TechProbe logo TechProbe.io
ServicesProcessFAQ
Start a project
Legal

Data Privacy Policy

What personal data TechProbe.io collects through this site, why we process it, who processes it with us, how long we keep it, and the rights you have over it.

Last updated 24 August 2026

1. Who this policy is from

This site is operated by TechProbe.io (“TechProbe”, “we”, “us”). We are the controller of the personal data described below — we decide why it is collected and what happens to it. Write to [email protected] about anything in this policy, including any request to exercise the rights in section 9.

This policy covers techprobe.io and its subdomains, including the public API served under /api/v1. It does not cover the software we build for clients under a separate engagement agreement — in those projects we normally act as a processor on the client’s instructions, and the client’s own privacy notice governs.

2. What we collect

Information you give us

The contact form (“Start a project”) is the only place this site asks you for anything. It collects:

  • Your name — so a reply is addressed to a person.
  • Your work email address — so we can reply.
  • Your company — optional; you can leave it blank.
  • Your message — whatever you choose to tell us about the product you want built or the problem you want solved.

Please don’t put confidential, sensitive or regulated information in that box. A first enquiry travels by ordinary email and sits in an ordinary inbox. Tell us the shape of the problem; keep patient data, credentials, trade secrets and anything under NDA until we have a signed agreement and a secure channel.

Information collected automatically

  • Usage data, if analytics is switched on: pages viewed, referring site, approximate location, device, browser and similar, collected by Google Analytics 4. See section 4 and the Cookie Policy.
  • Your IP address, which reaches us with every request. We use it in two ways: it is sent to Google as part of the reCAPTCHA anti-spam check when you submit the form, and it is held in the server’s memory for a short window to rate-limit abusive traffic. The rate-limit record is never written to disk and disappears when the process restarts.
  • Server logs, produced by our hosting provider in the ordinary course of running a web service.

What we do not collect

  • No accounts, passwords or logins — the site has none.
  • No payment or card details are taken through this site.
  • No special-category data (health, biometrics, beliefs, and so on) is asked for. Please do not volunteer any.
  • No advertising profiles, no cross-site tracking, and we do not sell personal data.

3. Why we use it, and on what legal basis

What we doData usedLegal basis (UK/EU GDPR)
Reply to your enquiry and discuss a possible engagementName, email, company, messageSteps at your request prior to entering a contract; legitimate interests
Send you a confirmation that your message arrivedName, emailLegitimate interests — you should know it was received
Keep a record of enquiries so nothing is lost or answered twiceAll form fields, timestampLegitimate interests in running the business
Block spam and automated abuse of the form and APIIP address, reCAPTCHA scoreLegitimate interests in keeping the service available and usable
Understand how the site is used and improve itAnalytics usage data Consent where required by local cookie rules; otherwise legitimate interests in measuring our own site

Where we rely on legitimate interests, we have weighed those interests against your rights and concluded they do not override them — the processing is limited, expected, and directly serves the reason you contacted us. You can object at any time (section 9).

4. Cookies and similar technologies

This site sets no cookies of its own. Two third-party services can set them: Google Analytics (measurement) and Google reCAPTCHA (anti-spam). Each is active only when it has been configured, and neither is needed to read the site. The full inventory — names, purposes, lifetimes and how to switch them off — is in the Cookie Policy.

5. Who else handles your data

We keep the list of processors deliberately short. We do not sell, rent or trade personal data, and no one on this list is permitted to use it for their own purposes beyond what is described here.

  • Google (Workspace) — your enquiry is emailed to our team through Gmail, you receive a confirmation the same way, and a record of the submission is written to a Google Sheet in our own Workspace account.
  • Google (reCAPTCHA) — receives your IP address and interaction signals to score whether the submission is human. Google’s Privacy Policy and Terms of Service apply to that check.
  • Google (Analytics) — receives usage data when analytics is switched on.
  • DigitalOcean — hosts the site and API, and therefore processes traffic and server logs on our behalf.

