Privacy Policy

This site sets no cookies, runs no analytics and loads nothing from a third party. There is very little to disclose, and this policy is short because of that rather than in spite of it.

1. Introduction

Kappataf, operated by Konstantinos Tsaldaris ("Kappataf", "we", "us" or "Company"), is committed to protecting your privacy and ensuring you have a positive experience on our website www.kappataf.com ("Site"). This Privacy Policy explains how Kappataf collects, uses, discloses and safeguards your information, in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

2. Data Controller

Kappataf is the Data Controller responsible for your personal data, operated by Konstantinos Tsaldaris (Founder/Owner), Greece. For data privacy inquiries, please contact us at:

email support ↗
Website: www.kappataf.com

3. Information We Collect

3.1 What the Site stores on your device

Three values, all held by your own browser and none of them sent anywhere:

  • kt-theme, in local storage. Remembers whether you chose the light or the dark theme so the choice survives between visits. It holds the word "light" or "dark" and nothing else.
  • pt-reveal, in session storage. A single flag telling the next page to play its arrival animation. It is deleted the moment that page reads it, and in any case disappears when you close the tab.
  • kt-dots-time, in session storage. One number, the elapsed time of the animated footer texture, so it does not restart from zero on every page. It disappears when you close the tab.

None of these is a cookie, none identifies you and none leaves your device. Clearing your browser data removes all three, and the Site works normally without them.

3.2 Correspondence

There is no contact form on this Site. If you write to us, we receive your email address, your message, anything you attach, and whatever you choose to tell us about yourself or your project.

3.3 Server logs

The Site is served by Cloudflare Pages. As with any web host, their servers necessarily see the technical details of a request in order to answer it and to protect the Site from attack: IP address, the page requested, and the browser user-agent string. That processing is carried out by Cloudflare on our behalf as hosting provider and is described in their own privacy documentation. We have no access to an identifiable log of visitors and we do not build one.

3.4 What we do not collect

  • No analytics of any kind. There is no Google Analytics, no Plausible, no Matomo, no self-hosted counter.
  • No advertising, no remarketing, no tracking pixels, no fingerprinting.
  • No embedded third-party content. Typefaces are served from this domain, not from a font service, so no request about you reaches anyone else.
  • No newsletter, no mailing list, no account, no login, no profile.
4. Purpose of Data Processing

We process personal data only for the following purposes:

  • To respond to and manage your project inquiries.
  • To provide quotes and service information.
  • To carry out a project once it has been commissioned.
  • To comply with legal and tax obligations.
  • To protect the Site and its users from fraud and security threats.
5. Legal Basis for Processing (GDPR Article 6)
ActivityLegal Basis
Correspondence and project inquiriesLegitimate Interest, Article 6(1)(f), and steps taken at your request prior to entering a contract, Article 6(1)(b)
Performing a commissioned projectContract, Article 6(1)(b)
Server logs, security and fraud preventionLegitimate Interest, Article 6(1)(f)
Retention of project and invoicing recordsLegal Obligation, Article 6(1)(c)
Theme and animation preferences on your deviceStrictly necessary to provide the service you requested. No consent required, and no personal data is involved
6. Data Recipients (Third Parties)

6.1 Service Providers

  • Cloudflare — hosting, content delivery and denial-of-service protection for the Site.
  • Our email provider — receives and stores correspondence sent to our address, as any mail provider does.

That is the complete list. No analytics provider, no advertising network, no video platform, no marketing platform receives anything from this Site.

6.2 Other Recipients

  • Our accountant and legal advisers, where a project record requires it.
  • Legal authorities, if required by law.

We do not sell personal data, and we do not pass it to anyone for their own marketing.

7. Data Retention
Data TypeRetention Period
Inquiries that do not become projectsDeleted once the enquiry is clearly closed, and in any case within 12 months
Project correspondence and filesFor the duration of the project and as long as the professional and tax record requires
Invoices and accounting recordsAs required by Greek tax law
Server logsHeld by Cloudflare under their own retention schedule. We keep no copy
Browser storage valuesUntil you clear your browser data, or until the tab closes for the two session values
8. Your Rights Under GDPR

8.1 Right of Access. You have the right to request a copy of the personal data we hold about you.

8.2 Right to Rectification. If any personal data we hold about you is inaccurate or incomplete, you have the right to have it corrected or completed without undue delay.

8.3 Right to Erasure. You can request deletion of your personal data in the circumstances set out in Article 17, the "right to be forgotten".

8.4 Right to Restrict Processing. You can request that we limit how we use your data.

8.5 Right to Data Portability. You can request your data in a structured, commonly used, machine-readable format.

8.6 Right to Object. You can object to processing based on legitimate interest.

8.7 Right to Withdraw Consent. Where we process data on the basis of consent, you can withdraw that consent at any time without affecting the lawfulness of processing carried out before the withdrawal.

To exercise any of these rights: email support ↗

9. Cookie Policy

This Site sets no cookies. Not essential ones, not performance ones, not functional ones, not marketing ones. Because nothing is stored that requires consent, there is no cookie consent banner, and its absence is deliberate rather than an oversight.

The three values described in section 3.1 are held in the browser's own local and session storage rather than in cookies, are strictly necessary to deliver the appearance you asked for, contain no identifier and are never transmitted. You can remove them at any time by clearing site data in your browser.

If analytics, advertising or an embedded booking tool are ever added to this Site, this section will be rewritten before they go live and a consent mechanism will be in place from the first day they run.

10. Data Security

We implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure or destruction. These measures include:

  • HTTPS with modern TLS across the whole Site, with HTTP Strict Transport Security enforced.
  • A strict Content Security Policy, with every script pinned by hash, so no third-party or injected code can execute.
  • A static build with no database, no server-side application, no user accounts and no administrative interface exposed to the public internet.
  • Referrer, frame-ancestor, MIME-type and permissions policies set to their restrictive values.
  • Project files and correspondence kept on encrypted storage, with access limited to those working on the project.
11. International Data Transfers

Personal data may be transferred to and processed in countries outside the European Union, for example by Cloudflare, whose network is global. These transfers are protected by appropriate safeguards, including Standard Contractual Clauses and adequacy decisions where applicable.

12. Contact Information

Data Controller: Kappataf, operated by Konstantinos Tsaldaris (Founder/Owner), Greece.

email support ↗
Website: www.kappataf.com

Response time: we will respond to your request within 30 days, as required by GDPR Article 12.

13. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in our practices, technology or legal requirements. Significant changes are published here with a new date at the top of the page. There is no archive of earlier versions; the current text is the whole of it. Your continued use of the Site after a change constitutes acceptance of the updated policy.

14. Right to Lodge a Complaint

You have the right to lodge a complaint with your local Data Protection Authority if you believe we have violated your rights under the GDPR. In Greece this is the Hellenic Data Protection Authority, at www.dpa.gr.