Legal
Privacy Policy
Last updated 24 June 2026 · Reviewed at least every 12 months
This Privacy Policy explains how this website (the “Site”) for Dani Hildreth handles information. It is written to meet the EU/UK GDPR and the California CCPA/CPRA. In plain terms: this is a portfolio site that collects as little as possible and does not track you.
1. Information we collect
- Contact form. If you use the contact form, we receive the information you choose to submit: your name, email address, optional organization, and your message. This is voluntary and used only to respond to you. We do not run analytics, advertising pixels, social-media trackers or fingerprinting.
- Assistant (chatbot). If you use the on-site assistant, the questions you type are sent to our AI provider to generate a reply about Dani's work. Please do not enter sensitive personal information into the assistant.
- If you email or call us using the links provided, we receive whatever you choose to send (your name, email address, phone number and message). This is voluntary and used only to reply to you.
- Hosting logs. Our host, Vercel Inc., automatically processes standard server logs (IP address, browser type, time of request) to deliver and secure the Site. These are retained briefly by the host for security and abuse-prevention.
2. Why we process it & legal basis (GDPR)
- To deliver and secure the Site: legitimate interests (Art. 6(1)(f)).
- To respond to you when you contact us: legitimate interests / steps prior to a contract (Art. 6(1)(b)/(f)).
- Any future non-essential cookies would be processed only with your consent (Art. 6(1)(a)), which you can withdraw at any time.
3. Cookies & similar technologies
The Site uses only strictly necessary first-party local storage to remember your privacy choices. It sets no analytics or advertising cookies. Fonts are self-hosted, so loading a page makes no request to Google or other third parties.
You can review or change your choices any time via the “Cookie Preferences” link in the footer. We honor the Global Privacy Control (GPC) browser signal automatically as a valid opt-out; when GPC is present, the preference center confirms it has been applied.
4. How we share information
We do not sell or share your personal information, and we have not done so in the preceding 12 months. We use a small number of service providers (sub-processors) strictly to operate the Site, each under its own data-processing terms:
- Vercel Inc.: hosting, CDN, and serverless functions.
- Resend: delivers contact-form messages to us by email.
- OpenRouter (and the AI model it routes to): processes the questions you type into the on-site assistant to generate a response. Assistant input is used only to answer you and is not used to build a profile of you.
We disclose information only if legally required.
5. Data retention
Emails you send are kept only as long as needed to correspond with you and meet our records obligations, then deleted. Hosting logs are retained by our host for a short period for security. Your cookie-preference flag lives on your own device until you clear it.
6. Your rights
If you are in the EU/UK (GDPR), you have the right to access, rectify, erase, restrict or object to processing, to data portability, and to withdraw consent. You may also lodge a complaint with your supervisory authority.
If you are a California resident (CCPA/CPRA), you have the right to know, delete, and correct your personal information, the right to opt out of the sale/sharing of personal information, the right to limit the use of sensitive personal information, and the right not to be discriminated against for exercising your rights.
Do Not Sell or Share My Personal Information
We do not sell or share your personal information and we do not use sensitive personal information for inferring characteristics, so there is nothing to opt out of or limit. We still honor the Global Privacy Control signal automatically. If you believe we hold information about you, you may exercise any right above by contacting us below, free of charge and without creating an account.
7. How to exercise your rights (DSAR)
Email hildreth.dani@gmail.com with the subject “Privacy Request.” We will verify your request and respond within the timeframes required by law (generally 30 days under GDPR; 45 days under CCPA, extendable once). We can provide a copy of your data in a structured, machine-readable format on request.
8. International transfers
Our host and service providers operate globally, so data may be processed in the United States and other countries. Where required, transfers rely on appropriate safeguards such as Standard Contractual Clauses.
9. Children
This Site is a professional portfolio aimed at organizations and is not directed at children, and we do not knowingly collect personal information from children.
10. Changes & breach notification
We review and timestamp this policy at least once every 12 months. In the event of a personal-data breach affecting your rights, we will notify the relevant supervisory authority within 72 hours where GDPR requires, and affected individuals without undue delay.
11. Contact
Dani Hildreth · hildreth.dani@gmail.com · +1 303 547 8752