Legal
Security
Last updated: January 2025
Security is part of how we build software for clients — and we apply the same standards to our own website. Since the only personal data this site handles comes from the contact form and the mailing list, our security posture here is deliberately simple: collect little, protect it well.
How we protect this website
Encryption in transit. All traffic to and from this website is encrypted via HTTPS/TLS, including everything you submit through the contact form.
Data minimization. We only ask for what we need to answer your inquiry. No accounts, no stored payment data, no unnecessary fields.
Access control. Inquiry and mailing-list data is accessible only to the small number of people who need it to respond to you, protected by strong authentication.
Reputable infrastructure. The site and mailing list run on established providers with their own strong security practices, preferring EU-based data processing.
Updates and monitoring. We keep the website's software components up to date and review access logs for anything unusual.
Incident response
If a security incident ever affects personal data from this website, we will investigate promptly, notify affected individuals and the supervisory authority where required by Art. 33/34 GDPR, and be straightforward about what happened and what we're doing about it.
Reporting a vulnerability
If you believe you've found a security issue on this website, we'd genuinely like to hear about it. Please contact us with the details and:
give us reasonable time to investigate and fix the issue before disclosing it publicly,
avoid accessing or modifying data that isn't yours,
don't run automated scans that could degrade the site for others.
We'll respond as quickly as we can and credit good-faith reports if you'd like.