Who holds the data and what reaches us
No.ClauseIn plain wordsWhy it applies here
01 Who runs this site Xavriqon, trading at xavriqon.com, 152 Oak Lane, Suite 4, Austin, Texas 33038, United States. We decide what is collected here and why, which makes us the controller. Privacy law needs a named party you can write to. There is no parent company and no agency standing between you and the office on Oak Lane.
02 What we collect From the inquiry form: name, phone, email, address, the kind of inquiry, your message, the specification you ask for and the consent tick. Sent with it automatically: your IP address, the browser user-agent string, the referring URL, the moment the form rendered and the moment you sent it. From the support chat: the conversation itself, plus a token kept in your browser so you can come back to it. From your browser: the consent choice under site_consent_v2, and, only after you allow it, the identifiers set by the ad platforms. From the link you arrived on: an advertising click identifier (gclid, msclkid or fbclid) if one was attached. That list is everything the site's own code records. No account, no password, no payment, no card number. Nothing is sold here, so none of that is ever asked for.
03 What each part is for Form fields: to read your letter and reply to it. IP, user-agent and timestamps: to tell a person from a script and to block repeated junk. The referring URL and click identifier: to know which advertisement or page sent you, so we can stop paying for ads that bring nobody useful. Chat transcript: to keep the thread readable for both sides. Consent record: to remember your answer so the banner does not ask twice. Every field has one job. We do not build profiles, we do not sell lists and we do not run a mailing list. You will not get a newsletter you never asked for.

Clause 04

The legal basis for each purpose

Three bases are used. Consent, where you tick a box or press Allow. Contract, or the steps before one, where you ask us about the open naming direction and expect a written scope in return. Legitimate interest, where we keep the site from being flooded by automated junk. Nothing on this site relies on a basis you cannot see in the table below.

