Privacy Policy
Last updated · 27 June 2026
1. Scope
This Privacy Policy explains how personal data is processed when you visit innerflect.tech, contact us, use booking or enquiry channels, or access related Innerflect digital services where made available.
Innerflect is a commercial brand. It is not a separate legal entity. This website is operated by Daniel Índias Fernandes, an independent service provider based in Portugal. In this Privacy Policy, “we”, “us” and “our” refer to that service provider in the context of website operation and enquiry handling.
Other independent service providers may operate under the Innerflect brand for specific client engagements. Where a client engagement is entered into with another independent service provider, the relevant provider will be identified in the applicable proposal, agreement or invoice and will be responsible for the personal data processed in connection with that engagement.
2. Controller
The data controller responsible for this website and website-related processing is:
Daniel Índias Fernandes
Rua Professor Hernâni Cidade n.º 5, 3.º L
1600-630 Lisbon
Portugal
Email: daniel@innerflect.tech
For all data-protection enquiries and requests, please contact: hello@innerflect.tech
3. Personal Data We Process
Depending on how you interact with this website, we may process the following categories of personal data.
Website and Technical Data
When you access this website, technical information may be processed automatically by our hosting and network infrastructure. This may include:
- IP address
- date and time of access
- requested URL or resource
- referring page, if transmitted by your browser
- browser type and version
- device type and operating system
- language settings
- HTTP status codes and technical error information
This information is processed through server logs and network infrastructure for the purpose of delivering the website, diagnosing technical problems and maintaining security.
Enquiry and Contact Data
You can contact us by email at hello@innerflect.tech and, where available, through contact forms, booking links or other enquiry channels.
When you email us, we may process:
- name
- business email address
- company name and professional role
- telephone number, where provided
- message content and subsequent correspondence
Please do not include sensitive personal data or confidential third-party information in an initial enquiry unless this has been expressly agreed with us.
Client and Commercial Data
Where we discuss or enter into an engagement, we may process:
- contact and organisational information
- proposals, agreements and project documentation
- correspondence and meeting notes
- billing and payment information
- project and delivery records
- information required for contractual, accounting, tax and legal purposes
4. Purposes and Legal Bases
Operating and Securing the Website
We process technical data to deliver the website, maintain its stability, diagnose errors and protect against misuse.
Legal basis: Article 6(1)(f) GDPR — our legitimate interest in providing a secure and functional website.
Responding to Enquiries
We process email enquiry data to respond to your request, understand your requirements and prepare proposals.
Legal basis: Article 6(1)(b) GDPR where processing is necessary to take steps at your request before entering into a contract; otherwise Article 6(1)(f) GDPR — our legitimate interest in communicating with prospective clients.
Performing Engagements
We process client and project data where necessary to deliver the services agreed under a written engagement.
Legal basis: Article 6(1)(b) GDPR. Where we communicate with employees or representatives acting on behalf of an organisation, the legal basis is Article 6(1)(f) GDPR — our legitimate interest in managing the relevant business relationship.
Complying with Legal Obligations
We retain and process data where necessary to comply with applicable tax, accounting, commercial and other legal obligations.
Legal basis: Article 6(1)(c) GDPR.
Establishing or Defending Legal Claims
We may retain or use relevant data where necessary to establish, exercise or defend legal claims.
Legal basis: Article 6(1)(f) GDPR.
5. Hosting and Technical Infrastructure
Website Hosting and Email Infrastructure
This website and the email inbox hello@innerflect.tech are operated using hosting and email infrastructure provided by Verpex Limited.
Verpex may process technical connection data, server logs, website files and email-related data where necessary to provide hosting, email delivery, security, maintenance and support services.
Where personal data is transferred to the United Kingdom in connection with Verpex services, such transfer is currently based on the European Commission’s adequacy decision for the United Kingdom.
DNS and Network Routing
DNS resolution, network routing and security-related network services for this website are provided through Cloudflare Inc.
Cloudflare may process visitor IP addresses, connection data, DNS data and related technical information as part of the infrastructure used to serve and protect this website. Cloudflare operates a global network, which may involve processing outside the European Economic Area.
Where personal data is transferred to countries outside the European Economic Area that are not subject to an adequacy decision, such transfers are based on appropriate safeguards, including Standard Contractual Clauses where applicable.
Fonts
The typefaces used on this website, including Inter and Satoshi, are served locally from our own hosting infrastructure. No requests are made to external font services when you visit this website.
6. Email, Contact and Booking Requests
You can contact us by email at hello@innerflect.tech and, where available, through contact forms or booking links on this website.
When you send us an email, submit a form, or request a call, we process the information you provide, such as your name, email address, company, role, message content, and any operational context you choose to share. We may also process technical transmission data required to deliver, secure, and manage the request.
Contact requests are delivered to and stored in the email and communication infrastructure used for this domain. Where a form or booking tool is used, the relevant website, form, hosting, or scheduling infrastructure may process the data required to transmit the request.
We use this data to respond to your enquiry, communicate with you, assess whether and how we can help, prepare proposals, and, where applicable, enter into or perform a service engagement.
