The form requires a reason, name, email, message and consent; organisation and phone number are optional. It does not add UTM, referrer, language or internal identifiers to the submission.

1. Scope

This policy describes the processing associated with fernandoarrieta.org. The primary framework is Argentina's Law 25.326. Regulation (EU) 2016/679 or Brazil's LGPD will apply only when their respective scope criteria are met; merely visiting from another jurisdiction is not presented here as an automatic legal conclusion.

2. Data controller

The data controller is Fernando Arrieta, owner of fernandoarrieta.org. For privacy enquiries or to exercise a right, write to contact@fernandoarrieta.org with the subject line “Privacy — rights request”.

3. Data processed

The web infrastructure receives the technical data needed to handle an HTTP request and may generate operational logs depending on the provider's configuration. At the form endpoint, the connection IP address is used in memory to limit repeated submissions. Only a pseudonymous HMAC token remains, which does not allow lists of candidate IP addresses to be tested without the server's secret key; neither the IP address nor the token is added to the email. Google explains that GA4 uses the IP address during collection for functions such as approximate geolocation and routing, and discards it before logging it on its servers; this is a statement by the provider, not a transformation performed by this site.

The form does not request sensitive data, credentials, identity documents or confidential information. As the message is free text, someone could include such information on their own initiative: we ask that they do not. If unnecessary data is received, its use will be limited to understanding the request, and any erasure request will be honoured unless there is a legal obligation to retain it.

4. Purposes and basis

  • Reply to the message · consent expressed in the form; where applicable, also steps requested before a professional relationship.
  • Prevent abuse · channel security and service availability.
  • Measure audience · separate consent in the banner; rejecting does not affect the site.
  • Meet obligations · when an applicable law requires information to be retained or disclosed.

The form is not used for scoring, automated decisions, data sales, behavioural advertising or automatic addition to commercial mailing lists.

5. Recipients and transfers

  • Hosting and email infrastructure · process the technical transmission and delivery to the personal inbox. The endpoint supports the hosting provider's transport or Resend, depending on the server's active private configuration. Confirmation of the current provider may be requested through the privacy channel.
  • Google Analytics · receives measurement data only after valid acceptance. Its processing may be international and is also governed by Google's privacy policy.

No general guarantee is made about the exact country of processing or contractual mechanisms that cannot be verified from this public interface. Where an international transfer requires safeguards, those appropriate to the provider and the applicable legal framework will be applied.

6. Retention

7. Automated decisions

The site does not use form information to make automated decisions with legal or comparable effects, or to score or profile the person writing. Google Analytics produces statistical measurements after opt-in; it plays no part in replying to the message.

8. Rights

You may request confirmation and access, correction or updating, deletion where applicable, withdrawal of consent and any other rights recognised by the applicable law. In Argentina, the AAIP specifies 10 calendar days to respond to an access request and 5 working days for rectification, updating or deletion. Under GDPR, where applicable, the general rule is one month, with a possible two-month extension in the circumstances set out in Article 12. The LGPD provides for, among other rights, confirmation, access, correction, deletion in certain cases and withdrawal of consent.

Official sources: rights before the AAIP, GDPR on EUR-Lex and rights according to Brazil's ANPD.

To protect the data subject, proportionate verification may be requested, preferably through the email address associated with the message. Do not send an identity document unless a justified request is made; if it is essential, conceal any details that are not necessary.

9. Security measures

The channel uses HTTPS in transit, a closed list of fields, length and size limits, origin validation, a honeypot and HMAC-based rate limiting, a dedicated key, restricted permissions, an atomic lock and global TTL-based clean-up. Content is escaped before the email is constructed. The IP address, anti-abuse token, UTM, referrer, language and internal identifiers are not included in the message. The Analytics tag is not downloaded before acceptance.

No measure eliminates all risk. An incident will be assessed and, where appropriate, reported to individuals or authorities within the period required by the applicable law.

10. Minors

The site and its form are not intended for minors. If it is detected that a minor has submitted data without the necessary authorisation, their representative may request a review or deletion through the privacy channel.

11. Changes

Material changes are reflected through a version number and effective date at this same URL. The policy does not replace an analysis of the law applicable to a specific case.

12. Supervisory authority and complaints

You may first contact the controller to try to reach a direct resolution. This does not limit your right to lodge a complaint with the competent authority:

WhatsApp G-CERTI