Last updated:
Privacy policy
What Dynamic Reactions LLC does with personal data on this site: what is collected, why, on which legal basis, who processes it, how long it is kept, and your rights under the GDPR.
In short
This site has no accounts, no cookies, no analytics and no advertising. The only personal data it handles is what you choose to send: a message through the contact form, or an email. Technical data about visits is processed by the hosting provider to deliver the pages and keep them secure, and is kept briefly.
Who is responsible
The controller is Dynamic Reactions LLC, a Delaware limited liability company, operating from Faro, Portugal. Its managing member is Ittai Perez. For everything in this policy, including requests about your data, write to ittai@dynamic-reactions.com.
The company is established in Portugal for the purposes of the General Data Protection Regulation (GDPR). The competent supervisory authority is the Portuguese data protection authority, the Comissão Nacional de Proteção de Dados (CNPD). The company is not required to appoint a data protection officer. The managing member handles all data protection matters personally.
What is processed, why, and on what legal basis
Visiting the site
When you open a page, the hosting provider receives the technical data any web server needs: your IP address, the address of the page you asked for, the time, your browser and operating system, and the page you came from if your browser sends it. This data is used to deliver the pages, to protect the site against abuse, and to diagnose faults. The legal basis is the company’s legitimate interest in running a secure and reliable website (Article 6(1)(f) GDPR). No profile is built from it, and it is not combined with anything else.
Sending a message through the contact form
The form asks for your name, your email address and your message. Nothing else. It is sent only after you tick the consent box. The data is used to read and answer your message. The legal basis is your consent (Article 6(1)(a) GDPR), which you can withdraw at any time by writing to the address above. If your message leads to a proposal or an engagement, the correspondence is then processed to take the steps you asked for before a contract (Article 6(1)(b) GDPR). You do not have to provide any of this data. Without it, the company simply cannot answer.
Writing by email
If you email ittai@dynamic-reactions.com directly, your email address, the content of your message and anything you attach are processed in the same way and on the same legal basis as a message sent through the form.
Keeping records
Correspondence that leads to an engagement is kept as part of the business relationship, on the basis of the contract (Article 6(1)(b) GDPR) and of the company’s legitimate interest in keeping records of its business (Article 6(1)(f) GDPR), for as long as the law on business and tax records requires.
How long data is kept
| Data | Kept for |
|---|---|
| Request logs at the hosting provider | A short period, at most a few days, then deleted |
| Delivery logs at the email delivery service | Up to 30 days |
| Contact-form messages and emails | Until the enquiry is closed, and at most 12 months after the last exchange, unless an engagement follows |
| Correspondence that is part of an engagement | For the duration of the relationship, and afterwards for the period the law on business and tax records requires |
| The record that you gave consent | As long as the message it relates to |
Who receives the data
The company does not sell personal data and does not share it with advertisers. It uses two service providers, each bound by a data processing agreement under Article 28 GDPR:
| Provider | What it does | Where | Safeguards |
|---|---|---|---|
| Vercel Inc. (United States) | Hosts and delivers this site and processes the request logs described above | United States, with delivery servers around the world | Data processing addendum with the EU Standard Contractual Clauses. Certified under the EU-U.S. Data Privacy Framework |
| Plus Five Five, Inc., trading as Resend (United States) | Carries contact-form messages from the site to the company’s mailbox as email, and keeps delivery logs for up to 30 days | United States | Data processing addendum with the EU Standard Contractual Clauses |
Messages arrive in the company’s business mailbox, hosted by its email service provider, and are read only by the managing member. Each provider publishes its own list of sub-processors on its website.
Transfers outside the European Economic Area
Both providers process data in the United States. These transfers rest on the European Commission’s Standard Contractual Clauses, which form part of each provider’s data processing agreement. Vercel is in addition certified under the EU-U.S. Data Privacy Framework. You can ask for a copy of the safeguards at the address above.
Cookies and local storage
This site sets no cookies and uses no analytics. Fonts, images and scripts are served from this site’s own domain, so loading a page sends no request to anyone other than the hosting provider that serves the site. The site stores nothing on your device.
Your rights
Under the GDPR you have the right to:
- access the personal data the company holds about you, and receive a copy;
- rectification of data that is wrong or incomplete;
- erasure, where there is no longer a reason to keep the data;
- restriction of processing while a question about the data is being resolved;
- portability, meaning a copy of the data you provided in a common machine-readable format;
- object to processing that rests on legitimate interest;
- withdraw consent at any time, without affecting what was done lawfully before.
To use any of these rights, write to ittai@dynamic-reactions.com. The company may ask you to confirm your identity before acting, answers within one month, and does not charge for this. There is no automated decision-making and no profiling on this site.
Complaints
If you believe the company has handled your data unlawfully, you can complain to the Comissão Nacional de Proteção de Dados (CNPD), the Portuguese supervisory authority, or to the supervisory authority of the EU or EEA country where you live or work.
Children
This site is meant for organizations and the people who work in them. It is not directed at children, and the company does not knowingly collect data from anyone under 16.
Security
The site is served only over HTTPS. The company collects the minimum data it needs, keeps it no longer than needed, and limits access to the managing member.
Changes
When this policy changes, the new version is published here with a new date at the top. Material changes are pointed out in the text.