Privacy policy

Draft for legal review. This text hasn’t been approved by our lawyers yet and may change before launch.

Last updated: 19 September 2026. Effective from: 19 September 2026.

This policy explains what personal data we collect through layert.net, why, what we do with it, who else handles it, how long we keep it, and the rights you have. It’s written to be read, so it’s short where it can be and specific where it matters.

The short version

  • The site sets no cookies, runs no analytics, shows no advertising and has no social media plug-ins. Your browser doesn’t contact anyone else when you visit: our fonts and images are served from this site.
  • Our hosting provider, Cloudflare, handles basic connection data (such as your IP address) so the site can reach you and stay protected from attacks.
  • If you request a demo, we use what you send us to reply, arrange the demo and follow up on your request. We don’t add you to a mailing list, and we don’t send you marketing unless you’ve agreed to it.
  • You can ask to see, correct or delete your data, or object to how we use it, by writing to privacy@layert.net.

Who we are

This website is run by LayerT, a company registered in Malta with company registration number company registration number, whose registered address is 23F, Triq Testaferrata, Ta’ Xbiex XBX 1405, Malta (“LayerT”, “we”, “us”).

For the personal data described in this policy, we are the controller: we decide why and how it’s used.

We haven’t appointed a data protection officer. Our privacy contact handles all data protection questions and requests:

  • Email: privacy@layert.net
  • Post: Privacy, LayerT, 23F, Triq Testaferrata, Ta’ Xbiex XBX 1405, Malta

What this policy covers

This policy covers:

  • visits to layert.net and its pages;
  • demo requests sent through the form on /contact;
  • emails you send to any of our layert.net addresses, including security reports.

It doesn’t cover the LayerT product. When an organisation uses LayerT, the data about its people is processed on that organisation’s behalf and under its instructions: the organisation is the controller and we act as its processor, under the customer agreement and data processing agreement we sign with it. If your employer uses LayerT and you have a question about your data in the product, please ask your employer first. Data handling describes what the product stores, where and for how long.

What we collect and why

When you visit the site

When your browser asks for a page, our hosting provider, Cloudflare, receives the information that any web request carries: your IP address, the date and time, the page requested, your browser’s user agent (the type and version of browser and operating system), the referring page if your browser sends one, and technical details of the connection. Cloudflare uses this to deliver the page to you and to protect the site against attacks, abuse and technical faults.

We don’t use this data to build a profile of you, and the site doesn’t use it to recognise you from one visit to the next.

  • Lawful basis: our legitimate interests in running a website that works and stays secure (Article 6(1)(f) GDPR).

When you request a demo

The form asks for your name, work email address, company, company size and what you’d like to solve, and lets you add a message. Name and work email are needed so we can reply. Please don’t include sensitive information (such as health data) or other people’s personal data in your message.

We use this information to:

  • reply to you and arrange the demo;
  • follow up on your request before any agreement, for example to answer questions or share material you asked for;
  • keep a record of the request so we know what we discussed.

When you submit the form, the site also stores a one-way hash of your IP address with your request. A hash is a scrambled value we can’t simply turn back into your IP address, but we still treat it as personal data. We use it only to spot and limit repeated or automated submissions from the same connection.

  • Lawful basis: our legitimate interests in answering people who contact us, developing business with the organisations they represent, and protecting the form from abuse (Article 6(1)(f) GDPR). Where you are yourself the person who would enter into a contract with us, we also rely on taking steps at your request before entering into a contract (Article 6(1)(b) GDPR).

We don’t add you to a mailing list and we don’t send you marketing messages unless you have agreed to receive them. If you have agreed, you can withdraw your agreement at any time by writing to privacy@layert.net or using the unsubscribe link in any message, without affecting anything we did before you withdrew it.

When you email us

If you write to us at any layert.net address (for example sales@layert.net, legal@layert.net or privacy@layert.net), we receive your email address, your name if you give it, the content of your email and anything attached, and the technical details that come with every email. We use them to read and answer your email, to deal with the matter you raise, and to keep a record of the correspondence.

