The short version
This website sets no cookies and runs no analytics. It loads nothing from a third-party server, so no other company learns that you were here. We only hold information you deliberately send us: a message through the contact form, or a domain you ask us to audit.
Who is responsible
Almano ("we", "us") is the controller of the personal data described here. We are based in Nha Trang, Vietnam and work with clients across the Nordic region and the wider EU. Because we offer services to people in the EU, this policy follows the GDPR.
You can reach us about anything in this policy at hello@almano.tech.
TODO_LEGAL: registered company name, registration number and registered address to be confirmed and inserted here.
Visiting this website
No cookie is set, and there is no analytics script of any kind on these pages. The fonts are served from our own domain rather than from Google, so your browser makes no request to any server but ours.
Our web server keeps standard access logs: the requesting IP address, the page requested, the time, and the browser's user-agent string. These exist to keep the site running and to spot abuse. They are not used to build a profile of you, are not combined with anything else, and are deleted within 30 days. The legal basis is our legitimate interest in operating a secure service.
The contact form
The form asks for your name and email address, and optionally your website, phone number and a message. We use them for one thing: to reply to you and, if it goes somewhere, to carry on the conversation about working together.
When you submit the form, the contents are delivered to our team as a notification message. They are not written to a database on this website. The legal basis is that processing is necessary to take steps at your request before entering into a contract, and our legitimate interest in answering people who contact us.
We keep the correspondence for as long as it is a live conversation, and for up to 24 months afterwards so we can pick up a thread you started. Ask us to delete it sooner and we will.
The free site audit
If you enter a domain, we fetch its publicly available pages the way any visitor would, take screenshots of them, and look up the domain's public DNS records, including the ones that govern email deliverability. The pages we fetched are then assessed by an AI model to produce the report you see.
The audit is about a website, not about a person. It may nonetheless pick up personal data if the site itself publishes it: staff names on an about page, for example. We do not seek that out and we do not use it for anything beyond producing your report.
The audit and its results are stored so the report can be shown and downloaded, and are deleted after 90 days. The legal basis is your request and our legitimate interest in demonstrating what we do.
Only run an audit on a domain you own or have permission to assess.
If you download the report
Downloading the full PDF requires signing in with Google. In that moment Google tells us your email address and name, and we use them to send and label your report. Your Google password is never seen by us. If you never click download, no Google sign-in happens and no request goes to Google at all.
Who else can see your data
We keep the list of outside parties as short as we can. It is currently:
- Our hosting provider, which runs the servers this site and its API sit on.
- Telegram, which carries contact-form notifications to our team.
- Anthropic, whose AI model assesses the pages fetched during a site audit.
- Google, and only if you choose to sign in to download an audit PDF.
Where your data is processed
Our servers are in the EU. Some of the services above process data outside the EU, including in the United States. Where that happens, transfers rest on the European Commission's standard contractual clauses or an adequacy decision.
How we protect it
Everything travels over HTTPS. Access to our systems is limited to the people who need it. We ask for the minimum a task requires, which is the most effective protection available: data that was never collected cannot leak.
Your rights
Under the GDPR you can ask us to:
- tell you what personal data we hold about you, and give you a copy;
- correct anything that is wrong;
- delete it;
- restrict what we do with it, or object to our processing;
- hand it over in a portable format.
Making a request or a complaint
Write to hello@almano.tech. We will answer within 30 days, and usually the same week. There is no charge.
If you are not satisfied with our answer, you can complain to the data protection authority where you live. In Sweden that is Integritetsskyddsmyndigheten (IMY).
Websites we build for clients
When we build and run a website for a client, that client is the controller of their visitors' data and we act as their processor under a separate agreement. The analytics we install for clients are cookie-free and do not identify individual visitors — the same standard we apply here.
AlmanoEye
AlmanoEye, our public-safety product, runs on our customers' own premises. It performs no facial recognition and no biometric identification, and no video frame leaves the customer's building. It has no connection to this website and processes nothing about its visitors.
Changes to this policy
If we change what we do with data, we change this page and update the date at the top. There is no archive of past versions; if you need one, ask and we will send it.