Privacy
Policy updated 1 August 2026
This Privacy notice explains how mostafijur.in (“this site”) handles personal information. The site is operated by Mostafijur Rahaman as a personal publishing and professional identity platform.
I aim to collect only what is needed to run the site, respond to professional enquiries, and keep the service secure. This notice is written in plain language so you can understand what happens to your information.
Who is responsible
Mostafijur Rahaman is the person responsible for this site and for personal data processed through it.
Privacy and data requests: [email protected], or the Contact form at /contact. For privacy-related messages, say so clearly in the subject or opening line.
Information this site may process
Depending on how you use the site, the following categories may be processed:
- Contact enquiries: name, email address, enquiry type, subject, message, and optional organisation, role, website, or phone number if you provide them.
- Security and abuse prevention: IP address, basic request metadata, rate-limit signals, and Cloudflare Turnstile challenge results used to reduce spam and automated abuse on the contact form.
- Technical operation: server and application logs needed to run, troubleshoot, and protect the site (typically IP address, user agent, timestamps, and error details—not contact-form message bodies in monitoring alerts).
- Media and content: files and text you do not submit as a visitor, but that I publish through the CMS (articles, case studies, images). Published content is public by design.
Information I do not intentionally collect
- Government identity documents
- Payment or banking details
- Health information
- Family or household details
- Account passwords from visitors (there is no public visitor account signup)
- Confidential employer or customer data that should not be shared publicly
Why information is used
Personal information from the contact form is used only to:
- Understand and respond to your enquiry
- Prevent spam, abuse, and automated submissions
- Keep operational records needed to run a professional correspondence channel
- Protect the security and integrity of the site
Cookies, analytics, and similar technologies
This site is designed to work without advertising trackers and without building cross-site advertising profiles.
Essential or security-related technologies may be used for hosting, TLS, CDN, and spam protection. Cloudflare may process connection data as part of DNS, CDN, and security services. Cloudflare Turnstile may set or read data needed to validate that a contact submission is likely human.
Product analytics are not currently enabled on this site. If privacy-conscious analytics are introduced later, this notice will be updated, and any non-essential tracking will follow applicable consent requirements (APC-010 remains an open product decision until then).
Admin users of the CMS may have session cookies required to sign in and manage content. Those sessions are not used for public visitor advertising.
Third-party services
To operate the site I may use the following categories of processors. Exact providers can change; the purposes below reflect the current architecture:
- Hosting and application runtime: cloud virtual machine hosting the Next.js and Payload application (currently Amazon EC2 under my account control).
- Database: PostgreSQL storing CMS content and operational enquiry records on the application host (localhost to the app).
- File storage: Amazon S3 when configured for media; otherwise local media storage on the application host.
- CDN and edge security: Cloudflare for DNS, caching, and TLS termination in front of the origin.
- Spam protection: Cloudflare Turnstile on the contact form.
- Email delivery: SMTP-based transactional email to deliver enquiry notifications to me. Message content is transmitted to that email channel so I can reply.
Where data is processed
Infrastructure and processors may process data in the regions they operate (for example cloud hosting, CDN edge locations, and email delivery). If you contact me from another country, your enquiry will necessarily cross networks to reach the systems that host and deliver it.
Retention
I keep personal data only as long as needed for the purposes above, or longer when a legal obligation requires it:
- Contact enquiries: retained while useful for communication and legitimate professional records, then deleted or anonymised.
- Rejected spam and clearly abusive submissions: deleted or anonymised promptly.
- Security and application logs: retained for a limited troubleshooting and security period, then rotated away.
- Analytics data: not currently collected; if introduced, retention will be set as short as practical.
- Published website content: retained under my editorial control until updated or removed.
Security
I apply reasonable safeguards appropriate to a personal professional site, including HTTPS, access-controlled administration, server-side validation, spam protection on contact, rate limiting, environment-managed secrets, and restricted database network exposure.
No method of transmission or storage is perfectly secure. If I become aware of a personal-data incident that requires notification, I will assess obligations and notify affected people and authorities when required.
Your choices and requests
Subject to applicable law (including India’s Digital Personal Data Protection Act, 2023, where it applies), you may ask me to:
- Provide information about personal data I hold about you from this site
- Correct inaccurate personal data
- Delete personal data where applicable
- Withdraw consent for optional processing if that processing is introduced later
- Raise a privacy grievance related to this site
How to make a request
Email [email protected] or use the Contact form. Include enough detail for me to find your enquiry (for example the email address you used and approximate date).
I will acknowledge requests, verify them in a proportionate way, and respond within applicable legal timelines. I may decline requests that are unfounded, excessive, or that would compromise another person’s privacy or security.
Children
This site is aimed at professional adult audiences. It is not directed at children, and I do not knowingly seek personal data from children through the contact form.
Confidentiality in published work
Case studies and writing on this site are intended to respect employer confidentiality and avoid disclosing customer or user personal data. If you believe published material includes information that should not be public, contact me and I will review it promptly.
Changes to this notice
I may update this notice when practices, processors, or legal requirements change. The “Policy updated” date at the top of this page reflects the latest substantive revision. Continued use of the site after an update means the revised notice applies to later visits and submissions.