Privacy policy · GDPR
Privacy, in plain words.
Last updated: July 2026
Draft — fill in the fields marked [LIKE THIS] before publishing, then delete this line in src/pages/LegalPage.jsx.
Who is responsible
The person running this website and deciding what happens with your data (the "controller" in GDPR terms):
Data controller
- Name
- [FULL LEGAL NAME]
- Address
- [STREET + No.], [POSTAL CODE + CITY], [COUNTRY]
- vaviloncompany@inbox.ru
- Phone
- [PHONE]
What this site collects, and why
The audit form. If you send it, we receive what you typed: your business name and city, your name, and the contact you chose (Telegram, phone or email). We use it for exactly one thing — replying to your request. Legal basis: taking steps before a contract at your request (Art. 6(1)(b) GDPR) plus the consent box you tick.
Your IP address, briefly. When the form is submitted, our server uses your IP to slow down spam and abuse (rate limiting). It is not tied to your request; in logs it appears only as a short-lived, non-reversible hash. Legal basis: our legitimate interest in keeping the form working (Art. 6(1)(f)).
Two values in your browser. The site stores your language choice and the fact that you closed the cookie note — in localStorage, on your device. They never leave it. No analytics, no ad pixels, no fingerprinting, no third-party cookies. We honestly don't know how many visitors this site has.
Proof that you agreed. Together with the form we store the exact wording of the consent checkbox you ticked and the moment you ticked it. That record exists only so both sides can show later what was agreed — it is never used to contact you.
Where your data goes
Nothing is sold, rented or shared for marketing. To make the form work, a few processors touch the data on our behalf:
- Vercel Inc. — hosts this site and runs the form endpoint. Your request passes through their infrastructure.
- Telegram — your submitted request is delivered to us as a private bot message so a human can answer fast.
- Resend — if email delivery is used, the request is sent to our inbox through Resend (EU region, Ireland).
- Upstash Redis — a backup copy of the request is kept on a server in Frankfurt, Germany, and deletes itself after 90 days.
- Google Fonts — the typefaces load from Google's servers, so your browser sends its IP to Google when the page opens. We plan to self-host the fonts to remove this request entirely.
How long we keep it
The backup copy in Frankfurt deletes itself after 90 days — no action needed from anyone. Messages in our Telegram and inbox stay until your request is handled, then get cleaned up. There is no CRM quietly hoarding your details, and no mailing list you get added to.
Cookies and that little bar
This site sets no cookies at all — no analytics, no advertising, no third parties. The bar you saw on arrival is therefore a notice, not a consent wall: whichever button you press, nothing starts tracking you. Your answer is written to localStorage so the bar stops appearing. Want it back? Use "Cookie settings" in the footer, or clear this site's data in your browser.
If we ever add real analytics, this bar becomes a genuine opt-in and nothing loads before you say yes.
Your rights
GDPR gives you the full set: ask what we hold about you, correct it, have it deleted, restrict or object to processing, take it with you, and withdraw consent at any time. One email to the address above does it — no forms, no hoops. We answer within a month, usually much faster.
If you think we handled your data badly, you can complain to a data protection authority in the EU country where you live or work. We'd appreciate the chance to fix it first, but that's your call.
Changes
If anything here changes — a new processor, a new feature — we update this page and the date at the top. No dark-pattern "we've updated our privacy policy" emails, because we don't have your email unless you wrote to us.
⏚ short, because there's honestly not much data here to write about.