Privacy notice
Information under Articles 13 and 14 of the General Data Protection Regulation (GDPR).
1. Controller
The controller responsible for data processing on this website is:
A data protection officer has not been appointed, as the legal conditions requiring one are not met.
2. The short version
- This website sets no cookies and uses no tracking and no advertising. It counts visits anonymously with Cloudflare Web Analytics, without cookies and without user profiles — see section 4b. You do not see a cookie banner because no cookies are set.
- No content is loaded from third-party servers: no web fonts, no maps, no social media widgets. There are two exceptions: every page loads the Cloudflare Web Analytics counting script (section 4b), and on the video course page a YouTube video is loaded only after you click its play button (section 4a).
- Apart from these anonymous visit counts, the only data processed automatically is what any web server needs to deliver a page, handled by our hosting provider.
- The TagAlly Pro plugin processes your documents exclusively on your own computer. See section 7.
3. Accessing the website (server log data)
When you open this website, your browser transmits technical data that our hosting provider processes to deliver the pages and to protect the service. This typically includes:
- your IP address,
- date and time of the request,
- the page or file requested and the amount of data transferred,
- the HTTP status code,
- the referring page, browser type and version, and operating system.
Purpose: delivering the website, ensuring stability and security, and defending against attacks.
Legal basis: Art. 6 (1) (f) GDPR — our legitimate interest in operating a functioning and secure website.
Retention: this data is processed by our hosting provider for a short period for security purposes and is not merged with other data sources by us. We do not create personal user profiles.
4. Hosting
This website is hosted on Cloudflare Pages, a service of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. Cloudflare delivers the pages over its global network and also provides protection against attacks. In doing so, Cloudflare processes the connection data described in section 3.
Legal basis: Art. 6 (1) (f) GDPR — legitimate interest in secure, fast and reliable provision of the website.
Processing agreement: a data processing agreement under Art. 28 GDPR is in place with Cloudflare.
Transfers to third countries: processing may take place on servers outside the European Union, including in the USA. Cloudflare relies on the EU Standard Contractual Clauses and is certified under the EU–US Data Privacy Framework. Further information is available in Cloudflare’s own privacy policy at cloudflare.com/privacypolicy.
4a. Videos on the course page (YouTube)
The tutorial videos on the course page are hosted on YouTube, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. When you open the page, nothing is loaded from YouTube: you see a preview image that comes from our own server. Only when you click the play button does your browser load the video player from YouTube. From that moment on, YouTube processes your IP address, information about your browser and device, and the fact that you watched this video, and it may set cookies or use local storage in your browser. We embed the videos in YouTube’s “privacy-enhanced mode” (youtube-nocookie.com), which limits this processing but does not rule it out.
Legal basis: Art. 6 (1) (a) GDPR — your consent, which you give by clicking the play button. You withdraw it for the future simply by not clicking; you can also watch every video directly on YouTube instead.
Transfers to third countries: Google may transfer data to Google LLC in the USA. Google LLC is certified under the EU–US Data Privacy Framework.
Further information: Google’s privacy policy at policies.google.com/privacy.
4b. Website statistics (Cloudflare Web Analytics)
To see how often this website and its pages are visited, we use Cloudflare Web Analytics, a service of Cloudflare, Inc. (see section 4). Every page loads a small script from static.cloudflareinsights.com that reports the page view to Cloudflare. It sets no cookies, uses no fingerprinting and builds no user profiles. We only see aggregated figures such as page views, country, browser and referring page.
We also count how often the TagAlly Pro trial file is downloaded. Our own server keeps one number per day and version, without IP address or any other personal data.
Legal basis: Art. 6 (1) (f) GDPR — our legitimate interest in anonymous statistics on the reach of our website.
Transfers to third countries: as described in section 4, Cloudflare relies on the EU Standard Contractual Clauses and is certified under the EU–US Data Privacy Framework.
5. Contacting us by email
If you write to us — for support, a bug report or a question before buying — we process the data contained in your message: your email address, your name if you give it, and the content of your enquiry, including any attachments such as a conformance report or a log file.
Purpose: handling your enquiry.
Legal basis: Art. 6 (1) (b) GDPR where your enquiry concerns a contract or pre-contractual steps, otherwise Art. 6 (1) (f) GDPR — our legitimate interest in answering enquiries.