We may also disclose data where the law requires it, or where it is necessary to establish, exercise or defend a legal claim. If the business is ever reorganised or transferred, enquiry records may pass to the successor under the same commitments.

6. Where your data goes

Our providers operate globally, so your data may be processed outside your own country, including in the United States. Where data leaves the UK or EEA, the transfer relies on the safeguards those providers put in place — standard contractual clauses and, where applicable, the EU–US and UK–US Data Privacy Framework. You can ask us for details of the safeguards that apply to a specific transfer.

7. How long we keep it

  • Enquiries that do not become projects — kept for up to 24 months from your last contact with us, then deleted. Two years is long enough for a conversation to be revived, which is genuinely common in this business.
  • Enquiries that become engagements — retained for the life of the engagement and for as long afterwards as tax, accounting and limitation periods require.
  • Rate-limiting records — held in memory only, for the length of the limiting window, then discarded.
  • Analytics data — retained according to the retention period set in our Google Analytics property; the underlying identifiers are cookie-based and expire as set out in the Cookie Policy.
  • Server logs — kept for the short period our hosting provider retains them.

Ask us to delete your enquiry sooner and we will, unless we are required to keep it.

8. How we protect it

Security is the thing we are hired to get right for other people, so we hold our own site to the same standard:

  • All traffic is served over HTTPS, with HSTS asserted in production.
  • A Content Security Policy, plus X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Cross-Origin-Opener-Policy and Permissions-Policy headers, limit what the page can do and what can be done to it.
  • Request bodies are size-limited and write endpoints are rate-limited.
  • Enquiry records live in our Google Workspace tenant, reachable only by the small number of people who need them, over accounts protected by multi-factor authentication.
  • Credentials are held as secrets in the deployment platform, never in source control.

No system is perfectly secure, and we do not claim otherwise. What we can promise is that we design for the failure, not just the happy path.

9. Your rights

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you, and get a copy.
  • Correct it if it is wrong or incomplete.
  • Delete it, where we have no overriding reason to keep it.
  • Restrict or object to our processing of it, including processing based on legitimate interests.
  • Port it to another provider in a machine-readable form.
  • Withdraw consent at any time, where consent is the basis we rely on.
  • Complain to your data protection authority. In the UK that is the Information Commissioner’s Office (ico.org.uk); in the EEA it is your national supervisory authority. We would rather you came to us first, but you are not obliged to.

To exercise any of these, email [email protected]. We will respond within one month, and we will not charge you or treat you differently for asking. We may need to confirm your identity first — usually by replying to the address that made the enquiry.

10. Children

This is a business-to-business site and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has sent us personal data, tell us and we will delete it.

11. Automated decision-making

The only automated scoring on this site is the reCAPTCHA check, which decides whether a form submission looks like a bot. A low score means your submission is rejected with a message asking you to reload and try again — it has no legal or similarly significant effect on you, and you can always reach us directly at [email protected] instead. We do not profile visitors or make automated decisions about them.

12. Changes to this policy

We update this policy when what we do changes. The “last updated” date at the top always reflects the current version. Material changes will be flagged on this page; continuing to use the site after a change means the revised policy applies.

13. Contact

Data protection enquiries, requests and complaints: [email protected]. We have not appointed a Data Protection Officer, as we are not required to; enquiries go straight to the senior team.

Questions about this document? Write to [email protected] and a person will answer.

Cookies →The cookies and similar storage this site uses — analytics and anti-spam only — what each one is for, how long it lasts, and how to turn them off.Terms of Use →The terms on which you may use the TechProbe.io website and its public API, and how they relate to any engagement agreement we sign with you.Disclaimer →What the information on TechProbe.io is — and is not. General information about our services, offered without warranty and not as professional advice.
← Back to TechProbe.io
TechProbe logoTechProbe.io
Data PrivacyCookiesTerms of UseDisclaimer
© 2026 TechProbe.io — Custom software engineering.