Skip to content
FAURITOR

Privacy

Data handled for one clear purpose

This implementation baseline covers https://fauritor.com: an informational company website with a project-intake form. It does not describe a future SaaS product or customer workspace.

Implementation baseline · review required before publication

1. What this notice covers

The current repository contains a marketing/company website and a project-intake form. There is no user registration, customer dashboard, billing, checkout, file upload or live product workspace in the current route tree.

The exact legal entity that controls this processing is not verified in the repository. The owner must confirm the controller identity and final notice details before treating this page as final legal information.

2. Information the form can receive

The form asks for the minimum fields currently needed to understand and respond to an inquiry:

  • name and company or organisation
  • email address
  • project description
  • budget range and timeline
  • optional product interest
  • technical intake metadata used for abuse prevention, including a one-way IP hash, user-agent string and timestamps

Please do not submit special-category data, credentials, secrets, customer records or other information that is not needed for an initial project conversation.

3. Purpose and use

The implementation uses inquiry information to review a project request, respond to the sender, prevent abusive submissions, maintain the intake service and keep a basic record of the request. It is not a newsletter signup and the current form does not request marketing consent.

The final lawful basis, controller/processor allocation and any secondary business record purpose require owner and lawyer confirmation. No unsupported legal conclusion is made by this baseline.

4. Storage and access

When the configured backend is deployed, the form is designed to send data to the `contactSubmit` Cloud Function, which validates the request and stores an application record in Cloud Firestore. Direct browser reads and writes are denied by the checked-in Firestore rules.

Optional email notification is supported through a configured mail provider. It is disabled by default in the repository configuration. The application logs are designed to omit form fields, but production logging and provider settings still require verification.

5. Providers and transfers

Firebase/Google Cloud, a mail provider and Google Analytics are conditional on production configuration. The technology and subprocessor registers record code-supported providers separately from providers confirmed as active. Their legal entities, regions, DPAs, subprocessors, transfer safeguards and retention must be confirmed before this notice is treated as final.

6. Optional analytics

The checked-in example leaves the GA4 measurement ID empty. If optional analytics is enabled, this implementation is designed to load it only after an affirmative analytics choice. The event layer excludes names, email addresses, company names, messages and other free-text form content; the final provider notice must still be reviewed before analytics is enabled.

7. Retention

Contact form submissions and the directly related operational records — the duplicate-protection idempotency keys and the rate-limit counters, which store only hashed IP addresses — are retained for a maximum of 365 days, the retention period approved by the owner on 24 September 2026. A daily scheduled deletion job automatically removes these records once they are older than that period; records without a usable timestamp are never selected for deletion by the job.

You may request deletion at any time before the period ends, through the privacy request route in section 8. Application logs and transactional email are held by their respective providers and are not covered by this automatic deletion job; their retention remains subject to provider configuration and review.

8. Privacy requests and rights

To ask about access, correction, deletion, restriction, objection or another data question, use the dedicated privacy request route or email privacy@fauritor.com. A request may require proportionate identity verification. The final procedure, response timing and supervisory-authority wording require lawyer review.

9. Changes

This page must be updated when the website, form, providers, analytics, email flow or business scope changes. The legal change log in the repository is internal and is not a substitute for publishing an approved version.