LEGAL & COMPLIANCE ZERO DATA MONETIZATION Effective: January 1, 2026

Privacy Policy

Transparency on data protection, client information privacy, and telemetry compliance.

256-Bit SSL
End-to-End Transit Encryption
SHA-256
CAPI Parameter Hashing
0% Selling
Zero Data Broker Sharing
Auto-Purge
30-Day Staging Credential Wipe
// COMPLIANCE STANDARDS
GDPR & UK-GDPR Ready Full compliance with European Union data subject rights.
CCPA / CPRA Compliant Guaranteed right to know, delete, and opt-out of data sale.
First-Party Telemetry Only Zero third-party advertiser cookies on our web properties.
// DATA SUBJECT REQUESTS

Request Data Export or Erasure

To exercise your statutory right to access, export, or permanently delete your contact data or project briefs, submit a request directly:

Submit DSAR Request
01

Data Controller & Scope of Policy

This Privacy Policy governs all digital assets, software consulting engagements, and web platforms operated by Mosarrof Sabuz ("we," "our," or "the Lead Architect"), accessible via mosarrofsabuz.com.

As an independent senior software developer and telemetry specialist, we act as the Data Controller for any personal details submitted directly to us, and as a Data Processor when engineering, deploying, or auditing server-side tracking pipelines (such as Meta Conversions API or Server Google Tag Manager) on client infrastructure.

02

Personal & Client Data Collected

We adhere to strict data minimization principles. We only collect information essential for fulfilling technical proposals, providing consultation, and executing development milestones:

// DIRECT INQUIRY DATA

Full name, business email address, phone/WhatsApp contact, company domain, target project budget tier, and project specifications submitted via our contact forms.

// TECHNICAL CREDENTIALS

Temporary staging SSH/FTP access, cPanel/Cloud hosting tokens, Google Tag Manager container IDs, and Meta Pixel tokens exchanged for project execution.

Note: We do not process sensitive personal data (such as health, biometric, religious, or political data) nor do we knowingly collect data from individuals under 18 years of age.

03

Lawful Basis for Processing (GDPR Article 6)

Under the General Data Protection Regulation (GDPR), every data processing activity is backed by a specific legal basis:

  • Contractual Necessity: Processing inquiry information, project scopes, and development milestones to deliver bespoke software and execute Statements of Work.
  • Legitimate Interests: Securing our web platform against bot spam, malicious SQL injection attempts, and DDOS vulnerabilities.
  • Legal Obligation: Maintaining compliant tax, financial billing, and invoice records as required by relevant financial authorities.
04

Meta Conversions API (CAPI) & SHA-256 Telemetry

As technical specialists in server-side telemetry and conversion engineering, we implement high-grade cryptographic privacy standards across all customer conversion pipelines:

// CRYPTOGRAPHIC DATA NORMALIZATION PIPELINE STATUS: ACTIVE

When conversion events (e.g. Lead, Purchase, InitiateCheckout) are captured via first-party window.dataLayer, all client personal parameters (email, telephone, postal code) are lowercased, whitespace-stripped, and irreversibly hashed using the SHA-256 cryptographic algorithm before transmission to Meta Graph API or Google Analytics 4.

sha256(normalize("User.Email@Domain.com")) => 7f83b1657ff1fc53b92dc18148a1d65dfc2d4b1fa3d677284addd200126d9069

This guarantees that raw unencrypted personal identifiers are never stored or transmitted across unverified network hops.

05

Third-Party Subprocessors & Hosting Architecture

We utilize an intentionally minimalist infrastructure stack to limit external data exposure. Our authorized subprocessors include:

Subprocessor Purpose Data Transferred Location
Hostinger / cPanel Cloud Primary Web Hosting & Compute Encrypted DB Records, Access Logs EU / US Cloud Zones
Meta Platforms Inc. Conversions API (CAPI) Optimization SHA-256 Hashed Event Telemetry United States (SCCs)
Google LLC (GTM / GA4) Aggregated Web Performance Analytics Anonymized IP, LCP/CWV Timings United States (SCCs)
06

Cookies & Local Browser Storage

Our web properties operate strictly without intrusive advertising cookies:

  • Essential Session Tokens: Secure CSRF verification tokens required for project form submissions and admin session management.
  • UI Preferences: Local storage parameters for theme selection and cost calculator configurations.
  • Zero Ad-Networks: No third-party behavioral advertising or tracking retargeting pixels run on our public blog or portfolio pages.
07

Data Retention & Staging Credential Purges

We maintain an automated data lifecycle management protocol:

  • Inquiry Records: Retained for 12 months to facilitate ongoing project consultation, then archived or purged.
  • Client Staging Credentials: All temporary SSH keys, database passwords, and FTP tokens are permanently deleted 30 days after live production deployment.
  • Financial Invoices: Retained for 7 years to comply with statutory accounting and tax regulations.
08

Client Statutory Rights (GDPR & CCPA)

You are entitled to exercise your statutory data subject rights at any time without fees:

1. Right to Access & Portability Receive an exported JSON copy of all personal records associated with your email.
2. Right to Erasure ("To Be Forgotten") Request immediate permanent deletion of all project correspondence and contact records.
3. Right to Rectification Update or correct inaccurate contact parameters or business invoice information.
4. Right to Object / Opt-Out Revoke processing permissions for future communications with a single email notice.
09

Security Safeguards & Anti-Spam Architecture

We employ robust defenses against unauthorized data interception and automated abuse:

  • TLS 1.3 Transport Security: Strict HTTPS enforcement across all routes with HSTS headers.
  • Zero-Execution Honeypots: Invisible honeypot inputs and automated rate-limiting to prevent bot spam without intrusive CAPTCHA friction.
  • Parameterized Database Access: Eloquent ORM and prepared PDO statements eliminating all SQL injection attack vectors.
10

Data Protection Officer (DPO) Contact

To submit a Data Subject Access Request (DSAR), execute a Data Processing Agreement (DPA), or resolve compliance inquiries:

Appointed Controller: Mosarrof Sabuz

Official Compliance Email: contact@mosarrofsabuz.com

Headquarters: Dhaka, Bangladesh (Global Remote Deliveries)

Response SLA: All formal privacy requests acknowledged and processed within 5 business days.

// ENTERPRISE COMPLIANCE

Need a Custom Data Processing Agreement (DPA)?

For enterprise and agency clients requiring custom DPA addendums or specific data boundary guarantees, let's connect and review your security requirements.

Chat on WhatsApp