Privacy
This notice describes what ChronoArx does with personal data, in the detail the code actually supports. It took effect on 2026-09-18.
Who holds the data
The data controller is TechnoDesign, inženirsko svetovanje in druge storitve, Tom Horvat s.p., a sole proprietor registered in Slovenia and trading as ChronoArx. The controller is therefore a natural person acting in the course of that business, not a limited company.
Registered address: Aškerčeva ulica 3, 2000 Maribor, Slovenia. Registration number (matična številka) 8496072000. Tax number (davčna številka) 66333300. Not registered for VAT.
Write to privacy@chronoarx.com about anything on this page, including any of the rights described below. Anything else reaches us at info@chronoarx.com.
What the waiting list form stores
If you join the waiting list, we store your email address exactly as you typed it, together with a normalised copy of it used only to tell whether that address has joined before. We do not display or send mail to the normalised copy.
Alongside it we store the exact wording of the consent you agreed to, a version identifier for that wording, the time you agreed according to our server’s clock, and the network address the form was submitted from. We keep the wording itself rather than a reference to it so that we can show what was agreed to, not merely that something was.
If you arrived through a campaign link, we also store what that link said about where you came from — the source, medium and campaign it named, and the referring page.
Your place on the waiting list is not confirmed until you open the link we email you. That link is stored only as a one-way hash, so we cannot reproduce it after it has been sent; it expires, and opening it records the time and the network address it was opened from. If you never open it, nothing further happens.
Why we hold it, and on what basis
The email address and consent record exist so we can send you three kinds of message, and so we can show afterwards what you agreed to: a welcome message from the founder right after you confirm, a short build update every three weeks, and two milestone emails — one when reservations open and one when Series One goes on sale. Nothing else. The network address exists for one narrower reason: the waiting list form is public and it sends mail, so it is rate-limited per address to stop it being used to deliver unsolicited mail through our domain.
The lawful basis for the waiting list mail is your consent, given by submitting the form having read the wording beside it, and confirmed by opening the link we send. You can withdraw it at any time, and the section on removal below says exactly what happens when you do. Keeping the rate-limiting record rests instead on our legitimate interest in not having our mail domain used to send messages nobody asked for.
If you hold an account on the collection app, the data behind it is processed to provide the service you signed up for, which is a contractual basis rather than a consent one. Withdrawing consent to marketing mail does not close an account, and closing an account is a separate request.
How long we keep it
Waiting list records are deleted 24 months after the last thing that happened on them, counting from the confirmation if you confirmed and from the signup if you never did. A job runs once a day and removes everything past that point. Deleting the record takes its confirmation with it, and the network address stored beside it goes at the same time: it is part of that record and has no separate, shorter life of its own.
Sign-in attempts on the collection app are kept separately and for a different reason, and they never hold your address. What is stored is a keyed one-way hash of it and of the network address, which is what lets us count attempts without keeping the things being counted. Nothing deletes those records today, and we would rather say so than name a period nothing enforces.
If you hold an account on the collection app, the data in it is kept for the life of the account.
Asking to be removed
Write to privacy@chronoarx.comand ask. Within one working day we record your request as a fingerprint of your address rather than as the address itself, and mail to you stops immediately — every message this system can send is checked against that record before it is sent.
Sign-in links for the collection app are still sent, because you ask for them at the moment you sign in.
Your waiting list records are then deleted at the next daily run, and what remains is the fingerprint. We keep it deliberately, and it is the reason this works: it is what remembers that your address must never be mailed again once the address itself is gone. Without it, a later signup or an old export would simply add you back.
The fingerprint is a keyed one-way hash. The key is held outside the database, so the record cannot be turned back into your address by anyone reading the data, and it does not identify you to us either. It is not a copy of your address kept under another name.
If you change your mind you can join again, and you should know what happens if you do: the form accepts you, your consent is recorded, and no mail is sent, because the request not to mail you is still on file. The page tells you so and asks you to write to privacy@chronoarx.com so we can lift it.
Your other rights
You can ask what we hold about you and get a copy of it, ask us to correct it, ask us to restrict what we do with it, object to processing that rests on our legitimate interest, and ask for the data you gave us in a portable form. Write to privacy@chronoarx.com.
If you think we have handled your data badly, you can complain to the Slovenian Information Commissioner (Informacijski pooblaščenec), Dunajska cesta 22, 1000 Ljubljana, or to the supervisory authority where you live.
Who else handles it
The site is hosted by Vercel, the database is Neon, and the confirmation email is delivered by Resend. Each of them necessarily handles the data described above in the course of providing that service.
When someone joins the waiting list or creates an account, we send ourselves a notification that contains that email address, and it arrives in our own mailbox, which runs on Google Workspace.
If you accept analytics, Google Analytics also receives the information described in the next section. It receives nothing at all if you do not.
These providers process data in the European Union and in the United States. Where data reaches the United States it does so under the provider’s own standard contractual clauses or an equivalent adequacy mechanism; we do not transfer anything outside those arrangements.
Cookies, and what the banner does
Nothing that identifies you is stored on your device until you choose it. The only cookie this site sets before you decide is none at all; the banner appears because there is a choice to make, not because something is already running.
When you answer it, we store your answer in a cookie named ca_consent, which lasts 365 days. It holds one value and nothing else: the word granted or the word denied. No identifier, no time, nothing that distinguishes you from anyone else who gave the same answer. It is what stops you being asked again, so declining and accepting both set it.
If you accept, Google Analytics loads and sets its own cookies to count visits and tell a returning browser from a new one. If you decline, it is never loaded and those cookies are never set. You can change your answer at any time using the Cookie settings link in the footer, which brings the banner back with your current answer shown, or by clearing this site’s cookies in your browser.
The banner is not shown on the pages you reach from a link in an email we sent you, because those links carry a token that identifies the message, and a consent choice made there could be tied to it. The token is never sent to Google Analytics; it is removed from the page address before anything is measured.
Analytics
Measurement runs in two parts. Vercel Web Analytics counts page views without cookies and without building a profile of you; it runs whatever you answer, because it identifies nobody. Google Analytics runs only if you accept, and records which pages were viewed, which links were pressed, and whether a waiting list signup was submitted and confirmed — never the address itself.
Google Analytics is loaded with consent mode, so until you accept it is told explicitly that it has no permission for analytics or advertising storage. No advertising or cross-site tracking technology runs on these pages at all.
How it is kept
The consent records are append-only: the system is deliberately built so that a record of what somebody agreed to cannot be edited afterwards, because a record someone could later dispute is worthless if it can be rewritten. The single exception is deletion under the rules above, which happens through one audited path and nothing else.
Changes to this notice
If this notice changes materially we will change the date at the top of it. We will not change what we do with data already collected without telling the people it belongs to.
TechnoDesign, inženirsko svetovanje in druge storitve, Tom Horvat s.p., Aškerčeva ulica 3, 2000 Maribor, Slovenia. Consent wording version 2026-09-23.