Privacy · analytics is off until you allow it
Privacy Policy
This site is quiet by default. Nothing that identifies you runs until you say yes, and refusing costs you nothing: every page, every estimator, the readiness check and the contact form work either way. What follows describes exactly what is collected in each case.
1Who is responsible
This site is operated by Serhii Skrypnyk, a sole trader registered in Ukraine as an individual entrepreneur, working remotely and worldwide. For anything on this page, write to [email protected].
Where this site processes your data for its own purposes, the controller is Serhii Skrypnyk. Where personal data is processed on behalf of a client during an engagement, the client is the controller and the role is set out in the Data Processing Addendum.
2What is collected, and when
2.1 What you send deliberately
The contact form on this site creates a record in Salesforce. It carries what you typed:
- Your name
- Your email address
- Your company, if you fill that field in
- Your message
- Which page you sent it from, and any estimate or symptoms you had produced on that page
There is no other form. Nothing is sent anywhere while you use the estimators or the readiness check; those run entirely in your browser and transmit nothing until you press send.
2.2 What is collected only if you allow it
Analytics is off until you choose to turn it on, and refusing costs you nothing: every page, every estimator, the readiness check and the contact form work either way. If you do allow it, three things start:
- Google Analytics 4 records pages viewed, approximate location from a truncated IP address, device and browser, and which tools you used. IP anonymisation is on.
- Salesforce Account Engagement sets a visitor cookie so repeat visits can be recognised.
- A visit history in your own browser, held in local storage: when you first arrived, which page you landed on, the referring site and any campaign parameters, how many visits, which pages you have seen, which tools you used and what those produced.
This is profiling, and it is described plainly because it is. If you then send the contact form, that visit history is attached to your message so a first reply can start from what you actually did rather than from a blank page. If you have not allowed analytics, there is no history to attach and none is sent.
You can change your mind at any time on this page. Switching to essential only stops new collection and clears the visit history held in your browser. If your browser sends Global Privacy Control or Do Not Track, that is treated as a refusal and you are never asked.
2.3 Cookies
With analytics refused, this site sets no cookies at all. It stores one entry in local storage recording your choice, which is what stops it asking again.
With analytics allowed, Google Analytics and Account Engagement each set their own cookies, and the visit history above is written to local storage.
3The legal basis for each of these
- Consent, Article 6(1)(a). Analytics, the Account Engagement tracker and the visit history. Withdrawable here at any time, with no effect on what happened before you withdrew.
- Steps before a contract, Article 6(1)(b). Replying to your enquiry and preparing a proposal.
- Legitimate interest, Article 6(1)(f). Keeping correspondence readable, and preventing abuse of the form.
4What your data is used for
- Replying to what you wrote, and preparing a scope or estimate if you asked for one
- Sending service information you actively requested
- Understanding which pages are useful, if you allowed analytics
- Detecting abuse of the contact form
It is never used for any of the following:
- Sold or rented to anyone
- Sent to advertising networks or used for cross-context behavioural advertising
- Used to train an artificial intelligence model
- Used for automated decisions that produce a legal or similarly significant effect on you
- Used to send marketing you did not ask for
5Who else touches it
These are the only third parties involved, each under a written agreement that limits them to the purpose listed:
| Service | What it does | Where | Safeguard |
|---|---|---|---|
| Bluehost | Hosting for solutions4sf.com | USA | Standard Contractual Clauses |
| Cloudflare | Content delivery and protection against abuse | USA and EU edge | Data Privacy Framework, Standard Contractual Clauses |
| Salesforce | The CRM record created when you send the contact form | USA and EU | Data Privacy Framework, Standard Contractual Clauses |
| Salesforce Account Engagement | Visitor tracking, only after you allow analytics | USA | Data Privacy Framework, Standard Contractual Clauses |
| Google Analytics 4 | Site usage, only after you allow analytics, IP anonymised | USA and EU | Data Privacy Framework, Standard Contractual Clauses |
| Google Workspace | Email correspondence | USA and EU | Data Privacy Framework, Standard Contractual Clauses |
Some of these are based in the United States. Transfers rely on the EU-US Data Privacy Framework where the provider is certified, and on Standard Contractual Clauses adopted by the European Commission otherwise, with encryption in transit and at rest as a supplementary measure.
If this list changes, this page changes with it, and clients with an active engagement are told at least thirty days beforehand and may object on data protection grounds. The same commitment is written into the Data Processing Addendum.
6How long any of it is kept
- Contact form records in Salesforce: three years from the last contact, then deleted, unless you become a client.
- Email correspondence: three years from the last message.
- Analytics: fourteen months, then aggregated beyond recovery.
- Visit history in your browser: until you clear it, refuse analytics, or clear your browser storage. It never leaves your device unless you send the contact form.
- Client engagement records: the length of the contract plus seven years, which is a tax and professional liability requirement rather than a choice.
7Your rights, and how to use them
If you are in the EU, the UK, or a jurisdiction with equivalent law, you can ask for any of the following:
- Access. A copy of everything held about you.
- Rectification. Correction of anything inaccurate.
- Erasure. Deletion, where there is no overriding legal reason to keep it.
- Restriction. A pause on processing while something is disputed.
- Portability. Your data in a machine readable file.
- Objection. To anything relying on legitimate interest.
- Withdrawal of consent. Immediately, on this page, without writing to anyone.
For all except the last, email [email protected] with "GDPR request" in the subject. The answer comes within thirty days. If it does not satisfy you, you may complain to the data protection authority where you live.
California residents have a separate set of rights, set out in the California Privacy Notice.
8How it is protected
- HTTPS on every page, with modern transport security
- Two factor authentication on every account that can reach personal data
- Encrypted disks, a password manager, and no client work over public wireless networks
- Access limited to one person, because there is only one person
If a breach affects your personal data, you will be told within seventy two hours, as GDPR requires.
9Children
This is a business to business service. Data is not knowingly collected from anyone under eighteen. If any is found, it is deleted.
10Changes to this policy
The date at the top of this page changes whenever the policy does. Where a change is material and you have an active engagement, you will be told directly rather than left to notice.
11Contact
Serhii Skrypnyk, RevOps Architect. Email [email protected]. Also on LinkedIn and Trailblazer.