Privacy Policy

We keep the website simple, transparent and privacy-conscious. This policy states exactly what we collect, why, for how long and what you can ask us about it — aligned with the GDPR (EU) and the LGPD (Brazil).

Who we are

SRARS — Self-Referential Architectural Systems — is the controller of the personal data processed on this website. You can reach our data protection contact for any request, question or complaint at [email protected].

What we collect

We collect only what is necessary to operate the service and respond to inquiries:

  • Contact form data: name, email address and message content, when you choose to write to us.
  • Visitor logs: IP address, date, request count, user agent, last visited path and referring host, stored on our own server to keep the service secure and to count anonymous aggregate visits.
  • Server metrics: request counts, latency percentiles and uptime, published in aggregate in the footer — these are not personal data.
  • Local UI preferences: your light/dark theme choice is stored in your browser's localStorage and never leaves your device.
  • Admin area: a username, an argon2id password hash and a session cookie, only for the site operator — not for visitors.

We use no tracking cookies, no advertising pixels and no third-party analytics. The only cookies ever set are the strictly necessary admin session cookie and a short-lived anti-CSRF cookie, both limited to the admin area.

Legal bases and purposes

  • Contact form data: processed on your consent (GDPR art. 6(1)(a); LGPD art. 7, I) and to take steps at your request before a possible contract (GDPR art. 6(1)(b); LGPD art. 7, V). Purpose: answering your message and following up on it.
  • Visitor logs: processed on legitimate interest (GDPR art. 6(1)(f); LGPD art. 7, IX). Purpose: keeping the service secure, preventing abuse and rate limiting, and measuring aggregate traffic. We never use them to profile you or to advertise.
  • Admin data: processed on the operator's legitimate interest in operating the service securely. Purpose: authentication and audit.

Who we share with

We do not sell, rent or trade personal data, and we do not use it for advertising. The only processor involved in serving this website is Cloudflare, Inc., which terminates TLS and proxies traffic between your browser and our origin server through its network. No other third party receives personal data from this website.

International transfers

Cloudflare operates a global network, so traffic may be processed outside your country, including in the United States. For visitors from the EEA or the UK, these transfers rely on the European Commission's Standard Contractual Clauses; for visitors from Brazil, on the transfer mechanisms of LGPD art. 33, including the ANPD's standard contractual clauses. Our origin server and database stay on hardware we control.

How long we keep data

  • Visitor logs: 90 days, then deleted automatically by the server. The optional geo cache is deleted after 180 days.
  • Contact messages: kept for as long as we have a legitimate support or legal need, then deleted. You can ask us to delete them at any time.
  • Theme preference: stored in your browser until you clear it.

Security

The site is designed with a small footprint and explicit boundaries: a single static binary, an embedded database, TLS everywhere with HSTS preload, argon2id password hashing (128 MiB, two passes), CSRF protection on every write, rate limiting on login and contact, and a scratch container with no shell. The admin surface is additionally gated at the edge by Cloudflare Access — only the operator's verified email can reach the login at all. We keep the stack simple, prefer minimal dependencies, and operate the service with security and observability as first-class concerns.

Your rights

Depending on where you are, you have the following rights over your personal data:

  • Under the GDPR (EU/EEA): access, rectification, erasure, restriction of processing, data portability, objection to processing and withdrawal of consent.
  • Under the LGPD (Brazil): confirmation of processing, access, correction, anonymization, blocking or deletion of unnecessary data, portability, information about data sharing and about the consequences of not providing consent, and revocation of consent.

To exercise any of these rights, write to [email protected]. We answer every request. You may also lodge a complaint with your local supervisory authority — in Brazil, the ANPD (Autoridade Nacional de Proteção de Dados).

Changes to this policy

This policy lives in the site's source code and changes are tracked in version control. When it changes, the updated version is published on this page.