1. Controller and contact
The controller responsible for the processing described here is Primanza LLC, 30 N Gould St Ste N, Sheridan, Wyoming 82801, United States — filing number 2026-002018263, State of Wyoming, United States of America.
For any question about this policy, or to exercise any right described in it, write to legal@primanza.com. That address reaches the company directly. The company has not appointed a statutory Data Protection Officer, because none of the conditions in Article 37 of the GDPR that would require one applies to it: it carries out no large-scale systematic monitoring and processes no special-category data at scale.
2. Scope of this policy
This policy covers the corporate website at primanza.com — including the message form on its contact page — and the correspondence you send to the company's published mailboxes. It does not cover the Primanza products.
Every Primanza product is an independent application on its own subdomain of primanza.com, with its own deployment, its own database, its own accounts and its own privacy policy published inside it. If you have an account with a Primanza product, that product's policy — not this one — governs your data. A shared parent domain is an addressing arrangement, not a shared system: this corporate site is not connected to any product's database or account system, and holds no product data.
3. Our position, stated plainly
primanza.com is an informational corporate website. It has no user accounts, no sign-up, no login, no dashboard, no shopping cart, no payment processing and no customer database. It sets no cookies, embeds no third-party advertising, and runs no analytics, tracking pixels, session recording, fingerprinting or profiling of any kind.
There is one place where you can deliberately give us personal data: the message form on the contact page, where that form is offered. It is an alternative way of writing to the same mailboxes, not a registration — it creates no account and stores nothing about you on this site. Section 4 describes exactly what it collects and what happens to it.
The consequence is that, unless you write to us — by email or through that form — we almost certainly hold nothing about you beyond transient server logs. The rest of this policy describes the narrow exceptions honestly rather than claiming an absolute that would be untrue.
4. Personal data we process
We process four categories of personal data, and no others:
- Server log data. Like every web server, our hosting infrastructure records requests: your IP address, the page or file requested, the date and time, the HTTP status, the referring page where the browser sends one, and your browser's user-agent string. These logs are generated automatically by the infrastructure and are not linked to any identity, profile or account, because none exists.
- Correspondence. If you write to one of our mailboxes, we receive your email address, whatever you put in your message, any attachments you send, and the metadata your mail provider attaches. This includes anything you volunteer — your name, your employer, a phone number — which is entirely your choice to send.
- Contact form submissions. Where the message form on the contact page is offered, it collects exactly four things, all of them typed by you: your name, an email address we can reply to, the subject you select from the fixed list, and your message. There are no hidden fields that collect anything about you, no attachments, and no optional extras. The server adds the time it received the message and nothing else.
- Security telemetry. Our infrastructure providers apply automated protections at the network edge — rate limiting and filtering of abusive or malicious traffic — which process request metadata, including IP addresses, for that purpose. The contact form additionally applies its own anti-abuse checks, described below.
Two details about the contact form are worth stating precisely, because a policy that says 'we take security measures' and stops is hiding the part you would want to know. First, to stop one source flooding the form, the server derives a short one-way hash from the network address the request arrives with, salted with a value generated fresh each time the server starts. That hash is held in memory only for the length of the rate-limiting window, is never written to a log, a database or a file, cannot be reversed to an address, and does not survive a restart. Second, the form carries a field hidden from human visitors and measures how long the page was open before submission; both are checks on automated submissions, and neither records anything about you.
When you submit the form, its four fields and the receipt time are transmitted to the Primanza mailbox for the subject you chose, through the delivery provider described in section 7. Nothing is written to this website: it has no database to write to. From that point the message is correspondence and is treated as correspondence.
We do not process special categories of personal data (Article 9 GDPR), we do not process criminal-offence data, and we do not knowingly process the data of children. We do not buy personal data, and we do not obtain it from data brokers or enrichment services.
5. Purposes and legal bases
Under Article 6(1) of the GDPR and its UK equivalent, each processing operation has one lawful basis:
- Delivering this website — server logs, for the technical purpose of responding to your request. Legal basis: our legitimate interests (Article 6(1)(f)) in operating the site you asked to see. There is no less intrusive way to serve a web page than to receive the request for it.
- Securing this website — logs and security telemetry, to detect, investigate and stop attacks, abuse and outages. Legal basis: our legitimate interests (Article 6(1)(f)) in keeping the service available and intact. Recital 49 of the GDPR recognises network and information security as a legitimate interest.
- Answering you — correspondence and contact form submissions, to read your message, respond to it, and keep a record of the exchange. Legal basis: our legitimate interests (Article 6(1)(f)) in conducting correspondence a person has initiated with us, or, where your message concerns a contract or a step before entering one, Article 6(1)(b). Nothing on the form is collected for any purpose beyond answering you: we do not add you to a mailing list, and there is none to add you to.
- Keeping the form usable — the anti-abuse checks in section 4, to stop automated and volumetric submissions making the channel unusable for people with something to say. Legal basis: our legitimate interests (Article 6(1)(f)). The measure is designed to hold as little as possible for as short a time as possible, which is why the rate-limiting key is a salted hash held in memory rather than an address in a log.
