Privacy and cookies
Privacy and cookie statement.
VlowCore respects the privacy of visitors to this website. Below you can read which personal data we process, why we do so, how long we keep it and what rights you have.
1. Who is responsible
The controller for the processing of personal data through this website is Almansio Figueiredo Soares, operating under the project name VlowCore.
VlowCore is in its concept and development phase. No legal entity has been incorporated yet. For that reason we do not state a company form, chamber of commerce number or VAT number. Once a legal entity has been incorporated, those details will be added to this statement.
No public correspondence address is available yet. You can reach us at info@vlowcore.com. If you need a postal address for a formal request, please ask us by email.
2. Which data we process
We only process data you enter yourself through the contact form, plus the technical data that arises with every website visit.
The contact form can process the following data:
- Name. Required.
- Email address. Required.
- Organisation. Optional.
- Role. Optional.
- Phone number. Optional. Processed only when you fill it in, and then included in the email we receive.
- Request type. A choice from a fixed list.
- Short context. Optional free text field.
- Selected language. A technical field that determines the language of the confirmation you see.
Filling in optional fields is voluntary. Without a name and a valid email address we may not be able to answer a request.
3. Why we use this data
- To answer your request or question.
- To contact you, by email or, if you left a number, by phone.
- To discuss a possible business collaboration.
- To take preparatory steps at your request for a possible agreement.
- To protect our communication against abuse and spam.
The processing rests on our legitimate interest in answering business enquiries and securing our website. Where the communication concerns a possible agreement, the processing may also be necessary to take preparatory steps at your request.
We do not use contact details for unsolicited marketing and we do not sell them.
4. Sending and storage of contact requests
The form is processed by our own PHP handler on our server. It sends the contents by email to info@vlowcore.com. Your email address is included as the reply address so that we can respond directly.
The website itself:
- uses no database for the contact form;
- creates no customer profile;
- does not store the form contents on the website;
- does not write names, email addresses, phone numbers or message contents to a log file.
The submitted data therefore arrives as a regular email in our mailbox and is kept there for as long as needed to handle the request and maintain the follow-up contact.
5. Technical spam protection
The website uses no reCAPTCHA, hCaptcha or Cloudflare Turnstile. To limit abuse we use:
- an invisible honeypot field;
- a timing check that treats submissions made within one and a half seconds of page load as automated;
- server-side validation of every field;
- a check on line breaks and control characters, which prevents header injection;
- a rate limit of sixty seconds per IP address.
The rate limiting processes the IP address temporarily and technically. The raw IP address is not stored. It is converted with a secret server key into a hash that cannot be read directly, and that hash serves only as a file name. The temporary file contains a timestamp only, so no name, email address, phone number, message content or readable IP address.
Expired temporary files are cleaned up when a following request comes in. That happens opportunistically and is not guaranteed to occur at a fixed moment. If the secret server key is missing on the server, the rate limiting is skipped. The honeypot, the timing check and the field validation remain fully active in that case.
The form also uses a technical timestamp to recognise automated submissions. That timestamp is not kept in a database.
6. Cookies, local storage and tracking
This website sets no cookies. No analytical, advertising, marketing, social media or tracking cookies are used either.
The website uses no localStorage and no sessionStorage.
The website does not use: Google Analytics, Google Tag Manager, Google Ads, LinkedIn Insight Tag, Meta Pixel, Microsoft Clarity, Hotjar, YouTube or Vimeo embeds, Google Maps, reCAPTCHA, hCaptcha or Cloudflare Turnstile.
Because the website uses no consent-requiring cookies or comparable technology, we show no cookie banner. If we later add analytics, marketing technology or other consent-requiring scripts, we will update this statement and, where legally required, ask for consent first.
7. Typefaces
The website uses the typefaces Space Grotesk, IBM Plex Sans and IBM Plex Mono. These typefaces are served locally from the same website. Your browser does not connect to Google Fonts or another external font service for them.
We use these typefaces to present the website consistently and in line with our visual identity.
8. Hosting and server logs
The website, the email and the domain registration run through Xel.
When someone visits the website, the web server may automatically record technical connection data, including the IP address, the date and time of the request, the browser type, the request method used, the requested part of the website and technical error messages.
This data is used for the security of the hosting environment, investigation of faults and abuse, technical error diagnosis and capacity planning. According to the publicly available privacy statement of Xel, this connection data is kept for four days.
The server logs are separate from the processing in the contact form. Our own form code writes no form contents or contact details to a server log.
Access to the hosting environment and the logs is limited to authorised people within VlowCore and to employees or system administrators of Xel who need that access for their work. Xel may engage sub-processors for its services.
9. Who we share data with
We share personal data only where necessary for the purposes described above or where we are legally obliged to do so. Data may be processed by:
- Xel as hosting, email and domain provider;
- technical service providers necessary for security, maintenance or support;
- government authorities where we are legally obliged to provide data.
With parties that process personal data on our behalf we make agreements where needed on security, confidentiality and data protection. We do not sell personal data.
10. Security
We take appropriate technical and organisational measures to protect personal data against loss, misuse and unauthorised access. These include:
- encrypted HTTPS connections;
- server-side validation of all form fields;
- protection against header injection;
- honeypot and timing checks;
- rate limiting without storing the raw IP address;
- security headers that prevent caching of the form response and protect the page against embedding by third parties;
- limited access to hosting, mailbox and server logs;
- not storing contact form data in a website database.
No digital system can guarantee absolute security. In the event of a security incident we act in line with the applicable legal obligations.
11. Retention periods
We do not keep personal data longer than necessary for the purpose for which it was collected. We apply the following principles:
- contact requests and the related correspondence are kept for a maximum of twenty-four months after the last substantive contact;
- data that becomes part of an agreement is kept for the applicable statutory and administrative retention periods;
- temporary rate-limit data exists only technically and is cleaned up on a following request;
- Xel states a retention period of four days for technical connection data;
- data is kept longer where necessary for a legal obligation, a dispute or a legal claim.
12. Your rights
To the extent the law allows, you have the right to:
- request access to your personal data;
- have incorrect data corrected;
- have data erased;
- have the processing restricted;
- object to processing based on a legitimate interest;
- receive data in a portable format;
- withdraw consent given earlier;
- lodge a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens.
You can send a request to info@vlowcore.com. We may ask for additional information where that is needed to verify your identity. We respond within one month in principle.
13. Links to other websites
This website may contain links to websites or services of other parties. VlowCore is not responsible for the privacy practices or the content of those external websites. When visiting an external website, always read the privacy statement of that party.
14. Changes
We update this statement when the website, our services or the legislation change. The most recent version is always on this page, with the date of the last change at the top.
15. Status of this statement
The technical description in this statement has been checked against the actual source code of this website, including the form markup, the PHP handler, the storage and sending behaviour, the spam protection, the security headers and the external requests the page makes.
The legal wording has not yet been reviewed by a lawyer. This statement will receive a final legal review before we mark it as definitive. If you have a question in the meantime, or you see something that is not right, let us know at info@vlowcore.com.
16. Contact
Questions about this privacy and cookie statement or about the processing of personal data can be sent to info@vlowcore.com, or asked through the contact form.