Privacy
Privacy notice
Last updated 20 July 2026
This notice covers ferritesystems.com. It explains what we collect, why we are allowed to, how long we hold it, and what you can make us do about it. We have tried to write it in plain language; where a legal term is unavoidable we say what it means.
Who is responsible
Ferrite Systems (TO CONFIRM: registered entity name and postal address) is the controller of the personal data described here. Privacy questions and rights requests: privacy@ferritesystems.com.
What we collect
When you browse. Page addresses you visit, how far down each page you read, roughly how long you spend, which site referred you (the domain only, never the full link), any campaign tags in the URL, your country and region, and whether you are on a phone, tablet or desktop.
We do not store your IP address or your browser user-agent. They are converted on our server into a one-way key using a secret we replace every day and destroy after 48 hours, which makes older activity impossible to link back to you. Unless you opt in to return-visit attribution, that key changes at midnight and your visits do not accumulate into a profile.
When you contact us. Your name, email, and anything else you type into a form — company, role, phone, your message, and any estimate you generated. This goes into our customer records so we can reply and work with you.
What we never do. We do not sell or share personal information, and we never have. We do not use advertising cookies, ad networks, data brokers, session recording, or cross-site tracking. We do not run Google Analytics or any third-party analytics product. We do not make automated decisions that produce legal or similarly significant effects about you, and we do not profile you for advertising.
Why we are allowed to (legal bases)
- Consent — for usage analytics and return-visit attribution where you are in the EU, UK, Quebec, or anywhere else with an opt-in rule. Nothing optional runs before you click, and you can withdraw at any time via .
- Legitimate interests — for aggregate, non-identifying measurement of a site we operate, and for basic security and abuse prevention. We rely on this only where the law permits it and where the data cannot be traced back to you.
- Steps prior to a contract — for handling an enquiry you send us. If you ask us to quote or build something, we need your contact details to do it.
- Legal obligation — for keeping the record of your consent choice, which we are required to be able to demonstrate.
How long we keep it
- Daily hashing secrets — 48 hours, then permanently destroyed.
- Analytics events — 14 months, then deleted.
- Consent records — 3 years after the choice, because they are the evidence that the choice was made and honoured.
- Enquiries and customer records — for as long as we are working together, and up to 7 years afterwards where tax and contract law requires it.
Who else sees it
Our own infrastructure providers, and nobody else. The site runs on Vercel; our records are stored in a Neon Postgres database; notification email is sent through Resend. Each acts as a processor under contract and may not use your data for their own purposes. We do not disclose personal data to advertisers or data brokers.
These providers operate in the United States, so data about visitors in the EU, UK, and Canada is transferred there. Those transfers rely on Standard Contractual Clauses (and the UK Addendum where applicable) in our agreements with each provider.
TO CONFIRM: whether an EU/UK Article 27 representative must be designated — see the note in the source of this page.
Your rights
If you are in the EU, UK, or Switzerland you can ask us for a copy of your data, correct it, delete it, restrict or object to how we use it, take it elsewhere in a portable format, and withdraw consent at any time. Withdrawing does not undo what was lawful beforehand. You can also complain to your national data protection authority — for the UK, the ICO.
If you are in Canadayou can ask what we hold, correct it, and withdraw consent. Under Quebec’s Law 25 you can additionally request de-indexing, ask for your data in a portable form, and object to profiling — which we do not do. Everything optional is off by default for Quebec visitors. You may complain to the Office of the Privacy Commissioner of Canada, or to the Commission d’accès à l’information du Québec.
If you are in California or another US state with a privacy law you can request access, correction, deletion, and portability, and you can opt out of sale, sharing, and targeted advertising. We do not sell or share personal information, so there is nothing to opt out of — but the control is there anyway, and we honour Global Privacy Control automatically. We will not discriminate against you for exercising any of these rights.
To exercise any of the above, email privacy@ferritesystems.com. We answer within 30 days. We may ask you to confirm your identity first, and for anonymous analytics we may genuinely be unable to find any data that is yours — if the hashing secret has rotated, there is nothing left to look up.
Children
This site is for business audiences and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe we have, tell us and we will delete it.
Changes
If we change what we collect or why, we update the date at the top and ask for your choice again rather than quietly carrying the old one forward.
Related
The itemised list of every cookie and storage key is on the cookies page. For how we handle data inside delivered software, see compliance.