Legal

Privacy

Last updated 14 September 2026.

This describes what the product actually does. Noticewin holds very little about you, and most of what it holds never leaves your own browser.

Who is responsible

House Flax (Italy, VAT-ID 12786200969) is the data controller for Noticewin. Write to hello@houseflax.com for anything on this page. We have not appointed a Data Protection Officer; we are not required to.

What we hold, and why

Your account — name, email address and a hashed password — is stored on our server so you can sign in. Legal basis: performance of the contract between us (Art. 6(1)(b) GDPR). Without it there is no desk to open.

Your instrument list — vendors, retainers, leases, prices, renewal dates, notes — stays in the browser you type it into, under this site’s own storage. We do not receive it, cannot read it, and cannot restore it for you. If you send it to us yourself (attached to a support email, say) we hold that email.

Payment records — when you buy a plan, Stripe processes the payment and tells us the email you paid with, the plan, and the subscription status. We store those to grant access. We never see your full card number. Legal basis: performance of the contract, and our legal obligation to keep accounting records.

Server logs — our host records the ordinary delivery data any web server records, including IP address, for security and troubleshooting. Legal basis: our legitimate interest in running a working, non-abused service (Art. 6(1)(f)).

Who processes it for us

Cloudflare hosts the application, stores its database (D1) and processes server logs on our behalf. Its edge network is global, so a request is served from a location near you.

Stripe processes payments as an independent controller for the payment itself, and passes us the confirmation described above.

Both may process data outside the EEA under the European Commission’s Standard Contractual Clauses. The database itself is created in the European region.

There is no third processor. Fonts are served from this domain, not a font host. There is no advertising, no cross-site tracker, no profiling, and no analytics company: the page loads nothing from anyone else, which you can confirm by viewing its source.

How we count visits and catch faults

Both are ours and both are aggregate. A pageview adds one to a counter for a date and a path — there is no visitor id, no cookie, no IP address and no session, so the record cannot be turned back into one person’s browsing even by us. Legal basis: our legitimate interest in knowing which pages are read (Art. 6(1)(f)); there is nothing here to consent to.

When a page breaks, the browser sends us the error message, the technical stack trace and the path it happened on — with the query string removed before sending, so a token or an address in a URL never reaches the log. Legal basis: our legitimate interest in running a working service. Kept 90 days.

Cookies and local storage

One cookie: the sign-in session. It is strictly necessary to keep you signed in, so it needs no consent banner and we do not ask for one. It is first-party, HttpOnly and Secure, and it expires when the session does.

Your instrument list uses this browser’s local storage. That is also strictly necessary — it is the product — and it never leaves your device.

How long we keep it

Account and entitlement records: for as long as you have a desk, and for 30 days after you ask us to close it. Invoicing records: ten years, as Italian tax law requires. Support correspondence: two years. Server logs: as retained by our host, typically weeks rather than months. Your instrument list: until you delete it, which you do by clearing this site’s data on your device — we cannot do it for you because we never had it.

Your rights

You may ask us for access to your data, correction, erasure, restriction of processing, or a portable copy; and you may object to processing based on legitimate interest. Write to hello@houseflax.com from the address on your account and we will answer within 30 days. There is no charge.

If you think we have handled your data badly, you can complain to the Italian supervisory authority, the Garante per la protezione dei dati personali (garanteprivacy.it), or to the authority where you live.

What we do not do

We do not sell workspace contents. We do not run advertising pixels. We do not connect to your bank, and we never ask for your vendors’ account passwords. We do not make automated decisions with legal effects about you.

Changes

If this policy changes materially we will say so on this page and email account holders before it takes effect. The date at the top is the version in force.