Skip to content
gatekey
Privacy Terms Imprint
Join early access
Privacy Terms Imprint Join early access
Legal · Privacy

Privacy, without the fog.

This notice explains how personal data is handled on the Gatekey landing page and when you join the early-access waitlist. It does not yet cover the future gateway service.

Effective 22 July 2026 GDPR · Austrian DSG · TKG 2021 Website & waitlist only
On this page 1. Controller 2. Scope 3. Cloudflare hosting 4. Early-access waitlist 5. Email communications 6. Cookies & tracking 7. Recipients & transfers 8. Retention 9. Your rights 10. Security 11. Changes & contact

1. Controller

The controller within the meaning of Article 4(7) GDPR for the processing described in this notice is:

Legal name
Timo Zürner
Address
Gerichtsstraße 13, 9300 St. Veit an der Glan, Austria
Email
service@xynatec.com
Privacy contact
service@xynatec.com

“Gatekey” is the product name. Full provider details are available in the Imprint.

2. Scope of this notice

This notice applies to:

  • visiting this landing page;
  • joining the Gatekey early-access waitlist; and
  • contacting us about the website or waitlist.
The gateway is not covered yet

Before Gatekey processes customer accounts, OAuth identities, MCP traffic, audit logs, service tokens or billing data, this notice will be expanded. Where Gatekey acts as processor, a separate Article 28 GDPR data-processing agreement will apply.

We do not use the landing page for automated decision-making or profiling within the meaning of Article 22 GDPR.

3. Website delivery through Cloudflare

This website is delivered through Cloudflare. When you request a page, Cloudflare may process network and request data such as your IP address, request date and time, URL, referrer, user-agent and browser information, routing data, and security signals.

Purpose
Delivering the website, TLS, availability, abuse prevention, and technical security.
Legal basis
Article 6(1)(f) GDPR, based on our legitimate interest in a secure, reliable website.
Processor
Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA.
Retention
Only as long as needed for delivery, security, troubleshooting, and legal obligations, according to the configured Cloudflare service and applicable contract.

More information is available in the Cloudflare Privacy Policy and its Data Processing Addendum.

4. Early-access waitlist

If you join the waitlist, we process the email address you enter, your consent expressed through the form, and information connected with the submission. MailerLite may also process technical request and response data such as IP address, date and time, form identifier, browser/user-agent, referrer, delivery status, and interaction or unsubscribe information where needed to provide and secure the service.

Purpose
Managing the waitlist and sending early-access, launch, and closely related product updates.
Legal basis
Your consent under Article 6(1)(a) GDPR and Section 174(3) Austrian TKG 2021.
Required?
Voluntary. Without an email address and consent, you cannot join the email waitlist.
Processor
MailerLite Limited, 88 Harcourt Street, Dublin 2, D02 DK18, Ireland.

MailerLite processes subscriber data on our instructions. Its Data Processing Addendum is incorporated into its terms for customers and describes the processing, security measures, retention criteria, and subprocessors. See the MailerLite Privacy Policy and Data Processing Addendum.

5. Email communications and withdrawal

We will only use the waitlist address for the communications described next to the signup checkbox. Consent is not preselected. You may withdraw it at any time, without giving a reason, by emailing service@xynatec.com. Withdrawal does not affect processing that was lawful before it was received.

Product marketing beyond the stated early-access and launch purpose requires a compatible legal basis and, where required, a separate consent. Every promotional email must provide a free and straightforward way to stop future messages.

6. Cookies, analytics, and local storage

We do not operate advertising analytics or load external web fonts on this landing page. No MailerLite resource is requested merely because you open the page. Only after you enter a valid address, tick the consent box, and actively submit the form does your browser retrieve MailerLite’s webform resources from assets.mlcdn.com, groot.mailerlite.com, and static.mailerlite.com, and make a technical form request to assets.mailerlite.com. These connections disclose ordinary request data such as IP address, time, referrer, and user-agent to MailerLite. They are necessary to carry out the signup you expressly requested; the related data processing is based on Article 6(1)(f) GDPR and our interest in providing a secure, functional signup form. The email address is processed on the consent basis stated above.

