Legal
Legal
- Site: David Azofeifa
- Responsible party: David Azofeifa
- Last updated: 2026-07-29
This notice explains who is responsible for this website, what personal data it collects, why, how long it is kept, and what rights you have. It is written to serve as the notice at collection required by privacy laws such as the EU/UK GDPR and U.S. state privacy laws.
1. Who is responsible
David Azofeifa is the party responsible for this website and decides why and how personal data here is used. The underlying website platform is built and operated by VirtuAmerica LLC. When the platform provider is a separate organization, it processes data only on David Azofeifa’s instructions as a service provider.
Questions, privacy requests, and data-rights requests: contact@davidazofeifa.com.
2. What we collect
Forms and messages. When you submit a form, we receive the fields you complete. Depending on the form, that may include your email address, name, phone number, country, preferences, and message.
Accounts and sign-in, when available. We process the email address or external-provider identity you use to sign in, basic profile details the provider returns, account and organization identifiers, session records, and authentication or account-security events.
Appointments, when available. A booking may include the requested service, location, staff member, date and time, party size, name, email address, phone number, preferences or accessibility needs, notes, booking status, confirmations, changes, cancellations, and feedback.
Search and AI tools, when available. We process the question or prompt you submit, recent conversation context, relevant excerpts retrieved from this site’s content, the generated response, and usage or rate-limit metadata. The query and response may be recorded for service quality and abuse prevention. Do not put confidential or sensitive personal information into a search or AI tool unless the page clearly asks for it.
Files, service, and transaction records, when available. A feature may process files you upload and their metadata, reactions or other content interactions, support history, organization and site configuration, subscription or order details, transaction identifiers, amounts, and payment status. When hosted payment is offered, the payment provider receives the payment-card details directly; this site receives the result and transaction references, not the full card number.
Information collected automatically. Normal web requests carry technical data such as your IP address, browser user-agent, requested page, referring page, language, request time, response status, and security or correlation identifiers. A form submission can also include an approximate country and city derived from the IP address and how long the page was open. These records operate the site, diagnose failures, enforce limits, and distinguish real use from automated abuse.
We do not ask you to include health, financial, government-identifier, or other sensitive information in an open text field unless a specific service clearly requires it. Because an open field can still contain information you choose to provide, submit only what is needed for your request.
3. Why we use it, and our legal basis
We use this information to answer requests; provide forms, accounts, search or AI responses, appointments, subscriptions, orders, and support; send confirmations and service messages; record consent; administer transactions; measure feature reliability; detect and block abuse; secure the site; and comply with legal obligations.
Where the GDPR or a similar law applies, the legal basis depends on the feature: your consent for optional communications; steps at your request or performance of a contract for bookings, accounts, orders, and services; our legitimate interests in answering enquiries and operating a reliable, secure service; and compliance with legal obligations.
4. Email confirmation and opting out
If you sign up to hear from this site, we send a confirmation email first and record nothing as confirmed until you click the link. That double opt-in is your consent record. You can withdraw consent at any time by contacting contact@davidazofeifa.com, and we will stop sending and remove you from the list. Service messages that answer a request you made are not marketing and may still be sent.
5. Cookies
This site sets only cookies that are strictly necessary for it to work. It runs no advertising cookies, no analytics cookies, and no third-party tracking pixels, so there is nothing here to consent to or opt out of for advertising purposes.
| Cookie | Purpose | Typical lifetime | Security attributes |
|---|---|---|---|
| Anti-spam timestamp | Records when the page loaded so automated form submissions can be detected. | Hours | Secure, HttpOnly, SameSite=Lax |
| Session or sign-in | Keeps you signed in on pages that require access. | The session or its configured expiry | Secure, HttpOnly, SameSite=Lax |
| External sign-in state | Binds a browser to the external sign-in request and its callback. | Minutes, until the callback | Secure, HttpOnly, SameSite=Lax, callback-path scoped |
| Sign-in profile prefill | Temporarily carries basic profile details from an external sign-in callback to the page that completes sign-up. | Up to 10 minutes | Secure, SameSite=Lax; intentionally not HttpOnly so the sign-up page can read it |
| Reaction identity | Remembers, without identifying you directly, that this browser already reacted to a piece of content. | Days | Secure, HttpOnly, SameSite=Lax |
| Search session | Limits how many searches one visitor can run, to prevent abuse. | Minutes | Secure, HttpOnly, SameSite=Lax |
| Authorized portal context | Preserves a short-lived privileged portal context for an already authorized operator. | Its configured administrative expiry | Secure, HttpOnly, SameSite=Strict |
These are first-party, essential cookies. Not every cookie applies to every page: a cookie is set only when the feature that needs it is present.
6. Who else sees your data
We do not sell personal data and we do not share it for cross-context behavioural advertising. Your data is shared only as needed with:
- VirtuAmerica LLC, which hosts and operates the site platform;
- cloud hosting and email-delivery services needed to store data and send you email;
- an external identity provider when you choose that sign-in method;
- an AI or model provider when you use a search or AI feature;
- calendar, communications, appointment, or hosted-payment providers when the corresponding feature is enabled and you use it;
- authorized personnel of the responsible party who need the information to fulfil your request; and
- professional advisers, or authorities, where the law requires it.
Each provider receives only the information needed for its role and is subject to its service and data-protection terms.
Data may be stored or processed in the United States and in other countries where these providers operate. Where required, transfers rely on an approved safeguard such as the European Commission’s standard contractual clauses.
7. How long we keep it
We keep form submissions and support messages while the request is active and for a reasonable recordkeeping period. Subscription and consent records remain until you unsubscribe, plus the period needed to demonstrate the request and consent. Account, appointment, order, and transaction records remain while the service is active and afterward for operational, dispute, tax, or other legal requirements. Search or AI queries and generated responses may remain in service-quality records. Technical, security, rate-limit, and anti-spam signals are kept for a limited operational period.
We then delete or anonymise records unless a legal obligation, active dispute, fraud-prevention need, or backup cycle requires a longer period. You may ask contact@davidazofeifa.com for the current retention period that applies to a particular feature.
8. Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, to correct it, to delete it, to object to or restrict how we use it, to receive a copy in a portable format, to withdraw consent, and to complain to a privacy regulator.
- EEA and UK: you may complain to your national data protection authority, or to the UK Information Commissioner’s Office.
- California and other U.S. states: you may request access, correction, or deletion, and you will not be treated differently for exercising those rights. We do not sell or share personal data.
- Costa Rica: you have rights of access, rectification, cancellation, and objection under Law 8968.
To exercise any right, contact contact@davidazofeifa.com. We may need to confirm your identity, and we respond within the period the applicable law allows.
9. Security
Traffic to this site is encrypted with HTTPS. Access to submitted data is restricted, forms are protected against automated abuse, and security settings are applied centrally by the platform so an individual page cannot weaken them. No system is perfectly secure, but we work to protect your data and to notify you and the authorities if a breach requires it.
10. Children
This site is not directed at children and we do not knowingly collect data from them. If you believe a child has given us personal data, contact contact@davidazofeifa.com and we will delete it.
11. Changes
We may update this notice as the site or the law changes. The date at the top shows when it was last revised; the current version is always the one published here.
12. Contact
Privacy questions and data-rights requests: contact@davidazofeifa.com.
© 2026 David Azofeifa.