Privacy and cookies
Updated: 7 October 2026.
Who is responsible
Bruno Ricardo Verissimo Marques, established in Switzerland, is responsible for the personal project BMDigital Services and for the data processing described on this page. BMDigital Services is the name of the project, not a registered company.
Contact for privacy matters: [email protected]. The processing is subject to the Swiss Federal Act on Data Protection (FADP). The GDPR applies in addition where the conditions of its territorial scope are met.
When you visit this site
This site presents the services of BMDigital Services and examples of how work can be organised. It has no user accounts, no payments, no advertising and no audience analytics. The scroll effects, the opening of the form, the automation and AI demonstration and the digital self-check run in your browser: your choices and answers are neither sent nor stored. The Cloudflare Turnstile anti-abuse check is only loaded once you start using the form.
Hosting is Cloudflare Pages, operated by Cloudflare, Inc. To deliver the page and protect the connection, the provider processes technical data such as IP address, browser information, date and time and HTTP request data. The purpose is to make the site available and keep it secure, not to build commercial profiles.
When you use the contact form
The form asks for your name, email, topic and message. Telling me how you found me is optional and helps me understand which channels bring enquiries. Cloudflare Pages receives the request, checks it with Turnstile and uses Resend to send it only to the professional BMD mailbox, which is forwarded to Gmail. The message and the delivery data pass through these providers. No marketing contact is created and no automatic reply is sent. The rules on correspondence and the retention period described below apply.
When you send an email
The contact button opens your email application; sending depends on an action by you. If you write to me, I receive your email address, the name you use and the content of your message. I use that data to answer your enquiry. Please avoid sending sensitive information or client data.
Messages sent to [email protected] are forwarded by Cloudflare to Gmail, from Google, where the correspondence is managed. Writing to me does not sign you up to a newsletter. I do not sell contacts and I do not use your enquiry to send unsolicited campaigns.
BMD Monitor and Google Drive
BMD Monitor is an internal working area, accessible only to authorised BMD users. When the administrator explicitly authorises the connection to Google Drive, the app receives the limited drive.file scope, the Google account address and a refresh credential. The credential is stored in Supabase Vault; the database only stores the state of the connection and the identifiers and links of the folders created.
The integration creates or reuses a “BMD Monitor” root and onboarding folders that the app itself created, after an internal approval. It does not receive general access to files, it does not share files and it does not use Gmail. The connection can be switched off in the Hub, which stops new Drive jobs and clears the reference to the root. Drive and Calendar use separate authorisations and credentials. To revoke all Google access, remove the BMD authorisation in your Google Account; to disconnect an individual service, use its controls in the Hub or contact BMD.
Project feedback and testimonials
After a delivery, BMD may manually send the registered project contact a private link to ask for feedback. Opening the page does not send emails. If you ask for a code, the registered address is used to send a six-digit transactional message through Resend. The code only confirms that, at that moment, you have access to the mailbox chosen by BMD; it does not prove civil identity, sole authorship or the truth of the opinion, and it does not create an account or access to BMD Monitor.
The form may collect the rating, whether the scope was met, the comment, a request to be contacted and the date the email was confirmed, linked internally to the project and to the delivery. The link is stored only as a hash. Challenges, attempts and confirmation proofs are temporary and are deleted automatically; the email provider's logs follow that provider's own controls and periods.
Feedback is used to follow up on satisfaction, solve problems and improve the service. The private answer is kept for 730 days. Giving permission to use a testimonial is optional, starts unticked and identifies exactly the text, the public name and the channels chosen. BMD reviews the testimonial before any publication. You can withdraw that permission through the private link or through the privacy contact; withdrawal blocks new exports and leads to the removal of published copies. The 730-day period also applies to the associated testimonial and permission.
Where the GDPR applies, the processing needed to follow up on the delivery and respond to problems is based on the performance of the service requested and on the legitimate interest in checking the quality of the work. Publishing a testimonial is based on your consent, which you can withdraw at any time without affecting earlier use.
Legal basis and retention
Processing is limited to what is necessary to answer your enquiry and keep the site available and secure. Where the GDPR applies, security and the handling of general correspondence are based on the legitimate interest in those purposes; pre-contractual steps that you request are based on Article 6(1)(b). There are no automated decisions and no profiling.
Contact form enquiries and correspondence without a contractual relationship will be deleted up to 12 months after the last interaction, unless there is a concrete need to keep information in order to meet a legal obligation or defend a right. This period is managed by the controller; it is not an automatic deletion by the site. The hosting provider's technical logs follow that provider's periods and controls; I do not keep my own copy for visitor analysis.
Providers and international transfers
Cloudflare, Inc. provides the hosting, the security, the form function, Turnstile and email forwarding; Resend sends the contact form messages and the feedback confirmation codes and keeps the corresponding sending logs; Google provides Gmail and, when authorised by the administrator, the Google Drive API; Supabase provides authentication, database, Edge Functions and Vault to BMD Monitor. Data is processed internationally, including in the United States. Cloudflare and Google state that they adhere to the Swiss-US Data Privacy Framework and use standard contractual clauses for transfers that require them; Resend's data processing agreement provides for standard contractual clauses. The providers' terms, processing locations and safeguards can be consulted at the links below; you can contact me for clarification or to request information about the applicable safeguards.
- Cloudflare privacy policy and transfers
- Google privacy policy
- Google data transfer frameworks
- Cloudflare Turnstile privacy information
- Resend privacy policy
- Resend data processing agreement
Cookies and browser storage
The code of this site installs no cookies, uses no local storage and loads no advertising pixels, embedded videos or third-party fonts. There are no marketing or audience measurement cookies to accept. The Cloudflare Turnstile anti-abuse check is only loaded when you use the form; the signals it collects are necessary to detect abuse and are described in the Turnstile privacy information.
Depending on the hosting security configuration, Cloudflare may use mechanisms that are strictly necessary to protect the service. Its cookie documentation explains the available mechanisms; the existence of that list does not mean that all of them are used on this site.
If tools that depend on consent are introduced, this information will be updated and those tools will only be activated after the visitor has made a choice.
Your rights
You can ask for access to, correction of or deletion of your data and, in the cases provided for by the applicable law, restriction of processing, portability or objection. Where processing depends on consent, you can withdraw it without affecting the lawfulness of the earlier processing. Send your request to the email address above; I will only ask for the information needed to confirm your identity.
You can also lodge a complaint with the competent data protection authority, in Switzerland the FDPIC and, where the GDPR applies, the supervisory authority of your country of residence. Mandatory rights provided for by law remain unaffected.
Changes
This information will be updated if the data collected, the purposes or the providers change. The activation of marketing or of optional tracking tools will be explained before you are asked to make a choice.