The legal basis is Article 6(1)(b) GDPR where processing is necessary to take steps prior to entering into a contract or to perform a contract, Article 6(1)(f) GDPR for our legitimate interest in handling business enquiries, securing communications, and managing client relationships, and Article 6(1)(c) GDPR where we are legally required to retain certain records.
We keep enquiry and communication data only as long as necessary for the relevant purpose, unless legal retention obligations require a longer period.
8. Service Providers
We share personal data with third-party service providers only where necessary to operate this website, secure the infrastructure, provide email communication or respond to enquiries.
The providers involved in website operation are:
Verpex Limited
Purpose: website hosting, email infrastructure, technical maintenance and support
Corporate entity: United Kingdom
Possible data processed: technical connection data, server logs, website files, email metadata and email content where emails are sent to us
Transfer basis for UK processing: European Commission adequacy decision for the United Kingdom
Cloudflare Inc.
Purpose: DNS resolution, network routing, performance, availability and security-related network services
Corporate entity: United States
Possible data processed: IP addresses, connection data, DNS data, security-event data and related technical information
Transfer safeguards: Cloudflare’s data-processing documentation and appropriate transfer safeguards, including Standard Contractual Clauses where applicable
Umami Analytics
Purpose: privacy-oriented website analytics
Possible data processed: page views, visited pages, referrers, approximate location at country level, browser type, device type, operating system and selected interaction events
Use: aggregated website usage analysis, not advertising, remarketing or cross-site tracking
We do not use CRM systems, marketing automation tools, advertising networks or session-recording tools in connection with this website. We use Umami Analytics as described in Section 7. We do not sell personal data.
Where engagements are entered into, additional service providers may be involved in delivering the agreed services. Those providers and the applicable data-processing arrangements will be identified in the relevant engagement documentation where required.
9. International Data Transfers
The website is operated using hosting, email and network infrastructure provided by third-party providers.
Where personal data is transferred to the United Kingdom, such transfer is currently based on the European Commission’s adequacy decision for the United Kingdom.
Cloudflare Inc. is incorporated in the United States and operates a global network. Visitor connection data processed by Cloudflare may be handled outside the European Economic Area. Where required, such transfers are based on appropriate safeguards, including Standard Contractual Clauses.
Further information about transfer safeguards is available on request: hello@innerflect.tech
10. Retention
We retain personal data only for as long as necessary for the relevant purpose.
Unless a longer period is required by law or otherwise justified:
- technical server logs are retained only for as long as necessary for website delivery, security, error diagnosis and abuse prevention;
- email enquiries that do not result in an engagement are retained for up to 12 months from the last substantive contact, after which they are deleted;
- client, contract, project and billing records are retained for as long as required under applicable commercial, tax and accounting laws in the relevant jurisdiction, and where necessary for the establishment, exercise or defence of legal claims.
Data may be retained for longer where required by law or where necessary to establish, exercise or defend legal claims.
11. Your Rights
Subject to applicable law, you have the following rights in relation to your personal data:
- Access — to obtain a copy of the personal data we hold about you
- Rectification — to request correction of inaccurate or incomplete data
- Erasure — to request deletion of your personal data where the legal conditions are met
- Restriction — to request that processing be restricted in certain circumstances
- Portability — to receive data you provided in a structured, machine-readable format where applicable
- Object — to object to processing based on legitimate interests, on grounds relating to your particular situation
- Withdraw consent — where processing is based on consent, to withdraw it at any time without affecting the lawfulness of prior processing
- Complain — to lodge a complaint with a competent supervisory authority
Where we rely on legitimate interests and you object, we will review your objection and cease processing unless we can demonstrate compelling legitimate grounds that override your interests or the processing is necessary for legal claims.
Requests may be sent to: hello@innerflect.tech
We may request reasonable information to verify your identity before responding.
12. Supervisory Authorities
The data controller for this website is based in Portugal. The competent supervisory authority is:
Comissão Nacional de Proteção de Dados (CNPD)
Av. D. Carlos I, 134, 1º
1200-651 Lisboa
Portugal
You also have the right to lodge a complaint with a supervisory authority in your country of habitual residence, place of work or the place of the alleged infringement.
13. Security
We apply technical and organisational measures appropriate to the nature and risk of the processing, designed to protect personal data against unauthorised access, accidental loss, alteration, destruction or disclosure.
Measures include encrypted transmission via TLS, access restrictions, infrastructure-level protections through our hosting and network providers, and internal handling practices designed to limit access to personal data to those who need it for the relevant purpose.
No internet-based service can guarantee absolute security. We review our security arrangements on a regular basis.
14. External Websites
This website may contain links to external websites and services, including LinkedIn. When you follow such a link, you leave this website.
Third-party websites process personal data under their own responsibility and their own privacy policies. We have no control over and accept no responsibility for third-party data-processing practices. This Privacy Policy does not apply to external websites or services.
15. Changes to This Policy
We may update this Privacy Policy where our services, technical infrastructure, legal obligations or organisational arrangements change.
The current version, with the date of the most recent update, is published on this website. Material changes will be reflected by updating the date at the top of this page.
16. Contact
For all data-protection questions and requests: hello@innerflect.tech