Europe & UK
GDPR Privacy Policy.
Last updated: August 28, 2026
This policy explains how eigenKOR handles personal data under the EU General Data Protection Regulation and the UK GDPR. It supplements our Privacy Policy and uses the terms the Regulation uses.
A note on why this exists. eigenKOR is a Houston company. We do not market to the EU or the UK, price in euro or sterling, or target either region. On that basis the GDPR very likely does not apply to us. We publish this policy and honor these rights anyway, as a matter of policy, because anyone can reach our contact form from anywhere — and if you have sent us your details from Europe, you should know exactly what happens to them.
Who Is Responsible
eigenKOR is the controller of the personal data described here. We decide why it is collected and what happens to it.
We have not appointed a Data Protection Officer. We are not required to — we do not carry out large-scale monitoring, and we process no special-category data. Anything a DPO would handle, the address above reaches.
What We Collect, And The Legal Basis For Each Use
Under Article 6 we must have a lawful basis for every purpose. Here is every purpose we have.
| What we process | Why | Lawful basis |
|---|---|---|
| Name, business name, email, phone, business city and state, and your message | To read your enquiry, reply to it, and scope possible work | Article 6(1)(b) — steps taken at your request before entering a contract |
| IP address, pages requested, time, browser and operating system | To keep the site available, diagnose faults, and block abuse | Article 6(1)(f) — our legitimate interest in operating a secure website |
| Technical browser and connection signals at the contact form | To tell real enquiries from automated spam | Article 6(1)(f) — our legitimate interest in preventing abuse |
| Analytics — pages viewed, approximate location from IP, referring source, device type | To understand which pages are useful | Article 6(1)(a) — your consent, and nothing loads until you give it |
Where we rely on legitimate interest, we have weighed it against your rights. Server logging and spam filtering are what any competent operator does, they involve no profiling, and nothing is combined to build a picture of you. You can object at any time — see Your Rights below.
We process no special-category data under Article 9. Nothing about health, race, ethnicity, politics, religion, philosophical beliefs, trade union membership, genetics, biometrics, sex life or sexual orientation. Please do not put any of it in the message field.
No automated decision-making. Article 22 does not bite here, because we make no decisions about you by automated means. A person reads every enquiry.
Where It Goes
| Who | Role | What they receive |
|---|---|---|
| Google LLC | Processor | Analytics data — only if you accept analytics cookies |
| Cloudflare, Inc. | Processor | IP address and technical signals, at the contact form only |
| Resend | Processor | Your contact-form submission |
Each acts on our documented instructions under a data processing agreement, and may not use your data for anything else.
Beyond these, we disclose personal data only to professional advisers bound by confidentiality, and where compelled by valid legal process. We do not sell personal data, and we do not use it to train AI models.
Transfers Outside The EEA And The UK
We are in the United States, and so are our processors. If you contact us from Europe, your data is transferred to the United States.
The mechanism. Both processors are certified under the EU-U.S. Data Privacy Framework — including its UK Extension and the Swiss-U.S. framework — which the European Commission has recognised as providing an adequate level of protection.
And a fallback, deliberately. Where the Framework is unavailable, lapses, or ceases to apply, we rely on the European Commission’s Standard Contractual Clauses, together with the UK Addendum, as incorporated into our agreements with each processor. We name both mechanisms because the Framework’s validity is under appeal at the Court of Justice, and a policy resting on a single mechanism would be wrong the day that changed.
Your data still leaves Europe. United States law affords different protections from EU law, including in respect of access by public authorities. We would rather say that plainly than bury it.
Your Rights
You have all of the following. Exercising any of them is free, and we will not treat you differently for it.
- Access — a copy of the personal data we hold about you, and an explanation of what we do with it.
- Rectification — correction of anything inaccurate or incomplete.
- Erasure — deletion, where we have no overriding reason to keep it.
- Restriction — a pause on processing while a dispute about accuracy or legitimate interest is resolved.
- Portability — the data you gave us, in a structured, commonly used, machine-readable format, or sent directly to someone else where technically feasible.
- Objection — to any processing based on legitimate interest, on grounds relating to your particular situation. If you object to direct marketing, we stop, full stop, with no balancing test.
- Withdraw consent — at any time, for analytics. Withdrawal does not affect the lawfulness of what happened before you withdrew.
How to exercise them
Email team@eigenkor.com. Tell us what you want; you do not need to cite an article number or use any particular form of words.
Our timetable. We will respond within one month. If your request is complex, or you have made several, we may extend by up to two further months — and we will tell you within the first month that we are doing so, and why. There is no charge. We will only refuse a request as manifestly unfounded or excessive in genuinely extreme cases, and if we ever do, we will explain why and tell you how to challenge it.
Verifying you. We may ask you to confirm your identity — usually just replying from the address that contacted us. We ask only what we need to be sure, and we do not use it for anything else.
Complaining
If you think we have handled your data badly, tell us first — we would rather fix it.
You also have the right to complain to a supervisory authority, and you do not need our permission or our agreement to do so:
- In the EEA, the data protection authority in the country where you live, work, or where you believe the problem occurred. The list is at edpb.europa.eu.
- In the UK, the Information Commissioner’s Office at ico.org.uk.
Cookies And Consent
Analytics on this site are opt-in. Until you choose, no analytics software loads at all — not in a reduced form, not anonymously. Nothing.
If you accept, two Google Analytics cookies are set, both lasting two years. If you decline, none are. Your choice is stored in your browser’s local storage under eigenkor_cookie_consent; it never reaches us. You can change it at any time using Cookie Settings in the site footer.
The strictly necessary parts of the site — serving pages, and the spam check on the contact form — do not use cookies and do not require consent.
Full detail is in the Privacy Policy.
How Long We Keep Things
| What | How long |
|---|---|
| Contact-form submissions that do not become client work | Two years from the date of submission, unless you ask us to delete it sooner |
| Records relating to client work | For the engagement, then as long as we must keep business and tax records |
| Server logs | A short operational period, then overwritten |
| Analytics data | 14 months — our analytics retention setting |
We keep nothing longer than the purpose requires, except where the law compels us or where we need it to establish or defend a legal claim.
Security, And What Happens If It Fails
The site is served entirely over HTTPS with strict transport security. Access to contact-form submissions is limited to the people who need it to answer you. Because analytics are consent-gated, we hold no behavioural data at all on visitors who decline.
We will not claim this is unbreachable. If a breach occurs and it is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, as Article 33 requires, and we will tell you directly where the risk is high. We will tell you what actually happened, not the minimum we can get away with.
Children
This site is for businesses. We do not knowingly collect personal data from children, and we offer no information society service directed at them. If you believe a child has sent us data, email team@eigenkor.com and we will delete it.
Changes
If we change this policy we will update the date at the top and post the new version here. If a change materially affects data you have already given us, we will email you before it takes effect.
Contact
See also our Privacy Policy, our California Privacy Notice, and our Terms of Service.