Privacy Policy

This Privacy Policy explains how the website administration collects, uses, stores, protects and, where necessary, discloses personal data when a visitor uses the website, submits a contact or inquiry form, creates an account, accesses a private or administrative area, or communicates through the website. The Policy is built around transparency, data minimisation, purpose limitation, security and respect for user rights.

1. Scope

This Policy applies to public pages, contact and inquiry forms, registration and login functions, the administrative environment, API submissions, security logs, spam-protection tools and site-health diagnostics. If a service is provided under a separate contract, that contract may supplement or specify the data-processing rules for that service.

The website may be operated by different businesses or organisations. Therefore, the actual legal name, registered address, tax details, responsible person, DPO/contact email and any service-specific retention schedule must be completed by the real website operator.

2. Controller and processors

The controller is the organisation or entrepreneur that determines the purposes and means of processing personal data collected through the website. Some technical processing may be performed by hosting providers, email services, analytics or security services, software maintenance teams or other authorised processors acting under documented instructions.

  • Website operator: to be completed by the site owner.
  • Privacy contact: to be completed with an official email or address.
  • Data Protection Officer, if applicable: to be completed according to legal or internal policy requirements.

3. Categories of personal data

The website may process data provided by the user or technically generated during use: name, surname, organisation, role, phone number, email, message content, selected service or interest, account username, password hash, role and permission information, registration and login timestamps, IP address, user-agent, referrer, URL path, language/locale, cookie or session identifiers, spam/security evaluation data, audit-log metadata and concise technical error context.

The website does not request special categories of data such as health information, religion, political opinions or biometric identifiers. If a user voluntarily includes such data in a free-text field, it will be processed only to the extent necessary to respond to the message or comply with a legal obligation.

4. Sources of data

Data may be obtained directly from the user, from the browser and device, from server logs, from security and spam-protection tools, from third-party integrations, from payment or communication providers, or from the organisation on whose behalf the user acts. The website does not seek to collect excessive data and each source is limited to a legitimate purpose.

5. Purposes of processing

  • to respond to inquiries, support requests and contact forms;
  • to provide and manage website services;
  • to create and maintain user accounts where registration is enabled;
  • to protect the website against spam, abuse, brute-force attempts and automated attacks;
  • to maintain audit records showing who changed what and when;
  • to improve performance, user experience and technical stability;
  • to comply with contractual, accounting, tax or statutory obligations;
  • to protect legitimate interests, document communications and resolve disputes.

6. Legal bases

Processing may be based on consent, performance of a contract or pre-contractual steps, compliance with a legal obligation, legitimate interests in operating and securing the website, or the establishment, exercise or defence of legal claims. Where consent is required, the user may withdraw it without affecting the lawfulness of processing carried out before withdrawal.

7. Cookies, sessions and technical identifiers

The website may use necessary cookies and session identifiers for login, CSRF protection, language choice, safe form submission and stable administration. Optional analytics or marketing cookies may be used only if enabled by the operator and, where required, after obtaining valid consent.

8. Server logs, audit and security records

For security purposes the system may store IP address, IP hash, user-agent, request path, action, actor id, role, permission-check result, spam rejection reason, country code, error context and timestamps. Audit logs are not intended for behavioural tracking; they exist to preserve accountability for administrative actions and system integrity. Log retention must be configured according to real risks, legal obligations and storage limits.

9. Spam protection and automated safeguards

The website may use honeypot fields, minimum submit time, IP rate limiting, link ceilings, keyword/domain/user-agent/IP filters and country blocking. These safeguards protect forms from spam, bot traffic and abuse. In rare cases a legitimate submission may be flagged as risky; the user may then contact the operator through another official channel.

10. Retention

Personal data is retained for as long as necessary to fulfil the relevant purpose, comply with legal obligations, investigate security incidents, resolve disputes or maintain contractual relations. Contact and inquiry data is normally retained for the duration needed to complete communication and maintain business records. Audit/security logs may be retained for short or medium periods depending on risk, and backups are removed under scheduled rotation.

11. Disclosure and processors

Data may be disclosed only to parties necessary for operating the website: hosting, email delivery, backup, security monitoring, analytics, CRM, payment or software maintenance providers. Such parties must process data only under instructions and observe confidentiality and security obligations. International transfers must rely on appropriate legal mechanisms, such as contractual safeguards, adequate jurisdictions or another permitted basis.

12. Security measures

The website applies technical and organisational measures such as HTTPS, CSRF protection, password hashing, role and permission controls, audit trails, access restriction, upload protection, rate limiting, spam filters, security headers, backups and update discipline. No system can guarantee absolute security, but safeguards are selected proportionately to risk and reviewed periodically.

13. User rights

Users may request information about processing, access their data, request correction or deletion, restrict processing, object to processing, request portability where applicable, and withdraw consent where processing is based on consent. Some rights may be limited by law, security requirements, the rights of others, or accounting and legal obligations.

14. Children

The website is not intended to knowingly collect personal data from children. If it becomes clear that a child’s data has been submitted without a proper legal basis or parental/legal guardian approval where required, the data will be restricted or deleted as soon as reasonably possible, subject to legal obligations.

15. Changes to this Policy

This Policy may be updated when laws, services, security mechanisms or business processes change. The new version will be published on this page with the updated date. Material changes may be communicated through additional channels.

16. Contact

For privacy questions, access requests or the exercise of data-subject rights, please use the official contact details of the website. The request should allow the operator to identify the requester and understand which data or action the request concerns.

This text is a professional baseline template and should be adapted and reviewed by counsel for the specific organisation, jurisdiction, industry and contractual commitments.