- Meeting legal obligations — retaining or disclosing data where the law requires it, including responding to lawful demands from authorities. Legal basis: legal obligation (Article 6(1)(c)).
- Establishing or defending legal claims — retaining relevant records where a dispute exists or is reasonably foreseeable. Legal basis: our legitimate interests (Article 6(1)(f)).
Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms and concluded they do not override them, principally because the data is minimal, is not used to build any profile of you, and is not shared for anyone else's purposes. You may object to that processing at any time — see section 11 — and you may ask us for our assessment.
We do not rely on consent for anything on this site, because nothing on this site requires it. This is why you are not shown a cookie banner: there is nothing to consent to.
6. Cookies and tracking
This website sets no cookies and uses no local storage, session storage, web beacons, pixels, device fingerprinting or similar tracking technologies. No third party places any such technology through this site.
Because no non-essential technology is stored on or read from your device, the consent requirement in Article 5(3) of the ePrivacy Directive and its national implementations is not engaged. The Cookie Policy explains this in full, including what would change if it ever stopped being true.
7. Recipients and processors
We do not sell personal data. We do not share it for cross-context behavioural advertising. We do not disclose it to advertisers, brokers or analytics companies, because we engage none.
The limited data described above is accessible to these categories of recipient, each bound by a data processing agreement and acting only on our instructions:
- Our hosting and content-delivery provider, which serves this site and generates the server logs.
- Our email provider, which transmits and stores our correspondence.
- Our message delivery provider, which carries a contact form submission from this site to the Primanza mailbox for its subject. It is a transport step, not a storage service: it is not permitted to use a message for its own purposes.
- Our domain and DNS provider.
- Professional advisers — lawyers, accountants — where a matter genuinely requires it, under a duty of confidentiality.
- Public authorities and courts, where a valid legal demand compels disclosure.
We publish categories rather than names because our infrastructure providers may change, and a named list would go stale and become a false statement. The current identity of any provider is not a secret: ask legal@primanza.com and you will be told. Where a legal demand for data is made and we are permitted to tell you, we will.
8. International data transfers
Primanza is established in the United States, and this website is operated from there. If you are in the European Economic Area, the United Kingdom or Switzerland, that fact has a specific and often misstated consequence, so we state it precisely.
When you choose to visit this site or send us an email, you are disclosing data directly to a controller outside your jurisdiction on your own initiative. Under the European Data Protection Board's Guidelines 05/2021, that direct disclosure is not a 'transfer' within the meaning of Chapter V of the GDPR, and no transfer tool is required for it. It does not follow that your rights disappear: the rest of this policy, and the rights in section 11, are honoured regardless.
Where our processors move data across borders on our behalf, those transfers are covered by the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where the UK GDPR applies, and by any adequacy decision that applies to the provider.
You should know, because it is true of any US company, that United States law gives public authorities powers of access that have no exact equivalent in EU law, and that the United States has not been found adequate for all purposes. Our mitigation is structural rather than contractual: this site holds almost nothing that could be demanded of it.
9. Retention
We keep personal data only as long as the purpose that justified collecting it survives.
- Server logs and security telemetry: retained for a short operational period — not more than 90 days — then deleted or aggregated beyond identification, unless a specific log is needed for an ongoing security investigation, in which case it is kept until that investigation closes.
- Correspondence, including messages sent through the contact form: kept for as long as needed to handle the matter and to maintain a record of it, and reviewed periodically. Correspondence with no continuing relevance is deleted.
- The contact form's rate-limiting key: held in memory for the length of the rate-limiting window, and discarded when the window closes or the server restarts, whichever comes first. It is never written to durable storage, so there is nothing to delete later.
- Anything under legal hold: kept until the obligation or the claim ends, then deleted.
10. Security
The corporate site is served over HTTPS with HTTP Strict Transport Security, a restrictive Content Security Policy and standard hardening headers. It runs as a statically rendered site with no database and no authenticated surface, which removes whole classes of risk rather than defending against them.
Access to correspondence is limited to the people who need it and protected by multi-factor authentication. Products are isolated from this site and from each other, a design intended to contain an incident to the product it affects rather than let it propagate. Our security posture and our responsible disclosure commitments are set out in full on the Security page.
No system is perfectly secure, and we will not pretend otherwise. Where a breach of personal data occurs and is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours where Article 33 requires it, and notify you directly where Article 34 or applicable state law requires it.
11. Your rights
If the GDPR or UK GDPR applies to you, you have the following rights over personal data we hold about you:
- Access (Article 15) — to be told whether we process your data and, if so, to receive a copy of it and the information in this policy.
- Rectification (Article 16) — to have inaccurate data corrected and incomplete data completed.
- Erasure (Article 17) — to have your data deleted where one of the grounds in Article 17 applies.
- Restriction (Article 18) — to have processing paused while a dispute about accuracy or legitimate interests is resolved.
- Portability (Article 20) — to receive data you provided to us in a structured, machine-readable format, where the processing is based on consent or contract and is automated.
