Privacy Policy

Last updated: 27 April 2026

1. Introduction

kanedias.com (“we”, “us”) operates a free, privacy-first developer utility platform for generating fictional test data (BSN, IBAN, VAT, names, addresses and similar). All generated data is created entirely in your browser using client-side JavaScript. No generated value ever leaves your device or reaches our servers. This privacy policy explains the limited personal data we do process, the legal bases under the EU General Data Protection Regulation (GDPR) and your rights.

2. What we collect

  • Generated test data — never collected by us. BSN numbers, IBANs, names, emails and any other generated values exist only in your browser tab and are discarded when you close it.
  • Server logs — our hosting provider (AWS CloudFront) records standard access logs containing IP address, user-agent string, requested URL and timestamp. These logs are retained for up to 30 days for security and debugging purposes and are not used to build user profiles.
  • Analytics — if you accept the cookie banner, we load Google Analytics 4 (measurement IDG-7QQB6LVZV7) with IP anonymization and Google Consent Mode v2. Without consent, no analytics cookies are set and no hits are sent.
  • UX heatmaps & session replays — if you accept the cookie banner, we load Microsoft Clarity (project ID wgray1w2mz) to record anonymized scroll, click and movement heatmaps. Input fields and generated outputs are masked (see section 9).
  • Advertising — if you accept the cookie banner, we load Google AdSense (publisher ID ca-pub-6712981032185831) to display contextual ads. AdSense may use cookies to limit ad frequency and measure performance.
  • Email correspondence — if you contact us by email, we retain your message and address only as long as needed to answer your question (maximum 12 months).

3. Why we process this data (legal bases under GDPR Art. 6)

  • Server logs: to keep the site available, detect abuse and resolve outages — legitimate interests, Art. 6(1)(f) GDPR.
  • Analytics (Google Analytics 4): to understand which tools are used and how to improve them — your consent, Art. 6(1)(a) GDPR.
  • UX research (Microsoft Clarity): to identify usability issues in the tool UI — your consent, Art. 6(1)(a) GDPR.
  • Advertising (Google AdSense): to fund the free service — your consent, Art. 6(1)(a) GDPR.
  • Email contact: to answer questions and feedback — your consent and/or legitimate interests, Art. 6(1)(a) and (f) GDPR.

4. Processors and third parties

We share data with the following processors strictly for the purposes described above:

  • Amazon Web Services (AWS) — hosting (S3 + CloudFront), region eu-west-1 (Ireland). Acts as processor under the AWS Data Processing Addendum.
  • Google LLC — Google Analytics 4 and Google AdSense, only when consent is granted. Processor under the Google Ads Data Processing Terms (with Standard Contractual Clauses for transfers to the United States).
  • Microsoft Corporation — Microsoft Clarity (UX heatmaps and session replays), only when consent is granted. Processor under the Microsoft Products and Services Data Protection Addendum (DPA, v10 or later, including EU Standard Contractual Clauses). The Clarity project is configured to use the EU data region.

5. Cookies

By default, kanedias.com sets no tracking cookies. The following cookies are placed only after you accept the cookie banner:

CookieProviderPurposeRetention
cookie-consentkanedias.comStores your cookie choice (functional)12 months (localStorage)
_ga, _gid, _ga_*Google AnalyticsDistinguish users and sessionsUp to 2 years
_gcl_*Google AdsConversion linkingUp to 90 days
NID, IDEGoogle AdSenseAd personalization and frequency cappingUp to 13 months
_clck, _clsk, CLIDMicrosoft ClarityHeatmaps and session replay (anonymized)Up to 1 year

You can withdraw your consent at any time by clearing your browser's local storage for this site. The cookie banner will reappear on your next visit.

6. Retention periods

  • Server logs (IP, URL, user-agent): 30 days
  • Google Analytics 4: 14 months (default retention, configured)
  • Microsoft Clarity: 1 year (default project setting)
  • Google AdSense: per Google's retention policy (typically up to 24 months)
  • Email correspondence: maximum 12 months after resolution

7. Your rights

Under the GDPR, you have the following rights with regard to personal data we process:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure / “right to be forgotten” (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR)
  • Right to withdraw consent at any time (Art. 7(3) GDPR)

To exercise any of these rights, send an email to martin.alex.de.heer@gmail.com. We respond within 30 days. You also have the right to lodge a complaint with your local supervisory authority — for users in the Netherlands, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).

8. Security

kanedias.com is served exclusively over HTTPS (TLS 1.2 or higher) via AWS CloudFront. The site has no server-side user accounts, no databases and no forms that store personal data, which keeps the attack surface minimal.

9. Masking in Microsoft Clarity

Because this site renders generated quasi-identifying strings (BSN, IBAN, credit card numbers, etc.), the Clarity project is configured with Masking mode “Strict”:

  • All <input> and <textarea> elements are masked by default in replays.
  • We add the HTML attribute data-clarity-mask="true" to all blocks that show generated test numbers, so those values appear as *** in session replays.
  • The Clarity project uses the EU data region (Ireland) so raw replay data does not leave the EU.

10. Data region

Where the processor allows it, we select EU regions: AWS hosts content in Ireland (eu-west-1), and Microsoft Clarity stores recordings in its EU region. Google services (Analytics, AdSense) operate globally; transfers to the United States are covered by the EU-US Data Privacy Framework and Standard Contractual Clauses.

11. Changes to this policy

If this privacy policy changes, we publish the new version on this page with an updated date at the top. Material changes are also announced through the cookie banner on your next visit.

12. Contact

For privacy-related questions or to exercise your rights, contact us at martin.alex.de.heer@gmail.com. See also the About page and our Terms of Service.