Privacy
This is short because there isn’t much to say — no advertising or analytics cookies and no database anywhere on this site. The one exception is a technical cookie that lasts 60 seconds if you send the form with JavaScript turned off: all it does is show whether your message went through. Visits are counted by Cloudflare Web Analytics, which sets no cookies and does not track individual visitors. Beyond that, the only thing collected is what you type into the contact form, and this page explains exactly what happens to it.
Who’s collecting it
Me — Serhii Lanchukovskyi, working as Sergius Design. There’s no separate company and no data protection team; enquiries land straight in my own inbox and phone.
What’s collected
Your name, your email address, the budget range you pick from a list, the project type if you choose one, and whatever you write in the message field. Your IP address is also read briefly, only to stop the same visitor submitting the form three times in a minute. Separately from the form: when you open a page, the Cloudflare Web Analytics script sends Cloudflare the page address, the site you came from, your browser and device type, and how fast the page loaded. Like any request on the web, it carries your IP address: Cloudflare uses it to work out the visitor’s country and discards the address straight away.
Why this is allowed
Sending a message here is a pre-contractual step you take yourself — you’re asking about work. Where the GDPR applies, that is Article 6(1)(b), not consent, which is why the notice under the form is a statement and not a checkbox: EU guidance (EDPB Guidelines 05/2020) treats a forced tick-box for something you’re already doing as consent that isn’t freely given, and therefore invalid. For the visit counter and the hosting logs the basis is legitimate interest (Article 6(1)(f) GDPR): I need to understand overall traffic and keep the site working and secure, without identifying individual people.
What it’s used for
Replying to you and, if we end up working together, running that project. Nothing else — never marketing, never profiling, never anything you didn’t ask for.
Who sees it
Two services carry the message to me, and both get all of it. The email goes through Resend — Plus Five Five, Inc., San Francisco — which acts as a processor under its published data processing addendum and keeps its own list of subprocessors public. The same submission also arrives in my Telegram: your name, your email address, what you picked from the two lists, and the full text of your message. Visits are counted by Cloudflare, Inc., San Francisco, acting as a data processor. The site is hosted on Vercel Inc. (United States). To secure and deliver the pages it handles network requests and visitors’ IP addresses as an independent data controller, under its own privacy policy: vercel.com/legal/privacy-notice. Beyond those four, nobody: no ad network, no third party you haven’t read about on this page.
Leaving the EU
All four services sit outside the EU, and they stand on very different footing — I would rather spell that out than leave it vague. Resend’s addendum covers the transfer to the United States with the EU Standard Contractual Clauses, and Resend is separately listed under the EU-U.S. Data Privacy Framework. Cloudflare stores data primarily in the United States and the European Economic Area; under its privacy policy, transfers to the United States rely on the EU-U.S. Data Privacy Framework and Standard Contractual Clauses. Vercel Inc. is listed under the EU-U.S. Data Privacy Framework, which is covered by a European Commission adequacy decision. Vercel offers no data processing agreement for free accounts, so it handles the technical logs under the terms of its own privacy policy. Telegram is the other case: it is a platform I do not control, the group companies its privacy policy names are registered in the British Virgin Islands and in Dubai, the European Commission has issued no adequacy decision for either, and Telegram offers bot developers no data processing agreement at all. Since the Telegram copy is the whole message, not a summary, that gap covers everything you write. If it matters to you, skip the form and email me at the address below — it reaches the same inbox and touches no second service.
How long it’s kept
There’s no database, so there is nothing to look up later even if I wanted to. Your message lives only where email and Telegram keep it — my own inbox and chat, for as long as I leave it there, exactly like any message you’d send me directly. The IP address used for the one-minute spam check stays in server memory only and is never written to disk. Aggregated visit statistics in Cloudflare Web Analytics are available to me for the past six months.
Your rights
Under the GDPR you can ask what I hold about you, have it corrected or deleted, object to the processing, or ask for a copy to take elsewhere. Write to the address below and I’ll act on it myself, directly — no request form, no queue. I work as a sole trader in Ukraine, outside the EU; if EU data protection law applies to you, Article 77 also gives you the right to complain to a supervisory authority — in the Member State where you live, where you work, or where you think the problem happened.
Get in touch about this
Questions about this page, or a request under the rights above — write directly.