Privacy · updated 8 September 2026
Minimal data. A clear purpose.
The site’s own code uses no visitor analytics, advertising, profiling, cookies or persistent browser storage. Submitted enquiries are stored encrypted in private storage on this site’s own server for 90 days.
Controller and contact.
Michael Paavola, Finland, is the controller for this site and its enquiries. Use the contact form below; choose Privacy request for data-protection matters. The form shows a reference only after storage is confirmed.
Contact formNo cookies or visitor analytics.
The site’s own code sets no cookies, uses no localStorage or sessionStorage, builds no profile, transmits no interaction data and requests no location. Animation reacts locally to pointer and keyboard input; those reactions are neither stored nor transmitted. This is why the site shows no cookie banner.
Language without location tracking.
The first page request may use the browser-supplied Accept-Language header to choose Finnish or English. Finnish is selected only when the browser prefers Finnish; otherwise English is the default. The choice is not inferred from the IP address or saved in a cookie or browser storage.
Technical delivery and security.
Cloudflare carries encrypted web traffic between the public domain and the mAI-Verse origin. It may process an IP address, request time, route, browser technical headers and security signals to deliver and protect the service, and may use strictly necessary security technology when required. The site’s own origin intentionally does not write visitor access logs.
Private enquiries.
The form sends your name, reply address, topic and message to this site’s server. Storage adds an opaque reference, receipt time and handling status. Records are protected by Windows user-bound encryption and access controls outside the public website. Michael reviews them locally. There are no attachments, AI analysis or automatic emails. Before submission, the draft exists only in this page’s memory.
Purpose, legal basis and retention.
Site delivery, security and handling ordinary enquiries rely on legitimate interests (GDPR Article 6(1)(f)). Steps you request before a contract may rely on Article 6(1)(b); handling data-protection rights relies on the legal obligation in Article 6(1)(c). Enquiry details expire 90 days after receipt. Cleanup runs at startup and every 15 minutes while the server is running; expired records are not returned when read. Files on a powered-off server are removed when it resumes. No separate message backups are made. After deletion, only the opaque reference and deletion time are retained for up to 90 more days to prevent replay. This is not a promise of forensic disk erasure.
Rights and request channel.
Where applicable, you may request access, correction, deletion, portability or restriction, and object to processing based on legitimate interests. Choose Privacy request and include your earlier reference if available. Do not send identity documents. Requests are verified before disclosure or deletion and handled without undue delay, normally within one month. You may complain to the Data Protection Ombudsman.
Providers and international transfers.
Enquiries are not stored in Google Sheets or another external database. They remain on the server controlled by Michael. Cloudflare, Inc. carries and protects web requests, including form submissions. HTTPS terminates at Cloudflare’s edge before the encrypted tunnel to the origin, so Cloudflare can process submitted content. Its international network and subprocessors may process data outside the EEA. Cloudflare’s data-processing terms describe transfer safeguards, including applicable standard contractual clauses; processing is not exclusively within Finland.