Context
This website
The site is designed to be server-rendered, uses no login or customer portal, and does not intentionally include analytics until configured. Enquiries are sent only when a delivery provider and durable rate limit are configured. Security headers, server validation, request-size limits, a honeypot, and minimum-submit-time checks reduce selected risks; they do not eliminate abuse.
Context
Data submitted through the form
Submitted fields are name, email, company, main challenge, and optional phone and industry. The application avoids logging enquiry content by design. The configured email provider and hosting platform process request data under the owner's accounts and terms. Retention and deletion practice must be completed by the owner before launch.
Action
Responsibility boundary
Client leaders remain responsible for risk acceptance, policies, regulatory interpretation, operational decisions, and qualified control-system or safety work. Project security requirements and evidence must be agreed for the actual environment.
