This page currently documents the public website's anti-abuse protection. A broader contact-data privacy notice will be added when that policy is finalized.
Anti-bot protection
The contact form uses first-party anti-bot protection to detect automated abuse and keep the form available.
Detailed interaction data, such as keystroke content or typing preferences, remains in the browser. The server receives only compact signals needed to decide whether a verification challenge is required.
What may be sent
- Aggregate counters such as focus, blur, click, pointer movement total, scroll total, paste/edit indicators, and timing values.
- A capped event sequence with internal event codes, relative timing, field category, and small numeric measurements where needed.
- Challenge reference, selected challenge mode, and submitted challenge answer metadata.
What is not collected for this protection
- Raw key values or message typing content.
- Exact pointer coordinates or full pointer traces.
- Data for AI training.
Legal basis and purpose
The purpose is website and network security. The legal basis is legitimate interest in preventing automated abuse, keeping the form available, and protecting public website infrastructure.