Privacy notice
1. Who is responsible (controller)
The controller responsible for processing personal data on this website is:
Vladyslav Tomko, sole trader (autónomo), Pasaje de Cox, 7, P01 B, 03012 Alicante, Spain.
Contact: ceo.vlad@gmail.com.
No Data Protection Officer (DPO) is appointed, as appointment is not mandatory for this activity under Art. 37 GDPR.
2. The exposure check
When you use the exposure check you enter a domain and confirm you own it or are authorised to assess it. For that domain we read only publicly available information: Certificate-Transparency logs, public DNS records, and version information that the relevant servers disclose to any visitor without authentication. We do not probe for hidden paths, scan ports, bypass authentication, or attempt to access protected data.
We do not store the results of the exposure check. They are computed and shown to you in your browser, then discarded. We do not build, keep, or sell a database of third-party exposure.
- Personal data involved: the domain you submit is generally company (not personal) data. Any connection data needed to run the check is handled as described under "Hosting & server logs" below.
- Legal basis: performance of a service you request / our legitimate interest in providing a self-service tool (Art. 6(1)(f) GDPR). A Legitimate Interest Assessment is kept on file.
3. Contact form & leads
If you contact us through the form or by email, we process the name, email address, company domain, company size and message you provide, solely to respond to you and discuss a possible engagement.
- Legal basis: steps taken at your request prior to entering a contract (Art. 6(1)(b) GDPR) and, where you are an existing or prospective business contact, our legitimate interest in responding to enquiries (Art. 6(1)(f) GDPR).
- Required data: name and email are required to reply; the other fields are optional.
- Retention: we keep enquiry messages only as long as needed to handle your enquiry and any follow-up. Enquiries that do not lead to an engagement are deleted no later than 6 months after our last contact. If an engagement begins, the relevant data is kept for the duration of the business relationship and thereafter only for as long as statutory tax and commercial retention obligations require, then deleted.
- Recipients / processors: the message is transmitted by our email-delivery provider Resend (Resend, Inc., USA) and delivered to our mailbox provided by Google (Gmail, Google Ireland Ltd. / Google LLC, USA). These providers process the data only to deliver and store the message. We do not sell your data or use it for advertising.
- Anti-abuse: the form uses a hidden field (honeypot) to reject automated spam. No tracking cookies and no third-party scripts are involved.
4. Hosting & server logs
The site and its functions are served by Cloudflare Pages (Cloudflare, Inc.). To deliver the site securely and defend against abuse, the host may process technical connection data (e.g. IP address, user-agent, timestamp, requested URL) for a limited time.
- Legal basis: our legitimate interest in a safe, available and functioning website (Art. 6(1)(f) GDPR).
- International transfers: Cloudflare, Resend and Google may process data outside the EU, including in the USA. Such transfers are safeguarded by the EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework, together with each provider's data-processing addendum.
5. No tracking
This site uses no advertising cookies, no third-party analytics, and no external font or script CDNs. No consent banner is required because no non-essential cookies or tracking are set. We will update this section, and add a consent mechanism, if we ever introduce analytics or embedded third-party content.
6. Your rights
Under the GDPR you have the right to access, rectification, erasure, restriction of processing, data portability, and to object to processing based on legitimate interests. Where processing is based on consent, you may withdraw it at any time with future effect.
To exercise any of these rights, contact ceo.vlad@gmail.com. You also have the right to lodge a complaint with a supervisory authority — in Spain the Agencia Española de Protección de Datos (AEPD, aepd.es); in Germany you may address the supervisory authority of your federal state.
7. Changes to this notice
We may update this notice to reflect changes to the site or the law. The current version always applies.
Last updated: 11 October 2026.