[MORSALIN]
Client login
PrivacyLast updated 26 September 2026

Privacy notice

This notice covers morsalin.online, its client portal and the emails I send. In short: I collect only what I need to answer you and do the work, I never sell personal data, analytics and advertising cookies are only used if you allow them (and never in the client portal), and you can see, correct or delete your data at any time.

When I work on a client’s own systems and handle their customers’ or staff’s data, I do that for the client, as their processor, under the Data Processing Agreement; the client’s own privacy notice covers that data.

Who is responsible: MD Morsalin, a sole trader based in Dhaka, Bangladesh, is the controller of the personal data described here. Contact: [email protected].

What I collect, why, and for how long

Inquiry form and emails to me

Data
Your name, email, company, website, tech stack, deadline, budget, your message and the page you wrote from.
Why
To reply, understand the work and prepare a proposal.
Legal basis
Steps you asked for before a contract (GDPR Art. 6(1)(b)).
Kept
2 years after the last activity if we don’t work together; 30 days if it’s spam. If you become a client, as long as your account exists.

AI summary of inquiries

Data
Your message, company and website, without your name or email, are sent to Google’s Gemini API, which drafts a private summary and questions for me.
Why
To read and answer inquiries faster. It only advises me; nothing is decided automatically.
Legal basis
My legitimate interest in handling inquiries efficiently (Art. 6(1)(f)).
Kept
The summary is kept with the inquiry.

The AI assistant on this site

Data
What you type in the chat, sent to Google’s Gemini API to write the answer. You’re told it’s an AI, and this site keeps no copy.
Why
To answer questions about my services.
Legal basis
Legitimate interest (Art. 6(1)(f)). Please don’t share personal or sensitive details in the chat.
Kept
Not stored by this site. Google processes it under its API terms.

End-of-life reminders

Data
Your email and the software versions you chose.
Why
To email you once, about two months before a version loses security support.
Legal basis
Your consent (Art. 6(1)(a)), which you can withdraw with the link in the email.
Kept
Until the reminder is sent or canceled, then 30 days.

Free tools (stack check, app safety check, upgrade planner)

Data
What you enter. The known-vulnerability check sends package names and versions to OSV.dev (Google’s open vulnerability database); the app safety check fetches the public address you give it.
Why
To show you the result.
Legal basis
Legitimate interest (Art. 6(1)(f)).
Kept
Not stored.

Client portal

Data
Your name, email and company (with its country and VAT or GST number, for invoices); what you share with me there (requests, comments, files, notes, feedback); payment reports; proposal decisions with the date and IP address; sign-in and security records with IP address.
Why
To deliver the work, bill for it and keep the portal secure.
Legal basis
Our contract (Art. 6(1)(b)); security and records of agreement are my legitimate interest (Art. 6(1)(f)).
Kept
As long as your account exists. IP addresses in the security log are removed after 90 days; the IP on a proposal decision stays with the proposal as a record of your agreement.

Invoices and payments

Data
Invoice details, amounts, payment dates and the transaction ID you give when you report a payment.
Why
Tax and accounting.
Legal basis
Legal obligation (Art. 6(1)(c)) and our contract.
Kept
6 years after the end of the financial year, even if you ask for deletion.

Referrals

Data
If a client refers you: your name, email and company, as given with your inquiry.
Why
To credit the client who referred you.
Legal basis
Legitimate interest (Art. 6(1)(f)).
Kept
2 years if you don’t become a client; if a credit was given, the record is kept without your details.

Privacy requests

Data
Your email, what you asked for and how it was answered.
Why
To handle the request and show it was handled.
Legal basis
Legal obligation (Art. 6(1)(c)).
Kept
2 years after it’s answered; unconfirmed requests 7 days.

Newsletter

Data
Your email and, if you give them, your name, phone number and company; when you confirmed; and, as Mailchimp records by default, whether you open the emails and click their links.
Why
To send you the newsletter you asked for.
Legal basis
Your consent (Art. 6(1)(a)), confirmed by email (double opt-in). Unsubscribe with the link in any newsletter.
Kept
Until you unsubscribe. Mailchimp then keeps your address as unsubscribed so you aren’t added again by mistake, unless you ask for deletion.

Analytics (only if you allow it)

Data
Pages you view and what you click, approximate location, device and browser, under a random ID in a cookie, collected by Google Analytics 4 through Google Tag Manager. Your IP address isn’t stored.
Why
To see how the site is used and improve it.
Legal basis
Your consent (Art. 6(1)(a) and the cookie rules), which you can withdraw from “Cookie settings” at any time.
Kept
14 months in Google Analytics.

