Skip to main content

Privacy notice

Last updated

This page explains what this website collects about you, why, who else handles it, how long it is kept, and what you can ask me to do about it.

How you may use the site and what it publishes is covered by the terms of use.

Who is responsible

I am Md Moniruzzaman, and Webanion is the name I work under. I am based in Dhaka, Bangladesh. I decide what happens to the personal data this site collects, which makes me its controller under the GDPR and the UK GDPR, and its data fiduciary under India’s Digital Personal Data Protection Act.

For anything on this page, email me at [email protected], the address on the contact page.

What the site collects, and why

Each part of the site that collects something is listed here with what it takes, what I use it for and the legal basis I rely on. Where the law you live under does not recognise legitimate interests, as India’s does not, I rely on you having sent the data yourself for the purpose stated next to the form, or on your consent.

The contact form

It takes your name, your email address, your message, and a file if you attach one (PDF or Word, up to 5 MB). They are stored in the site’s database, and a copy, file included, is emailed to my inbox. I use them to read and answer your message, and for nothing else.

With each message, the site also stores a key for the network it came from, and uses it only to limit how many messages one network can send in a day. The key is a hash of your IP address (for an IPv6 address, of the block it belongs to), keyed with a secret held on my server and with the date in UTC, so the same network has a different key the next day. Once the UTC day it was made for is over, the key is cleared from every message, at 00:05 UTC. Your IP address itself is not stored, and without that secret the key cannot be turned back into it. Like the visit counter’s key below, it is still pseudonymous rather than anonymous, because it is derived from your address.

Legal basis: my legitimate interest in answering people who write to me and in keeping the form from being flooded, and, when you ask about work, steps you have asked me to take before a contract.

Job applications

An application on a careers page goes through the same form: your name, email address, a note, and your resume if you attach one, linked to the role you applied for. It is stored and emailed the same way as a message. I use it to consider you for that role and to reply.

Legal basis: steps you have asked me to take before a possible contract.

The newsletter

It takes your email address and nothing else. I keep it to send you the newsletter. To leave the list, email me and I delete the address.

Legal basis: your consent, given by subscribing and withdrawn by asking me to remove you.

Signing in to the MCP server

The MCP server at mcp.webanion.com lets AI assistants read this portfolio (the guide says how). Signing in from an assistant, or registering for an API key, asks for your name and email address; registering for a key also takes an optional organisation and purpose. I store those, when you verified the address, when you last used the server and how many requests you have made. The six-digit code, the key and the sign-in tokens are stored only as hashes. A message you send through the server arrives in my inbox under your verified name and address, like one from the contact form.

I use this to send you the code, to let your assistant in, to know who is asking and to stop abuse.

Legal basis: providing the access you asked for, and my legitimate interest in preventing abuse.

The visit counter

When the counter is switched on, each page you open sends its path to the site. The server hashes your IP address and browser user agent together with a value that changes every day, and stores only the result, with the path and the date, so it can count how many different people read a page on a given day. Your address and user agent are not stored, no cookie is set, and the same visitor has a different key the next day. The key is still a pseudonymous identifier rather than an anonymous one, because it is derived from your address. The keyed rows are deleted after a week. What stays is each page’s count for each day, which holds no key.

Legal basis: my legitimate interest in knowing which pages are read.

The site assistant

When the assistant is switched on, what you type into it is sent, with the conversation so far, to Anthropic, whose Claude model writes the answer and looks things up on the public MCP server. This site does not store the conversation. To limit how many messages one address can send in an hour, the server keeps your IP address in its memory, and only there, until it restarts. Please keep personal details out of your questions.

Legal basis: answering the question you asked, and my legitimate interest in limiting abuse.

Server and network logs

Every request to the site passes through Cloudflare, which delivers and protects it, and then reaches my servers. Cloudflare processes your IP address, the page you asked for, your browser’s user agent and similar request details, and keeps its own logs under its own policy. My servers keep application logs of errors and of mail sent, which can include the email address a notification was about. Requests to the forms are limited per IP address, counted in memory, to stop abuse.

Legal basis: my legitimate interest in keeping the site secure and working.

What your browser fetches from elsewhere

One thing on the site comes straight from another organisation’s servers: the map on the contact page, whose tiles come from the OpenStreetMap Foundation. When your browser fetches them, it sends the OpenStreetMap Foundation your IP address, your user agent and the site’s address, without the page you are on. The site’s font is served by the site itself.

