Controller details are withheld until the legal entity record is complete and approved.
Privacy notice
Understand the data path before you continue.
This website is designed for global business visitors, with particular attention to European data-protection requirements. It does not use an enquiry form or ask for identity documents on public pages. Contact actions may move you to a separate provider with its own data practices.
The rights-request email remains withheld until ownership and access are verified.
No public enquiry form, account or document upload. Operational request data may be handled to serve and secure the site.
Only page path, CTA type and on-page source are included in the application event payload.
WhatsApp, email and booking providers process the information you choose to send after leaving this site.
GDPR applicability depends on establishment, offering services to people in the EU/EEA, monitoring and the actual processing involved.
Scope and controller
This notice covers the public website and its minimal contact-click event. It does not replace the privacy terms of an external communication provider.
The controller identity and privacy contact are sourced only from approved site configuration. Unapproved values are never shown, and public release remains blocked while the controller name, registered address or functioning privacy-rights channel is missing.
The GDPR may apply where processing is connected with an EU/EEA establishment or where a non-EU organisation offers goods or services to, or monitors the behaviour of, people in the EU. Other national and regional privacy laws may apply instead of, or alongside, the GDPR. European rules are not presented as universal rules for every visitor.
Data categories
The public website separates information needed to operate the service from information you voluntarily provide to a third party.
- Technical request data: hosting and security providers may process IP address, request time, requested path, browser or device information and security signals in operational logs.
- Contact-click event: the application sends only the page path, CTA type and on-page source to a same-origin endpoint. It omits cookies, credentials and the browser referrer.
- Information not collected on-site: no enquiry text, WhatsApp number, prefilled message, chat content, account, marketing profile, identity document or payment data is stored by this website.
- External conversation data: after you choose WhatsApp, email or a booking provider, that service and the receiving business may process your account details, message, attachments, appointment information and related metadata.
Purposes and legal bases
Every purpose and legal basis must be confirmed against the final controller, deployment and target market before launch.
- Deliver and secure the website, prevent abuse and diagnose faults. The intended basis, where GDPR applies, is the controller's legitimate interest in operating a secure business website, subject to the required assessment.
- Measure which contact routes are selected using the three-field event. The intended basis is a narrowly scoped legitimate interest in understanding service demand, subject to necessity, balancing and local ePrivacy rules.
- Respond to a conversation you initiate through an approved external channel. Depending on the request, processing may support steps requested before a contract, performance of a contract, legal obligations or legitimate interests.
- The site does not make decisions producing legal or similarly significant effects through automated processing and does not create advertising profiles.
Recipients and international transfers
A recipient receives only the information needed for its role, subject to the final provider contracts and configuration.
- Website hosting, security and operational-log providers may process technical request data on behalf of the controller or under their own legal responsibilities.
- WhatsApp and its affiliated infrastructure, an email provider or a booking provider becomes involved only when you choose that route. Their terms and privacy notices apply in addition to this notice.
- Professional advisers and authorities may receive information where necessary for advice, compliance, disputes or a binding legal requirement.
- A provider may process data outside your country. Before public launch, the controller must document the relevant locations, roles and any transfer mechanism required by applicable law.
Retention and security
The website does not create its own enquiry database, but operational and external systems may retain data.
- Contact-click events are written only to the deployment runtime log; there is no application analytics database, visitor ID or message-content store.
- Operational-log and security-data retention follows the final hosting configuration. A documented duration and deletion process remain a public-launch requirement.
- Messages and appointment details follow the receiving business's approved retention schedule and the external provider's own retention practices.
- Safeguards include data minimisation, strict event-field validation, same-origin requests, no-referrer requests and restricted publication of contact and legal-entity data.
Your choices and rights
Rights vary by location. Where the GDPR applies, they may include access, rectification, erasure, restriction, portability and objection.
- You may browse the site without starting an external conversation and without accepting non-essential marketing cookies, because none are currently enabled.
- Where processing relies on consent, you may withdraw it without affecting earlier lawful processing. Where it relies on legitimate interests, you may object in applicable circumstances.
- You may complain to the competent data-protection authority. The appropriate authority depends on where you live, work or where the alleged infringement occurred.
- A verified privacy-rights contact route will be published before launch. Requests concerning WhatsApp, email or booking-provider accounts may also need to be directed to that provider.
Safe first contact
Share only the minimum operating context needed to decide whether a conversation is relevant.
- Do not send passwords, access codes, full identity documents, full bank statements, card data, private keys or unrelated sensitive information in an initial message.
- Confirm the business identity and handling route before sending due-diligence materials.
- Contact services are intended for business users and are not directed to children.
Official reference context
Primary sources, not a substitute for case-specific advice.
These links support the general explanations above. The binding law, provider configuration and facts of a specific case still control.
Official guidance on personal data and when EU data-protection rules apply to EU and non-EU organisations.
↗European CommissionData-protection obligationsOfficial guidance on information duties, purposes, legal bases, retention and individual rights.
↗WhatsApp for BusinessBusiness privacy protectionsProvider information on business chats, hosting choices and controls available to WhatsApp users.
↗