Information for companies and DPOs
Before sharing data, agree both the outcome and how the work will be carried out.
Website protection
The website uses HTTPS. Its resource policy restricts script execution; protective headers prevent embedding in other websites and help prevent content-type confusion.
There are no visitor accounts, file uploads, advertising pixels or separate enquiry database. Fonts and images load from the website. Initial contact is by direct email.
Project terms
Purpose, party roles, data and person categories, permitted operations and authorised users.
Providers, processing and access locations, international transfer safeguards, processing agreement and technical measures.
AI rules, excluded data, verification of results and access boundaries.
Retention, return and deletion, handling individual requests, incident response and client notification duties.
Infrastructure and access
The website is published through OpenAI Sites; Cloudflare delivers pages and provides network protection. Domain email is served by Inbox.eu. Visitors cannot access our working systems or client project data through the website.
Required providers, users, processing locations and access terms are agreed separately before project data is shared. Your security team can request information by email.
Before work begins
Request processing terms for your task by email. A DPA, legitimate-interest assessment, transfer assessment or DPIA depends on the actual processing.
This page describes the measures used and how project terms are agreed. It does not replace a processing agreement, independent audit or your company’s risk assessment.
Version dated 15 September 2026