Privacy

Privacy notice for website enquiries.

This package is designed to collect only the contact and technical context needed to respond to an enquiry. Review and adapt this notice to your final production processes and legal requirements before launch.

Quick answer

Lead forms store the information you submit so the operator can respond. Do not submit authentication secrets, private keys, card data or sensitive personal information that is not necessary for the request.

Data handling

What the website package does by default

The contact forms collect name, email, optional company and phone details, the selected service and the technical message you write. The server also records basic request metadata such as time, IP address and user agent for operational and abuse-control purposes.

Submitted leads are written to a server-side CSV file under the storage directory. That directory is denied from direct web access by the included Apache configuration. Optional PHP mail notification can be enabled in config.php.

Before production launch, set your real retention period, legal basis, processor list, cookie/analytics policy and data-subject contact workflow. This starter notice is technical content, not jurisdiction-specific legal advice.

Minimise sensitive data

Do not request or accept passwords, SSH private keys, recovery codes or payment-card data through general enquiry forms. Use a dedicated secure channel if support work later requires privileged access.