Last updated: 9 September 2026 · operator details pending
01
Controller and outstanding identity details
This website is presented under the AGE ONE brand at https://age-one.com. Privacy questions and requests may be sent to [email protected].
Before this policy can be published as a final legal version, it must identify the controller’s exact legal name and form, registered office, tax identifier, register number, and, if one has been appointed, the data protection officer’s contact details. AGE ONE is a brand and cannot replace the controller’s legal identity.
02
Scope and AGE ONE’s roles
This policy covers visits to this website, the project enquiry form, and communications initiated through the email addresses or telephone numbers displayed here. It does not automatically cover personal data processed inside a client’s product or a delivered project.
For these public website flows, the legal entity operating AGE ONE determines the purposes and means of processing and acts as controller. AGE ONE may act as a processor on a client project; that role must be governed by the applicable project contract and data processing agreement rather than this public policy.
03
Information, sources, and collection
Information you provide
- your name, email address, and project description;
- company and telephone number, if you choose to provide them;
- the selected project type and indicative budget range;
- content in later email or telephone communications.
Technical form information
The browser creates a random submission identifier for deduplication and sends the time at which completion started. If the administrator explicitly configures a trusted infrastructure IP header, the IP address is used temporarily for abuse limiting. The anti-spam trap field is not forwarded in the email.
Provider technical data
Network and hosting providers may create technical logs needed to deliver and secure the service. The exact fields and periods depend on AGE ONE’s account and contract settings and must be confirmed in the internal processing record.
04
Purposes and lawful bases
- Answering an enquiry
- Understanding the project, contacting the sender, and preparing a discussion or proposal. Where the individual who may contract asks for these steps, Article 6(1)(b) GDPR may apply.
- B2B correspondence
- Handling a representative’s business correspondence may rely on the legitimate interest in answering genuine enquiries under Article 6(1)(f) GDPR, subject to the required balancing test.
- Security and abuse prevention
- Validation, deduplication, request limiting, and service defence may rely on the legitimate interest in keeping the website safe and available under Article 6(1)(f) GDPR.
- Legal duties and claims
- Information may be retained or disclosed to meet a legal obligation under Article 6(1)(c) GDPR or where necessary to establish, exercise, or defend legal claims.
- Optional analytics
- An optional measurement tool loads only after explicit consent. Consent can be withdrawn through the permanent cookie-settings control.
05
Required and optional fields
Name, email, project type, indicative budget, and description are required by the form so that an enquiry can be assessed and delivered. Company and telephone number are optional. If you prefer not to use the form, you may email AGE ONE directly.
Providing this information is not a statutory requirement and no solely automated decision is made about you. Without the required fields, AGE ONE cannot receive the form or provide a useful response. Do not submit passwords, payment data, medical information, or other sensitive data.
07
Recipients and technical providers
Information may be accessible, only as necessary, to:
- authorised people who handle AGE ONE enquiries;
- Cloudflare network/security services and Hetzner hosting used by the published configuration;
- Resend when email delivery is configured, together with the destination mailbox provider;
- professional advisers or public authorities where access is necessary and has a lawful basis.
Source code cannot establish the exact contracted legal entities, their roles, processing regions, DPAs, subprocessors, or provider retention. Those facts must be taken from AGE ONE’s accounts and contracts before final publication.
08
Transfers outside the European Economic Area
Some providers may involve access or processing outside the EEA. A transfer may take place only through a mechanism allowed by Chapter V GDPR: an adequacy decision applicable to the exact entity or, where appropriate, suitable safeguards such as the Standard Contractual Clauses together with the necessary transfer assessment and supplementary measures. A US entity’s certification can be checked in the official DPF list, while Decision (EU) 2021/914contains the Standard Contractual Clauses for transfers.
The relevant accounts and contracts were not supplied for audit. This version therefore does not make an unsupported claim that any specific entity is actively certified under the EU–US Data Privacy Framework and cannot yet list transfers or provide copies of safeguards.
09
Retention and deletion
The local analytics preference remains in the browser until the user clears it or its version becomes invalid. The form’s technical rate-limit window expires after 15 minutes; expired entries are removed from process memory during later checks.
Delivered enquiries reach the configured email system. If the discussion continues, relevant information may become part of the pre-contractual or contractual record. Data must be deleted or anonymised when no longer needed and no legal duty or justified right requires retention.
AGE ONE has not supplied approved periods for unsuccessful enquiries, opportunities, clients, inboxes, logs, or backups. We do not publish invented periods: the concrete schedule and deletion procedure must be operationally approved before the final legal version.
10
Your rights
Subject to the GDPR conditions, you may request access, correction, deletion, restriction, and portability of data you supplied in a structured format. You may object to processing based on legitimate interests. Where consent is used, it may be withdrawn at any time without affecting earlier lawful processing.
Send a sufficiently clear request to [email protected]. AGE ONE may request only the additional information reasonably needed to verify identity. A response is generally provided within one month; this may be extended by two further months for complex or numerous requests, with notice during the first month. Rights are not absolute and any lawful exception will be explained.
11
Complaints and supervisory authority
You may contact AGE ONE first without limiting your right to complain. The Romanian authority is the National Supervisory Authority for Personal Data Processing (ANSPDCP); information and complaint materials are available on its official website. You may also contact the competent authority where you live, work, or believe an infringement occurred.
12
Children, security, and incidents
The project form is not designed for children and does not intentionally request information about minors. If such information is found to have been submitted without a legitimate reason, its deletion and any necessary measures will be assessed.
The application uses field validation, size limits, origin checks, deduplication, timeouts, and abuse limiting when the infrastructure chain is configured. No online transmission is risk-free. Incidents will be assessed and, where legally required, notified to the authority and affected individuals.
13
United States residents
The same consent-first analytics approach applies globally. For California visitors, this policy identifies collected categories, recipients, the change process, and revision date for CalOPPA purposes. The audited application code does not implement personal-information sales or cross-context behavioural advertising.
The CCPA applies only when the relevant legal entity meets its statutory conditions and thresholds. Before claiming CCPA rights or introducing sale/sharing, profiling, or behavioural advertising, AGE ONE must document applicability and implement all required mechanisms, including Global Privacy Control where applicable. Replying to an enquiry does not subscribe the sender to marketing; any future US commercial-email programme must separately comply with CAN-SPAM.
14
Changes, contact, and legal sources
This policy will be revised when the form, infrastructure, providers, or purposes change. Material changes will be identified through the revision date and, where appropriate, a prominent notice or direct communication. Questions may be sent to [email protected].
Primary official sources used for this version: