Your data, in plain words.

What we collect when you visit this website or write to us, why, who receives it, how long we keep it and what you can do about it.

Last updated October 7, 2026

Who is responsible

Corvidint is the controller of the personal data described in this notice. For anything about your data, write to [email protected].

We have not appointed a data protection officer, because the law does not require one for what we do. The address above reaches the people who handle data protection.

Holder
Corvidint

What this notice covers

It covers this website, its analytics, the briefing request form, the emails you send us and the security reports you send us. It does not cover the data a customer collects with the platform: that is deployed in the customer’s own environment, and Corvidint does not receive it unless a separate agreement says so.

What we collect, and where it comes from

What you give us. When you request a briefing: your work email, your organization and, if you choose, what you are interested in. When you write to us or send a security report: your address, your message and any attachment.

What your browser sends us, only if you accept analytics. Our own analytics record:

  • Your IP address, the pages you view, where you came from and how long you stay.
  • How you use a page: sections seen and for how long, how far you scroll, where you click, questions you open, language changes, and the steps of the briefing form, including time spent in each field and whether a field showed an error. We never record what you type and we do not record your screen.
  • Your browser, device type, screen size and language, and how fast pages load.
  • Together these form a timeline of your visit.

What we work out. If you accept analytics, from your IP address we derive your approximate location (country, region, city) and the network or organization that owns the address, using public registries. If you send a briefing request, your IP address and browser details travel with it to prevent abuse, and we note the domain of your work email. If you had accepted analytics, the timeline of your visit goes with it too, so we can prepare the briefing.

Why we use it, and on what basis

  • Understanding and improving the website, knowing which topics and organizations show interest, and fixing slow or broken pages. Basis: your consent (Article 6(1)(a) GDPR and Article 22(2) of the Spanish Law 34/2002). You give or refuse it in the banner, and you can withdraw it at any time from “Privacy settings” in the footer.
  • Answering your briefing request and preparing a briefing that matches what you looked at. Basis: taking steps at your request, and our legitimate interest in answering well (Article 6(1)(b) and (f)).
  • Answering your emails and security reports. Basis: our legitimate interest in handling what you send us (Article 6(1)(f)).
  • Keeping the site secure and preventing abuse. Basis: our legitimate interest (Article 6(1)(f)).

Where we rely on legitimate interest, we weighed it against your rights and chose safeguards to match: no cookies, short retention, no sale or advertising use, and an easy way to object.

We do not sell personal data, we do not use it for advertising and we take no decision about you by automated means that has legal or similarly significant effects.

Which details are required

To answer a briefing request we need the work email and the organization. Without them we cannot reply. The interest you select is optional. You are never required to accept analytics to use the website, and declining costs you nothing.

Identifying the organization behind a visit

If you accept analytics, we try to tell which organization a visit comes from, using public network registries and, for a briefing request, the domain of your work email. We use it to understand which kinds of organizations are interested and to prepare relevant briefings. It is not used to make automated decisions about you.

You can stop this at any time, without giving a reason, by declining analytics in “Privacy settings” in the footer, or by writing to [email protected].

What is stored in your browser, and your signals

The website sets no cookies and the analytics place no identifier on your device. When you accept, a visit is recognised from the request itself, for up to 30 minutes of inactivity.

Your browser’s local storage holds at most two items, and neither is sent to us: your choice about analytics (accepted or declined) and, if you use that switch, your choice of reduced motion.

Until you choose, analytics do not run. They never run if your browser sends a Global Privacy Control or Do Not Track signal, which we treat as a refusal, and in that case the banner is not shown.

To change your mind, use “Privacy settings” in the footer. Declining or withdrawing stops analytics at once.

Who receives your data

Only Corvidint. The website, its analytics and the briefing requests run on our own server. We use these providers, which act on our instructions:

  • Cloudflare (United States) provides the domain name system, TLS and the network connection to our server. It sees your IP address and the traffic in transit.
  • Migadu (Switzerland) hosts our email, so your messages to us pass through it.
  • To describe a network, we query public information about the IP address: the domain name system through Quad9 (which does not store IP addresses) and the public registry services of the regional internet registries, through rdap.org.

Analytics reports and alerts go only to our team. We may disclose data to authorities when the law requires it.

Transfers outside the European Economic Area

Switzerland has an adequacy decision from the European Commission. Cloudflare serves traffic from data centres around the world, and its transfers are covered by the EU-US Data Privacy Framework or by standard contractual clauses. Ask us at [email protected] if you want a copy of the safeguards.

How long we keep it

  • Analytics records that contain your IP address or the timeline of your visit: 90 days. After that we keep only aggregated statistics that do not identify you.
  • Briefing requests, with the timeline of the visit and the abuse-prevention details: two years.
  • Emails and security reports: while we handle your matter and for up to two years after our last exchange, unless the law or a claim requires us to keep them longer.
  • The web server’s own access log keeps only the first three parts of an IP address.

Your rights

You can ask us for access to your data, correction, deletion, restriction and a portable copy. You can withdraw your consent at any time, without affecting what was done before. You can object to our use of it, and we will stop unless we can show compelling legitimate grounds.

Write to [email protected]. For analytics data, tell us your IP address and the approximate time of your visit so we can find it. We may ask you to prove who you are. We reply within one month, free of charge, and tell you if a complex request needs longer.

You can also complain to the Spanish Data Protection Agency (aepd.es) or to the authority of your own country.

How we protect it

All connections use TLS with strict transport security. The analytics run on our own infrastructure and send nothing to other analytics companies or advertising networks. Secrets are kept out of the code, access is limited to the people who need it, and backups are taken on our own storage.

Children

This website is aimed at professionals. It is not directed at children and we do not knowingly collect their data.

Changes

We will update this notice when what we do changes, and the date at the top shows the latest version. If a change affects how we use your data in a material way, we will say so on this page.