Last updated: 27 September 2025
1. Who we are
This website (“Site”) is operated by [Company/Owner Name], [Address, Country].
Contact: [email@example.com]. If applicable, our Data Protection Officer can be reached at [dpo@example.com].
2. What personal data we collect
We do not collect personal data via contact forms because the Site does not include any forms.
However, the following data may be processed when you use the Site:
- Usage data & analytics: pages viewed, clicks, referrer, approximate location (based on IP), device/OS/browser, session duration.
- Technical logs: IP address, timestamps, requested URLs, HTTP status codes, user-agent (for security and diagnostics).
We do not purposely collect special categories of data.
3. Cookies and similar technologies
We use cookies to run Google Analytics and measure traffic and performance.
- Type: analytics (non-essential).
- Examples of cookies: _ga, _ga_*, _gid (names may vary).
- Retention: Google Analytics stores identifiers for up to [e.g., 14 months] (configurable).
- Control: You can accept or reject analytics cookies via our cookie banner at any time. You can also clear or block cookies in your browser settings.
If you decline analytics cookies, Google Analytics will not load.
4. Google Analytics
We use Google Analytics (GA4) to understand how visitors use the Site.
- Controller & processor: We act as controller for our analytics implementation; Google acts as our processor for measurement services.
- IP handling: We configure Google Analytics to limit IP usage for geolocation; IP addresses are not stored in GA reports.
- Data location & transfers: Analytics data may be processed on servers outside the EEA (including the United States). Transfers rely on Google’s safeguards such as Standard Contractual Clauses.
- Opt-out: You can refuse analytics cookies in our banner or use your browser’s tracking protection. An optional Google Analytics opt-out add-on is also available from Google.
5. Legal bases (GDPR)
- Analytics cookies: Consent (Art. 6(1)(a) GDPR). The Site loads analytics only after you consent in the banner.
- Security & logs: Legitimate interests (Art. 6(1)(f) GDPR) to secure and administer the Site (e.g., server logs, troubleshooting).
6. How long we keep data
- Analytics events: retained according to our GA settings ([e.g., 14 months]).
- Server logs: kept for [e.g., 30–90 days] and then deleted or anonymized unless required for security or legal purposes.
7. Who receives your data
- Service providers: Google (analytics).
- Infrastructure: [Your hosting provider] for server operation and logs.
We do not sell your data.
8. Your rights (EEA/UK)
You may request:
- access to your personal data,
- rectification or erasure,
- restriction or objection to processing,
- data portability (where applicable),
- withdrawal of consent at any time (it won’t affect past lawful processing).
To exercise these rights, contact [email@example.com].
You also have the right to lodge a complaint with your local data protection authority.
9. Children
This Site is not directed to children under the age of [13/16]. We do not knowingly collect data from children.
10. Security
We use reasonable technical and organizational measures to protect data (e.g., HTTPS, access controls). No method is 100% secure.
11. Changes to this policy
We may update this Policy from time to time. The latest version is indicated by the “Last updated” date above.
12. Contact
For questions about this Policy or our data practices, contact [Company/Owner Name] at [email@example.com].