Legal

Privacy Policy

What actually happens to visitor data on petro-stone.am — no boilerplate, and no clauses that do not apply to us.

In force since 26 August 2026 Last updated — 26 August 2026

This policy is written to be read in full. It describes only what actually happens: no promises we do not keep, and no mention of technologies this site does not use.

Who we are

The data controller — the party that decides why and how data is processed — is PETRO STONE, a company that quarries and supplies natural stone from Armenia. The site petro-stone.am belongs to the company and is run by it.

PETRO STONE
natural stone of Armenia
Address
Армения, г. Ереван, ул. Республики, 22

We have not appointed a Data Protection Officer: the law does not require one from a company of our size and activity. All requests concerning this policy are handled by the company's management at the address above.

What data the site collects

There is not a single form on this site. No name, phone or email fields, no enquiry form, no newsletter sign-up, no chat, no call-back request. The site is technically incapable of receiving your personal data until you send it to us yourself.

We keep no visitor database, build no profiles, run no targeted advertising, and neither share nor sell data to anyone. No web analytics system is installed here: no Google Analytics, no Yandex.Metrica, no social network pixels, no counters of any other kind.

You can reach us through the “call” and “write” links. Clicking one opens your own phone app or mail client — the call and the message leave from there, the site takes no part in it and never sees the contents. What happens to your message afterwards is described in section 8.

Technical web server data

Like any site on the internet, petro-stone.am runs on a web server that keeps a technical request log. It automatically records:

  • the IP address of the device the request came from;
  • the date and time of the request;
  • the address of the requested page or file and the server response code;
  • the User-Agent string — browser, its version and operating system;
  • the address of the page you came from, if the browser sent it.

These entries are created automatically and are not linked to your name. They exist purely to keep the site working: finding errors, fending off attacks and password guessing, gauging load. We do not mine the logs for marketing and do not try to identify visitors from them.

The legal basis is our legitimate interest in operating the site securely and reliably, Article 6(1)(f) GDPR.

Cookies and local storage

The site sets no cookies at all — not first-party, not third-party, not advertising, not analytics. That is also why there is no cookie consent banner here: there is nothing to consent to.

Exactly one entry is saved in your browser: the ps-theme key in local storage, holding the value light or dark. That is the colour theme you picked with the switch in the header. The entry exists only so the page opens straight away in your chosen theme instead of flashing white. It contains no identifier, cannot be used to recognise you, is never sent anywhere and never leaves your browser. You can delete it at any time by clearing site data in your browser settings — the site will keep working and simply return to the default theme.

Beyond that, the browser tells the page two system signals: whether data-saver mode is on and whether you have asked for reduced motion. The site uses them to decide whether to play the background video. Both values are read when the page opens, are stored nowhere and are sent to no one.

Third-party services

There is one third-party service on the site, and it deserves a straight answer. The typefaces the site is set in are loaded from Google's servers — fonts.googleapis.com and fonts.gstatic.com, operated by Google LLC (USA). This means that on every page load your browser contacts Google, and Google receives your IP address, your User-Agent string and the address of the page the request came from. How Google handles that data is set out in its own privacy policy; we have no control over it.

The request goes out automatically as the page loads, before you do anything, so asking for consent is technically impossible — and we will not pretend to ask. If you would rather it did not happen, you can block it with a browser extension or at the network level: the site stays perfectly readable, only the lettering changes.

There are no other third-party services here. All images, icons and video are served from our own domain. No third-party CDN, no images from other people's servers, no embedded maps, players, social widgets or share buttons are used.

The footer and the contacts page carry links to Facebook, WhatsApp and Viber. Until you click one, no request is made to those services. If you do click, you leave for someone else's site, where their rules apply and not ours.

Where data is stored and how it is protected

The site and its administrative back end sit on a dedicated server in a Contabo GmbH data centre inside the European Union (France). The technical logs described in section 3 are kept there and are never exported off that server.

The connection to the site is always encrypted (HTTPS). The database and the content management system are reachable only from within the server itself, are password-protected and are not exposed to the internet; the administrative back end is closed to search engines.

We transfer visitor data to no third country, no ad network and no analytics provider — simply because we collect none. The only transfer outside the European Union is the Google Fonts request described in section 5, and it happens directly from your browser, bypassing our server.

How long we keep data

  • Web server technical logs — no longer than 30 days, after which they are overwritten automatically.
  • Email and messenger correspondence — for as long as it is needed to deal with your enquiry. If the enquiry turns into a supply order, the documents and the related correspondence are kept for the periods set by Armenian accounting and tax law. If no deal followed, we delete it at your request or once it is no longer needed.
  • Your colour theme choice — until you delete it in your browser yourself. On our side that entry is not stored at all.

If you write or call us

When you send us an email, message us on WhatsApp or Viber, or call the numbers listed, we receive the data you provide yourself: name, email address, phone number, company name, the content of your enquiry and any attached files. We use it for exactly one purpose — to answer you and, if it comes to a supply, to draw up and perform a contract. The legal basis is Article 6(1)(b) GDPR for pre-contractual correspondence and the contract itself, and Article 6(1)(f) for other business correspondence.

Correspondence is kept in the company's mailboxes and, for orders that went ahead, in our working documents. Only the employees handling your enquiry have access to it. We do not add your address to any mailing list unless you ask us to.

Note that WhatsApp and Viber are third-party messengers, and the handling of messages inside them follows their owners' rules, not this policy. If that does not suit you, email us or call instead.

Your rights

If you are in the European Union, the GDPR — Regulation (EU) 2016/679 — applies to this processing. In Armenia, the Law of the Republic of Armenia on the Protection of Personal Data applies. The set of rights is essentially the same:

  • to learn whether we process your data and to receive a copy of it — Article 15 GDPR;
  • to correct inaccurate data and complete incomplete data — Article 16;
  • to request erasure of your data — Article 17;
  • to restrict processing while a dispute is resolved — Article 18;
  • to receive your data in a machine-readable form or have it transmitted to another controller — Article 20;
  • to object to processing based on legitimate interest — Article 21;
  • to withdraw consent where processing rests on it; this does not affect the lawfulness of processing carried out beforehand;
  • to lodge a complaint with a supervisory authority: in the EU, where you live or work; in Armenia, with the Personal Data Protection Agency of the Ministry of Justice.

To exercise any of these rights, email the address given in section 1 — a plain message is enough. We reply within 30 days. If it is not clear from your message which data you mean, we may ask follow-up questions; we do not request or keep identity documents.

One honest caveat. If you only visited the site and never wrote to us, we most likely hold no data about you at all — beyond lines in a server log that cannot be tied to any person without a request to your internet provider. We make no such requests. So when someone asks us to delete their data, there is usually nothing to delete, and we will say so plainly.

Changes to this policy

If we change something on the site — add an enquiry form, switch on analytics, install a live chat — we will rewrite this page first and launch the change only afterwards. The date of the last update is always shown at the top. We do not publish previous versions: the one in force is the one you are reading now.

Questions about this policy go to our email address — we will answer on the merits.