Legal

Privacy Policy

1. Who we are

The data controller for the personal information described in this policy is Justin Pethers, trading as Caisson Foundry ("we", "us", "our"). We are established in Sofia, Bulgaria.

For anything to do with privacy, contact privacy@caissonfoundry.com.

We are not required to appoint a statutory Data Protection Officer: we do not carry out large-scale systematic monitoring, nor large-scale processing of special-category data, and our core activity is not data processing. Privacy questions go to the address above.

2. What this policy covers

This policy explains what personal information we collect through this website, why, what we do with it, who we share it with, how long we keep it, and the rights you have over it.

It covers the website only. How we handle personal data inside a paid client engagement is governed separately by the contract for that engagement.

3. What we collect, and how

When you request a Profit Leak Workshop. When you submit the form, we collect your name; your email address; your business or practice name; your website (optional); and a short description of the one thing costing you most right now (free text — whatever you choose to tell us).

Providing this information is voluntary. We need at least your name and email to respond; the rest helps us prepare, and you're free to leave it out.

The form includes a hidden anti-spam field. It is never shown to you and is not personal data — it exists only to catch automated submissions.

When you book a time. Scheduling runs through Cal.com. The booking tool does not load when the page opens — it loads only if you click to open it. If you do, you give Cal.com the details needed to make the booking (typically name, email, and your selected time), and Cal.com may set cookies necessary for the booking tool to work. We treat those as strictly necessary to a service you actively asked for. If you never open the scheduler, nothing is loaded and nothing is set.

Website analytics. We run our own analytics software (Umami) on our own server, hosted in Germany. Your visit data is not sent to an analytics company, and no third-party analytics service receives anything about you.

It works without cookies, and it does not track you across other websites or build a profile of you. It records which pages were viewed, where visits came from, and general technical details such as browser, device type and country.

To count a returning visit without a cookie, the software creates a short-lived anonymous identifier from your IP address, your browser details and a secret value that changes daily. Your IP address is used to produce that identifier and to determine your country — it is not stored, and the identifier cannot be reversed to recover it or reused to recognise you the following day. We rely on our legitimate interests (Art. 6(1)(f)) in understanding how the site is used. Because nothing is stored on your device and nothing identifies you, there is no consent banner and nothing for you to accept or reject.

Information our providers process automatically. Like any website, this site is delivered through a hosting provider (Netlify) that processes limited technical data — such as your IP address and basic request information — to serve the site securely and guard against abuse. Our analytics server runs on infrastructure provided by Hetzner in Germany, which processes the same kind of technical data in the course of running the server. Email sent to an address on our domain passes through our registrar's forwarding service (Porkbun) on its way to our inbox. We rely on our legitimate interests (Art. 6(1)(f)) for all three, and we don't use that data to identify or profile you.

Cookies. This site sets no tracking or analytics cookies. The only cookies that can appear are those strictly necessary for a function you have actively started — see the scheduler note above. Because there are no non-essential cookies, there is no consent banner and nothing for you to accept or reject.

We do not collect special-category data. We don't ask for — and you should not send us through the form — sensitive information such as health data or racial or ethnic origin. If you're a healthcare or other regulated practice enquiring, keep your enquiry to the business problem; don't include patient or client personal data.

4. Why we use it, and our lawful basis

Responding to your enquiry, scheduling and delivering the free workshop, and discussing whether to work together — Art. 6(1)(f), our legitimate interest in responding to business enquiries we receive.

Keeping a basic record of enquiries so we can follow up on a conversation you started, and serving the site securely — Art. 6(1)(f), our legitimate interest in managing genuine enquiries and running a secure website.

Understanding how the site is used, in aggregate, so we can improve it — Art. 6(1)(f), our legitimate interest in maintaining and improving our own website.

Meeting legal, tax and accounting obligations, where they apply to us — Art. 6(1)(c), legal obligation.

We rely on legitimate interests because you contacted us and expect a reply; the processing is limited to what answering you requires; and it has no impact on your privacy that you would not reasonably expect. We have assessed this balance and recorded it. You have the right to object to processing based on legitimate interests — see "Your rights" below.

We use your enquiry details only to handle the workshop you asked for and the conversation that follows. We do not add you to a newsletter or marketing list, and we do not use your details for marketing beyond responding to your enquiry.

We do not use your information for automated decision-making or profiling that produces legal or similarly significant effects.

5. Who we share it with

We don't sell your information, and we don't share it for anyone else's marketing.

We use a small number of service providers ("processors") who handle data on our behalf, under contract and on our instructions:

Netlify — hosts this website and receives enquiry-form submissions. Processed in the United States.

Cal.com — scheduling, if you open the booking tool. Processed in the United States.

Porkbun — domain registration, DNS, and forwarding email sent to our domain. Processed in the United States.

Hetzner — provides the server that runs our own analytics software. Processed in Germany.

Proton — our email inbox, where we read and reply to your enquiry. Processed in Switzerland.

Each provider operates under its own data processing terms, which apply to our use of their services.

6. International transfers

Hetzner is in Germany, so no transfer outside the EU arises there. Switzerland is recognised by the European Commission as providing an adequate level of data protection, so mail reaching our inbox is not transferred outside a protected jurisdiction.

Netlify, Cal.com and Porkbun are US-based, so some of your data is transferred to and processed in the United States. Those transfers rely on the safeguards set out in each provider's data processing terms — the EU–US Data Privacy Framework where the provider is certified, and/or Standard Contractual Clauses under Art. 46. You can ask us for more detail on these safeguards, or find them in each provider's published terms.

7. How we protect it

We take reasonable measures to keep your information secure, and we work only with established providers that maintain recognised security standards. We limit who can access your data, and we keep it only as long as we need it. No system can be perfectly secure, but we treat your information carefully and act quickly if anything goes wrong.

8. How long we keep it

Enquiries that don't become engagements: kept for up to 12 months from our last contact, then deleted — sooner if you ask.

Enquiries that become paid engagements: your information moves under the engagement contract and is retained for the period set out there, plus any period required for legal, tax or accounting reasons.

Submissions held by Netlify: we export and clear these on a routine basis so they aren't retained there indefinitely.

Analytics records: kept in aggregate form only. They contain no stored IP addresses and nothing that identifies you.

9. Your rights

Under the GDPR you have the right to: access the information we hold about you; ask us to correct it; ask us to delete it; restrict how we use it; object to processing based on our legitimate interests; and request portability of information you gave us.

To exercise any of these, contact us at privacy@caissonfoundry.com. We'll respond within one month, normally free of charge.

10. How to complain

Please tell us first so we can put it right.

You also have the right to complain to a data protection supervisory authority. Ours is the Commission for Personal Data Protection (Комисия за защита на личните данни) — Sofia 1592, 2 Prof. Tsvetan Lazarov Blvd — kzld@cpdp.bg — +359 2 915 3518 — www.cpdp.bg. You may alternatively complain to the supervisory authority in the EU or EEA country where you live or work.

11. Changes to this policy

If we change how we handle personal information, we'll update this page and the "last updated" date. Material changes will be made clear.

12. Last updated

30 July 2026