We collect very little
A name, an email, and whatever you choose to tell us. No hidden profiling, and nothing bought from a third party.
What we collect, why we hold it, how long it stays, and what you can ask us to do with it. Written to be read — not to be survived.
This is a carefully structured starting point, not a finished legal document. Privacy law changes with the country you operate in, the industry you serve and the exact data you touch. Before this page goes live under a company name, a qualified privacy lawyer has to go through every section, fill in the placeholders, and confirm that what it promises is what actually happens inside the business.
The full policy is below. If you only read one part, read this one.
A name, an email, and whatever you choose to tell us. No hidden profiling, and nothing bought from a third party.
Not to advertisers, not to brokers, not to anyone. Data leaves our systems only to the providers that help us run them.
Ask what we hold, correct it, take it with you, or have it deleted. One email, thirty days, no charge.
Encryption in transit and at rest, least-privilege access, separated environments, and monitoring that actually gets read.
We are a software house. We design and build multi-tenant platforms, custom systems and API solutions — some of which run in production for clients today. This policy covers the personal data that reaches us through this site and the direct contact around it.
Where this policy says "we", it means the company named below — the entity that decides how and why your data is used on this site.
When we build and host a platform for a client, that client decides what data is collected and why — they are the controller, and we act only as their processor under a written agreement. In that situation the client's own privacy policy governs the end users, not this one. On this website we wear the other hat: here the decisions are ours, and so is the responsibility.
Five categories, and nothing outside them. Each one exists because something on this site would not work without it.
What you type into a contact form, or send us directly when you want to talk about a project.
The support chat on this site keeps the conversation, so the next person who answers you does not start from zero.
Standard server records, created automatically for every request. Nobody types these in — this is how a web server works.
Aggregated analytics that tell us which pages are useful and which ones quietly fail.
If we end up working together, the paperwork a business relationship requires.
Stated plainly, so there is nothing left to infer.
Every use of personal data needs a lawful reason. Here is ours, purpose by purpose.
Data that no longer has a job to do gets deleted. These are the periods we work to.
Counted from the last exchange, then deleted or anonymised
Longer only while a support matter is still open
A rolling window — older entries rotate out automatically
Aggregated, and not tied back to an identified person
Required by tax and accounting law, not by us
Held precisely so we never contact you again by mistake
One exception: if a legal claim, audit or investigation is open, the records it touches are held until the matter closes.
We do not run every layer of the stack ourselves. These are the categories of provider that can touch personal data, and what each one actually sees.
The application and the data stored in it
Transactional and notification email
Aggregated measurement, no message content
Chat and messaging conversations
Invoices and payment records
Diagnostic traces and crash reports
A current list naming each provider is available on request — write to the privacy address at the bottom of this page.
Our primary infrastructure sits in the European Union. Some of the providers above operate globally, which means data may be processed outside your own country. We do not treat that as a technicality.
You can ask us which safeguard applies to a specific transfer, and we will tell you.
These are yours by law, not by our goodwill. Using them costs nothing and changes nothing about how we treat you.
Get a copy of the personal data we hold about you, and a plain explanation of what we do with it.
Have anything inaccurate fixed, and anything incomplete filled in.
Have data erased once we no longer have a lawful reason to keep it.
Freeze processing while a dispute about accuracy or grounds is being resolved.
Receive the data you gave us in a structured, machine-readable format.
Object to any processing we base on legitimate interest, including marketing.
Where processing rests on consent, withdraw it at any time — future use stops immediately.
Take the matter to your data protection authority, with or without talking to us first.
Write to the privacy address at the bottom of this page and say what you want. We will confirm who you are — that step protects you, not us — and answer within 30 days. If a request is genuinely complex we may need longer, and we will tell you why before the 30 days are up.
We do not charge for handling a request and we do not require a reason. The only exception is a request that is clearly excessive or repeated without purpose, and even then we will explain the decision rather than ignore it.
When we host a system for a client, that client decides what happens to the data in it. Send your request to them. If it reaches us instead, we will forward it, tell you that we did, and help them answer it.
Security is the part of this policy we can actually engineer, so we do.
Nobody can promise a breach will never happen. We can promise how we will behave if it does: contain it, notify the supervisory authority within 72 hours where the law requires it, and tell the people affected directly and without spin.
This is a business-to-business site. It is not designed for, marketed to, or intended to be used by children, and we do not knowingly collect data from anyone under 16.
If you believe a child has sent us personal data, write to us and we will delete it — no forms, no process, just tell us.
This policy will change as the business does. Every change updates the date at the top of the page, and that date always reflects the version you are reading.
When a change materially affects how your data is used, we will not rely on you noticing a date. We will say so directly — by email where we have an address, and prominently on the site where we do not. Earlier versions are kept and available on request.
One address, read by a person. Questions, requests and complaints all go to the same place.
You can complain to the data protection authority where you live or work, and you can do it without going through us first. We would rather you came to us — but the choice is yours, and using it will never count against you.
Privacy questions, a security review, or a project you want to scope — the same conversation window handles all of it, and a human answers.