Privacy Policy
How we collect, use, and protect your information
Last updated: 2026-05-13
Data controller
The controller of personal data processed via this website is:
Bravko LLC
9 Samuel Adams Rd, Gillette, WY 82718, USA
Privacy contact: info@bravko.com
Data Protection Officer: We are not required to designate a DPO under GDPR Art. 37. Privacy contact: info@bravko.com.
EU representative (GDPR Art. 27): Not yet appointed. Enquiries that would go to an EU representative can be sent to info@bravko.com.
What we collect, why, and the lawful basis
| Activity | Data | Lawful basis (GDPR Art. 6) | Retention |
|---|---|---|---|
| Contact-form submissions | Name, email, company, service interest, message | Performance of pre-contractual measures (Art. 6(1)(b)) | 24 months from last interaction |
| Discovery-call bookings (Cal.com) | Name, email, time-zone, calendar invite | Performance of pre-contractual measures (Art. 6(1)(b)) | 24 months from last interaction |
| Newsletter (Loops) | Email, optional first name, locale preference | Consent (Art. 6(1)(a)) — double opt-in | Until you unsubscribe |
| Resource downloads | Email (when required), first name (optional), resource ID | Consent (Art. 6(1)(a)) | 24 months |
| Analytics | Aggregate page views, country, browser — no IP, no cookies | Legitimate interest (Art. 6(1)(f)) — Cloudflare Web Analytics is cookieless | 90 days (Cloudflare default) |
| Bot protection | IP, user-agent (transient) | Legitimate interest (Art. 6(1)(f)) — abuse prevention | Logged ≤ 30 days |
| Rate-limit counters (Cloudflare KV) | Hashed IP + action key | Legitimate interest (Art. 6(1)(f)) | 1 hour TTL |
| Error tracking (Sentry) | Stack frames, request URL, browser version — form field values, emails, phones, cookies, auth headers stripped at the SDK level | Legitimate interest (Art. 6(1)(f)) — debugging and security | 90 days |
Recipients (sub-processors)
We share data with the following processors, each under a Data Processing Agreement (DPA) and the Standard Contractual Clauses (SCCs) where applicable. The same list is maintained verbatim in docs/integrations.md in our repository.
- Cloudflare, Inc. (USA / EU edge) — hosting, CDN, cookieless analytics, KV, R2, D1, Workers, Turnstile, Access. DPA · Privacy.
- Resend Inc. (USA) — transactional email delivery for contact, download, and admin sign-in flows. DPA · Privacy.
- Loops, Inc. (USA) — newsletter list and campaign delivery (with double opt-in). DPA · Privacy.
- Cal.com, Inc. (USA / self-hosted EU) — discovery-call booking embed. DPA · Privacy.
- Functional Software, Inc. d/b/a Sentry (USA) — error tracking and performance monitoring. Personal-data minimisation is enforced at the SDK level: form field values, IPs, cookies, and authentication headers are stripped before events are sent. DPA · Privacy.
- GitHub, Inc. (Microsoft, USA) — source repository and content backend; commit messages identify the human editor for audit purposes. DPA · Privacy.
International transfers
Where we transfer personal data outside the EEA (primarily to the United States), we rely on:
- The EU–U.S. Data Privacy Framework where the recipient is certified, or
- Standard Contractual Clauses (Module 2 — controller to processor) plus supplementary measures (encryption in transit and at rest, minimisation, short retention).
Your rights
You have the right to:
- Access the personal data we hold about you (Art. 15)
- Rectify inaccurate data (Art. 16)
- Erase ("right to be forgotten" — Art. 17)
- Restrict processing (Art. 18)
- Portability — receive your data in a machine-readable format (Art. 20)
- Object to processing based on legitimate interest (Art. 21)
- Withdraw consent at any time, without affecting prior lawful processing (Art. 7(3))
- Lodge a complaint with your supervisory authority — for EEA visitors, this is your local data-protection regulator
To exercise any of these, email info@bravko.com. We respond within 30 days.
Cookies and storage
See our Cookie policy for the explicit list of cookies and first-party storage.
Children
This site is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
California (CCPA / CPRA)
If you are a California resident: we do not sell personal information; we do not share personal information for cross-context behavioural advertising. You have the right to know, delete, correct, and opt out under the CCPA / CPRA. Email info@bravko.com with "California request" in the subject.
Security
Data is encrypted in transit (TLS 1.3) and at rest. Production traffic is served from Cloudflare's network with HTTP-strict-transport-security and a strict content-security-policy. Access to systems is via least-privilege accounts with hardware-key MFA.
Changes to this policy
Material changes are announced on the home page for 14 days and dated above. Non-material changes (typos, clarifications) are made silently.