Privacy Policy
Website: es-kiani.dev | Controller/Operator: Esfandiar Kiani | Contact: contact@es-kiani.dev
Last updated:
This document explains how we handle information on this website. It is written to be compatible with major privacy frameworks across Europe (GDPR/UK GDPR), the United States (CCPA/CPRA and related state laws), and common frameworks in Asia, plus practical realities for users in Iran. It is designed to be conservative (âultra-strictâ) in favor of user privacy.
1) Who We Are
es-kiani.dev (the âWebsiteâ) is a personal/professional site operated by Esfandiar Kiani (the âOperator,â âwe,â âusâ). The Website provides portfolio content, articles, project descriptions, and a way to contact the Operator.
2) Definitions
- Personal Data: information that identifies or can reasonably be linked to a person (directly or indirectly).
- Processing: any operation performed on data (collecting, storing, using, disclosing, deleting, etc.).
- Controller: the party that determines purposes and means of processing (here: the Operator).
- Processor: a service provider processing data on behalf of the controller (e.g., hosting, email delivery, security/CDN).
- Cookies: small files stored in a browser; can be first-party or set by infrastructure/security providers.
3) High-Level Privacy Commitments
- No sale of personal data.
- No advertising profiling and no âbehavioral advertisingâ by the Operator.
- No invasive analytics by default (we do not run ad pixels or cross-site trackers as the Operatorâs choice).
- Data minimization: we collect only what is needed for security, basic functionality, and communication.
- Purpose limitation: data is used only for the purposes described in this policy.
- Security by design: encryption-in-transit (HTTPS) and practical safeguards.
4) What We Collect
4.1 Data You Provide Voluntarily
When you contact us (e.g., via a contact form or email), you may provide:
- Name (optional unless the form requires it)
- Email address
- Message content (which may include project details, attachments, or personal information you choose to share)
4.2 Data Collected Automatically (Technical/Log Data)
When you visit the Website, infrastructure systems may automatically process:
- IP address
- Date/time of request
- Requested URL and status code
- User agent (browser/device information)
- Referrer (if provided)
- Security signals (e.g., bot scoring, rate limiting signals)
This is standard server/security logging used to keep the Website stable and safe. We do not attempt to identify you personally from logs unless required for security incident investigation.
4.3 Cookies and Similar Technologies
The Operator does not intentionally deploy advertising cookies or cross-site tracking pixels. However, infrastructure/security providers (e.g., CDN/WAF) may set essential cookies required for: security challenges, bot protection, load balancing, and abuse prevention.
5) Why We Process Data (Purposes)
- Communication: responding to inquiries and maintaining requested correspondence.
- Security: preventing fraud, abuse, attacks, spam, and unauthorized access.
- Performance: delivering content efficiently and reliably (CDN, caching, routing).
- Legal compliance: meeting lawful requests and maintaining records where required.
- Site operations: debugging, maintenance, and ensuring the Website functions.
6) Legal Bases (GDPR / UK GDPR â Ultra-Strict)
For users in the EEA/UK, we rely only on the following bases (and only where applicable):
- Consent (Article 6(1)(a)): when you choose to contact us and submit information, or when optional cookies are used (if ever enabled).
- Legitimate Interests (Article 6(1)(f)): security logging, abuse prevention, and essential operational monitoring. We apply a strict balancing test: these activities are necessary, proportionate, and privacy-preserving.
- Legal Obligation (Article 6(1)(c)): if we must comply with law enforcement or regulatory requirements.
We do not use your data for automated decision-making that produces legal or similarly significant effects (Article 22).
7) Data Sharing & Disclosure
We share data only with categories of recipients that are necessary to operate the Website:
7.1 Infrastructure & Security Providers
We use common website infrastructure providers for hosting, content delivery, security filtering, and email delivery. These providers may process technical data (including IP address and request metadata) to provide their services.
Common examples (may apply depending on current configuration):
- CDN/WAF/security (e.g., Cloudflare or equivalent)
- Hosting provider (server logs, uptime, backups)
- Email delivery (SMTP providers, inbox hosting)
7.2 Legal and Safety
We may disclose information if required to:
- Comply with applicable law, subpoena, court order, or lawful request
- Protect rights, safety, and security of the Website, users, or the public
- Investigate and prevent abuse, fraud, or attacks
7.3 No Sale / No Targeted Advertising
We do not sell your personal data. We do not share personal data for cross-context behavioral advertising as those terms are defined under applicable U.S. state privacy laws.
