Legal
Privacy Policy
How project inquiry and technical request data are intended to be handled on this website.
Last implementation update: August 26, 2026This draft describes the implemented website behavior but is not legal advice. Replace bracketed details and have qualified counsel review it for the actual company, jurisdiction, services, and data practices.
Who controls the data
[LEGAL COMPANY NAME], [REGISTERED ADDRESS], is intended to be the data controller for this website. Replace these placeholders and add an approved privacy contact before launch.
Information collected
The project inquiry form asks for a name, work email, company, optional website, project type, budget range, target timeline, and project description. Technical request data may be processed temporarily for security and rate limiting.
- Do not submit passwords, credentials, regulated records, or sensitive personal data through the initial inquiry form.
- The implementation does not intentionally log complete form bodies, project descriptions, or raw IP addresses.
Why information is processed
Inquiry information is intended to be used to evaluate and respond to a requested business conversation, protect the form from misuse, and maintain delivery records where a configured lead destination accepts the submission. Counsel must confirm the applicable lawful basis for each intended jurisdiction.
Recipients and service providers
Depending on deployment configuration, inquiry data may be sent to an approved lead webhook or email delivery provider. List the actual processors, locations, contractual safeguards, and transfer mechanisms here before launch. The codebase currently supports vendor-neutral lead routing and optional Resend notifications.
Retention
[DEFINE AND INSERT THE APPROVED RETENTION PERIODS] for unsuccessful inquiries, active opportunities, client records, security logs, and backups. Retention must match the configured CRM, database, webhook, and email systems.
Your rights
Describe the rights available in the company’s actual operating jurisdictions, how a person can exercise them, identity-verification requirements, complaint routes, and the responsible supervisory authority. Add the reviewed privacy contact: [PRIVACY CONTACT].
Security
The implementation includes server-side validation, request-size and origin checks, anti-spam controls, rate limiting, restricted security headers, and a lead-delivery abstraction. No website can guarantee absolute security; deployment, access control, vendor configuration, and operational processes must also be reviewed.
Changes
Update this policy when the company, processors, analytics, lead destinations, legal basis, or website behavior changes. Replace this implementation date with the actual publication and revision process.