Last updated: October 6, 2026

This privacy policy explains what personal data is processed when you visit sergops.com (the “site”) or contact me through it, why it is processed, and what rights you have. It is written to meet the requirements of the EU General Data Protection Regulation (GDPR), the Spanish Organic Law 3/2018 on data protection (LOPDGDD) and the privacy expectations of visitors from the United States, including the California Consumer Privacy Act as amended (CCPA/CPRA).

In short

  • This site uses no cookies, no analytics, no advertising and no tracking tools. Because nothing on the site stores information on your device, there is no cookie banner.
  • The only personal data I receive is what you choose to send through the contact form or by email.
  • I use it only to reply to you and, if we work together, to carry out the project. I never sell it and never share it for advertising.
  • Contact form data is stored on servers located in the European Union.
  • You can ask me to access, correct or delete your data at any time at hello@sergops.com.

Who is responsible for your data

The data controller is:

  • Serhii Karnaukh, independent freelancer, trading as SergOps
  • Based in Girona, Catalonia, Spain
  • Postal address: Ronda Fort Roig 15-20, P2-7, 17007
  • Tax ID (NIF): Y9948734Y
  • Email: hello@sergops.com

What personal data I process

When you use the contact form

I receive the name, email address and message you type into the form. I also record that you ticked the consent checkbox and the date and time of submission. Please do not include sensitive information (for example health data or government ID numbers) in your message. I do not need it to answer you.

When you write to me by email

If you email me, I process your email address, your name if you give it, and the content of your message and any attachments.

Technical data when you visit the site

To deliver a web page to you, your IP address and basic request information (such as the page requested, date and time, browser type and referring page) must be processed. This is done by the infrastructure provider that serves the site and protects it against attacks and abuse (see “Who receives your data” below). I do not use this data to identify visitors or to build profiles.

What I do not collect

This site does not use cookies, local storage, device fingerprinting, analytics, advertising pixels, social media plugins, or embedded third-party content such as videos or maps. I do not run automated tracking of any kind.

PurposeLegal basis (GDPR)
Replying to your inquiry and preparing a proposalYour consent, given when you submit the form and tick the checkbox (Art. 6(1)(a)), and steps taken at your request before entering a contract (Art. 6(1)(b))
Delivering the site and keeping it secureMy legitimate interest in running a secure and reliable website (Art. 6(1)(f))
Carrying out a project if we work together, including invoicingPerformance of a contract (Art. 6(1)(b)) and compliance with legal obligations such as tax and accounting rules (Art. 6(1)(c))
Handling legal claims or complaintsMy legitimate interest in defending my rights (Art. 6(1)(f))

You can withdraw your consent at any time. Withdrawing does not affect processing that took place before.

I do not use your data for marketing, newsletters or profiling unless you explicitly ask me to.

Who receives your data

I do not sell your personal data, and I do not share it for advertising or cross-context behavioral advertising. I use a small number of service providers (processors) who handle data on my behalf and only on my instructions:

  • Website hosting, DNS and security: Cloudflare, which serves the site and processes technical data such as IP addresses.
  • Contact form processing: Hetzner, where the automation that receives form submissions runs, on servers located in the European Union.
  • Email: Google Mail, which handles my correspondence.
  • Professional advisors such as an accountant or lawyer, only where necessary and under a duty of confidentiality.
  • Public authorities, only when I am legally required to disclose data.

Where the GDPR requires it, I have a data processing agreement with each processor.

Where your data is stored and international transfers

Contact form submissions are stored on servers located in the European Union. Some of my providers, such as Cloudflare, are based in the United States or operate globally, so technical data such as your IP address may be processed outside the European Economic Area. In those cases, the transfer relies on an adequacy decision (for example the EU-US Data Privacy Framework, for certified companies) or on Standard Contractual Clauses approved by the European Commission.

If you are visiting from the United States or another country outside the EU, please be aware that your personal data will be processed in the European Union and handled under EU data protection standards.

How long I keep your data

  • Inquiries that do not lead to a project: up to 12 months after our last communication, then deleted.
  • Clients: for the duration of the project, and afterwards for as long as tax, accounting or limitation rules require me to keep records.
  • Technical data: according to the retention periods of the hosting provider, which are short and not under my control.

If you ask me to delete your data earlier, I will do so unless I must keep it by law.

Cookies and similar technologies

This site does not set cookies and does not store or read information on your device. For that reason no cookie banner or consent request is shown. If this ever changes, for example if I add analytics or embed third-party content, I will update this policy first and ask for your consent before using any non-essential technology, as required by the ePrivacy rules and Spanish law (LSSI).

Your rights under the GDPR

If you are in the European Economic Area, the United Kingdom or Switzerland, you have the right to:

  • Access the personal data I hold about you and receive a copy
  • Rectify data that is inaccurate or incomplete
  • Erase your data (“right to be forgotten”) where there is no reason for me to keep it
  • Restrict processing in certain cases
  • Data portability: receive your data in a commonly used format
  • Object to processing based on legitimate interest
  • Withdraw consent at any time

To exercise a right, email hello@sergops.com. I will respond within one month. I may ask you to confirm your identity so that data is not disclosed to the wrong person. There is normally no charge.

You also have the right to lodge a complaint with a data protection authority. In Spain this is the Agencia Española de Protección de Datos (AEPD, www.aepd.es). You can also contact the authority of the country where you live or work. I would appreciate the chance to address your concern first.

Your rights if you live in the United States

Depending on the state where you live, such as California, Colorado, Connecticut, Virginia or others, privacy laws may give you the right to:

  • Know what personal information I collect, use and disclose
  • Access and obtain a copy of your personal information
  • Correct inaccurate personal information
  • Delete your personal information
  • Opt out of the sale or sharing of personal information and of targeted advertising
  • Not be discriminated against for exercising these rights

In practice: I do not sell personal information, I do not share it for cross-context behavioral advertising, I do not use it for targeted advertising or profiling, and I do not intentionally collect sensitive personal information. Even if a particular state law does not apply to a business of my size, I am happy to honor these requests.

To make a request, email hello@sergops.com. I may need to verify your identity before acting on it. You may use an authorized agent, in which case I may ask for proof of their authorization. I will respond within the time required by the applicable law, generally within 45 days.

Because this site does not track you, there is nothing for a “Do Not Track” or Global Privacy Control signal to switch off.

Children

This site and my services are aimed at businesses and are not directed to children. I do not knowingly collect personal data from anyone under 16. If you believe a child has sent me personal data, please write to me and I will delete it.

Automated decisions

I do not make decisions about you based solely on automated processing or profiling that produce legal or similarly significant effects.

Security

The site is served over HTTPS. I keep the amount of personal data to a minimum, limit access to it to myself, and use reputable providers with appropriate security measures. No system is completely secure. If a personal data breach occurs that puts your rights at risk, I will notify you and the competent authority as required by law.

The site may link to other websites, such as LinkedIn or GitHub. I am not responsible for their content or privacy practices, so please read their policies.

Changes to this policy

I may update this policy, for example if I add a new tool or the law changes. The date at the top shows the latest version. I will not make changes that reduce your rights without your consent where the law requires it.

Contact

For any question about this policy or about your data, write to hello@sergops.com.