// privacy

privacy policy

effective

// tl;dr — no ads, no analytics, no tracking cookies, no third-party requests of any kind, and no logs: we don’t keep server request logs or visitor IP addresses. The only personal data we hold is what you choose to type into the contact form, used to reply to you.

who we are

rouage is the development practice of verrou. This policy covers personal information collected through this website. Data we handle inside a client engagement is governed by that engagement’s written agreement, not this page — though this policy does say where that material is stored. The publisher of this site and the controller for the data described here is verrou, Inc., a Delaware corporation.

what we collect

One thing:

  • Contact form submissions — the name, work email, company, service selection, and message you choose to send us, plus the time you sent it.

That’s the whole list. This site sets no cookies and uses no local or session storage. It runs no analytics, advertising, or tracking scripts. It makes no requests to any third-party server — fonts and every other asset are served from our own infrastructure.

what we deliberately don’t collect

We operate a no-log policy:

  • No web server request logs. Access logs are written to /dev/null rather than to disk, so the pages you visit are never recorded in the first place.
  • No IP addresses. Your address is never stored — not on disk, and not in memory. To rate-limit the contact form against abuse we need to recognize a repeat sender, not to know who they are, so we keep only a one-way cryptographic digest of the address, computed with a secret that is generated fresh each time the service starts and never leaves memory. The digest cannot be turned back into your address, cannot be matched against one taken before the last restart, and is discarded once the rate-limit window expires. Your address itself is never written to a file, never included in the notification email we receive, and never appears in any log.

how we use it, and on what legal basis

We use your submission to respond to your inquiry and, if we end up working together, as an ordinary business record. We don’t sell personal data and we don’t share it for anyone else’s purposes.

Under the EU/UK GDPR our lawful basis is legitimate interests (Article 6(1)(f)) — answering someone who has deliberately contacted us about our services is what both sides expect, involves the minimum data needed to reply, and does not override your rights. Where your message concerns a possible engagement, processing also serves steps taken at your request before entering a contract (Article 6(1)(b)). We do not rely on consent, so there is no consent for you to withdraw — and nothing to click through on arrival.

third parties

Loading this site involves no one but us. Typefaces, styles, images, and every other asset come from our own servers, so no third party sees your visit.

  • Contact form — the form is handled by our own software running on the same server as this website. No third-party form service is involved; what you type goes directly to us.
  • Hosting1984 hosts this website and the contact form that receives your message, in Iceland, acting as our processor.
  • Email — our mail is operated by Proton in Switzerland; your submission reaches us as email and is stored there.
  • Project & code hosting — engagement material, including project repositories, is held on our own server in Iceland. No third-party code-hosting provider is involved.

If you follow an outbound link from this site — to verrou, to one of the causes in our footer, or to our LinkedIn page — that destination is beyond our control and its own privacy terms apply.

retention

Your submission is kept while we’re in contact about your inquiry and, if it becomes an engagement, for as long as we need it as a business record — after which it’s deleted. When the form is submitted successfully, your message reaches us as email and nothing at all is stored on the web server. Only if that delivery fails does the server keep a copy, so your message is not simply lost — and that copy is rotated out within roughly three months. There is nothing else to retain: no request logs, no IP addresses, no cookies. If you’d like your message deleted sooner, ask and we’ll do it.

your rights

Want to know what we hold about you, correct it, or have it deleted? Email hello@rouage.ai and we’ll handle it — no forms, no runaround.

Depending on where you live, those rights are also backed by law. Under the EU/UK GDPR they include access, correction, deletion, restriction, objection, and portability; under California’s CCPA/CPRA they include knowing what we hold, deletion, correction, and not being discriminated against for asking. We don’t sell or share personal information as California defines those terms. You can also complain to your local data protection authority — though we’d rather hear it first and fix it.

where your data lives

All of our infrastructure sits inside the European Economic Area or in a country the European Commission has recognized as offering an adequate level of data protection. This website and the contact form that receives your message are hosted in Iceland, which is part of the EEA; our email is operated in Switzerland, which holds an EU adequacy decision; and engagement material sits on that same Icelandic infrastructure. Because of this, no personal data is transferred to a country that would require Standard Contractual Clauses or an equivalent safeguard. If you contact us from outside these regions, your submission travels to that infrastructure.

legal requests

If we receive a legally binding demand for your data, we will comply with the law. We will also tell you it happened, unless we are legally prohibited from doing so. We will not volunteer your data to anyone who has not compelled it.

You should also know where we sit. verrou, Inc. is a US company, so a US court can compel us to produce what we hold, wherever in the world it is stored. That is ordinary jurisdiction rather than the CLOUD Act — which reaches providers of communication and remote-computing services, and we are neither. The providers we use are Icelandic and Swiss. We would rather state this plainly than let non-US hosting imply a protection it does not give. The practical mitigation is that we hold very little: no request logs, no IP addresses, and engagement material deleted on a defined schedule.

children

This site and our services are for businesses and aren’t directed at children. We don’t knowingly collect personal information from anyone under 16 — if you believe a child has sent us some, email hello@rouage.ai and we’ll delete it.

changes

If this policy changes, the new version appears here with a new effective date. We won’t quietly weaken it.

contact

Questions about privacy: hello@rouage.ai.