vittoria.design
Privacy Policy
How vittoria.design processes contact enquiries, technical anti-abuse data and aggregated website analytics.
Last updated: · Version 2026-10-04.2
Data controller
Vittoria Braica, an independent professional established in Spain, is responsible for the personal data processed through vittoria.design. This policy explains what data is handled, for what purposes and how you can exercise your rights.
Vittoria Braica · Spain · hello@vittoria.design
Data processed
- Contact form details: name, email address, brand or company, project type, current website, estimated budget, estimated start date and message.
- Evidence of the privacy notice accepted with the form, including its version.
- Minimum technical data needed to deliver and protect the form, such as request time, an in-memory HMAC-pseudonymised rate-limit key derived from the network address, the honeypot value and a temporary idempotency key. The raw network address is not stored in that bucket. Message bodies, names, email addresses, network addresses and their pseudonyms are not written to application logs.
- Aggregated visit and referrer information processed by Cloudflare Web Analytics when its production configuration is enabled.
Purposes
- Reply to enquiries, assess whether a project is a fit and take the pre-contractual steps you request.
- Keep the contact channel secure, prevent automated abuse and avoid duplicate deliveries.
- Send you a confirmation that the enquiry was received.
- Understand overall website usage through aggregated analytics without creating advertising profiles.
Legal basis
Enquiry data is processed to take pre-contractual steps at your request. Security and abuse-prevention measures rely on the legitimate interest in protecting this website and its communication channels.
The checkbox records your confirmation that you have read this privacy notice for the processing needed to handle the enquiry. It is not acceptance of the Legal Notice and it is not consent to marketing: the form does not subscribe you to a newsletter and no promotional mailing list is created.
Recipients and service providers
Data is shared only when needed to operate the service or comply with a legal obligation. Technical hosting is provided by infrastructure used to run this website; the provider is not named here because it has not been confirmed for publication.
- Resend provides server-side email delivery for the internal enquiry and receipt confirmation.
- Cloudflare supports website delivery, security and aggregated web analytics without tracking cookies by default.
- Cal.com is planned only as an external booking link, not as an embed in this website. If that link is enabled and you follow it, Cal.com will process the information you provide under its own privacy terms.
Retention
- Enquiries that do not become client relationships are kept for no longer than 12 months from the last meaningful contact.
- When a contractual relationship begins, relevant records are kept for the duration of that relationship and for the periods required by applicable legal, tax or professional obligations.
- The application keeps rate-limit keys in process memory for an absolute, non-renewable maximum of 30 minutes and successful idempotency outcomes for no more than 10 minutes. These temporary stores also disappear on a process restart.
- Operational records held independently by service providers follow the periods applicable to their services and legal obligations.
Your data protection rights
You may request access, rectification, erasure, restriction, portability or objection where each right applies. You may also withdraw consent where consent is the applicable basis, without affecting earlier processing.
To exercise a right, identify your request clearly. Additional information will only be requested when reasonably necessary to verify identity. You may also complain to the Spanish Data Protection Agency.
International transfers
Some service providers may process data from countries outside the European Economic Area. Where that occurs, the transfer must rely on a mechanism recognised by applicable data protection law, such as an adequacy decision or appropriate safeguards. The mechanism depends on the provider and processing location in force at the time; this policy does not claim unverified contractual guarantees.
Security
Reasonable technical and organisational measures are used to limit access, validate submissions, reduce automated abuse and keep secrets on the server. No internet service can guarantee absolute security, so sensitive information should not be sent through the contact form unless strictly necessary.
Children
This professional website and its contact form are not directed to children. If personal data from a child is submitted without appropriate authorisation, contact Vittoria so it can be reviewed and, where appropriate, deleted.
Changes to this policy
This policy may be updated when legal requirements, providers or website functionality change. The current date and version appear at the top of this page. Material changes will apply from publication.