Privacy notice
Last updated
This page explains what this website collects about you, why, who else handles it, how long it is kept, and what you can ask me to do about it.
How you may use the site and what it publishes is covered by the terms of use.
Who is responsible
I am Md Moniruzzaman, and Webanion is the name I work under. I am based in Dhaka, Bangladesh. I decide what happens to the personal data this site collects, which makes me its controller under the GDPR and the UK GDPR, and its data fiduciary under India’s Digital Personal Data Protection Act.
For anything on this page, email me at [email protected], the address on the contact page.
What the site collects, and why
Each part of the site that collects something is listed here with what it takes, what I use it for and the legal basis I rely on. Where the law you live under does not recognise legitimate interests, as India’s does not, I rely on you having sent the data yourself for the purpose stated next to the form, or on your consent.
The contact form
It takes your name, your email address, your message, and a file if you attach one (PDF or Word, up to 5 MB). They are stored in the site’s database, and a copy, file included, is emailed to my inbox. I use them to read and answer your message, and for nothing else.
With each message, the site also stores a key for the network it came from, and uses it only to limit how many messages one network can send in a day. The key is a hash of your IP address (for an IPv6 address, of the block it belongs to), keyed with a secret held on my server and with the date in UTC, so the same network has a different key the next day. Once the UTC day it was made for is over, the key is cleared from every message, at 00:05 UTC. Your IP address itself is not stored, and without that secret the key cannot be turned back into it. Like the visit counter’s key below, it is still pseudonymous rather than anonymous, because it is derived from your address.
Legal basis: my legitimate interest in answering people who write to me and in keeping the form from being flooded, and, when you ask about work, steps you have asked me to take before a contract.
Job applications
An application on a careers page goes through the same form: your name, email address, a note, and your resume if you attach one, linked to the role you applied for. It is stored and emailed the same way as a message. I use it to consider you for that role and to reply.
Legal basis: steps you have asked me to take before a possible contract.
The newsletter
It takes your email address and nothing else. I keep it to send you the newsletter. To leave the list, email me and I delete the address.
Legal basis: your consent, given by subscribing and withdrawn by asking me to remove you.
Signing in to the MCP server
The MCP server at mcp.webanion.com lets AI assistants read this portfolio (the guide says how). Signing in from an assistant, or registering for an API key, asks for your name and email address; registering for a key also takes an optional organisation and purpose. I store those, when you verified the address, when you last used the server and how many requests you have made. The six-digit code, the key and the sign-in tokens are stored only as hashes. A message you send through the server arrives in my inbox under your verified name and address, like one from the contact form.
I use this to send you the code, to let your assistant in, to know who is asking and to stop abuse.
Legal basis: providing the access you asked for, and my legitimate interest in preventing abuse.
The visit counter
When the counter is switched on, each page you open sends its path to the site. The server hashes your IP address and browser user agent together with a value that changes every day, and stores only the result, with the path and the date, so it can count how many different people read a page on a given day. Your address and user agent are not stored, no cookie is set, and the same visitor has a different key the next day. The key is still a pseudonymous identifier rather than an anonymous one, because it is derived from your address. The keyed rows are deleted after a week. What stays is each page’s count for each day, which holds no key.
Legal basis: my legitimate interest in knowing which pages are read.
The site assistant
When the assistant is switched on, what you type into it is sent, with the conversation so far, to Anthropic, whose Claude model writes the answer and looks things up on the public MCP server. This site does not store the conversation. To limit how many messages one address can send in an hour, the server keeps your IP address in its memory, and only there, until it restarts. Please keep personal details out of your questions.
Legal basis: answering the question you asked, and my legitimate interest in limiting abuse.
Server and network logs
Every request to the site passes through Cloudflare, which delivers and protects it, and then reaches my servers. Cloudflare processes your IP address, the page you asked for, your browser’s user agent and similar request details, and keeps its own logs under its own policy. My servers keep application logs of errors and of mail sent, which can include the email address a notification was about. Requests to the forms are limited per IP address, counted in memory, to stop abuse.
Legal basis: my legitimate interest in keeping the site secure and working.
What your browser fetches from elsewhere
One thing on the site comes straight from another organisation’s servers: the map on the contact page, whose tiles come from the OpenStreetMap Foundation. When your browser fetches them, it sends the OpenStreetMap Foundation your IP address, your user agent and the site’s address, without the page you are on. The site’s font is served by the site itself.
