1. Information submitted through the website
When you contact XYZ, we may receive your name, company, work email, phone number, country, project location, project requirements, messages, and any project brief you choose to upload.
2. How inquiry information is used
Submitted information is intended to help XYZ assess, respond to, and follow up on project or partnership inquiries. It is not intended for unrelated automated decision-making.
3. Project briefs and uploads
Do not upload confidential, export-controlled, security-sensitive, or personal data unless a suitable transfer and confidentiality process has been agreed. The launch configuration must define file storage, access, scanning, retention, and deletion.
4. Server logs, analytics, and cookies
Hosting providers may process technical logs such as IP address, browser information, timestamps, and requested pages for security and operation. Optional analytics are disabled unless configured. A cookie banner should appear only if non-essential cookies are enabled.
5. Third-party providers
Email delivery, form processing, file storage, analytics, or map services may process information when configured. The final policy must name the selected providers and explain their roles.
6. Retention and security
Inquiry data should be retained only as long as needed for the relevant business, legal, and security purpose. No website can guarantee absolute security; the production setup must define access control, retention, backups, and deletion procedures.
7. Your rights and requests
Depending on your jurisdiction, you may have rights to request access, correction, deletion, restriction, or information about processing. Official contact details for these requests must be added before launch.
8. Legal review required
This template does not claim automatic GDPR or other regulatory compliance. Counsel should review the final policy against XYZ’s operations, providers, hosting, users, and jurisdictions.
