Privacy and Cookie Policy
Effective October 2, 2026. This notice explains what personal data Cabrillo Coast uses on this site, why we use it, how long we keep it, and your rights. It also explains cookies and browser storage.
Controller and scope
Cabrillo Coast is the controller for this site. We decide how to use personal data that you submit. We use it to answer inquiries, protect the site, and remember your choices. This notice applies to this public site and its consultation form.
For a privacy request, email [email protected]. Do not send credentials or confidential material through the form.
Data we process
- Consultation data. Name, email address, optional organization, and the system or decision description that you submit.
- Delivery data. When you submit the form, the email contains the submission time, Cloudflare request identifier, and country code. The Worker does not add your IP address to the email.
- Security signals. Cloudflare says that Turnstile can process your IP address, TLS fingerprint, user-agent header, site key, and website origin. It can also process technical details about the request, browser, and network.
- Preference data. An optional theme cookie and session-only theme or notice values, as described in the Cookie Policy below.
- Infrastructure data. Cloudflare processes technical request, network, and security details to deliver the site and run the form.
The form identifies its required fields. You do not have to use the form, but we cannot receive or answer a form request without the required details. If the form is unavailable, you cannot submit a consultation request through this site.
Purposes and legal bases
- INQUIRIES
- If you ask us to take steps before entering a contract, we use your details for those steps under GDPR Article 6(1)(b). For other business inquiries, we rely on our legitimate interest in receiving and answering them under GDPR Article 6(1)(f).
- SECURITY
- We detect bots, limit repeated requests, protect email delivery, and keep the form working safely. We rely on our legitimate interest in secure operation under GDPR Article 6(1)(f).
- THEME COOKIE
- We set the optional theme cookie only after explicit consent. The legal basis is GDPR Article 6(1)(a). You can withdraw consent by deleting the cookie or selecting CONTINUE WITHOUT COOKIE.
- SESSION CHOICES
- We use session-only values to apply your current theme choice and avoid repeating the notice. We rely on our legitimate interest in remembering these choices during the current tab under GDPR Article 6(1)(f). You can delete the values in your browser or close the tab. You can also contact us to object to this processing.
- LEGAL DUTIES
- We can retain or disclose limited records when law requires it. The legal basis is compliance with a legal obligation. GDPR Article 6(1)(c).
Turnstile can block the form if it detects automated abuse. This affects only whether this form sends. It does not make a legal or similarly important decision about you. If the form is blocked, you cannot submit a consultation request through this site. Privacy requests remain available through the address in the Contact section.
Cloudflare Turnstile addendum
We configure the consultation form to use Cloudflare Turnstile in Invisible mode. It checks for automated abuse before it enables Send. If the check fails, Send stays disabled.
Cloudflare acts as our processor when it handles security signals to protect this site. Cloudflare also states that it acts as a controller when it uses those signals to improve Turnstile bot detection. Cloudflare says it uses the signals for bot detection instead of identifying, profiling, or targeting individuals.
TURNSTILE PRIVACY ADDENDUM ↗ Read it with the CLOUDFLARE PRIVACY POLICY ↗.
Retention
- WORKER
- The Worker does not create a contact database. It does not persist the Turnstile token or form body after delivery.
- RATE LIMIT
- We send the connecting IP address to Cloudflare’s rate-limiting service. It uses the address to count requests during a 60-second window. Our Worker does not add the address to the email or create a separate IP-address record.
- CLOUDFLARE
- Cloudflare applies the retention criteria in its privacy policy to Turnstile and infrastructure data. Those criteria include purpose, data sensitivity, risk, legal duties, and whether less data can meet the purpose.
- INQUIRY
- We delete an inquiry that does not become an engagement within 24 months after the last interaction.
- ENGAGEMENT
- We normally keep relevant engagement records for up to seven years. We may keep them longer if a law or active legal claim requires it.
- BROWSER
- The theme cookie expires after one year. Session storage ends when this tab’s page session ends. Cloudflare and the mailbox provider apply their documented retention.
Your data-protection rights
Depending on the applicable law, you can ask for a copy of your data. You can ask us to correct or delete it. You can limit its use or ask for it in a portable format. You can object when we rely on legitimate interests. You can withdraw consent at any time without making earlier use unlawful. Legal exceptions can apply.
Email the privacy contact above. We can ask for information reasonably needed to verify your identity. You can complain to the public data-protection regulator where you live, work, or believe an infringement occurred.
Security, contact, and changes
We limit access to submissions and encrypt them in transit. We check for bots and limit repeated requests. Server configuration fixes the sender and recipient addresses. Visitors cannot choose email headers or recipients. No internet transmission or mailbox is risk-free.
Questions and rights requests: [email protected]. We will update the effective date when this notice materially changes.