8) Data Retention (Strict)
- Contact messages: retained as long as needed to respond and maintain the correspondence, then archived or deleted based on relevance and legal necessity.
- Security logs: retained for a limited period (typically days to weeks) and rotated/deleted automatically unless needed for incident response.
- Backups: encrypted or access-restricted where possible; retained for operational continuity and disaster recovery, then overwritten on a schedule.
If you request deletion, we will delete data where feasibleâexcept where retention is required by law or necessary to establish, exercise, or defend legal claims.
9) Security Measures
We apply reasonable safeguards appropriate to a small professional website, including:
- HTTPS encryption in transit
- Access control to administrative panels
- Security filtering (WAF/bot protection)
- Least-privilege principles for credentials
- Monitoring for abnormal activity where available
No system is perfectly secure. Please avoid sending highly sensitive information (e.g., passwords, government IDs) through the contact form or email.
10) International Transfers
The Website may be accessed globally, and our infrastructure providers may process data in multiple countries. When GDPR/UK GDPR applies and data is transferred outside the EEA/UK, we rely on appropriate transfer mechanisms such as:
- EU Standard Contractual Clauses (SCCs) and/or UK IDTA/addendum where available
- Supplementary measures (e.g., encryption in transit, minimization, access controls)
- Adequacy decisions where applicable
11) Your Rights (Global Overview)
Depending on where you live, you may have rights including:
- Access to your data
- Correction of inaccurate data
- Deletion (erasure) in certain circumstances
- Restriction or objection to processing
- Portability (where applicable)
- Withdraw consent (where processing is based on consent)
To exercise rights, email: contact@es-kiani.dev. We may request reasonable verification to protect against fraudulent requests.
12) Region-Specific Disclosures
12.1 Europe (EEA) & United Kingdom â GDPR / UK GDPR (Ultra-Strict)
- Controller: Esfandiar Kiani (Operator)
- Lawful bases: Consent, Legitimate Interests, Legal Obligation (see Section 6)
- Right to complain: You may lodge a complaint with your local supervisory authority in the EEA/UK.
- Automated decisions: We do not conduct automated decision-making with legal/similar effects.
- Sensitive data: We do not intentionally collect special category data; please avoid sending it.
12.2 United States â CCPA/CPRA (California) + Other State Laws
For U.S. visitors, including California residents:
- No sale of personal information.
- No sharing for cross-context behavioral advertising.
- Categories collected: identifiers (email if you contact us), internet/technical data (IP/logs), and communications content.
- Purposes: security, operations, communications (see Sections 5 and 7).
- Retention: see Section 8.
- Consumer rights: access, delete, correct (varies by state law), and opt-out of sale/sharing (not applicable since we do not sell/share).
- Non-discrimination: we do not discriminate for exercising privacy rights.
12.3 Asia-Pacific â Common Frameworks (APPI / PDPA / DPDP and Similar)
Many APAC privacy laws emphasize notice, purpose limitation, security safeguards, and access/correction rights. Our practices are designed to align with those principles:
- Japan (APPI): we process personal information for stated purposes and honor reasonable access/correction requests.
- Singapore (PDPA): we process for reasonable purposes (security/communication) and provide contact for access/correction.
- India (DPDP): we process data with consent/legitimate uses, provide deletion where applicable, and secure data appropriately.
- Other APAC jurisdictions: we follow a minimal-collection approach and respond to rights requests where reasonably possible.
12.4 Iran â Practical Notice
If you access the Website from Iran, you still receive the same privacy commitments described above. Cross-border infrastructure may be involved due to global routing and security providers. Where local legal requirements apply, we will make reasonable efforts to comply while maintaining website security and operational integrity.
13) Childrenâs Privacy
The Website is not directed to children. We do not knowingly collect personal data from children under 13 (or the equivalent minimum age in your jurisdiction). If you believe a child provided data, contact us to request deletion.
14) External Links
The Website may link to external websites (e.g., GitHub, publications, or platforms). We are not responsible for third-party privacy practices. Please review their policies independently.
