Your data never leaves Europe. Not because we route it through an EU region of a US cloud provider — because every company in our stack is European. No US parent companies. No FISA 702 exposure. No Cloud Act risk. The service runs in Germany (EU); backups are kept in Norway (EEA).
Our sub-processors
Two companies. Both European-headquartered. That's the entire list.
| Company |
Purpose |
Location |
| netcup GmbH |
Infrastructure hosting |
Nuremberg, Germany |
| Armitage Labs OÜ (Creem) |
Payment processing |
Tallinn, Estonia |
Full details including data flow and change notification process in our sub-processor list.
We have a signed
Data Processing Agreement
available for customers who need one.
No third-party tracking.
No analytics cookies. No third-party scripts. No ad networks. The only cookies we set are strictly necessary for logging in (see section 10). We keep a simple first-party log of page visits on our own server to see which pages are used; it is pseudonymous (a salted hash of your IP address instead of the address itself) and deleted after 90 days.
At a glance
- 2 sub-processors — both EU-headquartered
- Zero US companies in the data chain
- Execution history auto-deleted — 30 days, all tiers
- Encrypted in transit (TLS 1.2+) and at rest
-
Delete or export any time — from your account and organization settings
-
European-owned, independently funded
— no US parent company, no outside pressure to change jurisdiction
- Company: Whitenoise AS, Oslo, Norway (Norwegian jurisdiction)
Whitenoise AS is a Norwegian company. Norway is part of the European Economic Area (EEA) and subject to GDPR through the EEA Agreement. Your data receives the same protection as in any EU member state.
Full Privacy Policy
The details above are the summary. Below is the full legal policy for your compliance team.
This Privacy Policy explains how Whitenoise AS ("we", "us", or "our"), operating the Runlater service, collects, uses, and protects your personal data. We are committed to GDPR compliance and protecting your privacy.
1. Data Controller
The data controller for your personal data is:
- Whitenoise AS
- Org.nr: 821 244 722
- Oslo, Norway
-
support@runlater.eu
2. Data We Collect
Account Information
- Email address (required for account creation and login)
- Organization name (if you create one)
- Team member information (email addresses of invited members)
Task Configuration Data
- Task names and descriptions
- Webhook URLs you configure
- HTTP headers and request bodies you specify
- Cron expressions and scheduling configuration
Execution Data
- Task execution timestamps and duration
- HTTP status codes from your webhooks
-
Response bodies (truncated to 256KB) and response headers returned by the URLs you call
- Error messages and Lua script logs
Inbound Webhook, Queue and Monitor Data
When a third party sends a request to one of your inbound endpoints, we store the request so you can inspect, forward and replay it:
-
All request headers as sent, including authentication headers such as
Authorization
or Cookie
if the sender includes them
- The request body (up to 256KB) and HTTP method
- The sender's IP address
Message queue messages (the bodies you enqueue) and monitor heartbeat pings (timestamp, status and optional message) are stored as well.
Usage Data
-
Page visits: path, referrer (with query strings removed), browser user agent, your user ID when logged in, and a salted hash of your IP address. This is pseudonymous rather than anonymous data: it does not contain your IP address, but it can be linked to your account.
- API requests and timestamps
- IP addresses, used transiently for rate limiting and abuse prevention
-
Error reports: when the application hits an unexpected error we record the error, the request path and the request parameters, for debugging
- A log of emails we have sent (recipient, subject, type, delivery status)
3. How We Use Your Data
We use your data to:
- Provide and operate the Service
- Send magic link emails for authentication
- Send usage alerts (when approaching limits)
- Send important service announcements
- Debug issues and improve the Service
- Prevent abuse and enforce our Terms of Service
We do not use your data for advertising or sell it to third parties.
