Legal

Privacy Policy

Last updated: 2026-06-17

ENDE

Privacy Policy

Controller

TWENTYELEVEN
Tom Kloevekorn
Eppendorfer Weg 176
20253 Hamburg
Germany
Email: mail@nocknock.cloud

No data protection officer has been appointed.

Purposes and legal bases

We process personal data in order to provide Nock, manage user accounts and workspaces, store feedback tickets and transfer them to connected services, process payments, prevent abuse and monitor the stability of the service.

The legal bases are in particular Art. 6 (1) (b) GDPR (performance of a contract and pre-contractual measures), Art. 6 (1) (c) GDPR (legal obligations, e.g. commercial and tax retention requirements) and Art. 6 (1) (f) GDPR (legitimate interest in secure, stable and data-minimised operation and improvement of the service).

Hosting and storage location

The application is operated on Vercel. Application data such as accounts, organisations, projects, tickets and images is stored on Supabase (Postgres, Storage, Auth). The Supabase project region is eu-central-1.

Processors and services used

  • Vercel – hosting, delivery and operation of the web application.
  • Supabase – database, authentication and file storage.
  • Hostinger – VPS in Germany for the self-hosted Plausible instance.
  • Stripe Payments Europe, Limited – payment processing, subscriptions, invoices and billing.
  • Anthropic (Claude API, USA) – AI-assisted preparation of submitted ticket content. Submitted ticket text may be transferred to Anthropic in the USA for processing.
  • Linear – optional synchronisation of tickets as issues.
  • Resend – delivery of transactional emails.
  • Cloudflare Turnstile – bot and abuse protection during registration and in forms.
  • Upstash / Vercel KV – rate limiting and abuse protection.
  • Sentry (Functional Software, Inc., EU region) – error and crash monitoring. Data categories: technical error data, stack traces, truncated request metadata, data-minimised user and workspace IDs. Processing and storage take place in the EU region, ingest host *.de.sentry.io. A data processing agreement (DPA) is in place.

Where providers process personal data outside the European Economic Area, this takes place on the basis of appropriate safeguards pursuant to Art. 44 et seq. GDPR, in particular the EU Standard Contractual Clauses, where required.

Widget data capture (feedback tool)

Nock is integrated by our customers as an embeddable feedback widget on their own websites. When an end user submits a ticket there, the widget automatically captures technical context so developers can reproduce reported issues. The embedding customer (the website operator) is responsible for deploying the widget on their site; Nock processes the captured data on their behalf.

On ticket submission, the widget transmits the following data to Nock:

  • Page address – only the origin and path of the page visited (without query string and fragment, as these can contain tokens, IDs or email addresses).
  • Browser and device information – browser name and version, operating system, and viewport and screen dimensions.
  • Console and network logs – error, warning and log messages emitted by the embedding website (including stack traces and serialised log content, as the site emits them), as well as failed network requests (method, status and a truncated error message). For the captured network errors, URLs they contain are truncated to origin and path before transmission (URL redaction) to remove query parameters containing personal data. Other log content is taken over unchanged, exactly as the site emits it. These logs are collected continuously into a bounded ring buffer from the moment the widget loads (not only at submission) and are transmitted together when a ticket is sent.
  • Content voluntarily provided by the user – the title and description text, optional screenshots and – where the AI follow-up is enabled – the answers the user enters.

The widget sets no cookies and performs no cross-device tracking. The capture serves solely to process the submitted feedback.

AI-assisted preparation (before submission): If the AI feature is enabled for the project and the end user uses the AI-assisted refinement or follow-up, the draft content entered so far (title, description and category) is transmitted for processing before the ticket is finally submitted, and may in that course be transferred to Anthropic in the USA (see the "Processors and services used" section).

Legal basis: Art. 6(1)(f) GDPR (legitimate interest of the website operator and of Nock in the traceable handling and reproduction of reported issues). Screenshots and free text are transmitted only on the user's explicit input.

Payments and subscriptions

For paid plans, Stripe processes payment, invoicing and subscription data. We do not store full card data in Nock. Payment processing is handled by Stripe.

During the free 14-day trial of the Lite plan, no payment method is on file and no data processing by Stripe takes place. Stripe is only involved once a payment method is added during the trial or a paid plan is activated.

Reach measurement (Plausible, self-hosted)

To improve the product and the user experience, we measure reach without cookies using Plausible Analytics, operated self-hosted on a Hostinger VPS in Germany (first-party). No cookies are set, no cross-device profiles are created and no transfer to third parties takes place through Plausible. The measurement also covers the logged-in application (which features are used) exclusively in aggregate and without individual tracking of identified users. URLs are stripped of personal path components such as IDs or tokens before being stored.

Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in data-minimised product and reach analysis). The depth of intervention is minimal: aggregated, cookieless and without storing the IP address.

Objection (Art. 21 GDPR): You can object to the measurement at any time, for example via the "Do Not Track" or "Global Privacy Control" setting of your browser, or by setting the localStorage key plausible_ignore to true.

As Plausible is operated self-hosted, there is no processing by Plausible as a third party. Hostinger is named above as the hosting provider of the instance.

Cookies and local storage

Only technically necessary cookies and comparable storage technologies are used, in particular for login sessions, security and Cloudflare Turnstile. No tracking with consent-requiring cookies takes place; a cookie banner is therefore not required.

Retention period

Personal data is stored only for as long as is necessary for the respective purposes or as long as statutory retention obligations exist. Account and workspace data is generally stored until the account or workspace is deleted. Invoicing and payment data is stored within the scope of statutory retention obligations.

Your rights

Under the GDPR you have the rights to access, rectification, erasure, restriction of processing, data portability and objection.

  • Erasure (Art. 17 GDPR): You can delete your account and the associated data via the "Account" page.
  • Data export (Art. 20 GDPR): To exercise the right to data portability, contact mail@nocknock.cloud. We will provide your data within 30 days.
  • Right to lodge a complaint: You have the right to lodge a complaint with a data protection supervisory authority. The competent authority may in particular be the Hamburg Commissioner for Data Protection and Freedom of Information, Ludwig-Erhard-Str. 22, 20459 Hamburg.