Who is responsible
Overspill Techonologics operates this website and is responsible for deciding how website personal information is used. Privacy questions can be sent to hello@overspill.net or through the contact form.
Information we collect
- Enquiries: name, email address, organisation, message, topic, status, and submission timestamps.
- Newsletter: email address, subscription request, and timestamps.
- Administration: authorised administrator email, Google/Supabase authentication identifiers, session information, and audit-relevant timestamps.
- Security and delivery: IP address, browser/request metadata, Turnstile results, hosting logs, and a one-way hashed rate-limit key. The rate-limit record does not store the raw email or raw IP address.
- Content you choose to load: third-party media providers may receive technical data after you actively load an embed.
Why we use it
- To review and answer enquiries and take steps requested before a possible business relationship.
- To send updates where a person has actively subscribed and to maintain a record of that choice.
- To authenticate authorised administrators and protect the website, forms, database, and users from abuse.
- To operate, diagnose, improve, and keep appropriate business records for the website.
- To comply with legal obligations and establish, exercise, or defend legal claims where necessary.
Depending on the situation, the applicable basis may be consent, steps taken at your request, legitimate interests in operating and securing the website and responding to business enquiries, or a legal obligation. You may withdraw newsletter consent at any time.
Service providers
Website information may be processed by Supabase for authentication, database, and storage services; Netlify for hosting, delivery, functions, and operational logs; Cloudflare Turnstile for bot and abuse prevention; and Google for administrator sign-in. These providers act under their own terms and may use infrastructure in more than one country.
Retention
- Enquiries are retained only while reasonably needed to respond, manage the relationship, keep appropriate records, or resolve a dispute. They should normally be reviewed for deletion within 24 months after the last meaningful interaction.
- Newsletter details are retained until unsubscribe or withdrawal, plus any minimal suppression record required to honour that choice.
- Rate-limit hashes are automatically removed after they become older than approximately two days when the limiter next runs.
- Administrator account and session data is retained while access is authorised and as required for security records.
Your choices and rights
Depending on the law that applies to you, you may ask for access, correction, deletion, restriction, portability, or objection, and may withdraw consent. We may need to verify identity before acting. You may also complain to the data-protection regulator that applies where you live or where the relevant processing occurs.
Children
This corporate website is not directed to children and is not designed to knowingly collect children’s personal information. Do not submit a child’s information through the forms.
Security and limits
We use access controls, server-side validation, rate limiting, human-verification checks, and restricted administrative access. No internet service can guarantee absolute security, so avoid sending secrets, credentials, health data, or other highly sensitive information through the contact form.
Changes
We will update the date above when this notice materially changes. Significant changes should also be reflected in the project handoff and operational records.