Legal
Privacy Policy
What data the FLUX website collects, why, where it is kept, for how long, and how to use your rights.
Last updated
This policy explains how Bash Soft ("we", "us") handles personal data on the FLUX website and in the services offered on it: the waitlist, the newsletter and email correspondence. We collect as little as we can, and we never sell personal data or use it for advertising.
The FLUX messenger itself will come with its own notice when it is released. Its messages are end-to-end encrypted: we cannot read their content (see the Security & Data Notice).
Who is responsible#
Bash Soft is the controller of the personal data described here. For anything about your data, write to Management@bash-soft.com.
What we collect#
Waitlist. Your email address, where you signed up (for example "landing"), and the status and dates of your place on the list (signed up, confirmed, invited).
Newsletter. Your email address, where you subscribed, your consent, and the status and dates of your subscription (subscribed, confirmed, unsubscribed).
Emails we send you. The address, the kind of email (for example a confirmation), and what our email delivery provider reports about delivery: delivered, bounced, or marked as spam. While an email waits to be sent, its content is stored encrypted; once it is sent, the content is erased.
Website statistics, without cookies. Daily counts of page views, of the pages viewed, of the domain of the site that linked to us (never the full address), and of a few named interactions such as pressing a sign-up button. To count unique visitors per day, we combine your IP address and browser identifier with a secret value that changes every day, and keep only the resulting code. The daily value and the codes are deleted when the day ends, so we cannot recognise you from one day to the next, and your IP address itself is not stored. Browsers that send Global Privacy Control or Do Not Track, and automated visitors, are not counted at all.
Protection against abuse. To limit how often forms can be used, we keep counters keyed by a one-way, keyed code of your IP address (or its network) and, for sign-ups, of the email address. They are deleted when their time window ends — at most one day.
Server logs. Our hosting provider records technical data about requests (such as IP address, address requested, time and browser identifier) for operation and security, for a short period it sets.
When you write to us. Your email address and what you write, to answer you.
What we never receive. The website refuses private keys, session keys, message content and any other cryptographic material. Donations go directly over public blockchains to the addresses on our support page: we receive no data about you from them, but blockchain transactions are public by nature.
Why we use it, and on what legal basis#
| Purpose | Legal basis (GDPR) |
|---|---|
| Waitlist: telling you when access is ready | Your consent (Art. 6(1)(a)) |
| Newsletter | Your consent (Art. 6(1)(a)) |
| Confirmation emails that check an address belongs to the person signing up | Your consent, and our legitimate interest in not mailing people who did not ask (Art. 6(1)(f)) |
| Website statistics without cookies | Our legitimate interest in understanding how the site is used (Art. 6(1)(f)) |
| Protection against abuse, security and logs | Our legitimate interest in keeping the site and its users safe (Art. 6(1)(f)) |
| Answering your messages | Our legitimate interest in replying, or steps you ask for before an agreement (Art. 6(1)(f), (b)) |
| Meeting legal obligations | Legal obligation (Art. 6(1)(c)) |
You can withdraw consent at any time — every email has an unsubscribe link — without affecting what happened before.
How long we keep it#
- Sign-ups never confirmed: the confirmation link works for 48 hours; the address is deleted 30 days after the link expired.
- Waitlist and newsletter: while you are on the list. After you leave it, the address is deleted within 30 days.
- Addresses that bounced or were blocked: kept as a do-not-send record, so we do not email them again. Ask us and we delete it.
- Records of emails sent: 90 days.
- Visitor codes for statistics: deleted at the end of each day. The daily counts that remain contain no personal data.
- Abuse-protection counters: at most one day.
- Your correspondence with us: as long as needed to deal with it, and as long as the law requires.
Who processes it for us#
We use service providers that process data only on our instructions:
- Vercel Inc. — hosts the website, in its Frankfurt (Germany) region.
- Neon Inc. — hosts the database, in the AWS Frankfurt (Germany) region.
- Our email delivery provider — sends the emails described above and reports on their delivery.
Fonts are served from our own site, so your browser does not contact a font provider. Some articles may show images hosted on other websites; loading them lets those sites see your IP address.
We do not sell personal data, share it with advertisers or data brokers, or use it to profile you. We disclose data to authorities only when the law requires it.
Transfers outside the EU#
Our data is stored in the EU. Some of our providers are companies based in the United States. Where data may be accessed from outside the European Economic Area, the transfer relies on the European Commission's Standard Contractual Clauses or an adequacy decision such as the EU–U.S. Data Privacy Framework.
Your rights#
Under the GDPR you can ask us to:
- tell you what data we hold about you and give you a copy (access, portability);
- correct it (rectification);
- delete it (erasure);
- limit how we use it (restriction);
- stop using it on the basis of our legitimate interest (objection);
- and you can withdraw consent at any time.
Write to Management@bash-soft.com. We answer within one month and may ask you to confirm that the address is yours. You can also complain to the data protection authority of the EU country where you live or work.
How we protect it#
Connections to the site are encrypted (HTTPS). Confirmation and sign-in tokens are stored only as one-way hashes, IP addresses only as keyed codes, and pending email content encrypted. Only a small team can access the data, each with two-factor authentication, and every administrative change is recorded in an audit log.
Children#
The website and its services are not intended for people under 16, and we do not knowingly collect their data. If you believe a child has signed up, write to Management@bash-soft.com and we will delete the data.
Changes#
When this policy changes, we update the date at the top. If a change affects how we use the data of subscribers in a meaningful way, we tell them by email before it takes effect.
Contact#
Privacy and data protection: Management@bash-soft.com. Everything else: Support@bash-soft.com.