Privacy and cookies
Last updated 25 September 2026
What this site does
One page, built by hand and served as static files. No advertising tags, no embedded video, no chat widget, no A/B testing tool.
By default it loads nothing from anybody else. The typefaces are served from this domain rather than from Google Fonts, which is deliberate: fetching them from Google would hand your IP address to Google before you clicked anything, and a Munich court ruled in 2022 that doing so without asking broke the GDPR.
There is one small script on the page. It switches between sections, opens and closes panels, and draws the lines on the stack diagram. It sends nothing anywhere.
Analytics, and the choice you are given
There is analytics on this site, and it does not run until you say yes.
The first time you arrive you are asked. Accept and the site loads Google Tag Manager, which in turn loads Google Analytics 4 and Microsoft Clarity. Decline and none of those load at all: no script is fetched, no cookie is set, no request goes to Google or Microsoft, and the site behaves exactly the same. You are not asked a second time either way.
This is a real gate rather than a banner that records a preference while the tags load anyway. You can check it: decline, then open your browser's network panel and reload. There are no third-party requests.
If you accept, here is what runs and what it does.
- Google Tag Manager loads the other two. It is a container, and by itself it measures nothing.
- Google Analytics 4 counts visits and shows which pages get read and roughly where people come from. It sets cookies beginning
_ga, which last up to two years. Google processes this, and Google operates worldwide. - Microsoft Clarity records how pages are actually used: scrolling, clicks, and session replays of the pages you visit. It masks text input by default, so what you type into a form is not captured, but a replay does show how you moved around the page. It sets its own cookies and stores an identifier in your browser.
I use both to see which parts of the page are read and which are ignored. Not to identify you, and neither is connected to an advertising audience.
Changing your mind
Your choice is stored in your own browser, not in a cookie and not on my server, and it never leaves your device.
There is a Cookie choice link in the footer of every page. It reopens the question whenever you want, and whatever you pick replaces what you picked before. Clearing your site data also resets it, and you will simply be asked again on the next visit.
Declining is a decision, not a deferral: I do not re-ask on every page load in the hope of wearing you down.
Who is responsible for it
Alexandra-Emily Kokova. I built this site, I run it, and I run RevOps XL, my operations practice. I am based in Bulgaria and I work remotely.
Under the GDPR I am the data controller for anything collected here. There is no marketing team behind this site and no agency. It is me.
What gets collected when you just read
From me, nothing. I have no way of knowing you were here. No visitor counter, no session, no fingerprint, no dashboard.
My web host keeps server access logs, which is true of every web server anywhere. A log line usually holds your IP address, the time of the request, the file requested, the response code, your browser's user agent, and sometimes the page you came from.
Those logs exist so the server can be kept running and defended. I do not use them for analytics and I do not export them. The host sets how long they live, not me. My host decides how long those logs live, not me, and they have not given me a fixed figure. I would rather say that than print a number I cannot stand behind.
When you send me something through a form
Two forms on this site can send me something, one in the section for agencies and one in the contact section. Neither is required. You can read the whole page and leave without sending anything.
If you submit one, it collects what you typed: your name, the reply address you gave me, your company if you chose to give one, and your message. It also records the time and which form it came from.
It lands in Houred, the CRM I built and run for my own practice. It does not go to Mailchimp, HubSpot, a lead vendor, or any advertising platform. I read it and I answer it.
Submitting a form does not sign you up for anything. There is no newsletter here and no automated sequence waiting for you.
Why I am allowed to hold it
Two lawful bases under Article 6 of the GDPR, and which applies depends on what you sent.
- Legitimate interests, Article 6(1)(f). You wrote to me about work, and answering you is the reason the form exists. My interest is running a business. Yours is getting a reply.
- Steps toward a contract, Article 6(1)(b). If the conversation becomes a proposal or an engagement, I am handling your details to do the thing you asked me to do.
The server logs sit under legitimate interests too, and the interest is keeping the site up.
How long I keep it
There is no fixed clock on this one. A submission stays while the conversation could still go somewhere. I review what I am holding at least once a year and delete what is plainly finished.
After that the submission is deleted.
If the conversation becomes paid work, the records attached to that engagement are kept longer, because Bulgarian accounting and tax law requires it. Those are kept for as long as Bulgarian accounting and tax law requires, which is longer than I would otherwise keep them and is not my choice to make.
You can ask me to delete your details before any of these run out.
Who else touches it
- My web host, which runs the server and keeps the access logs.
- Houred, which is my own system, and the server it runs on. Houred runs on the same server as this site, in Frankfurt, Germany. What you send me stays in the EU.
- My email provider, if I answer you by email.
- Google and Microsoft, but only if you accepted analytics. If you declined, neither of them ever sees you.
Nobody buys this data and nobody rents it. I do not sell contact details and I do not load them into an advertising audience. There is no enrichment vendor appending things to your record behind your back.
There is no automated decision-making here and no profiling. A person reads every message, and the person is me.
Links that leave this site
The page links out to LinkedIn, revopsxl.com, houred.io and a university site. Nothing is fetched from any of them while you read. They only see you if you click.
When you do, my server tells them you came from alexkokova.me and nothing more specific. What they do once you arrive is theirs to explain.
What you can ask me to do
The GDPR gives you rights over your own data and they are not decorative. You can ask me for a copy of what I hold, a correction, deletion, a restriction on what I do with it, a machine-readable export, or you can object to my legitimate-interests basis altogether.
I will answer within a month. I will not charge you, and I will not ask you to justify the request.
Write to aek@revopsxl.com and say what you want. This address is here and nowhere else on the site: for ordinary work I am reached on LinkedIn, but a request about your own data should not depend on you holding a LinkedIn account.
Complaining about me
If you think I have handled your data badly, tell me first and I will try to fix it. You do not have to. You can go straight to the Bulgarian Commission for Personal Data Protection, or to the supervisory authority where you live.
When this page changes
If what the site does changes, this page changes with it, and the date below changes too. Analytics shipped on 26 September 2026, behind the consent gate described above. If anything else is ever added it goes behind the same gate.