Privacy
Last updated: 11 August 2026
What this site does not do
This site does not use analytics, advertising, tracking pixels, or third-party marketing scripts. Fonts and other page assets are served from this domain.
As of the date above, no client-side JavaScript is used on any page, and the Content-Security-Policy sent with every response does not permit script execution. No cookie banner is required, because there is nothing to consent to.
The one cookie
One strictly functional cookie is set: ft, a signed timestamp that
proves a form submission came from a real page visit at a plausible speed. It
identifies nobody, contains no personal data, expires after four hours, and is
accepted only once. It is what lets the contact form resist bots without a
CAPTCHA.
The contact form
If you use the form we store the name, email address, company (if given) and message you submit, plus the time of submission, and nothing else. No IP address and no user agent are stored with the message. It is used solely to answer you, and deleted once the conversation is closed. The retention period and the legal basis are stated below.
Hosting and processors
The site and its form endpoint run on Cloudflare Pages (Cloudflare, Inc.), acting as our processor under Art. 28 GDPR. Submission rate limiting briefly processes your IP address in memory; the counter it keeps is discarded within one hour and is never stored alongside a message.
Retention and legal basis
- Controller
- CloudLift (registration in progress)
- Legal basis
- Art. 6(1)(b) GDPR: steps taken at your request prior to entering into a contract
- Retention period
- Six months after submission at the latest; deleted earlier once the conversation is closed or on request
Your rights
You may request access, rectification, erasure, restriction, portability, or object to processing at any time. Write to contact@cloudlift.co. You may also lodge a complaint with your supervisory data protection authority.