Who else handles it
| Who | What for | Where |
|---|---|---|
| Cloudflare | Delivers and protects every request, and carries the connection to my servers | Its global network; a US company |
| Resend | Sends the notification emails and the MCP sign-in codes | United States |
| Hosts my mailbox, where the notification copies of messages and applications arrive along with any email you send me directly | United States and elsewhere | |
| Anthropic | Writes the assistant’s answers, only while it is switched on | United States |
| OpenStreetMap Foundation | The map tiles on the contact page | Its own servers and a global network of cache servers; a UK non-profit |
| Google, Meta, TikTok | Analytics and ad measurement, only if switched on and only if you accept them (see cookies) | United States and elsewhere |
The website, the CMS and its database, the MCP server and the backups run on servers I own and operate myself. Nobody else hosts them.
Where it is stored and sent
Everything the forms and the MCP server collect is stored in a database on those servers, in Bangladesh, and backed up there. If you are outside Bangladesh, sending me anything through this site transfers it to Bangladesh, and the providers above handle parts of it in the United States and elsewhere.
Bangladesh has no adequacy decision from the EU or the UK. I rely on the transfer being necessary to do what you asked: answer your message, consider your application, or give you the access or the newsletter you signed up for. The providers above set out their own safeguards for the countries they work in, in their terms.
How long it is kept
Deleting a record removes it from the database at once, file included. The backups then age out as the last row says.
| What | Kept for |
|---|---|
| Contact messages, their attachments, and the copies in my inbox | 2 years after our last exchange, unless they become part of the records of work we do together |
| The network key stored with each message sent through the website | Until the UTC day it was made for is over. It is cleared from every message at 00:05 UTC |
| Applications, resumes, and the copies in my inbox | 6 months after I decide on the application |
| Newsletter addresses | Until you ask me to remove yours |
| MCP sign-ins and API keys | Until you ask me to delete them, or 12 months after their last use. A sign-in code expires in 15 minutes, an access token in an hour, and a refresh token 60 days after it was last used |
| Visit counter keys | 7 days. The daily count for each page, which holds no key, is kept |
| Assistant conversations | Not kept by this site |
| My servers’ logs | Up to 30 days |
| Database backups | Nightly copies are kept 14 days and weekly copies 8 weeks, so anything I delete is gone from the backups within 8 weeks |
Your rights
Wherever you live, you can ask me:
- for a copy of the personal data I hold about you, in a portable format if you want it;
- to correct it;
- to delete it;
- to stop using it, or to keep it without using it while we settle a disagreement about it;
- to stop using it on the basis of my legitimate interests, by objecting;
- to withdraw a consent you gave, which does not undo what was done before.
Email me at [email protected] from the address the data is about, or tell me how I can confirm it is you. I answer within a month and do not charge for it.
If you think I have mishandled your data, you can complain to the data protection authority where you live or work: in the EU, your national supervisory authority; in the UK, the Information Commissioner’s Office; in India, the Data Protection Board of India. I would like the chance to put it right first, but you do not need my answer before you complain.
No automated decisions, no sale
Messages and applications are read by a person, and no decision about you is made by software alone. I do not sell personal data, and I do not hand it to anyone to use for their own advertising. The Meta and TikTok pixels described below would tell those companies which pages you visited, which is why they only load if you accept them.
Cookies and browser storage
The site sets two cookies of its own. Both are strictly necessary for the site to work as you left it, so they need no consent.
| Cookie | What it holds | How long |
|---|---|---|
i18next | Your language, so pages open in it | Until you close the browser |
theme | Light or dark | Until you close the browser, or 30 days once you switch it |
It also keeps three small values in your browser’s storage, which are never sent anywhere: your language (i18nextLng, local storage), whether the assistant is on (webanion-assistant, session storage), and a note that the visit counter is off (visits, session storage).
Cloudflare can set its own security cookie, such as __cf_bm or cf_clearance, when it has to check that a request comes from a person. That cookie is Cloudflare’s and is strictly necessary.
The site’s code also includes three optional trackers: Google Analytics, under Analytics, and the Meta and TikTok pixels, under Marketing. Each one runs only once I have set it up, and then only after you accept its category. If this site has never asked you about cookies, none of them is set up. Until you choose, nothing loads, and refusing takes one click, as accepting does.
If you accept, the vendors set their own cookies: Google Analytics sets _ga and _ga_ followed by an id, for up to two years; the Meta pixel sets _fbp, for 90 days; the TikTok pixel sets _ttp, for up to 13 months. Those are the lifetimes the vendors document. Your choice is kept in a consent cookie and in local storage for 180 days, and then you are asked again. The Cookie settings link at the bottom of every page reopens your choice at any time.
Children
The site is meant for adults hiring or looking for work. It is not aimed at children, and I do not knowingly collect personal data from anyone under 18.
Changes to this notice
When this notice changes, the date at the top changes with it. If the site starts collecting something new or sending it somewhere new, this page says so first.