4. Legal Basis for Processing (GDPR)
We process your data based on:
- Contract: To provide the Service you signed up for (Art. 6(1)(b))
-
Legitimate interest:
To improve the Service and prevent abuse (Art. 6(1)(f))
- Legal obligation: To comply with applicable laws (Art. 6(1)(c))
5. Data Storage and Security
Your data is stored in the European Economic Area:
-
Location:
The application and primary database run in Nuremberg, Germany (netcup data center, EU)
-
Backups:
A continuously updated database replica, a continuous archive of database changes and nightly backups (kept for 30 days) are stored in Norway (EEA), on hardware operated by us
-
Encryption:
Data encrypted in transit (TLS 1.2+) and at rest — the production database, the standby replica and all backups are stored on encrypted disks
- Access: Limited to authorized personnel only
- API keys: Stored as irreversible hashes (never in plain text)
-
Email:
Sent directly from our server in Germany — no third-party email provider
6. Data Retention
- Account data: Retained while your account is active
-
Execution history
(including response bodies and headers), inbound webhook events
(including headers, bodies and sender IPs), queue messages
and monitor pings:
30 days, then automatically deleted
- Email logs: 30 days
- Error reports: 30 days
- Audit logs: 90 days
- Page visit log: Pseudonymous, retained for 90 days
-
Account or organization deletion:
You can delete your account (account settings) or an organization (organization settings, owners only) at any time. Deletion removes the data from our live database right away; clearing large histories finishes in the background shortly after. Entries you made in a shared organization's audit log are kept for that organization, with your email address removed.
-
Backups:
Deleted data can remain in our backups for up to about 60 days (30 days of nightly backups plus the change archive needed to restore them) before it is removed. Backups are only used to restore the service after a failure.
7. Sub-processors
We use a limited number of sub-processors to operate the Service. See our
Sub-processor list
for details. We only share data with:
-
Your webhook endpoints: We send HTTP requests to URLs you configure
- Infrastructure provider: netcup (Germany) for hosting
-
Payment provider:
Creem (Estonia) for payment processing as Merchant of Record
We do not share data with analytics services, advertising networks, or data brokers.
8. International Transfers
Your data is processed in the European Union (Germany) and backed up in Norway, which is part of the European Economic Area and applies the GDPR through the EEA Agreement. Both sub-processors are EU-based. See our
Sub-processor list
for details. We do not transfer personal data to countries outside the EU/EEA. Requests the Service makes to URLs you configure go wherever those URLs point, which is under your control.
9. Your Rights (GDPR)
Under GDPR, you have the right to:
- Access: Request a copy of your personal data (Art. 15)
- Rectification: Correct inaccurate data (Art. 16)
-
Erasure:
Request deletion of your data ("right to be forgotten") (Art. 17)
-
Portability: Export your data in a machine-readable format (Art. 20)
- Restriction: Limit how we process your data (Art. 18)
-
Objection: Object to processing based on legitimate interest (Art. 21)
You can exercise access, portability and erasure yourself: Export my data
and Delete my account
are in your account settings. Organization owners and admins can export an organization's data, and owners can delete it, in the organization settings. Exports are machine-readable JSON files.
For anything else, contact us at
support@runlater.eu. We will respond within 30 days.
10. Cookies
We use minimal, essential cookies only:
-
Session cookie
(
_app_key): keeps you logged in and holds the CSRF protection token (signed, HttpOnly, Secure). Expires when you close the browser or log out.
-
Remember-me cookie
(
_runlater_web_user_remember_me): only set if you choose to stay logged in; keeps you logged in for up to 14 days (signed, HttpOnly, Secure, SameSite=Lax). Removed when you log out.
We do not use tracking cookies, analytics cookies, or third-party cookies. No cookie consent banner is required as we only use strictly necessary cookies (GDPR Art. 5(3) ePrivacy Directive exemption).
11. Children's Privacy
The Service is not intended for users under 16 years of age. We do not knowingly collect data from children.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email. The "last updated" date at the top indicates when changes were made.
13. Complaints
If you believe we have not handled your data correctly, you have the right to lodge a complaint with your local data protection authority. In Norway, this is Datatilsynet.
14. Contact
For privacy-related questions or requests:
- Whitenoise AS
- Org.nr: 821 244 722
-
support@runlater.eu