Privacy statement

This privacy statement describes how Tavestra collects, processes and protects your personal data when you visit our website or use our services. In our operations, we comply with the EU General Data Protection Regulation (GDPR).

1. Controller

Name of the company: Tavestra
Business ID: 1896014-9
Email: [email protected]
Website: https://www.google.com/search?q=https://www.tavestra.com

2. What data do we collect?

We only collect data for the purposes that are necessary for the functionality of the website, data protection or customer service:

  • Contact forms: Name, email address and content of the message.
  • Analytics and performance: Data related to the use of the website (e.g. IP address, browser type, visited pages)
  • Data security information: Log data (such as IP addresses), which are used for protecting the website from attacks.

3. Technical services and forms on the website

On our website, we use the following services to ensure the functionality and security of the website:

1. Content management (WordPress)

Our website has been built on the WordPress platform. WordPress uses cookies to improve the user experience (e.g. choices of language and login data). WordPress in itself does not collect data on ordinary visitors but it enables the functioning of other services referred to in this notice.

2. Contact forms and communication (Forminator & WP Mail SMTP)

We use Forminator plugin for form management. When you fill in the form, we collect the data you have provided to be able to respond to your query. All messages are transmitted securely through the WP Mail SMTP plugin.

  • Retention: Data provided on a form is retained for 24 months to manage customer services.

3. Website protection (Wordfence & Cloudflare)

Data security is of primary importance to us. We use two overlapping security layers:

  • Wordfence Security: We use this plugin to protect the website from malware and unauthorised login attempts. Wordfence processes visitors' IP addresses to identify and prevent any harmful activities. The data is stored in the website's local database.
  • Cloudflare: The data traffic on our website is transferred using Cloudflare's global network. Cloudflare acts as a filter that stops DDoS attacks and accelerates the loading of the website (cache). Cloudflare processes technical log data (such as IP addresses) to ensure protection. Cloudflare is certified in accordance with the EU–US Data Privacy Framework.

4. Spam protection (Cloudflare Turnstile)

We protect our forms from bots using the Cloudflare Turnstile service. It is a privacy-preserving alternative to traditional CAPTCHAs; it uses technical signals to ensure that the user is human, without tracing the users for advertising purposes.

5. Performance and optimisation (LiteSpeed Cache & OMGF)

  • LiteSpeed Cache: Speeds up the website by caching pages. Does not store personal data.
  • OMGF: We download the Google fonts from our own server, so your IP address is not sent to Google when the site loads fonts.

6. Other tools

  • Yoast SEO: Used for SEO.
  • TranslatePress: Uses cookies to remember your choice of language.

4. Purpose and grounds of the processing of personal data

We process your personal data for the following reasons:

  1. Legitimate interest: Protecting the website (Wordfence/Cloudflare) and responding to contacts.
  2. Consent: Analytics and marketing cookies (managed via Cookiebot).
  3. Legal obligations: Such as accounting.

5. Disclosure of data to third parties

We do not sell your personal data. We use reliable service providers (incl. hosting service, Cloudflare, Defiant/Wordfence) that process data on our behalf to ensure technical implementation. Personal data is transferred outside the EU only if the service provider guarantees a level of protection that complies with the GDPR (e.g. Standard Contractual Clauses or Data Privacy Framework).

6. Cookies

We use cookies to ensure the functionality of the website and for statistical purposes. You can change or cancel your cookie consent any time via the cookie notice at the bottom of the website.

7. The rights of the data subject

You have the right:

  • To verify the personal data concerning you.
  • To request that any inaccurate data be rectified or erased.
  • To object or restrict the processing of your personal data.

Please contact: [email protected]

8. Information security

We use SSL protection (HTTPS). The security of the site is continuously monitored using Wordfence and Cloudflare services, and we make sure that the WordPress installation and all plugins are always kept up to date.

Last update of the statement: 4 March 2026