Legal
Privacy policy
What personal data this site collects through the contact form, why, for how long, who processes it and what rights you have.
Last updated:
Effective from: [launch date]
This policy explains how personal data is handled on this website. The site is a portfolio with a single contact form; it uses no cookies and no advertising technology. The parts in square brackets are completed before launch.
1. Controller
- Name: [full name or business name]
- Address: [registered address]
- Registration or tax number: [number]
- Email: privacy@example.com
No data protection officer has been appointed, because the law does not require one for processing of this scale.
2. What we process and why
2.1. Quote requests sent through the contact form
- Data: name, email address, type of business, budget range, message, the language of the form and the time of submission.
- Purpose: answering your enquiry and preparing a quote.
- Legal basis: steps taken at your request before entering into a contract (Article 6(1)(b) GDPR).
- Retention: 12 months, then automatic deletion. If we sign a contract, the data related to it is kept for the statutory periods (for example accounting rules).
- Providing the data is voluntary, but we cannot reply without the fields of the form.
2.2. Abuse prevention
- Data: an irreversible, salted hash of your IP address together with a submission counter, and the technical signals Cloudflare Turnstile examines (IP address, browser and device characteristics), which Cloudflare processes.
- Purpose: filtering out automated and mass abuse of the form.
- Legal basis: legitimate interest (Article 6(1)(f) GDPR): protecting the service. You may object; in that case you can contact us by email instead.
- Retention: the hash and the counter are deleted after 24 hours. Cloudflare handles the data of the Turnstile check under its own privacy policy.
2.3. Visitor statistics
- Tool: Plausible Analytics, without cookies or persistent identifiers.
- Data: page visited, referring site, country, browser and device type, in aggregate. No personal profile is created and visitors cannot be followed across pages or days.
- Legal basis: legitimate interest (Article 6(1)(f) GDPR): improving the site.
- Retention: a daily, salted hash is derived from the IP address and discarded within 24 hours; only aggregate statistics remain.
2.4. Technical logs
The server keeps short-lived technical logs for operating and securing the service (for example failed connection attempts, with IP address and time) for at most 30 days; the web server does not keep a log of page views. Legal basis: legitimate interest (Article 6(1)(f) GDPR): secure operation of the site.
3. Who has access to the data (processors)
- Amazon Web Services EMEA SARL (Luxembourg): hosting of the website and of the quote request database on a server in the EU (Frankfurt), under the AWS Data Processing Addendum.
- Resend, Inc.: delivery of the notification email.
- Cloudflare, Inc.: bot protection.
- Plausible Insights OÜ: visitor statistics (EU).
Where a provider is established outside the EU (in the USA), data is transferred under the EU–US Data Privacy Framework or the European Commission’s standard contractual clauses. We do not sell your data and do not pass it on for marketing.
4. Your rights
You can request access to your personal data, its rectification or erasure, the restriction of processing, object to processing based on legitimate interest, and ask for your data in a portable format. Send your request to privacy@example.com; we reply within one month of receiving it (Article 12(3) GDPR).
You can also lodge a complaint with a data protection supervisory authority, in particular in the EU member state where you live, or bring the matter before a court. The authority responsible for the controller: [name and contact details of the supervisory authority].
5. Cookies
The site uses no cookies or similar technologies. Details: Cookies.
6. Security
Data travels over encrypted connections (HTTPS) and access to it is limited to the smallest possible circle. Quote requests are stored in the EU (Frankfurt); providers outside the EU access data only under the safeguards described in section 3.
7. Changes
We update this policy when needed and flag material changes on the site. The date of the last change is shown at the top of the page.