MINIMUM PUBLIC-SITE DATA
Privacy boundary.
Effective July 21, 2026. This notice governs the public website and access-verification service. Separate customer projects require written data-handling and commercial terms.
1. What this site does not collect
The public site does not request or accept source code, confidential client files, passwords, recovery phrases, biometrics, payment-card numbers, medical data, regulated data, or proprietary workload inputs. Do not send those materials through this site or ordinary email.
2. Access and proposal-request records
When you request a code, the service processes your normalized email address, verification state, accepted terms version, acknowledged privacy version, optional marketing choice, selected service category, and timestamps. The verified proposal form uses that verified email as its only contact method and also processes the business context you provide, such as name, organization, role, optional website, requested service, decision, current state, desired outcome, success criteria, timing, procurement stage, expected data classification, named compliance requirements, and constraints.
Pending codes expire after ten minutes. Codes are stored only as keyed verification values and are subject to attempt and resend limits. Verified emails and proposal details are encrypted at rest; keyed values support lookup and abuse controls.
3. Sessions and security
Successful verification creates a random, short-lived session. The browser receives an HttpOnly, SameSite cookie; the service stores only a keyed token hash. Infrastructure providers necessarily process ordinary request metadata such as IP address, timing, browser headers, and security events.
4. Purposes
- verify access and resist automated abuse;
- record acceptance of the Terms and Conditions;
- respond to requested service communications;
- send marketing only when the separate optional box is selected;
- protect, diagnose, and operate the service.
5. Service providers
The current public service uses Cloudflare for DNS, hosting, edge security, serverless request processing, human-verification support, and the access database. Resend delivers verification, proposal-confirmation, and internal intake-notification email.
Each provider processes limited data for its assigned function under its own terms. Verahelm does not collect payment-card details through the public Site.
6. Retention
Pending access records expire automatically. Active public sessions expire after 24 hours. Verified email, consent, and proposal-request records are retained only while needed for access, requested follow-up, security, legal obligations, or a documented business purpose. Paid-engagement retention, return, and deletion obligations are established in the applicable written agreement.
7. Marketing choice
Marketing is optional and is not required for access. Transactional access or security messages are separate. Every production marketing message must provide a working unsubscribe mechanism.
8. Deletion and questions
Verified users may select DELETE ACCESS to request deletion of the public access, consent, proposal-request, and current-session records held by this service, subject to records retained for security, legal, or contractual obligations. For privacy questions or a manual request, contact [email protected]. Identity verification may be required before acting on a request.
9. Security and limitations
Verahelm uses data minimization, encryption, hashed lookup values, bounded request bodies, access controls, and short-lived sessions. These measures reduce risk but cannot make any internet service absolutely secure. Additional security, incident, and notification duties for paid work are stated in the applicable written agreement.