Privacy policy
Last updated: .
Data controller
Oritia is the digital services brand of ORITIA DEVELOPMENT LLC.
- Tax ID: 3892003L.
- Address: W49R+H9J Gustavia, St Barthélemy.
- Country of establishment: St Barthélemy.
- Contact and data protection rights: oritiadev@gmail.com.
1. Data we process and its origin
We process the details you provide when contacting us: name, email, project type and message. Business name and current website are optional. Asterisk-marked fields let us handle your enquiry; leaving optional fields blank does not prevent submission. We also process subsequent correspondence exchanged with you.
The enquiry includes a reference, date and source. When available, we use the IP address to limit abuse and identify duplicates. Your selected language helps prepare response emails. Infrastructure may record IP addresses, browser information, requests, errors and security signals.
An unsent form stays in memory during internal navigation. It is lost when the tab is reloaded or closed and cleared after a confirmed submission. Its fields are not stored in cookie preferences.
2. Processing purposes
We use data to answer enquiries, assess requirements, prepare proposals and maintain related communications. When an enquiry is saved, the system requests a confirmation email to your address and a notification containing the enquiry to Oritia's mailbox. Delivery also depends on providers and the recipient's filters.
Technical data supports service delivery and protection, incident investigation and abuse prevention. Hosting also incorporates visit measurement using browsing data, described in the cookie policy. This measurement is separate from form data and security controls.
An enquiry does not subscribe you to advertising or a newsletter. We do not sell contact-form data or use it to make solely automated decisions with legal or similarly significant effects on you.
3. Grounds for processing
Processing is governed by applicable data protection law, including the European Union General Data Protection Regulation where its territorial scope applies.
By sending an enquiry, you request its handling and authorise use of the information to respond and communicate with you. Where you request a service for yourself and the GDPR applies, steps needed to prepare a proposal rely on pre-contractual measures at your request under Article 6(1)(b). Communications with business representatives and proportionate service protection rely, where applicable, on legitimate interests in managing that relationship and preventing abuse under Article 6(1)(f).
We handle rights requests and official demands under applicable legal obligations. Where processing needs consent, it must be specific, informed and withdrawable. Form submission does not authorise advertising or optional analytics. The cookie policy explains available controls and the scope of hosting measurement.
4. Recipients and providers
Enquiries may be accessed by authorised people handling them for Oritia and providers needed to deliver the service. Depending on their involvement, providers may act as processors or process certain information under their own legal responsibilities.
Data may also be disclosed to authorities where legally required and advisers where necessary to handle claims or defend rights, limited to relevant information.
- Lovable: website hosting and operation, platform visit measurement and managed transactional email delivery.
- Supabase: storage of contact enquiries.
- Cloudflare: site delivery, traffic management and protection against bots and other abuse.
- Google/Gmail: receipt and handling of correspondence at oritiadev@gmail.com. Form notifications include the information you submit.
- Your email provider takes part in delivering replies and confirmations.
5. International processing
Oritia manages its activity from St Barthélemy. Infrastructure and email providers operate internationally and may process data in the United States and other countries depending on service and configuration. The owner's address alone does not determine where servers or backups are located.
Where an international-transfer regime applies, each transfer must have the mechanism and safeguards that regime requires. Hiring a provider or submitting an enquiry does not replace those safeguards. You may request information about recipients, countries and safeguards relevant to your processing through the privacy email.
6. Retention criteria
Enquiry retention is linked to the time needed to respond, complete project assessment and close related discussions or proposals. If a service is contracted, necessary information becomes part of managing that relationship and its applicable legal retention periods.
After the purpose ends, further retention is limited to what is necessary for legal obligations or to establish, exercise or defend claims for the applicable periods. Criteria include the nature of the enquiry, any contract, documentary obligations and limitation periods. The possibility of future contact does not authorise indefinite retention.
IP addresses and technical logs must be kept only as long as needed to prevent or investigate incidents. Emails and backups must also respect these criteria. The form does not automatically delete data on a fixed date; you may request erasure and information about any legally necessary retention.
7. Rights and complaints
Write to oritiadev@gmail.com to find out what data we process about you and request access, updating, rectification or erasure. You may object, request restriction or portability where applicable and withdraw consent to processing based on it without affecting its previous lawfulness.
Specify your request and the information needed to locate your relationship with Oritia. Do not send identity documents initially: proportionate additional information will be requested only if needed to verify identity. Applicable legal response periods apply; under the GDPR, the general period is one month, subject to its justified extensions.
You may contact the competent authorities or courts. If processing is subject to the GDPR, you may complain to a data protection authority, particularly in the member state of your habitual residence, work or the alleged infringement; in Spain, this is the Spanish Data Protection Agency. Contacting Oritia first is not a condition for exercising this right.
8. Security and responsible form use
The application validates submissions on the server and restricts public access to contact records. These measures reduce risk but do not guarantee the complete absence of incidents. Report suspected misuse of your data or impersonation of Oritia through the contact email.
The website is intended for people requesting services for businesses and professional projects, not for minors to contract independently. Avoid sensitive information, credentials, payment details or unnecessary third-party data. Appropriate channels and conditions for special documentation will be agreed beforehand.
9. Changes to this policy
The update date identifies this version. Material changes in purposes or processing will be communicated appropriately, with new authorisation obtained where necessary. Publishing a new version does not make earlier processing consented to or, by itself, expand the use of data already provided.