Privacy Policy
Last updated: 27 May 2026
1. Pre-launch notice
Leavz is currently in a pre-launch state. Public registration is closed, and the platform does not actively accept new user accounts or user-generated content from the general public. Accordingly, the data controller for the production service has not yet been formally appointed.
A specific data controller — including legal entity name, registered address, and contact details — will be published in this document before registration is opened. Until that point, no marketing communications, profile building, or behavioural analytics are performed on visitors.
2. Data we may process during the pre-launch phase
Even during pre-launch, certain technical data is processed when you visit this website. We minimise this to what is strictly necessary to operate the site:
- Server access logs: IP address, request URL, user-agent string, timestamp, HTTP status. Retained no longer than 30 days. Used solely for security monitoring and debugging.
- Essential session cookies: a session identifier, a CSRF token, and a locale preference cookie. None of these are used for tracking or advertising.
No analytics scripts, third-party tracking pixels, advertising networks, or social media trackers are loaded by the website at this stage.
3. Legal basis (GDPR)
Under the EU General Data Protection Regulation (Regulation 2016/679), the limited processing described above is performed on the basis of:
- Article 6(1)(f) — legitimate interests: for server logs and security monitoring; the interest being the integrity and security of the service.
- Article 6(1)(b) — performance of a contract: for essential session cookies that make the site technically operable.
4. Cookies
The website uses only strictly necessary cookies, which are exempt from prior consent requirements under Article 5(3) of the ePrivacy Directive (2002/58/EC, as amended). No optional, analytics, advertising, or third-party cookies are set.
A non-intrusive notice is shown on first visit to inform you of this. No accept/reject choice is required because no optional cookies exist.
5. Data sharing and international transfers
No personal data is shared with third parties, advertisers, or analytics providers. Server infrastructure is hosted on commercial cloud providers; technical data (logs, session state) may be processed on their infrastructure as part of normal operation. No outbound transfers of personal data are made beyond what is necessary to deliver website content.
6. Your rights under GDPR
If GDPR applies to you, you have the right to:
- Request access to any personal data we hold about you (Art. 15);
- Request rectification of inaccurate data (Art. 16);
- Request erasure (Art. 17);
- Request restriction of processing (Art. 18);
- Receive your data in a portable format (Art. 20);
- Object to processing based on legitimate interests (Art. 21);
- Lodge a complaint with a supervisory authority (Art. 77).
During the pre-launch phase, requests can be addressed to the contact channel listed in section 9. Once a formal data controller is appointed, the appropriate request channel will be specified here.
7. Data retention
Server access logs are automatically rotated and deleted after 30 days. Session cookies expire when you close the browser or after a short idle period. No long-term storage of visitor-identifying data is performed in the pre-launch state.
8. Changes to this policy
This policy will be updated when registration is opened, when a data controller is appointed, or when the scope of processing changes. The "last updated" date at the top of this page reflects the most recent revision. Material changes will be announced on the homepage prior to taking effect.
9. Contact
Questions or requests regarding this policy can be sent to ten.zvael@ofni .