Privacy

Privacy notice

Effective date: 21 September 2026

1. Who is responsible

Claudiu Doca, trading as CAFFTER, is responsible for the personal information described in this website-and-enquiry notice.

Public business/service address: 34 Coral Close, Romford RM6 5EH.

Public support and privacy contact: support@caffter.com.

2. What this notice covers

This notice covers visits to the public information website and messages that people choose to send to the public support address or business/service address.

This website-and-enquiry notice does not describe personal information handled inside the unfinished CAFFTER app, including accounts, business profiles, Business Activity, uploaded media, AI processing or connected platforms. A separate App/provider privacy notice will be needed after the relevant App and provider processing facts are verified. This website notice must not be used as the App/provider notice.

3. Information handled

Website visits

The website source is static. It contains no contact form, account creation, payment collection, upload feature, analytics, advertising tracker, cookie, browser storage, third-party embed or client-side script.

The Website is hosted using Cloudflare Workers Static Assets. Cloudflare may process technical information needed to deliver and protect the site, such as IP address, requested page/URL, browser/device/system information, timestamps, and traffic-routing/security data. CAFFTER has not configured client-side analytics, advertising tracking, third-party embeds or client-side scripts.

Support and privacy enquiries

When someone contacts CAFFTER, the information may include their name and contact details, the message and any attachment they choose to send, and the related correspondence and case notes needed to respond.

People should not send passwords, sign-in codes, access tokens, payment details, identity documents or customer records unless CAFFTER has specifically confirmed that they are necessary and provided an appropriate route.

4. How enquiries are received and answered

Inbound delivery to support@caffter.com has been verified. Cloudflare Email Routing forwards incoming messages to a Google Gmail inbox controlled by Claudiu.

If Claudiu replies manually, the reply will come from the actual Gmail address used to send it, which the recipient will see; CAFFTER does not claim that replies are sent from support@caffter.com.

No automated reply, marketing use, additional mailbox reader or guaranteed response time is established by this notice.

5. Purposes and lawful bases

Ordinary enquiries and support

CAFFTER uses the minimum information needed to understand, respond to and follow up an enquiry, keep the Website and correspondence secure, and maintain a short record for troubleshooting or complaint continuity. CAFFTER relies on legitimate interests for this processing. The purpose, necessity and balancing assessment, including reasonable expectations, likely impact and safeguards, was recorded on 21 September 2026.

Privacy-rights correspondence

CAFFTER will use the minimum information needed to identify, assess and respond to a privacy-rights request. The applicable legal basis and any necessary identification step will depend on the circumstances and will be recorded when a request is handled. Identity documents will not be requested routinely.

Other exceptional records

A complaint, security incident or documented legal hold may require a limited record for a specific legal, security or dispute purpose. The reason, lawful basis, minimum information retained and next review date must be recorded for each exception.

6. Recipients and international transfers

Enquiry information is intended to be accessible only to Claudiu as CAFFTER's support and privacy owner, and to service providers that transmit or store it as needed: Cloudflare for inbound email routing and Website delivery, and Google LLC through Gmail for the receiving inbox.

Cloudflare and Google LLC operate and process information internationally. Both providers publicly describe use of the UK Extension to the EU-US Data Privacy Framework (DPF) for UK-to-US transfers. Cloudflare also describes contractual safeguards under its self-serve Data Processing Addendum (DPA) where applicable. These are provider statements; CAFFTER has not independently certified those frameworks. CAFFTER does not claim UK-only storage, Google Workspace protections, a CAFFTER-specific Google processor/DPA arrangement, or project-specific Cloudflare localisation.

7. Retention

For an ordinary enquiry or support case, CAFFTER will retain the relevant content while it is needed to resolve the case and for six months after closure. It should be deleted earlier when no longer needed.

A monthly review will identify expired ordinary cases and remove them at the next review, no later than seven months after closure. Unnecessary attachments and identity copies will be removed promptly when their purpose ends.

For a complaint, privacy request, security incident or documented legal hold, CAFFTER will retain only the minimum justified record for the specific purpose. The reason and a next review date no more than 90 days away will be recorded. This is not a blanket six-year retention rule.

Deletion from CAFFTER-controlled inbox, sent items, exports and paper records does not mean immediate deletion from provider backup or security systems. Google states that deleted Gmail messages first move to Bin and are permanently deleted after 30 days unless deleted forever sooner; its wider storage systems and encrypted backups can retain data for longer under its published deletion process.

These retention periods apply from the effective date, 21 September 2026. From publication, the manual process includes inbox and post checking, minimal case records, privacy-rights deadline tracking and monthly retention reviews.

8. Privacy rights

Depending on the circumstances, rights may include access, correction, deletion, restriction, portability and objection. Some rights are limited or do not apply to every lawful basis. A request will be assessed under the law that applies at the time.

You can also raise a concern with the UK Information Commissioner's Office. Contacting the ICO does not prevent you from contacting CAFFTER first.

9. Cookies and automated decisions

CAFFTER's Website source sets no cookies and runs no analytics, advertising or AI. Verification of the previously deployed Website version observed no CAFFTER client-side script or tracker and no Set-Cookie response header; the production release is verified separately after deployment. This is distinct from Cloudflare's server-side technical processing described above. CAFFTER does not use website-visit or enquiry information to make solely automated decisions about people.

10. Updates

This notice is effective 21 September 2026. Future updates will be made if the Website, providers, purposes or enquiry process changes.