This notice is short because the practice is short. No cookies, no analytics, no advertising, no profiles - the list below is genuinely everything, written to be read rather than scrolled past.
Like effectively every web server, ours records requests: IP address, time, the page requested, the browser's user-agent string. We keep these briefly for security and capacity purposes - detecting abuse of the site itself is, after all, our line of work - and they are rotated and deleted automatically on a short schedule. Legal basis: legitimate interest in operating and defending the service (art. 6(1)(f)).
The typefaces load from Google Fonts, which means your browser sends a request - and therefore your IP address - to Google's servers. Google's own privacy policy governs what they do with the request.
The contact form runs Cloudflare Turnstile, which is why that one page loads a script from challenges.cloudflare.com. It exists to keep automated submissions out of a mailbox people answer by hand. Cloudflare already carries every request to this site, so it is not a new party to the conversation, and by their own documentation Turnstile "does not access, store, or transmit user communications, form entries, or other page inputs" - it judges the browser, not what you wrote. It sets no tracking cookie, and it never refuses a message it cannot judge: if the check fails to run - your browser cannot reach it, or it is having a bad day - the submission goes through regardless. Nobody reporting an attack is going to be stopped by a spam filter. Legal basis: legitimate interest in keeping the channel usable (art. 6(1)(f)).
None. No analytics, no trackers, no session cookies for visitors. The "No cookies here" notice stores your dismissal in your own browser's localStorage, which never leaves your machine and identifies nothing.
When you use the contact or under-attack form, what you type - name, email address, and your message - goes to the engineers who run the network, and is handled like any other correspondence: kept as long as the conversation (and any resulting business relationship) needs it, deleted when it no longer does. Reaching a person within seconds, rather than whenever a mailbox is next opened, means it passes through the messaging provider we use for on-call alerting, which may process it outside the EEA. The copy queued on our own server is deleted as soon as it has been delivered. If you would rather your message reached us with nobody in between, write straight to the addresses on the contact page - they are the same engineers. Legal basis: taking steps at your request before entering a contract (GDPR art. 6(1)(b)), or our legitimate interest in answering people who write to us (art. 6(1)(f)).
Under the GDPR you can ask what we hold about you, have it corrected or deleted, object to processing, or take your complaint to a supervisory authority (for us: the Bulgarian Commission for Personal Data Protection). For any of these, one email is the whole procedure: [email protected] - read by an engineer, like everything else here.
If this practice ever changes - analytics, cookies, anything - this page changes first, and the cookie notice becomes a real consent prompt rather than an announcement.
This site sets zero cookies - no analytics, no trackers, no profile of you. The only third-party requests are the fonts, served by Google Fonts, and the spam check on the contact form. Everything else stays between your browser and our network - the full privacy note.