Privacy notice
This notice covers morsalin.online, its client portal and the emails I send. In short: I collect only what I need to answer you and do the work, I never sell personal data, analytics and advertising cookies are only used if you allow them (and never in the client portal), and you can see, correct or delete your data at any time.
When I work on a client’s own systems and handle their customers’ or staff’s data, I do that for the client, as their processor, under the Data Processing Agreement; the client’s own privacy notice covers that data.
Who is responsible: MD Morsalin, a sole trader based in Dhaka, Bangladesh, is the controller of the personal data described here. Contact: [email protected].
What I collect, why, and for how long
Inquiry form and emails to me
- Data
- Your name, email, company, website, tech stack, deadline, budget, your message and the page you wrote from.
- Why
- To reply, understand the work and prepare a proposal.
- Legal basis
- Steps you asked for before a contract (GDPR Art. 6(1)(b)).
- Kept
- 2 years after the last activity if we don’t work together; 30 days if it’s spam. If you become a client, as long as your account exists.
AI summary of inquiries
- Data
- Your message, company and website, without your name or email, are sent to Google’s Gemini API, which drafts a private summary and questions for me.
- Why
- To read and answer inquiries faster. It only advises me; nothing is decided automatically.
- Legal basis
- My legitimate interest in handling inquiries efficiently (Art. 6(1)(f)).
- Kept
- The summary is kept with the inquiry.
The AI assistant on this site
- Data
- What you type in the chat, sent to Google’s Gemini API to write the answer. You’re told it’s an AI, and this site keeps no copy.
- Why
- To answer questions about my services.
- Legal basis
- Legitimate interest (Art. 6(1)(f)). Please don’t share personal or sensitive details in the chat.
- Kept
- Not stored by this site. Google processes it under its API terms.
End-of-life reminders
- Data
- Your email and the software versions you chose.
- Why
- To email you once, about two months before a version loses security support.
- Legal basis
- Your consent (Art. 6(1)(a)), which you can withdraw with the link in the email.
- Kept
- Until the reminder is sent or canceled, then 30 days.
Free tools (stack check, app safety check, upgrade planner)
- Data
- What you enter. The known-vulnerability check sends package names and versions to OSV.dev (Google’s open vulnerability database); the app safety check fetches the public address you give it.
- Why
- To show you the result.
- Legal basis
- Legitimate interest (Art. 6(1)(f)).
- Kept
- Not stored.
Client portal
- Data
- Your name, email and company (with its country and VAT or GST number, for invoices); what you share with me there (requests, comments, files, notes, feedback); payment reports; proposal decisions with the date and IP address; sign-in and security records with IP address.
- Why
- To deliver the work, bill for it and keep the portal secure.
- Legal basis
- Our contract (Art. 6(1)(b)); security and records of agreement are my legitimate interest (Art. 6(1)(f)).
- Kept
- As long as your account exists. IP addresses in the security log are removed after 90 days; the IP on a proposal decision stays with the proposal as a record of your agreement.
Invoices and payments
- Data
- Invoice details, amounts, payment dates and the transaction ID you give when you report a payment.
- Why
- Tax and accounting.
- Legal basis
- Legal obligation (Art. 6(1)(c)) and our contract.
- Kept
- 6 years after the end of the financial year, even if you ask for deletion.
Referrals
- Data
- If a client refers you: your name, email and company, as given with your inquiry.
- Why
- To credit the client who referred you.
- Legal basis
- Legitimate interest (Art. 6(1)(f)).
- Kept
- 2 years if you don’t become a client; if a credit was given, the record is kept without your details.
Privacy requests
- Data
- Your email, what you asked for and how it was answered.
- Why
- To handle the request and show it was handled.
- Legal basis
- Legal obligation (Art. 6(1)(c)).
- Kept
- 2 years after it’s answered; unconfirmed requests 7 days.
Analytics (only if you allow it)
- Data
- Pages you view and what you click, approximate location, device and browser, under a random ID in a cookie, collected by Google Analytics 4 through Google Tag Manager. Your IP address isn’t stored.
- Why
- To see how the site is used and improve it.
- Legal basis
- Your consent (Art. 6(1)(a) and the cookie rules), which you can withdraw from “Cookie settings” at any time.
- Kept
- 14 months in Google Analytics.
Advertising and marketing (only if you allow it)
- Data
- Pages you visit and whether you sent an inquiry or signed up (never what you wrote), with cookie IDs, device and browser, sent to Google, Meta, LinkedIn, Microsoft. Ad platforms may link it to your account with them.
- Why
- To see which ads bring inquiries, show my ads to people who visited, and follow up on what interested you.
