Skip to main content

Privacy

Privacy policy

This policy explains which data is processed when you visit mathdesigns.be, request a quote or use the project planner.

This policy describes the processing currently planned for the website. It will be reviewed before any service, tracker or new purpose is added.

Last updated
12 August 2026

1. Data controller

The data controller determines why and how the personal data described in this policy is used.

Full legal name
Mathéo Simeoni
Legal form
Natural person / sole trader
Trading name
MathDesigns
Address
Rue Noirefontaine 80, 4624 Romsée, Belgium
Enterprise / VAT number
BE1040.575.517
Phone
0483 57 66 27
Data protection officer
No data protection officer has been appointed.

2. Data processed

The data comes directly from you, except for technical data generated when connecting to the site.

  • Quote request: name, email, optional company and phone, contact preference, project type, description, optional current URL, timing, privacy and contact confirmations, and technical submission identifier.
  • Project planner: organisation and project type, problem, users, features, integrations, content and visual readiness, timing, declared nature and sensitivity of data, generated or edited brief, then the contact details supplied for submission.
  • Security and abuse prevention: network address used temporarily as a non-reversible HMAC fingerprint, submission identifier and technical information needed to process the request.
  • Infrastructure: technical connection, security and error logs that may include IP address, date and time, requested resource, response code, user agent, and network-protection or email-delivery events.

3. Purposes and legal bases

The site currently offers no newsletter, automated marketing or advertising profiling. Any new purpose must be disclosed before the relevant processing begins.

Respond to a request and prepare a quote
Steps taken at your request before entering into a contract — GDPR Article 6(1)(b).
Send and follow up the request by email
Requested pre-contract steps and, where you authorise contact in the form, consent — GDPR Article 6(1)(a) and (b).
Prevent abuse, duplicates and attacks
Legitimate interest in protecting the website and its forms — GDPR Article 6(1)(f), with a temporary HMAC fingerprint, rate limits and short retention.
Maintain infrastructure availability and security
Legitimate interest in security, error diagnosis and service availability — GDPR Article 6(1)(f).

4. Required and optional data

Fields marked as required are needed to understand and deliver the request and to respond. Without them, the form cannot be submitted. Fields explicitly marked optional may be left blank.

Do not provide passwords, API keys, business secrets, unnecessary third-party data, or sensitive data that is not essential to the initial assessment.

5. Recipients and processors

Access is limited to the people and service providers who need the data to handle the request, operate the site or keep it secure.

Authorised people at MathDesigns
Mathéo Simeoni only.
Hosting, proxy, DNS or network protection
OVHcloud (primary hosting in France), Contabo (supporting infrastructure), and Cloudflare (DNS, CDN, proxy and WAF).
Email delivery and hosting
Plus Five Five, Inc. (Resend) provides transactional delivery and processes data in the United States. Form submissions are delivered to Proton Mail, operated by Proton AG, with encrypted storage in Switzerland, Germany or Norway.

6. Retention periods

The site currently has no prospect database. Durable copies may nevertheless exist in the email services and their backups.

Abuse prevention
HMAC fingerprints: 15 minutes. Pending submission identifiers: 15 minutes. Identifiers marked as sent: 24 hours. These values are held in application-process memory.
Requests, quotes, correspondence and attachments in email
Enquiries that do not proceed are deleted no later than 12 months after the last exchange. Where a contractual relationship begins, necessary correspondence and documents are retained for the relationship and then for applicable statutory periods.
Backups and infrastructure logs
Technical logs are retained for no more than 30 days. Resend also states that production backups are retained for 30 days. Residual copies may remain in backups until their full rotation.

7. Transfers outside the European Economic Area

Data submitted through a form is processed by Plus Five Five, Inc. (Resend) in the United States for email delivery. Resend states that its Data Processing Addendum incorporates the Standard Contractual Clauses applicable to EEA-to-US transfers and that it participates in the transatlantic Data Privacy Framework. The safeguards are available in Resend’s DPA.

Cloudflare operates a global network, so requests may be processed at points of presence outside the EEA. Its Data Processing Addendum and the transfer mechanisms described there govern that processing. OVHcloud and Contabo use the European regions identified above for MathDesigns.

The form inbox is provided by Proton AG in Switzerland, which benefits from a data-protection adequacy decision. Proton Mail states that encrypted data is stored exclusively in Switzerland, Germany or Norway.

8. Your rights

Subject to the conditions in the GDPR, you may request access, correction or deletion, restriction of processing, object to certain processing and receive data you provided in a portable format where that right applies. Where processing relies on consent, you may withdraw it for the future.

Send your request to [email protected] and identify the right concerned. Mathéo Simeoni handles the request personally and forwards it to OVHcloud, Contabo, Cloudflare or Resend where necessary. Proportionate identity evidence may be requested where there is reasonable doubt. A response is provided within the GDPR period, normally one month, subject to legally permitted extensions.

You may also complain to the Belgian Data Protection Authority or to the competent supervisory authority for your residence, workplace or the place of the alleged infringement.

9. Cookies, local storage and tracking

At the technical review on 9 August 2026, the site set no cookie, used no localStorage, sessionStorage, IndexedDB or service worker, and loaded no analytics, advertising pixel, browser telemetry SDK or third-party browser script.

There is therefore currently no consent choice to store and no cookie banner. A separate cookie policy is unnecessary while this inventory remains empty. This section and the consent mechanism must be reassessed before adding analytics, third-party anti-spam, embedded video, chat, A/B testing or any other tracker.

10. Security and automated decisions

The site applies request-size and rate limits, server-side validation, duplicate protection, browser security headers and mandatory encrypted email transport. No safeguard can guarantee absolute security.

No decision producing legal or similarly significant effects is made solely by automated processing on this site.

11. Changes and official references

This policy must be updated before any material change to processing, recipients, retention, transfers or tracking technology. The date at the top identifies the applicable version.