What we do with what you send us.
You fill in a form to reach a person. This page says what happens to it after that, in the same plain words as the rest of the site.
Last updated 20 August 2026
Who we are
Enigmatic Dog is the company behind Enidog and AthlosID. We are based in Lisbon, Portugal, and we are the controller of the personal data described here, which means we decide what is collected and why, and we are the ones answerable for it.
Write to sara@enidog.com about anything on this page, including any of the rights further down. A person reads it.
What this covers
This website, and the contact form on it. Nothing else. The AthlosID product is not open to the public yet, so there is no account to create here, nothing to log in to, and no athlete data in this site at all.
What we collect, and only when you send it
Nothing is collected by reading these pages. Everything below comes from the contact form, and only once you press send:
- Your first name and last name.
- Your email address.
- Your phone number.
- Your message, if you write one.
- A document, if you attach one.
- The address of the page you sent the form from, which tells us where an enquiry came from and nothing about you.
- The internet address you sent it from, and the name your browser gives for itself. These are recorded by the form itself, not by reading the site, and we keep them so that if the form is ever flooded with junk we can tell one sender apart from another. We do not use them to work out who you are or where you live.
The name, email and phone number are required, because an enquiry we cannot reply to is not much use to either of us. The message and the document are optional, and the form says so.
Why we have it, and what allows us to
We use it to read your enquiry and to reply to it. That is the whole purpose. We do not add you to a mailing list, we do not send you anything you did not ask for, and we do not sell or share your details with anyone who wants to advertise to you.
Sending the form gets you one automatic email that repeats back what arrived, so you can see we have it and check we read your details correctly. It is a receipt, not marketing, there is nothing to unsubscribe from, and it is the only mail you get without a person writing it.
There is one thing we do beyond replying, and it is keeping the form usable: the internet address and browser name recorded with each enquiry let us recognise a machine sending junk. That is the only use they have, and it is the only reason they are kept.
Our lawful basis under the GDPR is our legitimate interest in answering people who contact us, in Article 6(1)(f), and where your enquiry is a step towards working together, the steps taken before a contract, in Article 6(1)(b). We are not relying on consent, so there is no consent for you to withdraw, but you can object to what we are doing at any time and we will stop unless we have a compelling reason not to.
If you attach a document
Your browser sends it straight to a private area of our own storage, using a permission we issue for that one file and which stops working after ten minutes. It is not published, it is not indexed, and it is not readable by anyone on the internet who happens to find the address.
The one way in is a private link that arrives in our email with your enquiry. It has no expiry date, so it keeps working for as long as we keep the file, and it stops the moment the file is deleted. We would rather tell you that than imply the link ages out on its own: what limits how long your document is reachable is how long we keep it, which is the section below, and nothing else.
Your own copy comes back to you. The receipt we send you carries the file you attached, as an attachment, so you can see exactly what reached us. That is worth being plain about: it means a copy of your document is in your mailbox as well as ours, and deleting our copy does not touch yours. If you would rather it did not travel back to you, tell us and we will send your receipt without it.
Two requests, because they protect you more than any setting we can change at our end:
- Send us the least you can. A diagram or a policy usually explains a setup better than a file full of real people.
- Please do not send health records, and do not send other people's personal details unless you are allowed to pass them on. If a registration list is the clearest thing you have, that is fine, but it stays your decision and your basis for sharing it.
If you send us something you should not have, tell us and we will delete it.
Who else can see it
Two suppliers, both working on our instructions under a data processing agreement, and neither of them free to use your details for their own purposes:
- Amazon Web Services, which hosts this site, stores anything you attach, and delivers the mail.
- Google, which runs the mailbox your enquiry arrives in.
Beyond that, nobody. No advertising networks, no data brokers, no analytics companies, and nothing you send is used to train a model.
Where it is kept
Our storage and our mail sending are in an Amazon Web Services region in the United States, and our mailbox is with Google. So your enquiry does leave the European Economic Area. Those transfers rely on the European Commission's adequacy decision for the EU US Data Privacy Framework, and on the standard contractual clauses in our agreements with both suppliers.
How long we keep it
We keep an enquiry, and anything attached to it, for as long as we might still need it to deal with what you asked us. We have not set an automatic deletion date yet, and we would rather say that than print a period we do not enforce. Ask us to delete yours and we will.
Your rights
Under the GDPR you can ask us to:
- show you what we hold about you,
- correct it if it is wrong,
- delete it,
- stop using it while a question about it is settled,
- stop using it altogether, which is the right to object, and
- hand it to you, or to somebody else, in a portable form.
Email sara@enidog.com and we will answer within one month. It costs you nothing and you do not have to give a reason for asking.
If you are not happy with how we handle it, you can complain to the Portuguese supervisory authority, the Comissão Nacional de Proteção de Dados, at cnpd.pt, or to the authority in the country you live in.
Cookies, and the things this site does not do
There are no cookies on this site. No analytics, no tracking pixels, no advertising tags, and no consent banner to click past, because there is nothing to consent to.
One thing is stored in your browser: whether you chose the light or the dark theme. It stays on your device, it is never sent to us, and clearing your browser storage removes it.
The fonts are served from this site rather than from a font service, so loading a page does not tell a third party that you were here. We do not keep a log of visits.
No automated decisions
Nothing here profiles you, scores you or decides anything about you automatically. A person reads your enquiry and a person replies to it.
Changes to this notice
If what we do changes, this page changes with it, and the date at the top changes too. AthlosID is early and still being built, so that is likely rather than theoretical.