Privacy Policy
Epimonos processes as little personal data as possible. Privacy isn't a marketing claim: it's the core of what we build. This policy explains what data we collect, why, and how long we retain it.
1. Data controller
Epimonos
[ADDRESS]
Chamber of Commerce: [REGISTRATION NUMBER]
Email: legal@epimonos.com
2. What data do we process?
2.1 Contact form and waitlist
When you send a message or sign up for the waitlist, we process:
- Name
- Email address
- Phone number (optional, only if you provide it)
- Message content / plan interest
This data is forwarded by email to the relevant department within Epimonos. It is not stored in a database.
Legal basis: legitimate interest (Art. 6(1)(f) GDPR), for handling your request.
2.2 Payments via Stripe
Payments are processed by Stripe Payments Europe, Ltd. Epimonos has no access to full payment card details. Stripe acts as an independent data controller for payment data. See stripe.com/privacy.
2.3 Visitor analytics (Plausible)
We use Plausible Analytics, a privacy-friendly, open source analytics tool that sets no cookies and stores no personal data. Plausible only records aggregated page statistics (page views, country of origin at country level). No cookie banner is required and Plausible falls outside the scope of GDPR personal data. See plausible.io/privacy.
We host Plausible entirely ourselves, on our own server, on our own network (not on Plausible's cloud service or any other third-party provider). Visitor statistics are measured without identifiable information, and this data never leaves our own network: your browser only ever talks to our website, which internally forwards the page-view count to our own analytics server. No data is sent to any external party.
2.4 Currency detection (IP address)
To display the correct currency (EUR or USD), we use a hashed version of your IP address. The raw IP address is never stored; only a non-reversible hash combined with the detected currency is temporarily held in a server-side cache. This cache expires automatically. No cookies or localStorage are used.
2.5 Server logs
Our server records standard Apache access logs (IP address, page, timestamp). These logs are used solely for security and debugging and are retained for a maximum of 30 days.
3. Retention periods
| Data | Retention period |
|---|---|
| Contact form (email) | As long as relevant for handling, then deleted |
| Currency region lookup | Processed locally; no visitor IP or hash is retained for this lookup |
| Server logs | Max. 30 days |
| Payment data (Stripe) | Per Stripe's retention policy (statutory period) |
4. Your rights
Under GDPR you have the following rights:
- Access: request what data we hold about you.
- Rectification: correct inaccurate data.
- Erasure: request deletion of your data.
- Objection: object to processing based on legitimate interest.
- Portability: receive your data in a structured format.
Send your request to legal@epimonos.com. We respond within 30 days.
You may also lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens): autoriteitpersoonsgegevens.nl, or with the supervisory authority in your country of residence.
5. Changes
We may update this policy. The most recent version is always on this page, with the date of the last update at the top.
Questions? Email legal@epimonos.com.