymise data after a reasonable period while preserving the integrity of the Work.
Under Articles 15-22 GDPR, you have the right to:
To exercise these rights, contact: contact@onenotenow.com
You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali, www.garanteprivacy.it).
The Work is an indivisible collective artistic composition. Upon receiving an erasure request the Administrator applies an anonymisation procedure based on Article 17(3)(a) GDPR (freedom of expression and information exception): the link between the Contributor and the sound event is severed, but the sound event itself is preserved as part of the artistic Work.
payment_intent_id) remains in operational records because it is an identifier on the side of the payment processor. The Contributor may exercise their rights with respect to that identifier directly toward Stripe under Stripe's own privacy policy.To demonstrate that the erasure was carried out, a small audit row is written for each fulfilled request, containing only the SHA-256 hash of the email address, a timestamp and counts of affected records. The audit row never contains the email address in clear text. It is retained under Article 5(2) GDPR (accountability).
Personal-data fields (email addresses) inside backup snapshots are encrypted with a key held separately from the backup repository, so the repository's version history never contains readable personal data. Snapshots are retained for evidentiary purposes only insofar as required by Article 17(3)(e) GDPR (defence of legal claims); because the backup copies are encrypted, they can be rendered permanently unreadable by destroying the key.
Send a request to contact@onenotenow.com from the email address you used when contributing. To help identify your contributions you may include any unique code received in your receipts. The Administrator responds within 30 days, as provided by Article 12(3) GDPR.
The Project is not directed to persons under 18 years of age and does not knowingly collect data from minors.
This Privacy Policy may be updated. The version in force at the time of each contribution applies to data collected at that time.