← Back to the site

Privacy Policy

Last updated: 20 July 2026

This page explains what data Osairis processes, why, with which providers, and what your rights are. The principle is simple: no advertising cookies, no marketing trackers, no individual profiling.

Data controller

The website osairis.ai is published by Gabrio Design, an independent web design studio based in Belgium.

The full administrative identity, registration number and business address will be completed once the legal structure is finalised and before any formal commercial contracting.

For any question or request regarding your data, write to [email protected] with “GDPR request” in the subject line.

Data collected

Contact form — where one is provided, it may collect your name, email address, message and an invisible anti-spam field.

Technical logs — like any website, the host and the delivery network record connection data: IP address, browser type, requested page, timestamp and referrer if any.

No account, no advertising profile and no individual browsing history is built.

Purposes

Form data is used solely to read your message and reply to you.

Technical logs are used to keep the site available, fast and protected against abuse (attacks, malicious bots).

Legal basis

Messages sent through the form are processed on the basis of your voluntary request and the legitimate interest in answering enquiries received (Art. 6(1)(f) GDPR).

Security and hosting logs rely on the legitimate interest in protecting the site and its infrastructure.

Processors and transfers

Vercel Inc. (United States) — website hosting.

Cloudflare, Inc. (United States) — delivery network, HTTPS and security layer; processes IP addresses and request metadata in that role.

Formspree, Inc. (United States) — delivery of contact form messages, where applicable.

These providers may process data outside the European Economic Area under their own data protection terms and transfer mechanisms.

Retention

Messages received are kept for as long as needed to handle the request, and at most 12 months after the last exchange.

Technical logs are retained under the operational policies of the host and the delivery network, for a limited period.

Cookies and trackers

This site uses no advertising cookies, no tracking pixels and no profiling tools.

The audience measurement described in the next section is cookieless and involves no profiling. If a marketing, advertising or profiling tool were added in the future, this page would be updated and, where the law requires it, a consent mechanism would be put in place before any non-essential cookie is stored.

Audience measurement

This site uses Cloudflare Web Analytics and Vercel Analytics, aggregate statistics tools that set no cookies, use no advertising identifiers and cannot identify you individually.

They only report global figures: number of visits, pages viewed, approximate origin and rendering performance. No profiling or individual tracking is performed, and no data is ever sold.

Your rights

You have the right to access, rectify, erase, restrict, port and object to the processing of your personal data.

To exercise them, write to [email protected].

You may also lodge a complaint with the Belgian Data Protection Authority (APD/GBA), Rue de la Presse 35, 1000 Brussels — autoriteprotectiondonnees.be.

Security

The site is served exclusively over HTTPS, with security headers and protection against malicious bots.

A vulnerability reporting address is published at /.well-known/security.txt.