15) Changes to This Policy
We may update this Privacy Policy to reflect technical or legal changes. The âLast updatedâ date at the top indicates the latest revision. Material changes will be posted on this page.
GDPR Addendum (Ultra-Strict)
This addendum clarifies GDPR/UK GDPR practices for EEA/UK users and applies in addition to the Privacy Policy above.
A) Data Mapping (What, Why, How Long)
- Contact Data (name/email/message): Purposeârespond to inquiries; Basisâconsent/legitimate interests; Retentionâsee Section 8.
- Technical Logs (IP, user agent, request metadata): Purposeâsecurity/abuse prevention; Basisâlegitimate interests; Retentionâshort, rotating.
- Security Cookies (if any): Purposeâsecurity/bot protection; Basisâlegitimate interests (strictly necessary).
B) Legitimate Interests Balancing Test (Summary)
We process minimal technical data to secure the Website against attacks and abuse. This processing is necessary to operate a public website safely, is limited in scope, and is balanced against user rights using minimization, short retention, and restricted access.
C) Data Subject Requests (DSAR)
Requests should be emailed to contact@es-kiani.dev with âPrivacy Requestâ in the subject line. We may request verification (e.g., confirming control of the email address used to contact us).
- Response timing: We aim to respond within a reasonable timeframe and within statutory deadlines where applicable.
- Limitations: We may refuse or limit requests where permitted (e.g., manifestly unfounded/excessive, legal obligations, security, or rights of others).
D) Special Categories & Sensitive Data
We do not intentionally collect special category data. If you choose to send it, you do so voluntarily; please avoid doing so unless necessary.
E) International Transfers
Where transfers occur outside the EEA/UK, we rely on SCCs/IDTA where applicable and apply supplementary security measures (encryption-in-transit, minimization, and access controls).
Terms of Service
These Terms of Service (âTermsâ) govern your access to and use of this Website. By accessing or using the Website, you agree to these Terms. If you do not agree, do not use the Website.
1) Purpose of the Website
The Website provides information about the Operatorâs work, projects, services, and professional background, and enables contact for professional inquiries.
2) Eligibility
You must comply with applicable laws in your jurisdiction. The Website is not intended for children (see Childrenâs Privacy section above).
3) Acceptable Use
You agree not to:
- Attempt to gain unauthorized access to the Website, server, or related systems.
- Probe, scan, or test the vulnerability of any system or network.
- Use the Website to transmit malware, spam, or abusive content.
- Interfere with normal operation (DDoS, scraping at harmful rates, automated abuse).
- Misrepresent identity or attempt social engineering of the Operator.
4) Intellectual Property
Unless stated otherwise, Website content (text, design elements, project descriptions) is owned by the Operator and protected by copyright and related laws. You may view and share links to pages. You may not reproduce substantial portions for commercial use without permission.
5) User Submissions
If you send messages, files, or other content to the Operator, you represent that you have the right to send them. Do not send confidential information unless you have a clear reason and appropriate permission.
6) Third-Party Links
The Website may link to third-party services (e.g., GitHub). We do not control third-party sites and are not responsible for their content or practices. Access them at your own risk.
7) Disclaimer (No Warranties)
The Website is provided on an âas isâ and âas availableâ basis. We make no warranties regarding accuracy, completeness, or uninterrupted availability. Some content may describe projects, opinions, or educational material and should not be treated as professional advice (legal, medical, financial, etc.).
8) Limitation of Liability
To the maximum extent permitted by applicable law, the Operator is not liable for indirect, incidental, consequential, or punitive damages arising from your use of or inability to use the Website.
9) Indemnification
You agree to indemnify and hold harmless the Operator from claims arising out of your misuse of the Website, violation of these Terms, or violation of applicable law.
10) Changes to the Website or Terms
We may update the Website and these Terms from time to time. Continued use after changes means you accept the updated Terms.
11) Governing Law & Jurisdiction (Multi-Region Compatible)
These Terms are intended to comply with mandatory consumer protection rules that apply in your place of residence. Where a choice of law is permitted, disputes will be governed by the laws of the jurisdiction where the Operator is established, without prejudice to mandatory local rights you may have under your country or state/province laws.
12) Contact
For questions about these Terms or privacy requests, contact: contact@es-kiani.dev