Privacy and security
7 articles
Privacy and securityMailchimp double opt in: what it turns on and who it costs you
What Mailchimp double opt in actually switches on, where it cannot be enabled, what the pending status costs you, and how to decide whether the confirmation step belongs on your form.
October 8, 2026
Privacy and securityIs Google Forms HIPAA compliant: what to check before you collect
Is Google Forms HIPAA compliant? What the BAA covers, the Included Functionality list, the settings that have to change, and the gaps a form alone leaves open.
October 7, 2026
Privacy and securityGDPR data retention: how long to keep what a form collected
GDPR data retention sets a test, not a number of months. How to set a defensible period for form responses, record it, and make the deletion actually happen.
October 5, 2026
Privacy and securityGDPR checkbox example: consent wording that holds up
A GDPR checkbox example set with the wording written out, plus what Article 7 and Recital 32 require, when consent is the wrong basis, and how to keep the proof.
October 5, 2026
Privacy and securityDouble opt in: why the second click changes what you can send
Double opt in proves an address is reachable, not that consent was given. What the second click actually settles, where the setting lives, and the edge cases that break it.
October 2, 2026
Privacy and securityPrevent contact form spam without a captcha: what actually works
How to prevent contact form spam without captcha: the four layers of defence, what each one costs in 2026, and the one setting that decides whether you can spot a false positive.
October 1, 2026
Privacy and securityConsent to be contacted: asking once, in a way you can show later
Consent to be contacted has to be provable months later. What the wording has to do, what to store alongside it, and how withdrawal reaches every form.
October 1, 2026