Advertising and marketing (only if you allow it)

Data
Pages you visit and whether you sent an inquiry or signed up (never what you wrote), with cookie IDs, device and browser, sent to Google, Meta, LinkedIn, Microsoft. Ad platforms may link it to your account with them.
Why
To see which ads bring inquiries, show my ads to people who visited, and follow up on what interested you.
Legal basis
Your consent (Art. 6(1)(a) and the cookie rules). Ad platforms also use the data for their own purposes, under their own privacy policies, as separate or joint controllers.
Kept
Cookies last up to 13 months; each service keeps its data under its own policy (linked in the cookie policy).

I never sell personal data, only use it for advertising if you allow advertising cookies, and make no decisions about you by automated means alone. Data that has passed its retention period is deleted automatically every day.

Who helps me process it

These providers process data for me under their data processing terms, and only for the purpose listed. Nobody else receives it unless the law requires it.

ProviderWhat forWhere
Google CloudHosting: the server, database and file storageLondon, United Kingdom
CloudflareDomain name service and network protectionGlobal network
Auth0 (Okta)Client sign-in (email and password)United States
ResendSending emailUnited States
Google Gemini APIThe AI assistant and inquiry summariesUnited States
HubSpotMy contact records, when I look a contact upUnited States / EU
Mailchimp (Intuit)Sending the newsletterUnited States
Google Tag Manager and Google AnalyticsLoading the tags you allow, and analytics (only with consent)United States
Google, Meta, LinkedIn, MicrosoftAd measurement, audiences and marketing tracking (only with consent; ad platforms are also controllers for their own purposes)United States / Ireland

International transfers

Your data is stored in Google Cloud’s London region, and I work on it from Bangladesh. Providers in the United States protect transfers with the EU–US Data Privacy Framework (and its UK extension) where they’re certified, or with the European Commission’s standard contractual clauses in their data processing terms. The same safeguards apply wherever I access the data: encrypted connections, two-step sign-in for administration, and encryption of stored secrets such as passwords you share through the portal.

Cookies and browser storage

These are always on: they’re needed for something you asked for or remember a choice you made. Analytics and advertising cookies are only set if you accept them in the cookie banner, and nothing from Google, Meta or any ad platform loads before you choose. Fonts are served from this site. The full list, and a way to change your choices, is in the cookie policy.

NameTypePurposeHow long
nuxt-sessionCookie (first-party)Keeps you signed in to the client portal7 days, or until you sign out
__a0_txCookie (first-party, set for Auth0)Protects a sign-in while it’s in progressA few minutes
__a0_sessionCookie (first-party, set for Auth0)Auth0’s sign-in session; removed as soon as you’re signed in to the portalSeconds
cookie-consentLocal storageRemembers your cookie choices, so you aren’t asked on every page1 year
morsalin-refSession storageRemembers a client’s referral code for this tab, so it can go with your inquiryUntil you close the tab
display-currencyLocal storageRemembers the currency you chose for pricesUntil you clear it

Your rights

Access
Get a copy of the data I hold about you. Clients can download it any time from the portal.
Correction
Have wrong or incomplete data fixed.
Deletion
Have your data deleted, except what the law makes me keep (invoices).
Restriction and objection
Ask me to pause or stop using your data, including where I rely on legitimate interest.
Portability
Get your data in a machine-readable format (JSON).
Withdraw consent
For end-of-life reminders, with the cancel link in the email; for analytics and advertising cookies, from “Cookie settings” at the bottom of every page.
Complain
To a data protection authority (below).

These rights apply under the GDPR and UK GDPR, and I honor the same requests from everyone, wherever you live. California residents: I don’t sell personal information. If you allow advertising cookies, that can count as “sharing” for targeted advertising; you can opt out at any time from “Cookie settings”, and a Global Privacy Control signal from your browser is treated as an opt-out. You can also ask to know, correct or delete your information without being treated differently.

Requests are free. I answer within one month; if a request is complex I may extend that by up to two more months and will tell you why. I’ll confirm it’s you by email first.

Complaints: I’d like to hear first, at [email protected]. You can also complain to the data protection authority where you live or work: in the EU, your national authority; in the UK, the Information Commissioner’s Office.

Make a request

Clients can download their data and ask for deletion from the portal. Anyone else, use this form.

The address the data is about. I’ll email it a link to confirm it’s yours.
Or email [email protected].

Security, children and changes

Connections are encrypted, the portal needs a password (and two-step sign-in for administration), files are private, and secrets you share through the portal are encrypted and wiped once read. If a breach puts your data at risk, I’ll tell the authority and, where needed, you, as the law requires.

This site isn’t meant for anyone under 16, and I don’t knowingly collect their data.

When this notice changes, the date at the top changes. If a change matters to clients, I’ll also tell them by email.