Privacy policy
What WPI LTD does with personal data in connection with this website and with messages sent to it. This is not a template: it describes a site with no forms, no accounts, no analytics and no cookies, and it says what the server actually records, which is close to nothing.
1. Who is responsible
WPI LTD, a private limited liability company registered in Malta under company number C 78563, registered office CMS House, Third Floor, St. Peter's Street, San Gwann SGN 2310, Malta, is the controller of the personal data described below, within the meaning of Article 4(7) of Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR").
The company has not appointed a Data Protection Officer and is not required to have one: it is not a public authority, its core activities do not consist of large scale regular and systematic monitoring of individuals, and it does not process special categories of data on a large scale (Article 37(1) GDPR).
Contact for anything in this policy
Or by post to the registered office above, marked for the attention of the board.
2. What this website is, and what it is not
This website is a single static page, plus this policy and the cookie policy. Everything it shows travels inside the page itself: the logo, the photograph, the diagrams and even the email address, which is an image rather than text. It loads no fonts, no scripts, no images and no frames from any other domain.
There is no contact form, no login, no newsletter sign-up, no comment section, no chat widget, no analytics package, no advertising or conversion tag and no social plugin. Nothing here asks you for data, and no third party is told that you visited.
The only way you can give WPI LTD your data through this site is by deciding, yourself, to write to the address published on it.
3. What is actually processed
a. Technical connection data
To send you a page, the web server necessarily receives your IP address, the address you asked for and the technical details your browser announces (browser and operating system string, accepted languages, protocol version). That is true of every website in existence: it is how a page finds its way back to you. The question that matters is what is kept.
We checked before writing this. The web server is Caddy 2.6.2 and the configuration block that serves wpi.ltd has no logging directive, which in Caddy means no access log is produced. On 1 September 2026 we issued requests to the site, successful ones and deliberately failing ones, and confirmed that not a single line about them was written anywhere on the machine.
So: individual page requests to this website are not recorded. There is no visitor log, no IP address list, no statistics file, nothing to hand over and nothing to lose in a breach.
The machine's system journal holds only the web server's own operational messages, such as start-ups, configuration reloads and TLS certificate renewals. Those contain no visitor addresses. The journal is capped by size (200 MB), which at the current rate means entries are overwritten automatically after roughly one to two weeks.
If an access log ever has to be switched on, for instance while dealing with an attack on the server, it will be limited to what that purpose requires, kept for no longer than 30 days, and this page will be updated to say so.
b. What you send by email
If you write to the address published above, WPI LTD receives your email address, your name if you give it, and whatever you choose to put in the message and its attachments. Mail for the wpi.ltd domain is delivered through Google Workspace.
Please do not send sensitive personal data (health, political or religious views, and the rest of Article 9 GDPR) by email. It is not needed for any purpose here, and ordinary email is not the right channel for it.
4. Purposes and legal bases
| Data | Purpose | Legal basis |
|---|---|---|
| Technical connection data, for the moment a request is being served, and any access log switched on temporarily | Delivering the page; keeping the server up and defending it from abuse | Legitimate interest, Article 6(1)(f) GDPR: running and protecting one's own website |
| Content of messages sent to the published address | Reading, replying, and keeping a record of the exchange | Article 6(1)(b) GDPR where the exchange concerns steps taken at your request before a possible contract; otherwise legitimate interest, Article 6(1)(f), in handling correspondence addressed to the company |
| Correspondence relevant to a transaction or a dispute | Establishing, exercising or defending legal claims, and meeting company record keeping duties | Article 6(1)(f) GDPR and, where a statutory retention duty applies, Article 6(1)(c) |
Nothing here relies on consent, because nothing on this site does anything that would require it.
5. How long data is kept
- Page requests: not recorded at all, so there is nothing to keep and nothing to erase.
- Server operational messages: overwritten automatically as the size capped journal rolls over, in practice within a few weeks.
- Correspondence: kept while the matter it concerns is open and, afterwards, for as long as it may be needed to establish, exercise or defend a legal claim, and in any case no longer than ten years from the last message. Unsolicited messages of no interest to the company are deleted, normally within twelve months.
6. Who else may see the data
- The hosting provider. The site runs on a virtual server rented from netcup GmbH (Daimlerstrasse 25, 76185 Karlsruhe, Germany) and physically located in its Austrian data centre. netcup acts as a processor under Article 28 GDPR for whatever passes through or sits on that server.
- The email provider. Mail for the domain is handled by Google Workspace, provided to the company by Google Ireland Limited, acting as a processor.
- Professional advisers (lawyers, accountants, auditors) and public authorities, where the company is legally required to involve them or legitimately needs to.
Personal data is never sold, rented or passed to advertisers or data brokers. There are no advertising or analytics recipients, because there is no advertising and no analytics.
7. Transfers outside the EEA
Serving this website involves no transfer outside the European Economic Area. The server sits in Austria and its provider is established in Germany.
Email deserves a straight answer rather than a comfortable one. Google Workspace is supplied by an EU established company, Google Ireland Limited, but Google's infrastructure can involve access from outside the EEA. Where that happens the transfer relies on the European Commission's standard contractual clauses and, for the United States, on Google's certification under the EU-US Data Privacy Framework. If you would rather avoid that, write to the registered office by post instead.
8. Your rights
Under Articles 15 to 22 GDPR you can ask WPI LTD for:
- access to the personal data it holds about you, and a copy of it;
- rectification of anything inaccurate or incomplete;
- erasure, where one of the grounds in Article 17 applies;
- restriction of processing, where Article 18 applies;
- portability of data you provided, in a machine readable format, where the processing is based on a contract and carried out by automated means;
- objection, at any time and on grounds relating to your situation, to processing based on legitimate interest.
Since no processing here is based on consent, there is no consent to withdraw. Since page requests are not recorded, an access request can only concern correspondence: on the browsing side there is genuinely nothing to produce.
Write to the address above to exercise any of these. You will get an answer within one month, as Article 12(3) GDPR requires. If it is not obvious who you are, the company may ask for information needed to be reasonably sure, and will use it for that check only. Exercising these rights costs nothing.
9. Complaints
If you think your data has been mishandled, you can lodge a complaint with the Maltese supervisory authority:
Office of the Information and Data Protection Commissioner (IDPC)
Floor 2, Airways House, High Street, Sliema SLM 1549, Malta
idpc.org.mt
Under Article 77 GDPR you may instead complain to the supervisory authority of the EU or EEA country where you live, where you work, or where you believe the infringement took place. You can also go to court. Telling WPI LTD first is welcome but is not a condition of any of this.
10. No profiling, no marketing, no automated decisions
WPI LTD builds no profiles from this website, tracks nobody across sites, and sends no marketing from it. No decision about anyone is taken by automated means, including profiling, within the meaning of Article 22 GDPR. There is no mailing list to be added to, because there is nothing here that could add you to one.
11. Applicable law, and changes to this page
This policy is governed by the GDPR as applied in Malta through the Data Protection Act (Chapter 586 of the Laws of Malta) and its subsidiary legislation. The cookie side is covered separately in the cookie policy.
If what the site does changes, this page changes with it, and the date below moves. Since the site keeps no record of who visits, nobody can be notified individually: that date is the only signal, so check it if it matters to you.
Last updated: 1 September 2026. Previous versions are not published; this page replaces anything said before it. See also the cookie policy.