- Legal basis
- Your consent (Art. 6(1)(a) and the cookie rules). Ad platforms also use the data for their own purposes, under their own privacy policies, as separate or joint controllers.
- Kept
- Cookies last up to 13 months; each service keeps its data under its own policy (linked in the cookie policy).
I never sell personal data, only use it for advertising if you allow advertising cookies, and make no decisions about you by automated means alone. Data that has passed its retention period is deleted automatically every day.
Who helps me process it
These providers process data for me under their data processing terms, and only for the purpose listed. Nobody else receives it unless the law requires it.
| Provider | What for | Where |
|---|---|---|
| Google Cloud | Hosting: the server, database and file storage | London, United Kingdom |
| Cloudflare | Domain name service and network protection | Global network |
| Auth0 (Okta) | Client sign-in (email and password) | United States |
| Resend | Sending email | United States |
| Google Gemini API | The AI assistant and inquiry summaries | United States |
| HubSpot | My contact records, when I look a contact up | United States / EU |
| Mailchimp (Intuit) | Sending the newsletter | United States |
| Google Tag Manager and Google Analytics | Loading the tags you allow, and analytics (only with consent) | United States |
| Google, Meta, LinkedIn, Microsoft | Ad measurement, audiences and marketing tracking (only with consent; ad platforms are also controllers for their own purposes) | United States / Ireland |
International transfers
Your data is stored in Google Cloud’s London region, and I work on it from Bangladesh. Providers in the United States protect transfers with the EU–US Data Privacy Framework (and its UK extension) where they’re certified, or with the European Commission’s standard contractual clauses in their data processing terms. The same safeguards apply wherever I access the data: encrypted connections, two-step sign-in for administration, and encryption of stored secrets such as passwords you share through the portal.
Cookies and browser storage
These are always on: they’re needed for something you asked for or remember a choice you made. Analytics and advertising cookies are only set if you accept them in the cookie banner, and nothing from Google, Meta or any ad platform loads before you choose. Fonts are served from this site. The full list, and a way to change your choices, is in the cookie policy.
| Name | Type | Purpose | How long |
|---|---|---|---|
| nuxt-session | Cookie (first-party) | Keeps you signed in to the client portal | 7 days, or until you sign out |
| __a0_tx | Cookie (first-party, set for Auth0) | Protects a sign-in while it’s in progress | A few minutes |
| __a0_session | Cookie (first-party, set for Auth0) | Auth0’s sign-in session; removed as soon as you’re signed in to the portal | Seconds |
| cookie-consent | Local storage | Remembers your cookie choices, so you aren’t asked on every page | 1 year |
| morsalin-ref | Session storage | Remembers a client’s referral code for this tab, so it can go with your inquiry | Until you close the tab |
| display-currency | Local storage | Remembers the currency you chose for prices | Until you clear it |
Your rights
- Access
- Get a copy of the data I hold about you. Clients can download it any time from the portal.
- Correction
- Have wrong or incomplete data fixed.
- Deletion
- Have your data deleted, except what the law makes me keep (invoices).
- Restriction and objection
- Ask me to pause or stop using your data, including where I rely on legitimate interest.
- Portability
- Get your data in a machine-readable format (JSON).
- Withdraw consent
- For end-of-life reminders, with the cancel link in the email; for analytics and advertising cookies, from “Cookie settings” at the bottom of every page.
- Complain
- To a data protection authority (below).
These rights apply under the GDPR and UK GDPR, and I honor the same requests from everyone, wherever you live. California residents: I don’t sell personal information. If you allow advertising cookies, that can count as “sharing” for targeted advertising; you can opt out at any time from “Cookie settings”, and a Global Privacy Control signal from your browser is treated as an opt-out. You can also ask to know, correct or delete your information without being treated differently.
Requests are free. I answer within one month; if a request is complex I may extend that by up to two more months and will tell you why. I’ll confirm it’s you by email first.
Complaints: I’d like to hear first, at [email protected]. You can also complain to the data protection authority where you live or work: in the EU, your national authority; in the UK, the Information Commissioner’s Office.
Make a request
Clients can download their data and ask for deletion from the portal. Anyone else, use this form.
Security, children and changes
Connections are encrypted, the portal needs a password (and two-step sign-in for administration), files are private, and secrets you share through the portal are encrypted and wiped once read. If a breach puts your data at risk, I’ll tell the authority and, where needed, you, as the law requires.
This site isn’t meant for anyone under 16, and I don’t knowingly collect their data.
When this notice changes, the date at the top changes. If a change matters to clients, I’ll also tell them by email.