Privacy policy
What we do (and don't do) with your data
cra-experts.com is built to be useful without being intrusive. We collect the minimum we need to send you what you've asked for, and nothing more.
Last updated 18 June 2026
The short version
- We collect your name, email, product type, and company size when you submit the lead form, so we can send you the CRA brief and our newsletter.
- We use Cloudflare Web Analytics (cookieless, no IP storage) and, only if you accept the cookie banner, Google Analytics 4 for traffic measurement.
- Google Analytics does not load until you click Accept. If you click Reject, no analytics cookies are set.
- We do not use advertising trackers, third-party social pixels, or session-replay tools, and we do not sell or share your data with advertisers.
- You can request access, correction, or deletion of your data at any time by emailing privacy@cra-experts.com.
Who we are
For the purposes of the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the controller of any personal data submitted through this site is the operator of cra-experts.com. For privacy questions, write to privacy@cra-experts.com.
What we collect
Information you give us directly
When you fill in the lead form on the home page or any landing page, we collect:
- Your name
- Your email address
- Your product type (mobile app, IoT, OSS, etc.)
- Your company size
We use this to send you the CRA briefing you requested and, if you've opted in, a weekly digest of regulatory updates. We don't ask for, store, or process more than this; there is no special category data, no health data, no financial data on this site.
Information collected automatically
We use Cloudflare Web Analytics for traffic measurement. Cloudflare's product is:
- Cookieless, so it doesn't drop a tracker on your device
- Does not store IP addresses
- Does not build cross-site profiles
Cloudflare's own privacy commitments for this product are documented at cloudflare.com/privacypolicy.
We also use Google Analytics 4 (GA4) for more detailed traffic measurement, but
only after you consent via the cookie banner. We run GA4 with Google
Consent Mode:
until you click Accept, analytics storage is denied and GA4 sets no cookies. If you click Accept,
GA4 sets cookies (for example _ga) to measure pages viewed, approximate location,
device and browser, and referral source. If you click Reject, GA4 stays off. You can change your
mind any time by clearing this site's storage in your browser, which brings the banner back.
Legal basis
Under Article 6(1) of the GDPR, our legal bases are:
- Consent (Art. 6(1)(a)) — for sending you the CRA briefing and the newsletter, when you submit the lead form. You can withdraw consent at any time using the unsubscribe link in any email or by writing to us.
- Legitimate interest (Art. 6(1)(f)) — for measuring aggregate, anonymous traffic via Cloudflare Web Analytics so we can understand which content is useful and improve the site.
- Consent (Art. 6(1)(a)) — for Google Analytics 4. GA4 only runs after you accept the cookie banner, and you can decline without losing any functionality.
Where your data lives
Form submissions are stored in Cloudflare D1, the database service provided as part of our hosting on Cloudflare Pages. Cloudflare is therefore a data processor for us. They process data in accordance with their customer Data Processing Addendum.
If you accept analytics cookies, Google acts as a data processor for the GA4 data, under the Google Ads Data Processing Terms. We do not use any other data processors, and we do not use email-marketing platforms that copy our list off-server.
How long we keep it
- Lead-form submissions: retained for as long as you remain subscribed, plus 12 months after unsubscription, after which the record is deleted.
- Cloudflare Web Analytics: aggregated by Cloudflare; we do not export or store raw event data.
- Email correspondence: retained for 24 months unless you ask us to delete it sooner.
Your rights
Under the GDPR you have the right to:
- Access the data we hold about you
- Correct it if it's wrong
- Delete it (the "right to be forgotten")
- Export it in a portable format
- Object to processing on the basis of legitimate interest
- Withdraw consent at any time, where processing is based on consent
- Lodge a complaint with your national data protection supervisory authority
To exercise any of these, email privacy@cra-experts.com. We aim to respond within 14 days; the GDPR gives us up to 30.
International transfers
Cloudflare and (if you consent) Google may process data outside the EU/EEA, including in the United States. They rely on the European Commission's Standard Contractual Clauses and their certification under the EU–US Data Privacy Framework as the basis for those transfers.
Cookies
By default this site sets no tracking or analytics cookies. We show a cookie banner on your first visit:
- If you click Accept, Google Analytics 4 sets analytics cookies (for example
_ga, valid up to two years) so we can measure traffic. - If you click Reject, or simply ignore the banner, no analytics cookies are set.
Your choice is remembered in your browser's local storage so the banner doesn't reappear on every page. The only other cookies you might encounter are strictly technical ones set by Cloudflare's edge for security (e.g. bot mitigation), which fall under the strict-necessity exemption in the ePrivacy Directive. We do not use advertising cookies.
Children
This site is aimed at compliance and engineering professionals. We don't knowingly collect data from anyone under 16. If you believe a minor has submitted information, write to us and we'll delete it.
Changes to this policy
If we change this policy, we'll update the "Last updated" date at the top and, for material changes, send a notice to subscribers. Material change means a change that expands what we collect, who we share it with, or how long we keep it.
Contact
Privacy questions, data requests, or complaints: privacy@cra-experts.com.
Security issues (vulnerability reports) go to our security policy page instead.