Skip to content
easyai.video

Privacy notice

Last updated 11 September 2026. This explains what easyai.video collects, why, who else sees it, and what you can ask for.

1. Who is responsible

easyai.video is operated from Portugal by Oleksiy Onishchenko, who is the data controller for everything described here. Reach the controller through the contact form.

2. What is collected

The waitlist form. Your name and email address, which are required, and three optional answers: which description fits you, the problems you want to solve, and which AI video tools you have already tried. Nothing else is asked for and nothing is inferred.

The contact and consultancy forms. Your name, email address and the message you write.

Technical signals needed to run the forms. Your IP address is turned into a keyed hash and stored in that form only; the original address is never written down. It exists so the same visitor cannot submit repeatedly within a minute. Your browser's user agent is recorded with a waitlist entry for the same reason. The record also keeps which channel you arrived from, if a campaign link said so.

Website analytics, only if you accept them. If you accept analytics in the banner, PostHog records which pages you view, which links and buttons you use, and which channel you arrived from. It assigns a random identifier so repeat visits can be counted; that identifier is not linked to your name or email, and the waitlist form is not connected to it. Decline and none of this runs at all — the banner is a real gate, not a notice. You can change your mind by clearing this site's data in your browser.

Nothing else. There is no advertising network, no purchase of data about you, and no session or screen recording.

3. Why, and on what legal basis

The waitlist runs on consent (GDPR Article 6(1)(a)). Submitting the form is not enough on its own — a confirmation email is sent, and you are only added when you open the link in it. That confirmation is the consent record. You can withdraw at any time using the unsubscribe link in any email, and withdrawing is as easy as giving it.

Website analytics run on consent too, given through the banner and recorded in your browser. Nothing is loaded or sent before you accept.

Answering a message you send is legitimate interest in replying to your own enquiry (Article 6(1)(f)). Rate limiting and the anti-bot check rest on the same basis: keeping the forms usable and preventing them being used to send mail to people who never asked for it.

4. Who else processes it

Cloudflare hosts the site, stores the waitlist database, and provides Turnstile, the check that tells a person from a script. Turnstile is used because it works without tracking you across sites and sets no advertising cookie.

Resend delivers the confirmation email and any reply generated by a form.

PostHog provides the website analytics described above, and only after you accept them. The account is on PostHog's European infrastructure.

Both act as processors under contract. Neither is permitted to use your data for their own purposes, and your details are not sold, rented or shared with anyone else.

5. International transfers

Resend is configured to its Ireland region and PostHog to its European infrastructure, so the mail and the analytics are processed inside the European Economic Area. Cloudflare runs a global network and may process data outside the EEA; those transfers rely on the European Commission's Standard Contractual Clauses in its data processing agreement.

6. How long it is kept

Waitlist entries are kept for as long as the waitlist is running, including entries that were never confirmed, which are retained as a record of what was submitted and to stop the same address being mailed repeatedly. Messages sent through the contact forms are kept as long as needed to deal with what they are about. The hashed rate-limit records are technical and hold no name or address.

Nothing here is deleted on a timer. If you want your data removed, say so and it is removed — see section 7.

7. Your rights

Under the GDPR you can ask for a copy of what is held about you, ask for it to be corrected or deleted, ask for processing to be restricted or object to it, ask for it in a portable form, and withdraw consent at any time. Ask through the contact form and you will get an answer within a month.

If you are not satisfied you can complain to your local supervisory authority. In Portugal that is the CNPD.

8. Cookies and local storage

What is stored in your browser, why, and how to change your choice is set out in the cookie policy.

Registration and payment for events happen on Luma, and some events are also listed on Meetup. Once you follow one of those links you are on their service and their privacy policy applies. Outgoing links carry a parameter naming the channel you came from; it identifies the channel, not you.

9. Security

The site is served over HTTPS with a restrictive content security policy. Confirmation links are random, single-use in effect, expire after three days, and only a hash of each one is stored, so the database cannot be used to confirm anyone's address. IP addresses are stored only as keyed hashes.

10. Changes

If this notice changes materially, the date at the top changes with it, and anyone on the waitlist is told by email before the change takes effect.