MINIMUM PUBLIC-SITE DATA
Privacy boundary.
Effective July 21, 2026. This notice governs the public website and access-verification service. Separate customer projects require written data-handling and commercial terms.
1. What this site does not collect
The public site does not request or accept source code, confidential client files, passwords, recovery phrases, biometrics, payment-card numbers, medical data, regulated data, or proprietary workload inputs. Do not send those materials through this site or ordinary email.
2. Access and proposal-request records
When you request a code, the service processes your normalized email address, verification state, accepted terms version, acknowledged privacy version, optional marketing choice, selected service category, and timestamps. The verified proposal form uses that verified email as its only contact method and also processes the business context you provide, such as name, organization, role, optional website, requested service, decision, current state, desired outcome, success criteria, timing, procurement stage, expected data classification, named compliance requirements, and constraints.
Pending codes expire after ten minutes. Codes are stored only as keyed verification values and are subject to attempt and resend limits. Verified emails and proposal details are encrypted at rest; keyed values support lookup and abuse controls.
3. Sessions and security
Successful verification creates a random, short-lived session. The browser receives an HttpOnly, SameSite cookie; the service stores only a keyed token hash. Infrastructure providers necessarily process ordinary request metadata such as IP address, timing, browser headers, and security events.
4. Purposes
- verify access and resist automated abuse;
- record acceptance of the Terms and Conditions;
- respond to requested service communications;
- send marketing only when the separate optional box is selected;
- protect, diagnose, and operate the service.
5. Service providers and storage boundary
The current public service uses approved Verahelm accounts at Cloudflare for DNS, hosting, edge security, serverless request processing, human-verification support, and the access database. Resend delivers verification, proposal-confirmation, and internal intake-notification email. Provider infrastructure may process limited request or delivery data in locations those providers operate, subject to their terms and applicable law. Geographic access controls do not constitute a data-residency guarantee.
Public-intake records are not placed in arbitrary personal drives, advertising networks, or unapproved analytics tools. Verahelm does not sell public-intake data, disclose it for cross-context behavioral advertising, or collect payment-card details through the public Site.
6. Retention
The public service applies the following default active-system schedule: pending codes become ineligible after ten minutes; sessions after 24 hours; expired rate-limit records during maintenance; keyed security events after seven days; verified access records with no marketing choice and no proposal request after 30 days; and unconverted proposal-request records after 180 days. Pseudonymous consent evidence may be retained for up to three years. An opted-in marketing address is retained until consent is withdrawn, access is deleted, or the purpose ends.
Expired records are removed during recurring maintenance. Provider backups may age out on the provider's separate backup cycle. A record may be retained longer when reasonably necessary for a legal hold, dispute, fraud or security investigation, or legal obligation. If a proposal becomes a signed engagement, the required record is moved into the engagement's approved system and governed by the applicable written agreement rather than the public-intake schedule.
7. Marketing choice
Marketing is optional and is not required for access. Transactional access or security messages are separate. Marketing may be sent only to an address with a recorded affirmative choice. Every production marketing message must identify Verahelm, provide a working unsubscribe mechanism, and honor withdrawal as required by applicable law.
8. Deletion and questions
Verified users may select DELETE ACCESS to request deletion of the public access, consent, proposal-request, and current-session records held by this service, subject to records retained for security, legal, or contractual obligations. For privacy questions or a manual request, contact [email protected]. Identity verification may be required before acting on a request.
9. Security and limitations
Verahelm uses data minimization, encryption, hashed lookup values, bounded request bodies, access controls, and short-lived sessions. These measures reduce risk but cannot make any internet service absolutely secure. Additional security, incident, and notification duties for paid work are stated in the applicable written agreement.