Purpose and basis
PurposeData usedLegal basis
Reading and answering your inquiryForm fields, consent tickConsent; steps before a contract when you ask about a naming assessment
Keeping a chat thread openChat messages, browser tokenConsent, given when you start the chat
Stopping spam and abuseIP address, user-agent, render and send timesLegitimate interest in a working inbox
Measuring which ads bring lettersClick identifiers, ad platform cookiesConsent only; denied by default
Remembering your cookie answersite_consent_v2Legitimate interest; strictly necessary storage
Advertising, consent and who else receives data
No.ClauseIn plain wordsWhy it applies here
05 Ad platforms that send traffic here This site receives paid clicks today. Google Ads, Microsoft Advertising and Meta Ads send visitors to it. Each attaches its own identifier to the link you click: gclid for Google Ads, msclkid for Microsoft Advertising, fbclid for Meta Ads. When you send the form, that identifier travels in a hidden field called source so we can tell which advertisement produced the letter. An office paying for clicks has to know whether they lead anywhere. The identifier names the ad, not you. No platform has reviewed or vouched for this site, and we do not suggest otherwise.
06 Consent Mode v2 Google consent mode, version 2, runs on every page. Four signals start at denied before anything else loads: ad_storage, ad_user_data, ad_personalization and analytics_storage. They switch to granted only when you press Allow. Press Decline, or withdraw later from Cookie settings in the footer, and all four go back to denied at that moment. Denied by default means the ad tags may count a visit without cookies, but they cannot store an identifier on your device or use your data for targeting until you agree.
07 Global Privacy Control If your browser sends the Global Privacy Control signal (the Sec-GPC header), we treat it as an opt-out of sale and sharing for advertising. The four consent signals stay denied and we do not ask you again. California and several other states require the signal to be honoured. It costs us nothing to honour it everywhere, so we do.
08 Who receives data, one by one Google Ireland Ltd and Google LLC, for Google Ads, which attaches gclid and receives the consent signals. Microsoft Ireland Operations Ltd, for Microsoft Advertising, which attaches msclkid; its handling is set out in the Microsoft privacy statement at privacy.microsoft.com/privacystatement. Meta Platforms Ireland Ltd, for Meta Ads, which attaches fbclid where a campaign runs there. The hosting provider that serves this site and stores the inquiry database. The mail provider that carries the notification of your letter to our inbox. Five recipients, no more. We do not pass your letter to a broker, a list seller or another office. Google's own terms are at policies.google.com/privacy.
09 Transfers abroad The office is in Texas, so data collected from a visitor in Europe crosses into the United States. The ad platforms may also move data between their Irish entities and the United States. Those transfers rest on the EU-US Data Privacy Framework where the recipient is certified, and on the European Commission's standard contractual clauses where it is not. A European visitor is owed a lawful route for data leaving the EU. Those two mechanisms are the routes the named recipients use.
How long, how it is kept and who it is not for
No.ClauseIn plain wordsWhy it applies here
10 How long each thing is kept Inquiries and their email copies: 24 months. Chat transcripts: 18 months. Server and access logs: 90 days. The record of your consent choice: 6 months, after which the banner asks again. After each period the record is deleted, not archived. Twenty-four months covers a slow conversation about a name, which can stall for a year and come back. Logs older than 90 days have never once helped us find a problem.
11 How it is protected Every page and every form travels over HTTPS. The inquiry store sits outside the public web folder and is reached only through a password-protected operator panel. Two hidden honeypot fields and a render timestamp filter out scripts before anything is written. Access is limited to the people who answer the letters. A small office is a small target, but a contact form is the first thing bots find. Fewer copies and fewer hands is the most reliable protection we have.
12 Children This site is not meant for anyone under 16 and we do not knowingly take data from children. If a letter from a child reaches us, we delete it and do not reply. Naming consultation and domain questions are adult business. Nothing here is aimed at a younger reader.
Your rights and how to use them
No.ClauseIn plain wordsWhy it applies here
13 Rights under the GDPR If you reach this site from Europe, the GDPR gives you the right to access what we hold, to have it rectified, to have it erased, to restrict how we use it, to receive it in a portable format, to object to processing based on legitimate interest, and to withdraw consent at any time without affecting what happened before you withdrew. The office is American, but the GDPR follows the visitor. Ad clicks come from wherever the campaign reaches.
14 Rights under US state law In California the CCPA, as amended by the CPRA, gives you the right to know what we collect, to delete it, to correct it, to limit use of sensitive data, and to opt out of the sale or sharing of personal information for cross-context advertising. Texas, Virginia, Colorado, Connecticut and the other states with privacy laws in force give similar rights. We do not sell personal information. Ad measurement through consented cookies can count as sharing under the CCPA, which is why it stays off until you allow it and switches off when you decline or send Global Privacy Control. The office is in Texas and the ads run across the United States. We will not treat you differently for using any of these rights.
15 Complaints You can complain to the Attorney General of your state. In California you can also go to the California Privacy Protection Agency. In Europe, to the data protection authority of the country you live in. Write to us first if you like, and we will try to fix it. You do not have to, and asking us does not stop you going to a regulator.
16 Making a data request Use the data request form, email [email protected], or write to 152 Oak Lane, Suite 4, Austin, Texas 33038, United States. We answer within 7 days. The legal ceiling for a Texas data privacy request is 45 days, extendable once by 45 more where a request is complex; we tell you if that happens and why. We ask for enough to match you to a record, usually the email you wrote from. We do not ask for ID unless the request is to delete or hand over a record we cannot otherwise match.
17 Changes to this policy A change is published on this page with a new version number and a new "last updated" date at the top. If it changes what we collect or who receives it, the cookie banner asks you again on your next visit. We hold no mailing list, so the page itself is the notice. Earlier versions are kept and sent on request.

Clause 18 · contact

A person reads privacy letters

No ticket system and no bot. Privacy questions go to the same inbox as everything else and are read by the people who run the office. Mark the subject "privacy" and it is pulled to the top of the pile.

Write
Xavriqon
152 Oak Lane, Suite 4
Austin, Texas 33038
United States