Privacy Policy
Privacy Policy
Last updated — 2026-09-24
Who is responsible
The controller for personal data processed through this website is the company named in the imprint. You can reach us with any data protection question at the email address given there. Where a transfer described in this policy relies on standard contractual clauses (Art. 46(2)(c) GDPR), you can request a copy of them at the email address given in the imprint.
Hosting and server logs
This site is hosted on Cloudflare Pages (Cloudflare, Inc.), and its serverless functions run on the same Cloudflare edge. When you open a page, your browser necessarily transmits technical data — IP address, time of request, the page requested, referrer, browser and operating system. Cloudflare processes this to deliver the site and to defend against attacks.
No cookies are set for hosting and delivering this site. The legal basis for the processing described above is our legitimate interest in operating a secure, functioning website (Art. 6(1)(f) GDPR).
Cloudflare also sends your browser a network error logging policy. Your browser keeps it for this domain for seven days and can use it to report failed connections to Cloudflare (a.nel.cloudflare.com). This is how we learn that pages are failing to reach visitors at all; the legal basis is our legitimate interest in a reliably available website (Art. 6(1)(f) GDPR).
A data processing agreement is in place with Cloudflare. Cloudflare, Inc. is certified under the EU–US Data Privacy Framework, so transfers to the United States rest on the European Commission’s adequacy decision (Art. 45 GDPR); transfers to other third countries are covered by standard contractual clauses (Art. 46(2)(c) GDPR). Server-side access logs are kept only for as long as security and normal operations require, then deleted, unless a concrete security incident makes longer retention necessary.
Fonts
All typefaces are served from our own domain. No request is made to Google Fonts or any other font host, so no data about you reaches a third-party font provider.
The contact form
If you send an enquiry, we process the details you enter — name, company, email address, phone number if you give one, and your message — to answer it. You are not legally or contractually obliged to give us these details, but without your name, company, email address and message we cannot process your enquiry. We also process the technical details described below — the language version of the site you used, the country that Cloudflare derives from your IP address, the address of the page from which you sent the form (including any parameters in that address), the address your browser transmits as the referrer and the result of our automated spam check — and any campaign parameters in the link that brought you to the form (for example the click identifier of an advertisement, or tags naming the source and campaign of a link), in order to assess the enquiry, recognise automated submissions and understand which pages, advertisements and campaigns lead to enquiries.
The legal basis for answering your enquiry is Art. 6(1)(b) GDPR where it concerns a contract to which you personally are, or are to become, a party (for example as a sole trader), and otherwise our legitimate interest in responding to business enquiries (Art. 6(1)(f) GDPR). The legal basis for the technical details and the campaign parameters is our legitimate interest in assessing enquiries, recognising automated submissions and knowing which of our pages, advertisements and campaigns lead to enquiries (Art. 6(1)(f) GDPR).
We are notified of your enquiry by email. Any such notification is delivered through Resend (Plus Five Five, Inc., United States), acting as our processor under a data processing agreement. The sending domain is configured in Resend’s EU region (Ireland), which governs only where the mail is sent from; Resend stores the data it processes in the United States, including the content of the email, delivery logs and API records, and keeps email and log data for 30 days. This transfer is based on the European Commission’s standard contractual clauses (Art. 46(2)(c) GDPR), which are part of Resend’s data processing agreement; in addition, Plus Five Five, Inc. is certified under the EU–US Data Privacy Framework, for which the European Commission has adopted an adequacy decision (Art. 45 GDPR). Where this website sends the notification itself, it contains, besides the details you entered, the language version of the site you used, the country that Cloudflare derives from your IP address, the address of the page from which you sent the form (including any parameters in that address), the address your browser transmits as the referrer and the result of our automated spam check, so that we can assess the enquiry and recognise automated submissions; your IP address itself is not included. Any campaign parameters in the link that brought you to the form (for example the click identifier of an advertisement, or tags naming the source and campaign of a link) are submitted with your enquiry so we can tell which advertisement or campaign produced it; they are read from the web address only and are not stored on your device.
Where this website sends the notification itself and Resend cannot accept the email, the complete enquiry, including the additional details listed above, is stored temporarily in Cloudflare KV so that it is not lost; it is deleted there automatically after 90 days at the latest.
Below the required box, the form carries a second one that is optional: you may allow us to write to you again later. Your enquiry is handled exactly the same without it. If you do tick it, we record what that box said in the wording you were shown, when you ticked it, the page you sent the form from and your IP address converted into a hash value — that is the evidence for a consent under Art. 6(1)(a) GDPR. You can withdraw it at any time, informally and at no cost; the lawfulness of what happened before the withdrawal is unaffected.
We receive enquiries in a mailbox hosted on Microsoft 365 / Exchange Online (Microsoft Ireland Operations Ltd., with possible sub-processing by Microsoft Corporation in the United States). A data processing agreement is in place with Microsoft, and any third-country transfer is covered by the standard contractual clauses. The legal bases set out above apply to the mailbox as well.
We keep enquiries for as long as we need them to deal with the matter and any resulting business relationship, and for any statutory retention period that applies (for example commercial-law and tax-law obligations); after that, they are deleted. This does not extend the 90-day limit for the temporary copy in Cloudflare KV described above.
