Privacy Policy
Transparency on data protection, client information privacy, and telemetry compliance.
Policy Sections
Request Data Export or Erasure
To exercise your statutory right to access, export, or permanently delete your contact data or project briefs, submit a request directly:
Submit DSAR RequestData Controller & Scope of Policy
This Privacy Policy governs all digital assets, software consulting engagements, and web platforms operated by Mosarrof Sabuz ("we," "our," or "the Lead Architect"), accessible via mosarrofsabuz.com.
As an independent senior software developer and telemetry specialist, we act as the Data Controller for any personal details submitted directly to us, and as a Data Processor when engineering, deploying, or auditing server-side tracking pipelines (such as Meta Conversions API or Server Google Tag Manager) on client infrastructure.
Personal & Client Data Collected
We adhere to strict data minimization principles. We only collect information essential for fulfilling technical proposals, providing consultation, and executing development milestones:
Full name, business email address, phone/WhatsApp contact, company domain, target project budget tier, and project specifications submitted via our contact forms.
Temporary staging SSH/FTP access, cPanel/Cloud hosting tokens, Google Tag Manager container IDs, and Meta Pixel tokens exchanged for project execution.
Note: We do not process sensitive personal data (such as health, biometric, religious, or political data) nor do we knowingly collect data from individuals under 18 years of age.
Lawful Basis for Processing (GDPR Article 6)
Under the General Data Protection Regulation (GDPR), every data processing activity is backed by a specific legal basis:
- Contractual Necessity: Processing inquiry information, project scopes, and development milestones to deliver bespoke software and execute Statements of Work.
- Legitimate Interests: Securing our web platform against bot spam, malicious SQL injection attempts, and DDOS vulnerabilities.
- Legal Obligation: Maintaining compliant tax, financial billing, and invoice records as required by relevant financial authorities.
Meta Conversions API (CAPI) & SHA-256 Telemetry
As technical specialists in server-side telemetry and conversion engineering, we implement high-grade cryptographic privacy standards across all customer conversion pipelines:
When conversion events (e.g. Lead, Purchase, InitiateCheckout) are captured via first-party window.dataLayer, all client personal parameters (email, telephone, postal code) are lowercased, whitespace-stripped, and irreversibly hashed using the SHA-256 cryptographic algorithm before transmission to Meta Graph API or Google Analytics 4.
sha256(normalize("User.Email@Domain.com")) => 7f83b1657ff1fc53b92dc18148a1d65dfc2d4b1fa3d677284addd200126d9069
This guarantees that raw unencrypted personal identifiers are never stored or transmitted across unverified network hops.
Third-Party Subprocessors & Hosting Architecture
We utilize an intentionally minimalist infrastructure stack to limit external data exposure. Our authorized subprocessors include:
| Subprocessor | Purpose | Data Transferred | Location |
|---|---|---|---|
| Hostinger / cPanel Cloud | Primary Web Hosting & Compute | Encrypted DB Records, Access Logs | EU / US Cloud Zones |
| Meta Platforms Inc. | Conversions API (CAPI) Optimization | SHA-256 Hashed Event Telemetry | United States (SCCs) |
| Google LLC (GTM / GA4) | Aggregated Web Performance Analytics | Anonymized IP, LCP/CWV Timings | United States (SCCs) |
Cookies & Local Browser Storage
Our web properties operate strictly without intrusive advertising cookies:
- Essential Session Tokens: Secure CSRF verification tokens required for project form submissions and admin session management.
- UI Preferences: Local storage parameters for theme selection and cost calculator configurations.
- Zero Ad-Networks: No third-party behavioral advertising or tracking retargeting pixels run on our public blog or portfolio pages.
Data Retention & Staging Credential Purges
We maintain an automated data lifecycle management protocol:
- Inquiry Records: Retained for 12 months to facilitate ongoing project consultation, then archived or purged.
- Client Staging Credentials: All temporary SSH keys, database passwords, and FTP tokens are permanently deleted 30 days after live production deployment.
- Financial Invoices: Retained for 7 years to comply with statutory accounting and tax regulations.
Client Statutory Rights (GDPR & CCPA)
You are entitled to exercise your statutory data subject rights at any time without fees:
Security Safeguards & Anti-Spam Architecture
We employ robust defenses against unauthorized data interception and automated abuse:
- TLS 1.3 Transport Security: Strict HTTPS enforcement across all routes with HSTS headers.
- Zero-Execution Honeypots: Invisible honeypot inputs and automated rate-limiting to prevent bot spam without intrusive CAPTCHA friction.
- Parameterized Database Access: Eloquent ORM and prepared PDO statements eliminating all SQL injection attack vectors.
Data Protection Officer (DPO) Contact
To submit a Data Subject Access Request (DSAR), execute a Data Processing Agreement (DPA), or resolve compliance inquiries:
Appointed Controller: Mosarrof Sabuz
Official Compliance Email: contact@mosarrofsabuz.com
Headquarters: Dhaka, Bangladesh (Global Remote Deliveries)
Response SLA: All formal privacy requests acknowledged and processed within 5 business days.
Need a Custom Data Processing Agreement (DPA)?
For enterprise and agency clients requiring custom DPA addendums or specific data boundary guarantees, let's connect and review your security requirements.