Privacy notice
Last updated: 8 September 2026 · Version 2026-09-08
Controller and scope
Lafayette Raymon Matulessy, trading as SolutionMAX, sole trader (autónomo). Calle Creta 74, Bloque 01 nº 105, 03130 Gran Alacant, Alicante, Spain. NIF / VAT: ESZ2822653Y. Telephone: +34 671 58 92 79. Email: [email protected].
This notice covers solutionmax.net, the Pharos website and customer account, contact requests, purchases and withdrawal requests. A customer who operates their own Pharos installation is responsible for the personal data processed on that installation. We do not receive its subscribers, incidents or monitoring data just because they use Pharos.
Data, purposes and legal bases
- Contact and proposals: name, email or WhatsApp number, company if supplied, product interest, project details, budget, message and language. We process a request for a quote to take steps at your request before a contract (Article 6(1)(b) GDPR); other enquiries and business contact-person details are processed in our legitimate interest in answering correspondence (Article 6(1)(f)). Fields marked required are needed to answer; optional fields can be left blank. Please do not send passwords, card details or medical or other sensitive information.
- Orders and accounts: contact and billing details, purchased product, status-page domain for a Pharos key, licence, transaction references, delivery choices and the applicable terms version. We use these to fulfil the contract, provide support and operate account access (Article 6(1)(b)); statutory invoicing and record keeping rely on Article 6(1)(c). Stripe processes payment details; our applications do not receive your full card number or CVC.
- Withdrawal, complaints and disputes: name, email, contract reference, statement, receipt time and correspondence, to meet legal obligations and handle your rights (Article 6(1)(c)); establishing or defending claims relies on legitimate interests (Article 6(1)(f)).
- Technical operation and abuse prevention: IP address, request time, browser/user-agent and requested route are processed by our hosting and security providers. Forms also use an empty anti-spam field and may check time spent before submission. Necessary security processing relies on our legitimate interest in operating a secure service (Article 6(1)(f)).
Installed Pharos update checks
Installed copies may request pharos.solutionmax.net/releases/latest.json hourly to check for updates. The request exposes the server IP address and normal HTTP metadata to our server and Cloudflare, but carries no account, licence or status-page content. It can be disabled under Settings → General. Licence verification itself is local.
Optional Umami statistics on SolutionMAX
Only after you select Allow analytics, solutionmax.net loads our self-hosted Umami installation at stats.solutionmax.net, on infrastructure we operate in Spain. It measures page paths, approximate location derived from the request, browser, operating system, device, screen and language, visit times and referring site. Umami processes the IP address to derive statistics and session identifiers; it does not store the raw IP in its analytics tables. Hosting and security logs are separate.
We do not send form contents, URL query strings, fragments, order identifiers or user identifiers to Umami. We do not enable advertising, cross-device identification, session replay or recording of form entry. We use your consent (Article 6(1)(a)). Refusing does not affect purchases or contact. Use Privacy settings on any SolutionMAX page to withdraw consent for future measurement. We also respect the browser's Do Not Track setting. The Pharos marketing, documentation and account pages do not load Umami.
Where data is processed
- Hoasted: SolutionMAX web hosting and our email service.
- Contabo: hosting of the Pharos portal and contact/purchase automation. Our n8n instance processes submissions and sends transactional email through our mail provider.
- Cloudflare: content delivery and security in front of our websites; it can process IP addresses and request metadata on its international network.
- Stripe: checkout, payment processing, invoices, fraud prevention and the billing portal. Stripe acts as a processor for certain services and as an independent controller for its own regulated and security purposes. See Stripe's privacy notice.
- Telegram: from 8 September 2026, new website enquiries and shop orders generate only a generic notification to us, without your name, contact details or message. Before this date our notifications included contact/order information. If you contact us directly through Telegram or WhatsApp, the chosen messaging provider processes that conversation under its own terms.
- Professional advisers and authorities: where necessary for accounting, legal obligations or claims. We do not sell personal data.
We serve fonts locally on both sites and the Pharos account; loading those pages does not request fonts from Google. External links take you to services with their own privacy notices, including Stripe checkout and GitHub.
International transfers
Cloudflare and Stripe may process data outside the EEA, including the United States. Their data-processing terms provide for EU Standard Contractual Clauses and, where applicable to the certified recipient and processing, an adequacy framework. Details and copies of the applicable safeguards are available in Cloudflare's DPA and Stripe's DPA, or by contacting us. We assess the recipient, location and safeguards when selecting a provider; a provider being European does not by itself rule out onward transfers. For historic Telegram messages, contact us about access or deletion; we no longer send new customer content there through these website workflows.
Retention
- Umami records for SolutionMAX: removed by a daily task once older than 12 months.
- Unconverted enquiries: reviewed and deleted within 12 months after the last meaningful contact unless an ongoing request or legal claim requires retention.
- Project and support correspondence: for the engagement and normally up to two years afterwards, except records needed for accounting, a continuing licence or a claim.
- Invoices and necessary transaction records: normally six years from the last relevant accounting entry under Spanish commercial record-keeping rules. A specific tax obligation, investigation or legal hold may require longer retention; this does not mean we retain all unrelated messages.
- Pharos account/licence records: while needed to provide the purchased licence and key retrieval, then only as required for statutory records or claims. A perpetual licence can require a continuing entitlement record.
- Withdrawal records: retained with the relevant transaction, normally six years, to prove receipt and handling.
- Automation execution history: up to 14 days on the website automation server; the delivered email and financial records follow the periods above.
- Security logs and backup copies: retained according to operational rotation and incident-recovery needs, with access restricted. Records specifically needed for an incident or claim may be isolated and retained until it is resolved. Contact us for details of the applicable provider and system.
Cookies and browser storage
SolutionMAX stores your privacy choice and its timestamp locally for up to six months; an older choice is not treated as fresh consent. Umami uses no analytics cookies. Pharos account and withdrawal forms use necessary session and CSRF protection cookies. These are needed for security and are not advertising cookies. Stripe and Cloudflare may use cookies necessary for payment and security on their own services; their notices explain them.
Your rights
You may request access, correction, deletion, restriction or portability where applicable, object to processing based on legitimate interests, and withdraw consent without affecting prior lawful processing. Email [email protected]. We normally respond within one month; if a permitted extension is necessary, we explain it within that first month. We may ask for proportionate identity verification. You can complain to the Spanish AEPD or the supervisory authority where you live or work. We do not make decisions with legal or similarly significant effects about website visitors solely by automated processing.
Security and changes
We use HTTPS, access controls and measures proportionate to the data and risks. No system can be guaranteed completely secure. This notice describes our website and sales processing; managed customer workflows require their own agreed processing instructions and safeguards. We update the date when this notice changes and provide additional notice where required.