Our own customer system
We also copy the enquiry into our own customer system, so that none is left lying. It runs on Supabase (Supabase Pte. Ltd., Singapore) as a processor, with the database in Frankfurt am Main, Germany. It receives the details you entered, the address of the page from which you sent the form and any campaign parameters described above, and records them as a deal, a contact, a note and a task to answer you. The language version you used, the country derived from your IP address, the referrer and the result of the spam check are not passed to it.
Normally the customer system sends the notification email, and this website then sends none of its own. If it does not — because it could not accept the enquiry, or accepted it without sending the notification — this website sends the notification described under “The contact form” instead. Either email goes out through Resend, under the conditions described there. The customer system’s email reports only that an enquiry has arrived and points us to the customer system: it carries the details you entered — company, name, email address, telephone number and your message — together with the page you sent the form from, any campaign parameters, and a link to the matching record. It does not carry the technical details listed under “The contact form” — the language version, the country derived from your IP address, the referrer and the result of the spam check — because those are never passed to the customer system in the first place. Unlike the record in the customer system, a copy of this email stays in our mailbox and, for the period described under “The contact form”, with Resend.
To limit automated mass submissions, your IP address is passed to this system as well and immediately turned into a keyed hash; the address itself is not stored there, and the counter entry holding that hash is removed by an hourly clean-up, at the latest about two days after the hour it counted. A data processing agreement is in place with Supabase, and any transfer to a third country is covered by the European Commission’s standard contractual clauses (Art. 46(2)(c) GDPR). The legal bases set out under “The contact form” apply here as well.
Abuse protection on the contact form
To slow down automated mass submissions of the contact form, we briefly count how many enquiries are sent from each IP address. This counter is stored in Cloudflare KV under your IP address as its key, deletes itself automatically ten minutes after the last submission it counted, and is used for no other purpose. In addition, a global counter, also stored in Cloudflare KV, counts all enquiries per clock hour; it contains no IP address and deletes itself automatically two hours after the last enquiry it counted. The legal basis is our legitimate interest in protecting the form against automated misuse (Art. 6(1)(f) GDPR).
Spam protection on the contact form
The contact form is protected by Cloudflare Turnstile (Cloudflare, Inc.), which distinguishes human visitors from automated submissions. When you open the form, Turnstile receives your IP address and technical information about your browser, and may read and set a value in your browser for this purpose. It does not use tracking cookies and does not profile you across sites. This access to your browser is strictly necessary to protect the form you are using against automated abuse (§ 25(2)(2) TDDDG; Art. 22(2) LSSI).
The legal basis is our legitimate interest in protecting the form against automated abuse (Art. 6(1)(f) GDPR). Cloudflare acts as our processor under a data processing agreement for this check. According to its Turnstile privacy addendum, Cloudflare also uses this information as an independent controller to improve its bot detection. Transfers to the United States rest on Cloudflare’s certification under the EU–US Data Privacy Framework (Art. 45 GDPR), and any other third-country transfer on standard contractual clauses (Art. 46(2)(c) GDPR). We do not store the data Turnstile collects; only the result of the check is added to your enquiry and kept as described under “The contact form”. For its own processing as an independent controller, Cloudflare determines the retention period itself (cloudflare.com/turnstile-privacy-policy). If you have JavaScript switched off, the check does not run and you can still send your enquiry.
Contacting us directly
You can also reach us without the form, at the email address and telephone number given in the imprint. An email you send us arrives in the same Microsoft 365 mailbox described under “The contact form” and is handled there and nowhere else — none of the further steps described for the form applies to it; if you telephone us, we process what you tell us on the call. Either way the purpose is to answer your enquiry. The legal basis is Art. 6(1)(b) GDPR where the enquiry concerns a contract to which you personally are, or are to become, a party, and otherwise our legitimate interest in responding to business enquiries (Art. 6(1)(f) GDPR). We keep such enquiries under the same criteria as enquiries sent through the form.
Storage on your device
Except where a specific function or service is described as doing so in its own section of this policy, this site sets no cookies, stores nothing of its own in your browser, and reads nothing stored there. Two things are nevertheless kept by your browser for this domain, both set by our delivery network Cloudflare: the instruction to reach this domain over HTTPS only (HTTP Strict Transport Security, 30 days) and the network error logging policy described under “Hosting and server logs” (7 days). They serve transport security and error reporting; neither is used to recognise you or to follow you across sites.
Your rights
You have the right to obtain confirmation of whether we process your data and to receive a copy of it, to have inaccurate data corrected, to have data erased or its processing restricted, to receive your data in a portable format, and to object to processing based on legitimate interest. Where processing rests on consent, you may withdraw it at any time without affecting the lawfulness of what happened before.
Right to object: where we process your data on the basis of legitimate interest (Art. 6(1)(f) GDPR), you may object at any time on grounds relating to your particular situation (Art. 21(1) GDPR). We will then stop processing it unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.
You also have the right to complain to a supervisory authority. Our lead supervisory authority is the Spanish data protection authority (Agencia Española de Protección de Datos — AEPD, www.aepd.es). You may nonetheless lodge a complaint with any other supervisory authority in the EU or EEA, in particular in the member state where you habitually live, where you work or where the alleged infringement took place (Art. 77 GDPR).
Changes to this policy
We update this policy when the site changes. The date above always shows the current version.