Legal / Privacy
v1.2

What we know about you. What we don't.

A plain-English account of the data we collect, why we collect it, and what we'll never do with it. Last updated June 2026.

Scroll to deconstruct
TL;DR
Last updated · June 4, 2026
01Collect

Only what's needed to deliver the project or respond to your inbound.

02Store

Encrypted, in EU/US-based infrastructure, for the minimum useful window.

03Share

Never sold. Shared only with named processors we're bound to by DPA.

04Delete

On request, end of engagement, or by automated retention policy.

01.LIVE

What happens when data hits us.

A live trace of how a single form submission is processed — captured, masked, encrypted, and logged. Every interaction with data leaves a trail you can audit.

audit.log · live
inorva@audit
00:00:00[INGEST]
What we collect

Data we hold.

Every item below is tied to a specific reason. If we can't justify keeping a field, we don't keep it.

  • 01
    Contact details

    To reply to your inbound, send proposals, and run the engagement.

    Name · Email · WhatsApp · Company

    3 years from last contact
  • 02
    Project artefacts

    Documents, briefs, content, and credentials you share so we can build.

    Briefs · API keys · Access tokens · CMS exports

    Through engagement + 90 days, then deleted
  • 03
    Site analytics

    Anonymised page views and Core Web Vitals to improve this site.

    Country · Browser · Page · Referrer (no IP retention)

    13 months rolling
  • 04
    Billing records

    Issued invoices and payment confirmations.

    Invoice line items · Payoneer references

    10 years (Egyptian commercial law)
  • 05
    AI assistant conversations

    So we can follow up on what you asked, and see where the assistant answers badly. Covers both the assistant on this site and the one on WhatsApp.

    Your messages · Its replies · Voice notes as text · WhatsApp number (WhatsApp only) · Language

    12 months from the last message
What we never do

Lines we don't cross.

  • We will never sell your data to third parties.
  • We will never use your private project content to train third-party AI models without explicit written consent.
  • We will never email-spam you. No newsletters unless you actively opt in.
  • We will never track you across other sites with cross-domain identifiers.
  • We will never retain login credentials for your systems beyond the project lifecycle.
Lifecycle

From collection to deletion.

Every data point moves through these four stages. You can ask for deletion at any of them.

Collect

Captured at point of consent — form submit, contract signing, or platform connect.

Store

Encrypted at rest in EU/US infrastructure. Access limited to named team members on the engagement.

Process

Used only for the stated purpose. Logged so we can audit who accessed what.

Delete

Removed on the retention schedule above, or on your explicit request — typically within 30 days.

Your rights

What you can ask us to do.

R1Access

Get a full export of the data we hold on you.

R2Correct

Have inaccurate data corrected.

R3Delete

Have your data deleted (subject to legal retention).

R4Portability

Receive your data in a portable format.

R5Object

Object to processing on legitimate-interest grounds.

R6Restrict

Restrict processing while a dispute is resolved.

Sub-processors

Named third parties we share with.

Each is bound by a Data Processing Agreement. Adding a new sub-processor updates this list within 14 days.

  • 01VercelHosting & edge runtimeGlobal · US-DE
  • 02CloudflareCDN & DNSGlobal · US
  • 03ResendTransactional emailEU
  • 04PayoneerBilling & invoicingUS · EU
  • 05OpenAI / AnthropicLLM inference (with no-training flags)US · EU
  • 06SanityContent platform & assistant conversation recordsEU · US
Compliance

Where we stand.

Snapshots of our compliance posture across the frameworks our clients ask about.

01Compliant
0ready
GDPR
Active DPA · EU sub-processors
02Compliant
0ready
CCPA
California rights honoured
03Aligned
0ready
ISO 27001
Controls in place · audit Q4 2026
04Roadmap
0ready
SOC 2 Type II
Targeting H2 2026
The button

Right to be forgotten.

Privacy regulation gives you the right to ask us to delete everything we hold on you. Here's the button. Press it.

Result · 0 records

You're not logged in. We don't know who you are. If you've worked with us before, email our DPO from the address on file and we'll process a formal deletion request within 30 days.

Records found
00
Time to delete
30d
Contact

Questions, complaints, requests.

Reach our data protection contact. We respond within 5 business days for most requests, 30 days for formal access/deletion.