Privacy policy
Last updated 22 July 2026
This policy explains what happens to your personal data when you use datalyvia.com. It covers this website and its contact form only — our products are separate services, are not yet publicly available, and will carry their own notices when they launch.
Who we are
Datalyvia Ltd ("Datalyvia", "we", "us") is the controller of the personal data described here — we decide why and how it is processed. We are a company registered in the United Kingdom.
For anything in this policy, including any of the rights set out below, write to privacy@datalyvia.com.
What we collect
The contact form is the only place on this site where you can give us personal data. When you submit it, we receive:
- Your name.
- Your email address.
- Your company, if you choose to give one — this field is optional.
- The area of interest you select.
- The content of your message.
Alongside that submission we record a small amount of technical information, used only to keep the form from being abused:
| What | Why we hold it |
|---|---|
| A salted, irreversible hash of your IP address | Lets us see that many submissions came from one source without ever storing the address itself. |
| The two-letter country your request came from | Supplied by our hosting provider. Used for spam triage. |
| Your browser's user-agent string, truncated | Distinguishes real browsers from scripted submissions. |
| Whether the bot check passed | Records whether the submission cleared Cloudflare Turnstile. |
| The date and time of the submission | Ordering, and enforcing the retention period below. |
We do not store your IP address. It is used in memory for the rate limit and the bot check, and only the salted hash is written to our database — the hash cannot be turned back into an address.
What we do not do
It is worth being specific about what this site does not do, because the list is unusually short for a commercial website:
- No analytics. There is no Google Analytics, no Plausible, no Fathom, no product analytics of any kind.
- No advertising or marketing trackers, and no pixels from any social network.
- No profiling, no automated decision-making, and no attempt to identify you across sites or sessions.
- No selling, renting or sharing of your data with anyone for their own purposes.
- No newsletter or marketing list. We reply to your enquiry and nothing else — we will not add you to a mailing list because you contacted us.
Why we use it, and our legal basis
| Purpose | Legal basis |
|---|---|
| Reading and replying to your enquiry, and any follow-up conversation about working together. | Steps taken at your request before entering a contract, and our legitimate interest in responding to people who contact us. |
| Keeping the form usable: blocking bots, rate-limiting, and investigating abuse. | Our legitimate interest in protecting the site and preventing misuse of a public form. |
Where we rely on legitimate interests, we have considered the effect on you. The technical data is minimal, the IP address is hashed before it is stored, and none of it is used to build a profile of you or to market to you.
Cookies
This site sets no cookies of its own, and stores nothing in your browser's local or session storage. There is no consent banner because there is nothing non-essential to consent to.
The one exception is the bot check on the contact form. Cloudflare Turnstile loads a script from challenges.cloudflare.com and may store a short-lived token in your browser in order to complete the check. Cloudflare states that Turnstile is not used to track individuals across sites and does not feed advertising. It runs only on the page containing the form.
Why you were not asked to accept cookies
Most sites greet you with a consent dialog. This one does not, and that is deliberate rather than an oversight — so here is the reasoning, in case you were looking for it.
The rule requiring that dialog is not the GDPR itself. It is the ePrivacy rules — the Privacy and Electronic Communications Regulations in the UK, and their equivalents across the EU — which require your consent before anything is stored on or read from your device, unless it is strictly necessary for something you have actively asked for.
We store nothing on your device. No cookies, no local or session storage, no analytics of any kind. The requirement is therefore never triggered: there is no consent to ask for, because there is nothing to consent to. The bot check on the contact form is the sole thing that touches your browser, and it is exempt as strictly necessary — without it the form would be filled by spam within days.
A banner here would be theatre. It would also be self-defeating, because remembering your answer would mean storing something on your device — which is precisely what we currently avoid. If we ever add anything that genuinely requires consent, this page changes first and you get a real choice before anything is stored.
Who else handles it
We use three service providers. Each processes data on our instructions only, under a contract, and none of them may use it for their own purposes.
| Provider | What it does | What it sees |
|---|---|---|
| Cloudflare | Hosts and serves the site, runs the bot check and the rate limit. | Your request metadata, including your IP address in transit. |
| Supabase | Stores the enquiry in a database that is locked to our server key and unreachable from any browser. | Everything listed under “What we collect”. |
| Resend | Delivers the notification email that tells us an enquiry has arrived. Sends from the EU (Ireland) region. | Your name, company, email, area of interest, country, and message. |
We may also disclose data if we are legally required to — for example in response to a valid court order. We will not do so voluntarily.
International transfers
Cloudflare serves this site from a global network, so your request is handled by whichever location is nearest to you. Email notifications are sent through Resend's EU (Ireland) region. Where any of our providers processes data outside the UK or EEA, that transfer is covered by the safeguards in their data processing terms, such as the UK Addendum and the EU Standard Contractual Clauses.
How long we keep it
We keep contact-form enquiries for 24 months from our last exchange with you, then delete them. If it is obvious sooner that an enquiry is spam, we delete it as soon as we have dealt with it.
You can ask us to delete your enquiry before then, and we will unless we have a legal reason to keep it.
How it is protected
- The whole site is served over HTTPS, with HSTS enabled.
- The enquiries table has row-level security switched on with no access policies, and permissions revoked from the public database roles. Nothing reachable from a browser can read or write it — only our server can, using a key that never reaches your device.
- Your IP address is hashed with a secret salt before storage, and the salt is held as an encrypted server secret.
- Error messages returned by the form are deliberately generic, so that database detail is never echoed back to the internet.
Your rights
Under the UK GDPR and the EU GDPR you can ask us to:
- Give you a copy of the personal data we hold about you.
- Correct it if it is wrong or incomplete.
- Delete it.
- Restrict how we use it, or object to our use of it where we rely on legitimate interests.
- Provide it in a portable, machine-readable form.
Write to privacy@datalyvia.com and we will respond within one month. There is no charge. We may ask you to confirm your identity before we act, so that we do not disclose your data to someone else.
If you think we have handled your data badly, please tell us first so we can put it right. You also have the right to complain to a regulator: in the UK that is the Information Commissioner's Office (ico.org.uk); in the EU it is the supervisory authority for the country where you live or work.
Children
This is a business-to-business site and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has sent us their details, contact us and we will delete them.
Changes to this policy
If we change what we collect or who we share it with, we will update this page and the date at the top. The page is version-controlled alongside the code that implements it, so the two cannot drift apart unnoticed.
