Van ZandtVan Zandt home

GDPR & data-protection rights

Effective date: 31 August 2026 · Last updated: 31 August 2026

This page summarizes how Van Zandt, LLC approaches the EU General Data Protection Regulation, UK GDPR, and similar laws for visitors of vanzandt.ai. Read it with the full Privacy Policy.

Product apps will publish their own GDPR notices. This page is for the company website (contact form, waitlist, and technical logs) only.

Data controller

Van Zandt, LLC
30 N Gould St Suite N, Sheridan, Wyoming 82801, United States
[email protected]

We are a Wyoming limited-liability company. We do not currently maintain an EU or UK Article 27 representative. You may still exercise your rights by writing to the controller at the address above.

1. Your rights

Subject to applicable law, you may have the right to:

  • Access — confirmation of processing and a copy of your personal data.
  • Rectification — correction of inaccurate data.
  • Erasure — deletion in the circumstances GDPR Article 17 provides.
  • Restriction — limited processing in certain cases.
  • Portability — receive data you provided, in a structured, commonly used, machine-readable format.
  • Object — object to processing based on legitimate interests; we will stop unless we demonstrate compelling grounds or the processing is for legal claims.
  • Withdraw consent — where we rely on consent, without affecting prior lawful processing.
  • Lodge a complaint — with your supervisory authority (for example your EU member-state DPA, or the UK ICO).

2. How to exercise rights

We may need to verify your identity. We aim to respond within one month, or explain if an extension is needed (complex or numerous requests). There is no fee unless a request is manifestly unfounded or excessive.

3. What we process on this Site

Name, email, topic, message, IP address, user agent, and timestamps — to answer you, run a waitlist you requested, and secure the Site. We do not run advertising cookies. Legal bases are described in Section 5 of the Privacy Policy (contract / steps at your request, legitimate interests, legal obligation).

4. International transfers

Processing occurs in the United States (controller and origin host) and on Cloudflare’s network. Where required, we use appropriate safeguards such as Standard Contractual Clauses offered by our processors, plus TLS and data minimisation on this Site.

5. Processors

Cloudflare (DNS, tunnel/CDN, transactional email). Our self-hosted origin. Details are in the Privacy Policy. We do not sell personal data.

6. Retention

Correspondence typically up to 24 months after last contact unless you request earlier deletion and law does not require keeping it. Security logs 30–90 days unless an incident requires longer.

7. Children

The Site is not directed at children under 16. We do not knowingly collect their data.

8. Automated decisions

Rate limits and a honeypot may drop likely automated abuse. That is not a GDPR Article 22 decision producing legal or similarly significant effects.

9. Supervisory authorities

You may complain to the authority in your EU member state, or to the Information Commissioner’s Office in the UK. We would rather fix the issue first — write to [email protected].