- Objection (Article 21) — to object at any time, on grounds relating to your situation, to processing based on legitimate interests. We will stop unless we can show compelling legitimate grounds that override your interests, or the processing is needed for legal claims.
- Complaint (Article 77) — to lodge a complaint with the supervisory authority in your country of residence, place of work, or the place of the alleged infringement. You do not need our permission and you do not need to contact us first, though we would rather you did.
To exercise any of these, write to legal@primanza.com. We will respond within one month, extendable by two further months for genuinely complex requests, and we will tell you if we extend. We do not charge for this. We will ask for enough information to be sure the request is yours, and no more — we will not demand identity documents to answer a question about data we may not even hold.
Because this site collects so little, the honest answer to most access requests will be that we hold nothing about you other than the email you sent us. We would rather tell you that than manufacture a process around it.
We do not carry out automated decision-making producing legal or similarly significant effects, and we do not profile you, so Article 22 has nothing to bite on here.
12. United States state privacy rights
If you are a resident of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Tennessee, Maryland, Indiana, Kentucky, Rhode Island or another state with a comprehensive privacy law, you may have rights to know, access, correct, delete and obtain a copy of your personal information, to opt out of its sale, sharing or use for targeted advertising or certain profiling, and to be free from discrimination for exercising those rights.
Three statements dispose of most of these in our case, and all three are literally true:
- We do not sell personal information, and have not in the preceding twelve months, under any of these laws' definitions of 'sell'.
- We do not share personal information for cross-context behavioural advertising or targeted advertising, and have not in the preceding twelve months.
- We do not process sensitive personal information, and we do not profile you for decisions producing legal or similarly significant effects.
In the categories of the California Consumer Privacy Act, the personal information described in section 4 is: identifiers (name, email address, IP address), internet or network activity information (page requests), and the contents of a communication you choose to send us — by email or through the contact form — which California treats as personal information belonging to you rather than to us. It is collected from you directly or from your browser, for the business purposes in section 5, and disclosed only to the service providers in section 7.
To exercise a state privacy right, including through an authorised agent, write to legal@primanza.com. We will verify the request against the information we hold and respond within the period the applicable law allows — 45 days in most states, extendable once where the law permits. Where a state gives you a right to appeal a refusal, you may appeal to the same address, and if we refuse the appeal we will tell you how to complain to your state's Attorney General.
Because we operate no tracking, there is nothing on this site for a Global Privacy Control or Do Not Track signal to switch off. We honour such signals by never having built what they exist to stop.
13. Children
This website is directed at businesses and professionals, not at children. We do not knowingly collect personal data from anyone under 16, and we do not offer any information-society service to a child. If you believe a child has sent us personal data, write to legal@primanza.com and we will delete it.
14. Representatives in the EU and UK
Article 27 of the GDPR requires a controller outside the Union to designate a representative in the Union where it offers goods or services to people in the Union or monitors their behaviour. Primanza has not designated one, for a stated reason rather than by omission: this corporate website offers no goods or services and monitors no behaviour, so the condition that triggers Article 27 is not met. The same reasoning applies to the UK GDPR.
This is a considered position, not a permanent one. If a Primanza product offers services to people in the EEA or the UK, the entity operating that product will designate representatives as required and will name them in that product's own privacy policy. Which entity that is, and how it is identified to you, is governed by the Product Terms Framework.
15. Government and law enforcement requests
Section 7 says we disclose data where a valid legal demand compels it. That sentence appears in every privacy policy and almost none of them say what it means in practice, so this one does.
A demand for data — a subpoena, a court order, a warrant, a request from a regulator or a foreign authority — is handled as follows:
- It is reviewed before it is answered. We check that it is authentic, that it comes from an authority with jurisdiction over us, that it is issued in the correct legal form, and that it asks for something the law actually entitles it to. A request that fails any of those is refused or challenged, not quietly honoured.
- It is read narrowly. We disclose only the specific data the demand covers, and only for the accounts, addresses or period it names. We do not volunteer adjacent data because it was easier to hand over the whole file.
- We tell you, unless we are forbidden to. Where a demand concerns data identifiable to you and we are legally permitted to notify you, we will — with enough time to seek your own remedy where that is possible. Where a gag or non-disclosure order forbids it, we comply with the order and give notice as soon as it lapses.
- An informal request — a request without legal compulsion, from any authority in any country — is not a legal demand. We do not disclose personal data on one. If an authority wants data, it can use the process the law gives it.
We have received no such demand to date. If that ceases to be true we will say so here, in a form that does not identify any individual and does not breach any order — a count, not a story.
The honest limit on all of this is the one already stated in section 8: no policy binds a government, and a US company is subject to US legal process. Our protection against a demand is not this paragraph. It is that this website holds almost nothing that could usefully be demanded of it — no accounts, no customer database, no behavioural record, and logs measured in days.
16. Changes to this policy
If this policy changes, the revised version is published on this page with a new revision date, and the sitemap reports that date so the change is visible to anyone watching. We do not backdate. Where a change materially affects your rights, we will make it prominent rather than quiet.
Questions, objections and requests all go to legal@primanza.com.