Privacy notice
Draft for the website owner to complete before publication. This page is a practical template, not legal advice. Replace the bracketed fields, check the hosting settings, and confirm the wording fits how the service actually operates.
1. Who is responsible for your information?
The controller is [insert legal name or registered business name], based in Riga, Latvia. Privacy enquiries: wallywest712@gmail.com.
2. What information may be collected?
A quote request may collect your name, email address, institution, study level, requested service, target deadline, approximate document length, and project description. The thesis audit collects the uploaded PDF/DOCX file, selected programme profile, study level, technical upload information, a one-time Cloudflare Turnstile security token, and a hashed connection identifier used for rate-limiting. Cloudflare Turnstile may process technical/browser data and the connection IP to assess whether a visitor is automated. The audit does not ask for your name or email address.
Do not upload documents containing identifiable research-participant records, special-category personal data, trade secrets, or confidential/client material unless you are authorised to share it for this purpose. Remove student numbers, names and other identifiers where practical. Do not use this service for work covered by an NDA unless you have permission.
3. Why is the information used?
The information is used to review your enquiry, assess the requested service, reply to you, prepare a quote, and—if you decide to proceed—communicate about the agreed service. It is not intended to be used to sell personal details or for unrelated marketing.
4. Hosting, temporary file storage and AI processing
The website is designed for hosting on Cloudflare Pages with Cloudflare Pages Functions for its server-side routes. For the optional thesis audit, the uploaded file is transferred to a private Supabase Storage bucket using a short-lived upload URL. The backend extracts text, runs document checks, sends only selected text excerpts (the opening section and available conclusion excerpt, plus check results) to Cloudflare Workers AI to generate the review, and returns the report to the browser. The complete uploaded file is not intentionally sent to the AI model. Quote requests submitted through the website are stored in a private Supabase database table; they are not sent to Netlify Forms on the Cloudflare deployment.
The application attempts to delete the uploaded file after the audit finishes. Files from interrupted requests are eligible for deletion after 24 hours, but cleanup is opportunistic and occurs during subsequent website API requests rather than on a guaranteed schedule; an abandoned file can remain longer if the site receives no further requests. The report is displayed in your browser and is not intentionally saved as a client record by the audit application. Cloudflare, Supabase and other infrastructure providers may retain technical, security and abuse-prevention logs under their own policies.
The Cloudflare deployment uses Cloudflare Workers AI. Cloudflare states that Workers AI inputs and outputs are not used to train or improve its or third-party models by default; see Workers AI data usage. This does not mean no technical logs are kept by any infrastructure provider. The site owner must review current provider terms, processing locations and any required data-processing agreements before enabling real student uploads. Cloudflare Turnstile is used for anti-abuse verification; see Cloudflare's privacy policy.
5. How long is information kept?
Audit files older than 24 hours, hashed rate-limit records older than 90 days, and quote requests older than 90 days are eligible for opportunistic cleanup during subsequent API requests. These are application cleanup targets, not a guaranteed deletion deadline, and the owner may need to inspect or delete records in Supabase when appropriate. Quote enquiries and client records are kept subject to applicable legal/accounting requirements and the owner's actual retention policy; the owner must specify and verify that policy before launch.
6. Access, correction and deletion
You may contact the controller using the business email above to ask about your personal information or request correction or deletion where applicable. Depending on the circumstances, data protection law may also give you rights to access, restrict or object to certain processing, and to complain to the competent supervisory authority.
7. Security and sharing
Audit files are intended to be stored in a non-public Supabase Storage bucket and accessed by the backend only through server-side credentials. The backend has file-size/type checks and daily rate limits. Quote requests are stored in a private Supabase table. No website can guarantee zero risk; do not upload a thesis if your university, client, supervisor, research participants or confidentiality agreement prohibits this processing. Information may be processed by Cloudflare and Supabase to operate the website and audit service.
8. Your choices and rights
You can choose not to use the upload audit and instead request general guidance without sharing your thesis file. Depending on the applicable law and circumstances, you may have rights to access, correct, erase, restrict or object to processing, and to complain to the competent supervisory authority. Contact the controller using the contact details above.
9. Changes to this notice
This notice must be updated if the service, hosting, AI provider, data locations, or retention settings change. Last updated: 11 October 2026. This template is not legal advice. Have the final wording reviewed against the actual deployed configuration.
← Back to the website