Retention: we keep correspondence for as long as it is needed to deal with your matter and to answer follow-up questions, and beyond that only where statutory retention periods apply. You may object to further storage at any time.
Please note that email is not an encrypted channel by default. Please do not send confidential documents unless we have agreed a secure route with you.
6. Purchases through the Adobe Creative Cloud Marketplace
TagAlly Pro is sold through the Adobe Creative Cloud Marketplace. In that channel the purchase contract is concluded with the marketplace’s merchant of record (currently FastSpring), which sells in its own name and collects and remits VAT.
This means your payment and billing data is processed by Adobe and by the merchant of record under their privacy policies, not by us. We receive from them only the information we need to fulfil the licence and provide support — typically your name, email address and the licence purchased. We do not receive your payment details.
Legal basis: Art. 6 (1) (b) GDPR (performance of the licence relationship).
Retention: for the duration of the licence relationship and beyond that only where statutory retention periods under commercial and tax law apply.
6a. Purchases directly from us
Our own store’s checkout runs entirely at FastSpring (Bright Market, LLC d/b/a FastSpring, Santa Barbara, USA), which sells as an authorised reseller and merchant of record and is an independent controller for the purchase. Payment data never reaches us. FastSpring’s privacy policy applies to the checkout.
To issue your licence key, FastSpring transmits to our licence service the order and subscription reference, the buyer or organisation name, and the number of seats. We store this — together with the issued key and its expiry date — at our hosting provider Cloudflare (see section 4), because renewals must update your key and the panel’s silent key retrieval must find it. Legal basis: performance of the contract, Art. 6 (1) (b) GDPR. The data is kept for as long as keys may still need to be issued for the contract, plus the statutory retention periods.
When the plugin retrieves a current key, our licence service processes the contract reference and, transiently for rate limiting, the requesting IP address; the IP is not stored beyond one hour. For purchases on invoice we additionally process the billing details you give us, kept for the statutory retention period of ten years (§ 147 AO).
7. Data processing in the TagAlly Pro plugin
This section describes the software, not the website. It matters because it is where your actual documents are.
TagAlly Check, the free edition, processes even less. It requests no network permission at all — you can read that in its plugin manifest before you install it — so the last two points below cannot apply to it: there are no AI features and no API keys. It has no helper program either. Everything it does happens inside the InDesign document you have open, and the only things it ever writes are the document title and the export language, and only when you ask it to.
- Your documents never leave your computer. Checking, exporting, repairing and validating all run locally. The helper program listens only on the local loopback interface (
127.0.0.1) and is not reachable from your network or the internet. - Optional veraPDF installation. veraPDF, the validator, is not part of the plugin. If it is missing, the panel offers to fetch it, and only when you press that button does the helper program download the veraPDF installer from software.verapdf.org, a server run by the veraPDF consortium. Like any download, the request shows that server your IP address; nothing about you or your documents is sent, and we receive nothing. On a machine that must not go online, install veraPDF by hand instead, as described in the FAQ.
- No account, no login, no cloud storage.
- No telemetry. The plugin contains no analytics and sends us no usage data.
- Optional AI alt texts. This feature is switched off by default. If you enable it and enter your own API key, the individual images for which you request a description are transmitted to the provider you have chosen (Anthropic, OpenAI or OpenRouter) for that purpose. No other document content is sent. The processing is then governed by that provider’s terms and privacy policy; the relationship is between you and that provider. If instead you use a local model via Ollama, no data leaves your machine at all.
- API keys that you enter are stored locally in the helper program’s configuration file on your own computer. They are never written into the InDesign document and never transmitted to us. You can delete each key from within the panel.
8. Your rights
Under the GDPR you have the right to:
- access (Art. 15) — to obtain confirmation whether we process personal data about you, and a copy of it;
- rectification (Art. 16) — to have inaccurate data corrected;
- erasure (Art. 17) — to have your data deleted, where no legal obligation requires us to keep it;
- restriction of processing (Art. 18);
- data portability (Art. 20) — to receive data you provided in a structured, machine-readable format;
- object (Art. 21) — to object to processing based on legitimate interests, on grounds relating to your particular situation.
To exercise any of these rights, write to tagallypro@axeptdesign.com.
9. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your residence, place of work or the place of the alleged infringement. The authority responsible for us is:
10. Changes to this notice
We update this notice when the service changes or the legal situation requires it. The version below applies.
Version: 29 September 2026