Legal

Privacy Policy

Umbrella privacy notice covering indexiumlabs.com, indexaro.com, and launchauditor.com. Written to align with the EU General Data Protection Regulation (GDPR, Regulation 2016/679) and the ePrivacy Directive.

This policy is maintained by Indexium Labs. It is provided for transparency and is not legal advice. Where mandatory local law grants you stronger rights, those rights prevail.

Last updated

01

Data controller

Indexium Labs ("we", "us", "our") is the data controller for personal data processed through the marketing site at indexiumlabs.com and, as an umbrella controller, for cross-product privacy inquiries. Product-specific processing inside Indexaro (indexaro.com) and Launch Auditor (launchauditor.com) is governed by each product's own privacy notice, which prevails on conflict for that product.

You can reach us via either product's contact page: indexaro.com/contact or launchauditor.com/contact.

02

What we collect on this site

indexiumlabs.com is a static marketing site. We do not run analytics, advertising, or behavioural tracking here. The only personal data processed on this domain is:

  • Server request metadata — IP address, user-agent string, requested path, HTTP status, and timestamp — logged by Cloudflare, our edge provider, for security, abuse prevention, and reliability.
  • Strictly-necessary security cookies set by Cloudflare (see the Cookie Policy).

We do not knowingly collect special-category data (Art. 9 GDPR) through this site.

03

Legal bases (Art. 6 GDPR)

  • Art. 6(1)(f) — legitimate interests: operating and securing the site, preventing abuse, and maintaining edge infrastructure. You may object at any time (see §7).
  • Art. 6(1)(b) — contract performance: only where you engage a product on indexaro.com or launchauditor.com.
  • Art. 6(1)(c) — legal obligation: to respond to lawful requests and comply with statutory retention duties.

04

Retention

Cloudflare edge request logs are retained for a short operational window (up to 30 days) and then discarded or aggregated. Data submitted through a product's contact form is retained by that product per its own retention schedule.

05

Recipients & processors

We use a minimal set of processors on this site:

  • Cloudflare, Inc. — global edge, DDoS protection, and bot mitigation.
  • Lovable — hosting platform for the marketing site.

We do not sell personal data and we do not share it with advertising networks. Product-side subprocessors are listed on each product's site.

06

International transfers

Our edge infrastructure is global. Where personal data is transferred outside the EEA (for example, to Cloudflare data centres in third countries), transfers rely on the European Commission's Standard Contractual Clauses (Decision 2021/914) and appropriate supplementary technical and organisational measures.

07

Your rights under GDPR

Chapter III of the GDPR gives you the following rights, exercisable free of charge and, in ordinary circumstances, answered within one month:

  • Access to your personal data (Art. 15).
  • Rectification of inaccurate data (Art. 16).
  • Erasure — the "right to be forgotten" (Art. 17).
  • Restriction of processing (Art. 18).
  • Data portability (Art. 20).
  • Object to processing based on legitimate interests (Art. 21).
  • Withdraw consent at any time where processing is consent-based (Art. 7(3)).
  • Lodge a complaint with your national supervisory authority (Art. 77) — a directory is available at edpb.europa.eu.

To exercise any of these rights, contact us via either product page above with the subject line "Data Subject Request".

08

Automated decision-making

We do not carry out automated decision-making producing legal or similarly significant effects on visitors of this site (Art. 22 GDPR).

09

Children

This service is not directed to children under 16, or the lower age of digital consent set by your EU member state under Art. 8 GDPR. We do not knowingly process children's data on this site.

10

Security

We implement appropriate technical and organisational measures (Art. 32 GDPR) including TLS in transit, hardened edge configuration, least-privilege access, and a published security disclosure channel at /.well-known/security.txt.

11

Changes

We may update this notice. Material changes will be reflected in the "Last updated" date at the top of this page and, where required by law, notified in advance.