Privacy Policy
This policy explains what personal data is processed when you visit inquesticaconsulting.com or contact us, and the rights you have under the EU General Data Protection Regulation (GDPR).
Note: This text is a carefully prepared template for a static website without cookies or analytics, but it is not legal advice — please have it reviewed by a qualified data-protection professional or lawyer before launch.
1. Controller
The controller responsible for data processing on this website is:
Inquestica Consulting — Inhaber: Neeraj Khandelwal
Schützenstraße 21
12105 Berlin
Germany
Email: consult@inquesticaconsulting.com
2. Overview: our privacy-by-design approach
This website is deliberately built to process as little personal data as possible:
- It sets no cookies and uses no tracking, analytics or advertising services.
- It loads no third-party fonts, scripts or embeds, with a single exception: the bot-protection check on our contact form (see section 5).
- It is served over an encrypted connection (HTTPS) only.
3. Hosting and server log data
This website is hosted on Cloudflare Pages, a service of Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA, and its EU affiliate Cloudflare Germany GmbH. When you access the website, technically necessary data is processed by Cloudflare's servers to deliver the pages and protect the site against attacks. This may include your IP address, the date and time of the request, the requested URL, the referrer URL, browser type and version, and operating system.
Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in providing a secure, reliable and performant website.
Cloudflare processes this data on our behalf under a data-processing agreement in accordance with Art. 28 GDPR. Transfers to the USA are safeguarded by the EU–US Data Privacy Framework, to which Cloudflare is certified, and by the EU Standard Contractual Clauses. Further information: Cloudflare Privacy Policy.
4. Contact form and email
If you contact us via the contact form or by email, we process the data you provide (name, email address, optional organisation, selected topic and your message) exclusively to handle your enquiry and any follow-up questions.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures at your request) and, for general enquiries, Art. 6(1)(f) GDPR (our legitimate interest in responding to enquiries). Where you have given consent via the form checkbox, Art. 6(1)(a) GDPR applies; you may withdraw consent at any time with effect for the future.
Form submissions are transmitted over an encrypted connection and forwarded to our mailbox using a transactional email provider (Resend, Inc., 2261 Market Street, San Francisco, CA 94114, USA). We do not store submissions in a database on the website itself. Your data is deleted once your enquiry has been fully dealt with, unless statutory retention obligations require longer storage or a contractual relationship follows.
5. Bot protection (Cloudflare Turnstile)
To protect the contact form against automated abuse, we use Cloudflare Turnstile. When the contact page is loaded, Turnstile analyses technical signals from your browser (such as IP address, browser characteristics and interaction behaviour) to determine whether the request originates from a human. Turnstile does not use cookies for advertising and does not track you across websites.
Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in protecting the website and our mailboxes from spam and abuse. Provider: Cloudflare (see section 3).
6. Links to third-party websites
Our website contains links to external websites, such as our LinkedIn company page. When you follow such a link, the respective operator is responsible for the processing of your data. We have no influence over that processing; please consult the privacy policy of the respective provider (for LinkedIn: LinkedIn Ireland Unlimited Company).
7. Recipients and international transfers
Apart from the processors named in this policy (hosting, bot protection, email delivery), we do not pass your data to third parties unless we are legally obliged to do so. Where processors are located outside the EU/EEA, appropriate safeguards under Chapter V GDPR are in place.
8. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you (Art. 15);
- rectification of inaccurate data (Art. 16);
- erasure (Art. 17) and restriction of processing (Art. 18);
- data portability (Art. 20);
- object to processing based on legitimate interests (Art. 21);
- withdraw consent at any time with effect for the future (Art. 7(3));
- lodge a complaint with a supervisory authority (Art. 77), in particular in the EU member state of your residence, workplace or the place of the alleged infringement.
To exercise your rights, contact us at consult@inquesticaconsulting.com.
9. Data security
We apply technical and organisational measures appropriate to the risk, including transport encryption (TLS), strict browser security headers, a minimal-attack-surface static architecture and access controls for our systems.
10. Changes to this policy
We may update this policy to reflect legal or technical changes. The current version is always available on this page.
Last updated: September 2026