Privacy policy
What we do (and don't do) with your data
cra-experts.com is built to be useful without being intrusive. We collect the minimum we need to send you what you've asked for, and nothing more.
Last updated 7 May 2026
The short version
- We collect your name, email, product type, and company size when you submit the lead form, so we can send you the CRA brief and our newsletter.
- We use Cloudflare Web Analytics, which is cookieless and does not store IP addresses.
- We do not use Google Analytics, advertising trackers, third-party social pixels, or session-replay tools.
- We do not sell or share your data with advertisers.
- You can request access, correction, or deletion of your data at any time by emailing [email protected].
Who we are
For the purposes of the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the controller of any personal data submitted through this site is the operator of cra-experts.com. For privacy questions, write to [email protected].
What we collect
Information you give us directly
When you fill in the lead form on the home page or any landing page, we collect:
- Your name
- Your email address
- Your product type (mobile app, IoT, OSS, etc.)
- Your company size
We use this to send you the CRA briefing you requested and, if you've opted in, a weekly digest of regulatory updates. We don't ask for, store, or process more than this; there is no special category data, no health data, no financial data on this site.
Information collected automatically
We use Cloudflare Web Analytics for traffic measurement. Cloudflare's product is:
- Cookieless, so it doesn't drop a tracker on your device
- Does not store IP addresses
- Does not build cross-site profiles
Cloudflare's own privacy commitments for this product are documented at cloudflare.com/privacypolicy. That's the only analytics tool we use.
Legal basis
Under Article 6(1) of the GDPR, our legal bases are:
- Consent (Art. 6(1)(a)) — for sending you the CRA briefing and the newsletter, when you submit the lead form. You can withdraw consent at any time using the unsubscribe link in any email or by writing to us.
- Legitimate interest (Art. 6(1)(f)) — for measuring aggregate, anonymous traffic via Cloudflare Web Analytics so we can understand which content is useful and improve the site.
Where your data lives
Form submissions are stored in Cloudflare D1, the database service provided as part of our hosting on Cloudflare Pages. Cloudflare is therefore a data processor for us. They process data in accordance with their customer Data Processing Addendum.
We do not use any other data processors. Specifically, we do not use email-marketing platforms that copy our list off-server.
How long we keep it
- Lead-form submissions: retained for as long as you remain subscribed, plus 12 months after unsubscription, after which the record is deleted.
- Cloudflare Web Analytics: aggregated by Cloudflare; we do not export or store raw event data.
- Email correspondence: retained for 24 months unless you ask us to delete it sooner.
Your rights
Under the GDPR you have the right to:
- Access the data we hold about you
- Correct it if it's wrong
- Delete it (the "right to be forgotten")
- Export it in a portable format
- Object to processing on the basis of legitimate interest
- Withdraw consent at any time, where processing is based on consent
- Lodge a complaint with your national data protection supervisory authority
To exercise any of these, email [email protected]. We aim to respond within 14 days; the GDPR gives us up to 30.
International transfers
Cloudflare may process data outside the EU/EEA. They rely on the European Commission's Standard Contractual Clauses and their participation in the EU–US Data Privacy Framework as the basis for those transfers.
Cookies
This site does not use any cookies for tracking, analytics, or advertising. We don't display a cookie banner because there's nothing to consent to. The only cookies you might encounter are strictly technical ones set by Cloudflare's edge for security (e.g. bot mitigation), which fall under the strict-necessity exemption in the ePrivacy Directive.
Children
This site is aimed at compliance and engineering professionals. We don't knowingly collect data from anyone under 16. If you believe a minor has submitted information, write to us and we'll delete it.
Changes to this policy
If we change this policy, we'll update the "Last updated" date at the top and, for material changes, send a notice to subscribers. Material change means a change that expands what we collect, who we share it with, or how long we keep it.
Contact
Privacy questions, data requests, or complaints: [email protected].
Security issues (vulnerability reports) go to our security policy page instead.