Privacy
Last updated 8 September 2026
Two things happen on this site. We count what people do with the page, without identifying anybody. And if you fill in the early-access form, we keep what you told us so we can reply.
Nothing is stored on your device, so there was nothing to ask you to accept. The detail of that is on the cookies page.
Who is responsible
The controller for the processing described here is Simon Berriman, Karl-Rothe-Str. 4, 04105 Leipzig, Germany. Email hello@cantheydoit.com.
Can They Do It? is operated by Simon Berriman as a sole trader. There is no data protection officer, because the scale of this processing does not require one under Art. 37 GDPR.
If you request early access
What we store is what the form asks for:
- Your email address, and your name if you gave one.
- The product name and URL.
- What you told us the product does, who to test it as, what they should try to accomplish, and anything else you added.
- Which research option you were interested in.
- Which link on the site you arrived by, so we can tell which part of the page led people to get in touch.
- The exact wording of the confirmation you ticked, and the time you ticked it.
The wording you agreed to is: “I agree that Can They Do It? may contact me by email about this early-access request, and I have read the privacy notice. I understand this expresses interest and is not a purchase.”
The lawful basis is Art. 6(1)(b) GDPR: you asked us to look at your product, and replying to you is the step before any agreement. Our own interest in knowing which parts of the proposition people responded to rests on Art. 6(1)(f).
Submitting the form does not create an account and does not charge you.
What we count on the site
Event name, page path, a random per-page-load session value and a short label such as which section came into view. No IP address, no browser fingerprint, no cookies, no identifier that outlives a page load. The basis is Art. 6(1)(f): we need to know whether this page explains the product.
Because nothing is stored on or read from your device, § 25 TDDDG does not apply and no consent is needed for it.
Server logs
Our host processes the connection data that any web server sees, including your IP address, in order to serve pages and defend against abuse. We do not copy that into a database of our own, do not analyse it and do not join it to anything above. The basis is Art. 6(1)(f).
Who else processes it
Three services, each acting on our instructions under Art. 28 GDPR:
Supabase Database hosting
Early-access submissions and analytics events.
Location: To be confirmed on project creation. An EU region is intended.. Their privacy notice
Resend Email delivery
Your email address, your name if you gave one, and the contents of the two messages about your request.
Location: United States. Their privacy notice
Vercel Website hosting
Serves the site. Processes the connection data any web server sees, including your IP address, to deliver pages and defend against abuse.
Location: United States, with edge delivery from the region nearest you. Their privacy notice
All three are United States companies, so your data reaches the United States even where the storage itself is in the EU. Those transfers rely on the standard contractual clauses in each provider’s data processing terms, and where the provider is certified, on the EU-US Data Privacy Framework. We use no other processors and sell nothing to anybody.
How long we keep it
Early-access submissions are kept for as long as we might reasonably reply to them, and no longer than 24 months from the day you sent them.
To be straight about the mechanism: there is no automated deletion job doing this yet. Today it is done by hand on request and when the list is reviewed. When a scheduled purge exists, this paragraph will say so.
Analytics events carry nothing that identifies a person and are kept indefinitely as counts.
Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21). Where processing rests on consent, you can withdraw it at any time.
Email hello@cantheydoit.com and say what you want done. Asking to be deleted is enough; you do not have to explain why, and it will not be treated as a negotiation.
You can also complain to a supervisory authority. Ours is the Saxon Data Protection and Transparency Officer (Sächsischer Datenschutzbeauftragter), and you may instead go to the authority where you live or work.
Email we send you
If you submit the form you get one confirmation that we received it, and then a reply from a person. That is all. There is no newsletter, no drip sequence and no marketing list, so there is nothing to unsubscribe from. If we ever want to send you something that is not a direct answer to your request, we will ask first.
Automated decisions
None. Nothing here is decided about you automatically, and no profiling within the meaning of Art. 22 GDPR takes place.