  • Lawful basis: our legitimate interests in answering the people who write to us and keeping records of our correspondence (Article 6(1)(f) GDPR). If you write to exercise your data protection rights, we use your details to meet our legal obligations (Article 6(1)(c) GDPR).

When you report a security issue

If you report a vulnerability to security@layert.net, we use your contact details and your report to understand and fix the issue, to keep you updated, to credit you if you ask us to, and to keep a record of the issue and how we fixed it. Our rules for security research are on /security and in our terms of use.

  • Lawful basis: our legitimate interests in keeping our website and product secure and keeping a record of security issues (Article 6(1)(f) GDPR).

We may use any of the data above where we need it to establish, exercise or defend legal claims, to comply with a legal obligation (for example a lawful request from a court or authority), or to keep records that show we complied with the law.

  • Lawful basis: our legal obligations (Article 6(1)(c) GDPR) and our legitimate interests in protecting our rights (Article 6(1)(f) GDPR).

Our legitimate interests

Where we rely on legitimate interests, they are:

  • running a website that loads reliably and stays secure;
  • answering people who contact us, and developing business with the organisations they represent;
  • stopping spam and abuse of the demo form;
  • keeping our website and product secure;
  • keeping proper records and protecting our legal rights.

We’ve considered your interests alongside ours. We collect only what we need, we don’t use it for anything you wouldn’t expect, and you can object at any time (see “Your rights”). You can ask us for more detail about how we balanced these interests.

Do you have to give us your data?

No law or contract requires you to give us personal data. If you don’t give us your name and a working email address, we can’t reply to your demo request or your email. Connection data is needed for your browser to load the site at all.

Who we share it with

We don’t sell your personal data, and we don’t share it with anyone for their own marketing.

We share it only with:

  • Cloudflare, Inc. (USA), which hosts the site, runs the function that receives the demo form, stores demo requests in its database service (Cloudflare D1) and forwards our notification emails (Cloudflare Email Routing). Cloudflare acts as our processor under a data processing agreement. For some security and network data, Cloudflare may also act as a controller in its own right to protect its network, under its own privacy policy.
  • Our email provider, which hosts our layert.net mailboxes, including the one that receives demo request notifications and any email you send us. It acts as our processor.
  • Professional advisers, such as lawyers, accountants and auditors, where they need it to advise us. They are bound by duties of confidentiality.
  • Courts, regulators, the police and other public authorities, where the law requires us to, or where we need to establish, exercise or defend legal claims.
  • A buyer or successor, if we reorganise, merge or sell all or part of our business. They would have to use your data in line with this policy.

Transfers outside the European Economic Area

Cloudflare, Inc. is based in the United States and runs a global network, so connection data may be handled in a Cloudflare data centre near you, including outside the European Economic Area (EEA). Demo requests themselves are stored in a Cloudflare database held within the European Union. Our email provider may also process data outside the EEA.

When personal data leaves the EEA, we make sure it’s protected by one of the safeguards the GDPR allows:

  • an adequacy decision of the European Commission, including the EU-US Data Privacy Framework for US companies certified under it;
  • the European Commission’s standard contractual clauses, with any additional measures needed.

You can ask for a copy of the relevant safeguards by writing to privacy@layert.net.

How long we keep it

DataHow long
Connection data handled by CloudflareOnly as long as Cloudflare needs it to deliver and secure the site, under its own retention rules. We don’t collect or keep these logs ourselves
Demo requests24 months after our last contact with you. If your organisation becomes a customer, the customer agreement then sets how long we keep it
The IP address hash stored with a demo request30 days
Emails you send us24 months after our last contact with you, unless the matter needs a longer record (for example a contract or a legal claim)
Security reports5 years after the issue is closed, as a record of the issue and the fix
Records of data protection requests5 years after we close the request, which matches the general period for bringing a claim under Maltese law, to show how we handled it

We may keep data for longer where the law requires it, or where we need it for a legal claim until that claim, or the period in which it could be brought, has ended. When a retention period ends, we delete the data or make it anonymous.

