This Privacy Policy explains how seosath (“we”, “us”, “our”) collects, uses and protects personal data when you visit seosath.com or interact with us through this website.

1. Controller

The data controller within the meaning of the General Data Protection Regulation (GDPR) for personal data processed via this website is:

Patrick Sosath
c/o seosath LLC
30 N Gould St Ste N
Sheridan, WY 82801, USA
Email:

1.1 Note on geographical data processing

Although the controller maintains a US business address (Wyoming, USA), all hosting and storage of personal data takes place exclusively on servers in the European Union. Access to those systems by the controller may also take place from a third country (United Arab Emirates); appropriate technical and organisational safeguards such as encrypted connections and access controls are applied.

As an exception, request data (including IP addresses) is processed by Cloudflare, Inc. (USA) as part of our CDN and WAF infrastructure. This constitutes a transfer to a third country; it is covered by Cloudflare’s Data Processing Addendum (DPA) and Standard Contractual Clauses. See Section 4 for details.

EU representative (Art. 27 GDPR):
Marco Berndt, Bahnhofstraße 20, 91560 Heilsbronn, Germany, designated as the point of contact for supervisory authorities and data subjects within the EU.

2. What data we collect

We process personal data only where necessary, lawful and proportionate to the purpose. The categories below cover the main cases.

2.1 Contact form & enquiries

  • Name, email, optional company name
  • Project budget & interest selection
  • Message content you provide
  • Time of submission, IP address (for spam protection & rate limiting), user-agent string
  • After a successful submission, a minimal application-level log entry is written server-side: timestamp, email address and selected service interest. This log is stored in a server-side directory not accessible via the web and is used solely for submission auditing and spam detection.

2.2 Server logs

Our hosting provider records standard web-server logs including IP address, request time, requested URL, response status, referrer and user-agent. These logs are used to operate, secure and troubleshoot the site.

2.3 Cookies & analytics

We use a small number of essential cookies to operate the site (e.g. to remember your cookie consent choice). Optional analytics cookies are loaded only after you give consent. See our Cookie Policy for details.

3. Purposes & legal bases (GDPR)

  • Responding to enquiries - Art. 6(1)(b) GDPR (pre-contractual measures) and (f) (legitimate interest in business communication).
  • Operating & securing the site - Art. 6(1)(f) (legitimate interest).
  • Analytics - Art. 6(1)(a) (consent), withdrawable any time via Cookie Settings.
  • Compliance with legal obligations - Art. 6(1)(c) where applicable.

4. Recipients & processors

Personal data may be processed by carefully selected service providers acting on our behalf, including:

  • Hosting: Hostinger International Ltd. (servers in the EU/EEA).
  • Email delivery: Hostinger SMTP (transactional email for the contact form).
  • CDN, WAF & DDoS protection: Cloudflare, Inc. (USA) - acts as a reverse proxy for all page requests. This means request data (including IP addresses) passes through Cloudflare’s global edge network. Cloudflare provides a Data Processing Addendum (DPA) with Standard Contractual Clauses; further information is available at cloudflare.com/trust-hub. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in website security and performance).
  • Spam protection (contact form): Cloudflare Turnstile - an invisible CAPTCHA that verifies form submissions without setting tracking cookies or collecting personal data beyond a temporary challenge token. Cloudflare’s DPA applies as above.
  • Email address obfuscation: Cloudflare Email Obfuscation - email addresses shown on this site are encoded server-side and decoded locally in your browser by a small JavaScript snippet (email-decode.min.js). No data is sent to Cloudflare or any third party during this process.
  • Analytics (only with consent): Google Ireland Ltd. - Google Analytics 4 with IP anonymisation.

Where transfers outside the EEA take place (in particular via Cloudflare’s global network), we rely on Standard Contractual Clauses or equivalent safeguards as provided in the respective processor’s DPA.

5. Retention

  • Enquiry data: retained as long as needed to respond and continue the business relationship; deleted or anonymised when no longer needed and after applicable retention periods expire.
  • Server logs: typically 14–30 days.
  • Contact form application log (timestamp, email, interest): maximum 30 days, then deleted.
  • Consent records: stored client-side in your browser’s local storage.

6. Your rights

You have the right to access, rectify, erase, restrict or object to the processing of your personal data, and the right to data portability. Where processing is based on consent, you have the right to withdraw it at any time. To exercise any of these rights, write to .

You also have the right to lodge a complaint with a data protection supervisory authority.

7. Security

The site uses HTTPS, hardened HTTP security headers and a strict Content-Security-Policy. Form submissions are validated server-side and rate-limited. Despite these measures, no internet transmission can be guaranteed 100% secure.

8. Children

This site is intended for business audiences and is not directed at children under 16. We do not knowingly collect personal data from children.

9. Changes to this policy

We may update this Privacy Policy to reflect changes in our processing or in applicable law. The “last updated” date at the top of the page reflects the most recent revision.

10. Contact

For any privacy-related questions: .