Legal / Privacy
v1.2

What we know about you. What we don't.

A plain-English account of the data we collect, why we collect it, and what we'll never do with it. Last updated June 2026.

Scroll to deconstructarrow_downward
TL;DR
Last updated · June 4, 2026
01Collect

Only what's needed to deliver the project or respond to your inbound.

02Store

Encrypted, in EU/US-based infrastructure, for the minimum useful window.

03Share

Never sold. Shared only with named processors we're bound to by DPA.

04Delete

On request, end of engagement, or by automated retention policy.

01.LIVE

What happens when data hits us.

A live trace of how a single form submission is processed — captured, masked, encrypted, and logged. Every interaction with data leaves a trail you can audit.

audit.log · live
inorva@audit
00:00:00[INGEST]
01 / What we collect

Data we hold.

Every item below is tied to a specific reason. If we can't justify keeping a field, we don't keep it.

  • 01
    mailContact details

    To reply to your inbound, send proposals, and run the engagement.

    Name · Email · WhatsApp · Company

    3 years from last contact
  • 02
    descriptionProject artefacts

    Documents, briefs, content, and credentials you share so we can build.

    Briefs · API keys · Access tokens · CMS exports

    Through engagement + 90 days, then deleted
  • 03
    analyticsSite analytics

    Anonymised page views and Core Web Vitals to improve this site.

    Country · Browser · Page · Referrer (no IP retention)

    13 months rolling
  • 04
    receipt_longBilling records

    Issued invoices and payment confirmations.

    Invoice line items · Payoneer references

    10 years (Egyptian commercial law)
02 / What we never do

Lines we don't cross.

  • blockWe will never sell your data to third parties.
  • blockWe will never use your private project content to train third-party AI models without explicit written consent.
  • blockWe will never email-spam you. No newsletters unless you actively opt in.
  • blockWe will never track you across other sites with cross-domain identifiers.
  • blockWe will never retain login credentials for your systems beyond the project lifecycle.
03 / Lifecycle

From collection to deletion.

Every data point moves through these four stages. You can ask for deletion at any of them.

Collect

Captured at point of consent — form submit, contract signing, or platform connect.

Store

Encrypted at rest in EU/US infrastructure. Access limited to named team members on the engagement.

Process

Used only for the stated purpose. Logged so we can audit who accessed what.

Delete

Removed on the retention schedule above, or on your explicit request — typically within 30 days.

04 / Your rights

What you can ask us to do.

R1Access

Get a full export of the data we hold on you.

R2Correct

Have inaccurate data corrected.

R3Delete

Have your data deleted (subject to legal retention).

R4Portability

Receive your data in a portable format.

R5Object

Object to processing on legitimate-interest grounds.

R6Restrict

Restrict processing while a dispute is resolved.

05 / Sub-processors

Named third parties we share with.

Each is bound by a Data Processing Agreement. Adding a new sub-processor updates this list within 14 days.

  • 01VercelHosting & edge runtimeGlobal · US-DE
  • 02CloudflareCDN & DNSGlobal · US
  • 03ResendTransactional emailEU
  • 04PayoneerBilling & invoicingUS · EU
  • 05OpenAI / AnthropicLLM inference (with no-training flags)US · EU
06 / Compliance

Where we stand.

Snapshots of our compliance posture across the frameworks our clients ask about.

01Compliant
0ready
GDPR
Active DPA · EU sub-processors
02Compliant
0ready
CCPA
California rights honoured
03Aligned
0ready
ISO 27001
Controls in place · audit Q4 2026
04Roadmap
0ready
SOC 2 Type II
Targeting H2 2026
07 / The button

Right to be forgotten.

Privacy regulation gives you the right to ask us to delete everything we hold on you. Here's the button. Press it.

Result · 0 records

You're not logged in. We don't know who you are. If you've worked with us before, email our DPO from the address on file and we'll process a formal deletion request within 30 days.

Records found
00
Time to delete
30d
06 / Contact

Questions, complaints, requests.

Reach our data protection contact. We respond within 5 business days for most requests, 30 days for formal access/deletion.