NARTRIC

Privacy notice

This notice explains the processing of personal data in the local test version, including the configured form delivery. The signed Zoho data processing agreement has been reviewed. Account-specific subprocessors and transfer safeguards, and future public hosting, still require final verification. This version is therefore not yet approved for publication.

1. Controller under the GDPR

Nigar Seyidova · NARTRIC Digital Agency
Lucas-Cranach-Str. 2A
65428 Rüsselsheim am Main, Germany
Email: support@nartric.com

2. Provision of the local website

This version runs on the local computer. To provide the website, the local server processes the connection address, requested address, HTTP method and transmitted request information. It does not create persistent access logs. The legal basis is Article 6(1)(f) GDPR, with the legitimate interest in providing a functioning and secure website. Public hosting has not been set up for this version. Cloudflare is planned but is not an active hosting or CAPTCHA service for this local website. Hosting providers, logs, retention and any international transfers must be specified before public launch.

Technical preparation: conditional Turnstile integration is prepared in the code. It loads only when form delivery is enabled with a configured site key. It is not loaded in the current local test mode with the local challenge bypass. Before activation, the actual account terms, legal basis, retention and international transfers require final verification.

The planned provider is Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. Its Turnstile Privacy Addendum describes processing of IP address, TLS fingerprint, User-Agent, site key and associated origin. Cloudflare acts as processor when protecting our website and as a separate controller when improving bot detection. This provider description does not mean that Turnstile is already active here. Exclusively European processing and a universal 24-hour retention period are not promised.

3. Contact form and email

Submitting sends your first name, last name, email address and message to our local server and, through the Zoho Mail API, to support@nartric.com. We use them to handle and answer your enquiry. After the mail provider accepts the enquiry, we send an automatic acknowledgement to the email address you supplied in the language selected in the form. The form is a non-binding enquiry; the acknowledgement is not contractual acceptance. It solely confirms your contact request, contains no advertising and does not reproduce your message. It does not guarantee delivery or a response deadline. Where processing is necessary to take pre-contractual steps at your request or to perform a contract with you, the legal basis is Article 6(1)(b) GDPR. Other enquiries are handled under Article 6(1)(f) GDPR, with the legitimate interest in appropriately addressing incoming enquiries.

Providing these details is not required by law or as a condition of merely visiting the website. All four fields are marked as mandatory in the form, which cannot be submitted without them. Alternatively, you may contact us directly by email. Permission to save language and theme is not required to contact us.

The form does not save messages in localStorage or cookies. Entries remain in the fields during editing and after submission; browser autofill and restoration depend on your settings. The message is processed as email in the Zoho mailbox. The local form server does not maintain an additional database of message contents.

4. Mail provider and recipients

We use Zoho Mail to process message content and delivery information. The data processing agreement completed on 7 October 2026 names Zoho Corporation GMBH, II. Hagen 7, 45127 Essen, Germany, as processor. It provides for storage in data centres in the European Economic Area (EEA). Schedule 2 permits need-based access by Zoho group entities in India for support and debugging; additional recipients outside the EEA may be involved depending on the services used. EEA storage therefore does not mean processing exclusively within the EEA.

Zoho contractually commits to a valid GDPR basis for international transfers. Its general privacy FAQ describes standard contractual clauses and supplementary measures for support access from India. The contractual chain for this account, applicable subprocessors and access to copies of transfer safeguards still require final verification before publication. The processing clauses in Schedule 1 alone do not establish complete international-transfer arrangements. Provider information: recipient directory and Zoho privacy policy.

Only Nigar Seyidova has access to the mailbox. When she assigns a specific task to a specialist, she shares only the information necessary for that task, rather than all customer data or the entire correspondence. Depending on the task, the necessary information may include personal data. The recipients, their data protection roles and any required contractual arrangements must be established before information is actually shared.

