1. Who is responsible
Astana Digital s.r.o., IČO 11915137, Jagellonská 1473/27, Žižkov, 130 00 Praha 3, Czech Republic, is the controller of the personal data described here, within the meaning of Article 4(7) of Regulation (EU) 2016/679 (GDPR). Czech Act 110/2019 Coll. applies alongside it.
Data protection questions and requests go to admin@astanadigital.net or by telephone to +420 225 132 725. We have not appointed a data protection officer, because the criteria in Article 37(1) GDPR are not met; the managing director answers these requests personally.
2. What we collect, why, and on what basis
| What | Why | Legal basis | Kept for |
|---|---|---|---|
| RFP and audit requests: organisation, contact name, email, telephone if given, service area, technology interest, your own budget band if selected, your message, and the estimator parameters if you chose to attach them | To answer the enquiry and prepare a proposal | Art. 6(1)(b) — steps at your request before a contract; Art. 6(1)(f) — our legitimate interest in responding to business enquiries | 24 months |
| Contact form messages: name, email, organisation, subject, message | To answer the question you asked | Art. 6(1)(b) and Art. 6(1)(f) | 24 months |
| Evidence that the privacy notice was shown: the acknowledgement flag and the time it was given | To be able to show what you were told when you submitted the form | Art. 6(1)(c) with Art. 5(2) — accountability | 24 months |
| A one-way salted hash of your IP address, taken when a form is submitted. The address itself is not stored | Rate limiting, so the forms cannot be used to flood our systems | Art. 6(1)(f) — security of processing, Art. 32 | 7 days |
| Web server access logs: IP address, timestamp, request line, status, user agent, referrer | Operating the service, diagnosing faults, detecting abuse | Art. 6(1)(f) — legitimate interest in a working, secure website | 14 days |
| Your cookie decision | To honour it and not ask you again | Art. 6(1)(a) — your consent; Art. 6(1)(c) for the record of it | 12 months, in your browser |
We do not ask for and do not want special-category data (Article 9 GDPR) through this website. Please do not put health, biometric, political, religious, trade-union or similar information into a contact form. If you send it anyway we will delete it.
3. What we do not do
- We do not sell personal data, and we never have.
- We do not add enquiry contacts to a marketing list, and we send no newsletters or promotional email from this website.
- We do not share your details with advertising networks or data brokers.
- We take no automated decisions about you in the sense of Article 22 GDPR, and we do not profile you.
- There is no analytics service, no advertising pixel and no third-party script of any kind on this site today. Consent Mode v2 is wired and denied by default so that if measurement is ever added, it starts from your recorded choice rather than ignoring it.
- Our fonts are served from our own domain. Loading a webfont from a third-party CDN would disclose your IP address to that CDN, so we do not do it.
4. Who else can see your data
Enquiry data is stored in a database on the server that runs this website. The categories of recipient are:
- Our hosting provider, Namecheap, Inc. (AS22612), acting as a processor for the server itself. It has no reason to read the data and is contractually barred from using it for its own purposes.
- Professional advisers or authorities, only where the law requires it or to establish or defend a legal claim.
We use no third-party CRM, no marketing platform, no cloud form service and no external analytics provider, so there is no other recipient to list.
5. Transfer outside the EEA — please read this
The server that runs this website is located in Los Angeles, California, United States, which is outside the European Economic Area. Personal data you submit through this website is therefore transferred to a third country within the meaning of Chapter V GDPR.
The transfer is made on the basis of Standard Contractual Clauses under Article 46(2)(c) GDPR, incorporated into our agreement with the provider. We do not rely on, and do not claim, certification of our hosting provider under the EU-US Data Privacy Framework. We assessed the transfer before making it: the data involved is business contact information and the content of an enquiry, it is encrypted in transit, access to the server is restricted to key-based administrative accounts, and we hold no special-category data on it.
You may ask us for a copy of the safeguards relied on. If you would rather not have your data leave the EEA at all, contact us by telephone on +420 225 132 725 instead of using a form, and say so.
Hosting location established by measurement on 2026-09-09: TCP handshake latency measured from the server itself to regional cloud endpoints: 21 ms to Northern California, 54 ms to Ashburn, 136 ms to London, 144 ms to Frankfurt, 190 ms to Singapore. A round trip to Frankfurt of 144 ms is not physically possible from inside the EEA. Corroborated by the ARIN RDAP record for the address (NAMEC-4, Namecheap) and by IP geolocation naming Los Angeles.
6. How the data is protected
- The whole site and API are served over HTTPS only, with HTTP redirected.
- Form submissions carry a cross-site request forgery token, are rate limited, and are validated on the server rather than only in the browser.
- The application database account can read and write its own tables and nothing else. Server credentials are not readable by the account that deploys the code.
- IP addresses used for rate limiting are stored only as a salted one-way hash, so the log cannot be turned back into a list of visitors.
- Application error logs are written without personal data. If a piece of your data ever appears in a log by accident, tell us and we will remove it.
7. Your rights
Under the GDPR you may ask us to:
- confirm whether we hold data about you and give you a copy (Article 15);
- correct anything inaccurate (Article 16);
- erase it (Article 17);
- restrict how we use it while a question is resolved (Article 18);
- send it to you or another controller in a portable format (Article 20);
- stop processing that rests on legitimate interest, by objecting to it (Article 21) — for enquiry data we will comply unless we need it to defend a legal claim;
- withdraw a consent you gave, such as a cookie choice, at any time (Article 7(3)).
Write to admin@astanadigital.net. We answer within one month, and we do not charge for it. We may ask a question to confirm who you are, but only enough to be sure we are not disclosing someone else’s data to you.
If you are not satisfied you may complain to the Úřad pro ochranu osobních údajů (Office for Personal Data Protection), Pplk. Sochora 27, 170 00 Praha 7, Czech Republic, telephone +420 234 665 111, or to the supervisory authority in your own EU country.
8. Is any of this required?
You are under no obligation to give us anything. The fields marked required on a form are simply the minimum we need to reply usefully; if you leave them blank we cannot answer, and that is the only consequence.
9. Cookies
Cookies and browser storage are covered in detail in the Cookie Policy, which lists every item, its purpose and its lifetime, and lets you change your decision.
10. Changes
If this policy changes we update the date at the top and, where the change is material, say what changed. The version in force is always the one on this page.