Bitware Labs Est. 2022

Bitware Labs/Privacy

Privacy

The short version: this site sets no cookies, runs no analytics, loads nothing from anyone else's servers, and only collects something if you write to me.

In one paragraph

No cookies. No analytics. No tracking pixels, no fonts or scripts fetched from a third party — everything this page loads comes from this server. If you use the contact form, your name, email address, message, IP address and the time are emailed to me and nowhere else. Web server access logs are kept 14 days. Nothing is sold, shared or added to a mailing list.

Who is responsible

Bitware Labs in Skåne, Sweden, is the data controller for this website. In practice that is one person, Henrik Robertsson, reachable at henke@bitwarelabs.com. Mail about your data goes to the same address as everything else and gets a real reply.

What is collected, and why

If you use the contact form

The form collects your name, email address and message because I cannot answer without them. It also records your IP address and the time of submission, which are included in the email I receive and used to rate-limit submissions — five per hour per address. Without that the form becomes a spam relay within days.

The legal basis is legitimate interest (GDPR Art. 6(1)(f)): answering correspondence you initiated, and keeping the form usable. If a message leads to work together, the basis for what follows becomes performance of a contract.

The message is delivered by SMTP to a mail server on this same machine and into my mailbox. It does not pass through a form service, a CRM, or any third-party processor.

Web server logs

Like essentially every web server, this one records requests: IP address, timestamp, requested URL, HTTP status, referrer and browser user-agent. These exist for security and diagnostics — spotting attacks, finding breakage. They are not used to build any profile of you and are not connected to anything else.

Rate-limit counters

Submitting the form writes a small counter file keyed by a SHA-256 hash of your IP address — the address itself is not stored in it. Counters are swept automatically two hours after last use.

How long things are kept

  • Web server access logs — 14 days, then deleted automatically.
  • Rate-limit counters — swept two hours after last use.
  • Contact form emails — kept in my mailbox while the conversation is live and for as long as it is useful to have the thread. Ask and I will delete it.
  • Client project correspondence — retained for the life of the engagement, and afterwards where Swedish bookkeeping law requires it (seven years for accounting records).

What this site does not do

  • No cookies. None at all — which is also why there is no cookie banner to dismiss.
  • No analytics. Not Google Analytics, not a self-hosted alternative, nothing. I genuinely do not know how many people read this.
  • No third-party resources. Fonts, images, stylesheets and scripts are all served from this domain. No CDN, no font service, no embedded widgets — so no one else gets to see your request.
  • No advertising, no profiling, no automated decision-making.
  • No data transfers outside the EU/EEA. The servers are in Europe and the data does not leave them.

Other things on this domain

This domain also serves some of the lab's own applications on separate paths and subdomains. Those are separate systems with their own behaviour — several require an account and therefore do set a session cookie. This notice covers the public website at bitwarelabs.com and the contact form. If you use one of the applications and want to know what it stores, ask.

Your rights

Under the GDPR you may request access to the personal data I hold about you, its correction, its erasure, restriction of its processing, a portable copy, and you may object to processing based on legitimate interest.

Write to henke@bitwarelabs.com. There is no form and no ticket system — I will answer within 30 days, and realistically much sooner, because it is one person reading one inbox.

If you are not satisfied with how I handle it, you may complain to the Swedish authority for privacy protection, Integritetsskyddsmyndigheten (IMY).

Security

The site is served over HTTPS only, with HSTS. It runs on infrastructure the lab owns and administers rather than shared hosting. If you believe you have found a security problem, the security.txt explains how to report it — and you will get a human reply.

Changes

If this notice changes materially, the version here changes with it. It currently describes the site as of 28 July 2026.

Not legal advice

This notice describes what the site actually does, in plain language, rather than reproducing a template. If you need a formal DPA or a processor agreement for an engagement, ask and one will be drawn up.