1. Scope
This policy covers the website at vinculixos.com (the “website”). It does not cover the VinculixOS software, which is installed and operated by each client on their own infrastructure. Personal data processed inside a client’s installation is processed by that client, under that client’s own policies, and never reaches us.
2. Who is responsible
The controller for the processing described here, within the meaning of the EU General Data Protection Regulation (GDPR), is the operator of the website identified in the legal notice. You can reach us about anything in this policy at contact@vinculixos.com.
3. Hosting and server logs
The website is a static site hosted on Cloudflare Pages by Cloudflare, Inc., which acts as our processor. To deliver pages and protect the service against abuse, Cloudflare’s network necessarily processes technical data for each request, such as your IP address, the page requested, the time of the request, and your browser’s user agent.
- Purpose: delivering the website securely and reliably, including filtering malicious traffic.
- Legal basis: our legitimate interest in operating a secure website (Article 6(1)(f) GDPR).
- Retention: request data is kept by Cloudflare for a limited period under its own retention schedule and is not used by us to identify visitors.
If a request looks automated or abusive, Cloudflare may ask your browser to complete a short security check and may then set a strictly necessary security cookie. See our cookie statement.
4. Visitor statistics
We use Cloudflare Web Analytics to count page views in aggregate, so we know which pages are read. It sets no cookies, stores nothing on your device, and does not fingerprint your browser. A small script from Cloudflare sends one measurement per page view; your IP address is used to deliver it but is not stored as part of the statistics. We cannot use the statistics to identify you, and they are not used to follow you across other websites.
For each page view, the following may be recorded:
- the time of the page view, the page address and the referring page;
- your country, derived from the request;
- your browser, operating system and device type (desktop, mobile, tablet);
- how quickly the page loaded and rendered.
- Purpose: understanding, in aggregate, how the website is used and how fast it is, so that we can improve it.
- Legal basis: our legitimate interest in measuring the reach of our website without tracking individuals (Article 6(1)(f) GDPR).
- Your choice: you can object at any time by writing to us. Blocking JavaScript, or using a content blocker, also prevents the statistics from being sent.
5. When you email us
The website has no forms. If you write to us, we process the content of your message, your email address and any details you choose to include, in order to reply.
- Legal basis: taking steps at your request before entering into a contract (Article 6(1)(b) GDPR) where you enquire about our product; otherwise our legitimate interest in answering correspondence (Article 6(1)(f) GDPR).
- Retention: as long as needed to deal with your enquiry and any relationship that follows, and then only as long as the law requires.
- Recipients: our email service provider, which acts as our processor. We do not sell, rent or share your details for anyone else’s marketing.
6. What we do not use
- No cookies of our own. The only exception is the security cookie our host may set, described in our cookie statement.
- No advertising or cross-site tracking technology.
- No third-party fonts, embeds or social media plugins. Fonts are served from this website. The only third-party script is the Cloudflare Web Analytics beacon described above.
- Our profiles on X, GitHub and YouTube are reached through ordinary links. Nothing is loaded from those services until you follow a link, and from then on their own privacy policies apply.
- No automated decision-making or profiling.
7. International transfers
Cloudflare, Inc. is established in the United States and operates a global network, so data processed for hosting and visitor statistics may be processed outside the European Economic Area. Such transfers rely on the safeguards set out in Cloudflare’s data processing addendum, including the European Commission’s Standard Contractual Clauses. You can ask us for more information about these safeguards.
The operator is based outside the European Economic Area. If you email us, your message and the personal data in it are therefore read and answered outside the European Economic Area. We send it to no one else, and we apply the protections described in this policy wherever it is processed.
8. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased;
- restrict how we process it;
- receive your data in a portable format;
- object to processing based on our legitimate interests.
To exercise any of these rights, write to contact@vinculixos.com. We will respond within one month. You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU member state where you live or work.
9. Changes
We will update this policy when what the website does changes, for example if we add a contact form. The date at the top of this page shows when it last changed.