Privacy
How BIRTH Systems handles your information.
This is the privacy notice for the public website at birth-systems.com. It describes plainly what happens to the information you give us here. It is written to match how the site actually behaves — nothing more is claimed. It is not a client contract or a data-processing agreement; those are separate documents agreed per project.
What we collect, and why
The enquiry form sends the details you choose to provide to the BIRTH Systems public Cloudflare Worker. A successful submission is stored in a private Cloudflare D1 database and receives an opaque enquiry receipt. This can include your name, professional email, company, objective, supporting detail, requested timing, budget context, source link and an attachment reference. A salted hash of the request IP may be stored for rate limiting; the raw IP is not written to the enquiry record.
Files and sensitive information
Optional files are stored under opaque object keys in a private Cloudflare R2 bucket; no public object URL is enabled. File metadata — including original name, size, content type and SHA-256 hash — is recorded in D1. An opaque upload reference is sent with the enquiry so the service can associate the records, but the current receipt does not claim that every attachment was linked transactionally. Uploaded files remain untrusted and quarantined. Executable/script signatures and forbidden types are rejected, but no malware scanner is claimed: “quarantined” does not mean “safe” or “scanned”.
Do not upload passwords, access codes, private keys, live credentials or material you do not have the right to share. Send only what is needed to understand the work — a representative sample is often better than a whole database.
Booking & calendar
The booking interface shows availability only when its Calendar capability reports a real live connection. If you choose a time, the service rechecks it before creating a Google Calendar event and Meet link. If that capability is unavailable, the page shows an honest enquiry/email fallback and does not invent slots. Only the details needed to hold the meeting are used; your full request is not placed in the calendar title.
Who it reaches (providers)
We keep the number of providers deliberately small, and list only those we actually use:
- Google Workspace (Google LLC) — the founder's professional email, calendar and Meet.
- Cloudflare — serves the website and public Worker, stores enquiry records in D1, and stores optional files in a private R2 bucket.
Some providers may process data outside the UK/EU under their own terms. We do not send enquiry text to advertising networks, and we do not use it for model training.
Cookies & analytics
This site sets no advertising or analytics cookies and runs no third-party trackers. There is nothing to consent to for tracking, so there is no cookie banner. The pages load only from birth-systems.com.
How long we keep it
Enquiry records, quarantined uploads and correspondence are not assigned a fixed public retention period. They are kept only as long as needed to review the request and manage the relationship, subject to legal and operational needs. If we work together, project information and retention are governed by the agreement made for that engagement. We remove records when they are no longer needed, subject to those obligations, and handle legitimate deletion requests against the data we hold.
Your data isn't turned into BIRTH's memory
Information you send for one request is used for that purpose. It does not silently become marketing data, training data, or long-term general memory. Service messages (answering your enquiry) are kept separate from any future marketing, and we won't add you to marketing without asking.
Your rights
You can ask us what we hold about you, to correct it, or to delete it, and to object to a particular use. We'll action legitimate requests against the data we actually hold. Email dinis@birth-systems.com for any privacy matter.
Security & honesty
The public service has scoped enquiry and upload routes; it does not expose BIRTH's private operating environment. Anything you submit is treated as data, never as authority over any system. We describe only measures we actually operate. BIRTH Systems does not claim malware scanning, GDPR certification, ISO, SOC 2 or any accreditation it does not hold; if that changes, this page will change with it.