Privacy Policy
Last updated: 3 Sept 2026
This Privacy Policy explains how seosath (“we”, “us”, “our”) collects, uses and protects personal data when you visit seosath.com or interact with us through this website.
1. Controller
The data controller within the meaning of the General Data Protection Regulation (GDPR) for personal data processed via this website is:
Patrick Sosath
c/o seosath LLC
30 N Gould St Ste N
Sheridan, WY 82801, USA
Email: info@seosath.com
1.1 Note on geographical data processing
Although the controller maintains a US business address (Wyoming, USA), all hosting and storage of personal data takes place exclusively on servers in the European Union. Access to those systems by the controller may also take place from a third country (United Arab Emirates); appropriate technical and organisational safeguards such as encrypted connections and access controls are applied.
As an exception, request data (including IP addresses) is processed by Cloudflare, Inc. (USA) as part of our CDN and WAF infrastructure. This constitutes a transfer to a third country; it is covered by Cloudflare’s Data Processing Addendum (DPA) and Standard Contractual Clauses. See Section 4 for details.
EU representative (Art. 27 GDPR):
Marco Berndt, Bahnhofstraße 20, 91560 Heilsbronn, Germany, designated as the point of contact for supervisory authorities and data subjects within the EU.
2. What data we collect
We process personal data only where necessary, lawful and proportionate to the purpose. The categories below cover the main cases.
2.1 Contact form and enquiries
- Name, email, optional company name
- Project budget and interest selection
- Message content you provide
- Time of submission, IP address (for spam protection and rate limiting), user-agent string
- After a successful submission, a minimal application-level log entry is written server-side: timestamp, email address and selected service interest. This log is stored in a server-side directory not accessible via the web and is used solely for submission auditing and spam detection.
2.2 Server logs
Our hosting provider records standard web-server logs including IP address, request time, requested URL, response status, referrer and user-agent. These logs are used to operate, secure and troubleshoot the site.
2.3 Cookies and audience measurement
This website sets no cookies of its own and uses no analytics tool and no marketing technology. There is no audience measurement and no cross-site tracking. Because no consent-requiring services are loaded, there is no cookie banner either. See our Cookie Policy for details.
2.4 Fonts
All fonts are served locally from our own server. No connection is made to Google Fonts or any other font CDN.
2.5 WhatsApp contact
The website carries a link to WhatsApp (wa.me). It is a plain link: as long as you do not click it, no data is transmitted to WhatsApp. If you click it, you leave our website and the terms and privacy policy of WhatsApp Ireland Ltd. respectively Meta apply. The content of the conversation is then known to us as the recipient and is handled like an email enquiry.
3. Purposes and legal bases (GDPR)
- Responding to enquiries: Art. 6(1)(b) GDPR (pre-contractual measures) and (f) (legitimate interest in business communication).
- Operating and securing the site: Art. 6(1)(f) (legitimate interest).
- Spam protection for the contact form: Art. 6(1)(f) (legitimate interest in preventing automated submissions).
- Compliance with legal obligations: Art. 6(1)(c) where applicable.
4. Recipients and processors
Personal data may be processed by carefully selected service providers acting on our behalf, including:
- Hosting: Hostinger International Ltd. (servers in the EU/EEA).
- Email delivery: Hostinger SMTP (transactional email for the contact form).
- CDN, WAF and DDoS protection: Cloudflare, Inc. (USA), acts as a reverse proxy for all page requests. This means request data (including IP addresses) passes through Cloudflare’s global edge network. Cloudflare provides a Data Processing Addendum (DPA) with Standard Contractual Clauses; further information is available at cloudflare.com/trust-hub. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in website security and performance).
- Spam protection (contact form): Cloudflare Turnstile, an invisible CAPTCHA that verifies form submissions without setting tracking cookies or collecting personal data beyond a temporary challenge token. Turnstile is not loaded when the page opens; it loads the first time you click into a field of the contact form. Visitors who do not use the form never connect to Turnstile. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in preventing spam and abuse). Cloudflare’s DPA applies as above.
Where transfers outside the EEA take place (in particular via Cloudflare’s global network), we rely on Standard Contractual Clauses or equivalent safeguards as provided in the respective processor’s DPA.
5. Retention
- Enquiry data: retained as long as needed to respond and continue the business relationship; deleted or anonymised when no longer needed and after applicable retention periods expire.
- Server logs: typically 14 to 30 days.
- Contact form application log (timestamp, email, interest): maximum 30 days, then deleted.
6. Your rights
You have the right to access, rectify, erase, restrict or object to the processing of your personal data, and the right to data portability. Where processing is based on consent, you have the right to withdraw it at any time. To exercise any of these rights, write to info@seosath.com.
You also have the right to lodge a complaint with a data protection supervisory authority.
7. Security
The site uses HTTPS, hardened HTTP security headers and a strict Content-Security-Policy. Form submissions are validated server-side and rate-limited. Despite these measures, no internet transmission can be guaranteed 100% secure.
8. Children
This site is intended for business audiences and is not directed at children under 16. We do not knowingly collect personal data from children.
9. Changes to this policy
We may update this Privacy Policy to reflect changes in our processing or in applicable law. The date at the top of the page reflects the most recent revision.
10. Contact
For any privacy-related questions: info@seosath.com.