CAVEMANAIQ

What this site collects, and for how long

Two forms: one starts a conversation; one runs an outside-in audit and emails the result.

Written to be read, not to be defended.

What is collected

The contact form collects what is slowing you down, how long it has been like that, what you have tried, an email address and an optional name.

The free audit stores the email, the normalized public site address and host, the job state and timestamps, results or failure reason, a one-way confirmation-token hash, and one-way keyed values used to enforce per-address, per-site and per-network limits. The raw network address is not stored. It also stores whether optional follow-up was requested, the consent wording, its version and the time recorded for that request. Final follow-up consent and its time are stored only if the unticked choice is selected again when the audit is confirmed.

There is no audience-building or advertising analytics on this site. When scripts run on an audit form, Cloudflare Turnstile processes browser and connection signals to distinguish people from bots; its Turnstile Privacy Addendum explains those signals and any strictly necessary cookies.

Why, and the legal basis

Delivering what you ask for. The email and site address are used to confirm the request, run the audit and send the result. A contact enquiry is used to answer you. The basis is taking steps at your request before a contract, or performing one where the conversation becomes work (GDPR Article 6(1)(b)).

Preventing abuse. Confirmation, Turnstile, the honeypot and keyed rate-limit values stop this service being used to email strangers or fetch unsafe addresses. The basis is legitimate interests in operating a secure, available service (Article 6(1)(f)); the stored network value cannot be reversed here into the address it came from.

One optional follow-up. This happens only if the unticked box is selected again on the confirmation page. Opening the emailed link does not start the audit or confirm follow-up consent. The basis is your consent (Article 6(1)(a)); the audit and its result do not depend on saying yes.

How long it is kept

Unconfirmed requests are deleted after seven days. Audit leads are deleted after two calendar years, including their result, status, consent record and abuse-limit values. A contact enquiry is kept only as long as it is useful to its conversation and for up to two years after the last message. Where work is invoiced, records that belong to it are kept for as long as Greek tax law requires, which may be longer.

Who sees it

One person receives the operator copy. The data is not sold, rented, used to build an advertising audience or added to a mailing list.

Cloudflare hosts the page and function, stores the audit job in its EU-jurisdiction D1 database, applies Turnstile when scripts run, and keeps security request records. Resend carries confirmation, result and contact email. Google receives the public site address when PageSpeed Insights and Chrome UX Report are asked for speed data; Google does not receive the visitor email from this service.

These processors may handle data outside the European Economic Area. Their data-processing terms provide transfer safeguards, including European Commission standard contractual clauses where required: Cloudflare, Resend, and Google Cloud.

Who is responsible

This site is run by Alexandros Mimilidis, trading as Caveman AIQ, an independent technical consultancy based in Athens, Greece. Questions about anything on this page go to [email protected], and a person answers them.

Withdraw, erase or ask for a copy

Reply to any email or write to [email protected]. You can withdraw consent to the optional follow-up at any time without affecting what was lawful before withdrawal. You can also ask for access, correction, deletion, restriction or portability, or object to processing based on legitimate interests. Deletion needs no explanation; legal recordkeeping limits still apply.

Your rights

Under the GDPR you can ask me for a copy of what I hold about you, ask me to correct it, ask me to delete it, or object to how I use it. Write to [email protected] and you will get an answer from a person, not a ticketing system. If you think I have handled your data badly, you can complain to the Hellenic Data Protection Authority.

Last updated 19 September 2026. If this page changes materially, the date changes with it.

Back into the site

A privacy page should not be where a visit ends.