5. Technical safeguards and retention

The local server limits requests using a protected hash of the connection address, counters and time windows. It detects repeat submissions using a random submission identifier, a protected hash of message content including the form language, and delivery status. An automatic acknowledgement is attempted for each newly accepted enquiry. Repeated transmission of the same submission identifier does not trigger another acknowledgement. These records contain no plain-text IP address or message content. The basis is Article 6(1)(f) GDPR: preventing abuse and duplicate delivery.

Rate windows last ten minutes per connection address and one hour overall; submission records expire after 24 hours. In this local version, these technical records are stored in a local database outside publicly served files and survive a restart. A sequential counter containing no message content or contact details is retained to prevent reuse of reference numbers. Expired entries are removed on the next request, not necessarily at the exact expiry time.

Enquiries that do not lead to an order or contract are deleted as soon as they are definitively no longer needed for handling the enquiry, and no later than three months after the correspondence ends. This is a maximum period, not a minimum retention time. Longer retention applies only where required by applicable statutory retention duties (Article 6(1)(c) GDPR) or necessary to establish, exercise or defend specific legal claims (Article 6(1)(f) GDPR). It is limited to the scope and duration required for those purposes. Contracts, invoices and supporting records needed for those purposes are therefore not automatically subject to this three-month limit. Application documents follow section 8. The retention periods applicable to contractual and business records in each case still require specification before publication. The form server’s technical windows are not mailbox deletion periods.

Clause 8 of the Zoho agreement addresses termination of processing: deletion from active systems in the next six-monthly cleanup cycle, and from backups within three months after deletion from active systems. It does not automatically delete current mailbox messages after six months. Our stated retention periods must be implemented separately.

6. Language, theme and privacy choice

Only after your permission does this website read and save nartric-theme and nartric-language in localStorage. Without permission, both work in memory for the current page; language can also be included in the URL. The basis is section 25(1) TDDDG and, where personal data are involved, Article 6(1)(a) GDPR.

nartric-privacy-v1 records your choice, timestamp, text version and 180-day validity. It respects your privacy choice under section 25(2)(2) TDDDG and, where personal data are involved, Article 6(1)(f) GDPR. No tracking identifier is assigned. Refusing or withdrawing removes optional preferences. On your next visit after expiry, they are also removed and the choice is shown again. Change your choice through “Privacy settings” in the footer or clear site data in your browser. Declining does not block the website or form.

7. Other features

The website uses system fonts and local animations. The reviewed page code contains no analytics or advertising trackers, external font requests or cookie writes. Form availability checks and submissions use the local server, which establishes the connection to the mail provider. There is no profiling or automated decision-making with legal or similarly significant effects.

8. Applications by email

The careers page opens your email application. You choose the content, attachments and whether to send; this website does not upload CVs. Applications received are processed to consider possible cooperation. Section 26(1) and (8) BDSG applies to employment applications; Article 6(1)(b) GDPR applies to requested freelance cooperation. The mailbox and mail provider are the same as above. Application documents, including CVs, are retained for six months from the date they are received and then deleted. This period sets out the agreed retention policy. Automated mailbox deletion is not configured. Only Nigar Seyidova has direct access to the mailbox. No permanent candidate pool is planned.

9. Your rights

Subject to the statutory conditions, you have rights of access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18) and data portability (Article 20). Portability applies in particular to data you have provided that are processed by automated means on the basis of consent or a contract. To exercise your rights, contact support@nartric.com.

Under Article 7(3) GDPR, you may withdraw consent at any time with effect for the future. Withdrawal does not affect the lawfulness of processing before withdrawal.

Right to object: Where processing is based on Article 6(1)(f) GDPR, Article 21(1) entitles you to object on grounds relating to your particular situation. We will cease that processing unless we demonstrate compelling legitimate grounds overriding your interests, rights and freedoms, or the processing is necessary to establish, exercise or defend legal claims.

Under Article 77 GDPR, you may complain to a supervisory authority, particularly where you normally live or work or where an alleged infringement occurred. For our establishment in Hesse: The Hessian Commissioner for Data Protection and Freedom of Information, Postfach 3163, 65021 Wiesbaden, Germany; poststelle@datenschutz.hessen.de.

Updated: 8 October 2026 · Local test version