Skip to content

GDPR and data protection

Data responsibilities and rights for NaviVision activities.

Updated

Controller and processor roles

A controller determines the purposes and means of personal-data processing; a processor acts on its behalf. Website inquiry handling and customer-controlled product records are different activities. The applicable arrangement must identify the controller, processing instructions, categories and lawful basis. This overview is not an executable DPA or a declaration of GDPR compliance.

Information and purposes

The contact form collects your name, email, organization, topic and message. Cloudflare Pages delivers this public site. Its contact Function validates Turnstile and stores inquiries in Cloudflare D1, including IP address, country, user agent, origin and referrer for inquiry handling and abuse prevention. Theme preferences are stored in this browser; language is represented by the page URL. This informational site links to independent portfolio sites. Recruiting records, customer software environments, leases, investment documents and other engagements have a separate purpose and agreement.

Individual rights

Where the GDPR applies, individuals may have rights of access, correction, erasure, restriction, objection, portability and withdrawal of consent, subject to conditions and exceptions. They may complain to the relevant supervisory authority. Contact [email protected] with enough context to locate your inquiry or record. You may request access, correction, deletion or communications changes. We may ask for reasonable identity or authority evidence before disclosing or changing personal or organization information. Do not send passwords, access tokens or government identity documents in the initial request. A request review identifies the records, checks any retention requirements and the responsible customer, and determines eligible deletion and any information that must remain. Ask for an explanation of required retention. Customer-controlled records should be directed to the organization that determines their use; we can help route the request.

Processing terms and suppliers

Customer processing terms should establish documented instructions, confidentiality and authorized access, security measures, supplier authorization, assistance with rights and incidents, and return or deletion at the end of service. Confirm those obligations and supplier coverage in the actual signed agreement; this public overview does not execute one.

Hosting and transfers

Cloudflare delivers the public website through a distributed network. This does not establish a single storage or processing country. Customer-product hosting regions, backups, supplier support access and international transfers must be confirmed for the specific engagement. No customer-region AWS commitment is made by this website. Where transfer safeguards such as a provider DPA or standard contractual clauses are relevant, the parties must verify the applicable executed terms and supplier coverage; this page is not that agreement.

Retention and minimization

Identify the information needed for the specific purpose, authorized recipients and retention requirements. The public contact form has defined fields and validation. Organizational retention procedures, product deletion controls and commitments must be verified for the engagement; no unsupported organization-wide guarantee is made here.

Contact: [email protected]

Back to Legal