The current integration does not intentionally write MailerLite cookies or persistent MailerLite identifiers to your browser and does not use form data for cross-site advertising. Cloudflare may use strictly necessary technical identifiers where a security or delivery feature requires them. If analytics, embedded media, or non-essential device storage is added later, it must remain disabled until any required consent has been obtained, and this notice must be updated.

7. Recipients and international transfers

Personal data may be disclosed only where necessary to:

  • Cloudflare for website delivery and security;
  • MailerLite for waitlist storage, email delivery, and unsubscribe administration;
  • professional advisers bound by confidentiality; or
  • courts or authorities where disclosure is legally required.

Cloudflare

Cloudflare may process data outside the EEA. For transfers to the United States it states that it relies on its EU–US Data Privacy Framework certification and, if that mechanism is unavailable, the European Commission’s Standard Contractual Clauses with supplementary safeguards. Its DPA also provides SCCs for other restricted transfers.

MailerLite

For customers in the EEA, the MailerLite service is provided by MailerLite Limited in Ireland. MailerLite states that subscriber data for EEA customers does not leave the EU. Its current subprocessor list identifies Google Cloud EMEA Ltd, with the new MailerLite data centre in the Netherlands, and Vercom S.A. in Poland.

Account configuration still matters

The operator must keep the MailerLite account country and billing details accurate, review changes to the DPA and subprocessor list, and reconcile this notice with the actual account, confirmation, tracking, and retention settings.

We do not sell personal data.

8. How long data is kept

  • Waitlist entry: until you withdraw, until the waitlist is closed, or no later than 24 months after signup if no invitation has been sent, whichever occurs first.
  • MailerLite service copies and backups: for the duration needed to provide the service and carry out our deletion instructions, subject to isolated backups and any retention required by applicable law under the MailerLite DPA.
  • Withdrawal/suppression record: the minimum information needed to honour your opt-out and demonstrate compliance may be kept for up to three years, based on Article 6(1)(f) GDPR and our interest in compliance and legal defence.
  • Website security data: according to necessity and the configured Cloudflare service; we do not create a separate analytics profile on this site.
  • Correspondence: for as long as needed to answer the request and, where relevant, for statutory limitation or record-keeping periods.

Data is deleted or anonymised when the relevant period expires, unless law requires longer retention.

9. Your data-protection rights

Subject to the statutory conditions, you have the right to:

  • access your personal data (Article 15 GDPR);
  • rectify inaccurate data (Article 16);
  • erase data (Article 17);
  • restrict processing (Article 18);
  • receive portable data (Article 20);
  • object to processing based on legitimate interests (Article 21); and
  • withdraw consent at any time (Article 7(3)).

Contact service@xynatec.com to exercise a right. We may request proportionate information to verify your identity.

You may also lodge a complaint with the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, Austria, or with another competent supervisory authority.

10. Security

We use proportionate technical and organisational safeguards, including encrypted transport (HTTPS), access controls, data minimisation, and restricted administrative access. No online service can guarantee absolute security.

11. Changes and contact

We may update this notice when the website, providers, or legal requirements change. The current version and effective date will remain available here. Material changes to consent-based purposes require renewed consent where the law requires it.

service@xynatec.com

Drafting basis reviewed 22 July 2026: Articles 6, 7, 12–22, 28 and 44–49 GDPR; Austrian DSG; Sections 165(3) and 174 TKG 2021; public privacy/DPA materials of Cloudflare and MailerLite. This document must be reconciled with the operator’s actual processing records, contracts, settings, and retention procedures before publication.

gatekey

OAuth infrastructure for remote MCP.

ProductHow it worksSecurityPricing
LegalPrivacyTermsImprint
Contactservice@xynatec.comEarly access

© Gatekey. Built for the open MCP ecosystem.

Back to home