Home

Documents

Privacy policy

Updated 17 August 2026

Who processes the data

The data controller is GIVSITE. This policy covers information that you voluntarily send through the website’s contact form.

Information we receive

Your name, company name, selected contact method and channel, telephone number or email, country code, an optional preferred-contact-time note, selected services, and message. A voluntarily submitted request may also include the current page path, service or design-concept context, the source page’s domain and path, and only the campaign parameters utm_source, utm_medium, utm_campaign, utm_content, and utm_term. Query strings, URL fragments, usernames, and passwords from a source address are not stored. When the browser supplies the current page’s technical address, the server uses its path to verify the context claimed by the page.

To protect the form from abuse, the site temporarily stores only pseudonymous HMAC identifiers for the network address, calculated with a secret key separately for incoming requests and validated delivery attempts. The original address is not written to the rate-limit table.

To prevent a repeated native-form submission from creating a duplicate before delivery is confirmed, the server also creates a pseudonymous HMAC fingerprint from the validated and normalized request semantics. The fingerprint covers the meaningful enquiry fields; source context, original field text, and contact details are not written to this technical table. It stores only the opaque submission identifier, technical delivery state, and the record’s creation and expiry times.

Why we need the information

Only to answer your request, contact you and agree a call, prepare a proposal, and protect the form from automated submissions. Form data is not used for marketing email without separate consent.

Transfer and retention

Cloudflare Email Service sends the form contents by email to hello@givsite.com; Hostinger operates that mailbox. Limited source context travels with the same enquiry so we can understand which page led to the contact. We do not sell data.

The site does not store the original enquiry contents in its D1 database. For rate limiting, D1 stores separate pseudonymous HMAC identifiers rather than the IP address, with a technical lifetime of up to 20 minutes. To prevent repeat delivery, D1 stores the pseudonymous native-form fingerprint described above, an opaque identifier, and technical delivery state; a separate email-delivery receipt likewise contains only an opaque identifier and state. These records are retained for no more than 24 hours and contain none of the original enquiry fields. Until the server records delivery confirmation, another attempt uses the same identifier and does not extend its lifetime. After confirmation is recorded, the next identical enquiry receives a new identifier even if the browser did not display the success page. Expired records are removed by scheduled cleanup or during later form processing, so physical deletion may occur later when no new requests arrive. Retention of the enquiry itself is determined by GIVSITE’s mailbox settings.

Your rights

You can request access to, correction of, or deletion of your data. Open the contact form , choose Email, and write ‘Personal data request’ in the message. The form also works without JavaScript.

Local settings

GIVSITE uses dark presentation only and does not store a theme choice in the browser. The current site has no advertising or analytics cookies. Technical form state exists only while the open page is in use and is not used to track you between visits.