How we protect it

The site is served only over encrypted connections. The demo form sends your details to our own site, not to a third party, and access to stored requests is limited to the people at LayerT who need it. No system is perfectly secure, but we take care to protect your data, and if a breach puts your rights at risk we’ll tell you and the authorities as the law requires.

Cookies and similar technologies

This site sets no cookies. It doesn’t use local storage, pixels, fingerprinting or any similar technology to track you, and it has no analytics or advertising. Because nothing is stored on or read from your device for these purposes, we don’t show a cookie banner.

If we ever add a cookie or similar technology, including a security feature from Cloudflare that sets one, we’ll update this policy first and list what it is, why it’s there and how long it lasts. We’ll only use cookies that aren’t strictly necessary if you agree to them, and they’ll stay off unless you do.

Automated decisions

We don’t make decisions about you based solely on automated processing that have legal or similarly significant effects on you, and we don’t profile you.

The only automated step is the limit on repeated form submissions: if many requests come from the same connection in a short time, further submissions may be refused for a while. If that stops you from reaching us, email sales@layert.net and a person will read it.

Your rights

Under data protection law you have the right to:

  • access your personal data and get a copy of it;
  • correct data that’s wrong or incomplete;
  • erase your data, for example when we no longer need it;
  • restrict how we use your data, for example while we check a complaint about its accuracy;
  • data portability: receive data you gave us in a structured, machine-readable format, or have it sent to someone else, where we rely on a contract or your consent;
  • withdraw consent at any time, where we rely on it, without affecting what we did before;
  • complain to a data protection authority (see below).

Your right to object. You can object at any time, on grounds relating to your particular situation, to our use of your data based on legitimate interests. We’ll then stop unless we have compelling legitimate grounds that override your interests, rights and freedoms, or we need the data for legal claims. If we ever use your data for direct marketing, you can object at any time and we’ll stop, with no need to give a reason.

How to use your rights

Write to privacy@layert.net or to the postal address above. We’ll reply within one month. If your request is complex or we receive many, we may extend this by up to two further months, and we’ll tell you why within the first month. Using your rights is free. If a request is clearly unfounded or excessive, we may charge a reasonable fee or refuse it, and we’ll explain why. We may ask you to confirm your identity before we act, so that we don’t give your data to someone else.

These rights have limits set by law, and we’ll tell you if one applies.

Complaining to the regulator

We’d like the chance to sort out any concern first, so please write to us. You also have the right to complain to a supervisory authority, in particular in the EU country where you live, work or think your rights were infringed. In Malta, that is:

Information and Data Protection Commissioner (IDPC) Floor 2, Airways House, Triq Il-Kbira, Tas-Sliema SLM 1549, Malta Phone: +356 2328 7100 Email: idpc.info@idpc.org.mt Website: idpc.org.mt

Children

This site is for businesses and the people who work in them. It isn’t aimed at children, and we don’t knowingly collect personal data from anyone under 16. If you think a child has sent us personal data, write to privacy@layert.net and we’ll delete it.

The site links to other websites. Once you follow a link, that website’s own privacy policy applies, and we aren’t responsible for how it handles your data.

Changes to this policy

We’ll update this policy when what we do changes, and we’ll change the “Last updated” date at the top. If a change materially affects how we use personal data we already hold about you, we’ll tell you directly where we can before it takes effect.

Contact

For anything about this policy or your personal data, write to privacy@layert.net, or to Privacy, LayerT, 23F, Triq Testaferrata, Ta’ Xbiex XBX 1405, Malta.

The law that applies includes the General Data Protection Regulation (EU) 2016/679 (GDPR), Malta’s Data Protection Act (Chapter 586 of the Laws of Malta) and the Processing of Personal Data (Electronic Communications Sector) Regulations (Subsidiary Legislation 586.01).