Who else handles it

WhoWhat forWhere
CloudflareDelivers and protects every request, and carries the connection to my serversIts global network; a US company
ResendSends the notification emails and the MCP sign-in codesUnited States
GoogleHosts my mailbox, where the notification copies of messages and applications arrive along with any email you send me directlyUnited States and elsewhere
AnthropicWrites the assistant’s answers, only while it is switched onUnited States
OpenStreetMap FoundationThe map tiles on the contact pageIts own servers and a global network of cache servers; a UK non-profit
Google, Meta, TikTokAnalytics and ad measurement, only if switched on and only if you accept them (see cookies)United States and elsewhere

The website, the CMS and its database, the MCP server and the backups run on servers I own and operate myself. Nobody else hosts them.

Where it is stored and sent

Everything the forms and the MCP server collect is stored in a database on those servers, in Bangladesh, and backed up there. If you are outside Bangladesh, sending me anything through this site transfers it to Bangladesh, and the providers above handle parts of it in the United States and elsewhere.

Bangladesh has no adequacy decision from the EU or the UK. I rely on the transfer being necessary to do what you asked: answer your message, consider your application, or give you the access or the newsletter you signed up for. The providers above set out their own safeguards for the countries they work in, in their terms.

How long it is kept

Deleting a record removes it from the database at once, file included. The backups then age out as the last row says.

WhatKept for
Contact messages, their attachments, and the copies in my inbox2 years after our last exchange, unless they become part of the records of work we do together
The network key stored with each message sent through the websiteUntil the UTC day it was made for is over. It is cleared from every message at 00:05 UTC
Applications, resumes, and the copies in my inbox6 months after I decide on the application
Newsletter addressesUntil you ask me to remove yours
MCP sign-ins and API keysUntil you ask me to delete them, or 12 months after their last use. A sign-in code expires in 15 minutes, an access token in an hour, and a refresh token 60 days after it was last used
Visit counter keys7 days. The daily count for each page, which holds no key, is kept
Assistant conversationsNot kept by this site
My servers’ logsUp to 30 days
Database backupsNightly copies are kept 14 days and weekly copies 8 weeks, so anything I delete is gone from the backups within 8 weeks

Your rights

Wherever you live, you can ask me:

  • for a copy of the personal data I hold about you, in a portable format if you want it;
  • to correct it;
  • to delete it;
  • to stop using it, or to keep it without using it while we settle a disagreement about it;
  • to stop using it on the basis of my legitimate interests, by objecting;
  • to withdraw a consent you gave, which does not undo what was done before.

Email me at [email protected] from the address the data is about, or tell me how I can confirm it is you. I answer within a month and do not charge for it.

If you think I have mishandled your data, you can complain to the data protection authority where you live or work: in the EU, your national supervisory authority; in the UK, the Information Commissioner’s Office; in India, the Data Protection Board of India. I would like the chance to put it right first, but you do not need my answer before you complain.

No automated decisions, no sale

Messages and applications are read by a person, and no decision about you is made by software alone. I do not sell personal data, and I do not hand it to anyone to use for their own advertising. The Meta and TikTok pixels described below would tell those companies which pages you visited, which is why they only load if you accept them.

Cookies and browser storage

The site sets two cookies of its own. Both are strictly necessary for the site to work as you left it, so they need no consent.

CookieWhat it holdsHow long
i18nextYour language, so pages open in itUntil you close the browser
themeLight or darkUntil you close the browser, or 30 days once you switch it

It also keeps three small values in your browser’s storage, which are never sent anywhere: your language (i18nextLng, local storage), whether the assistant is on (webanion-assistant, session storage), and a note that the visit counter is off (visits, session storage).

Cloudflare can set its own security cookie, such as __cf_bm or cf_clearance, when it has to check that a request comes from a person. That cookie is Cloudflare’s and is strictly necessary.

The site’s code also includes three optional trackers: Google Analytics, under Analytics, and the Meta and TikTok pixels, under Marketing. Each one runs only once I have set it up, and then only after you accept its category. If this site has never asked you about cookies, none of them is set up. Until you choose, nothing loads, and refusing takes one click, as accepting does.

If you accept, the vendors set their own cookies: Google Analytics sets _ga and _ga_ followed by an id, for up to two years; the Meta pixel sets _fbp, for 90 days; the TikTok pixel sets _ttp, for up to 13 months. Those are the lifetimes the vendors document. Your choice is kept in a consent cookie and in local storage for 180 days, and then you are asked again. The Cookie settings link at the bottom of every page reopens your choice at any time.

Children

The site is meant for adults hiring or looking for work. It is not aimed at children, and I do not knowingly collect personal data from anyone under 18.

Changes to this notice

When this notice changes, the date at the top changes with it. If the site starts collecting something new or sending it somewhere new, this page says so first.