Privacy Policy
Version 2.2 · last updated 16 July 2026
Confidentiality is the substance of this practice, not a footnote to it. This policy explains exactly what happens to information you provide through this website or during an engagement — what is collected, why, on what legal basis, who else can see it, how long it is kept, and what you can require of me. It is written to be read, not to be survived.
- No cookies, no analytics, no trackers, no advertising. This site sets no cookies of any kind and does not profile you.
- No third-party content. Fonts and images are served from this domain — visiting the site discloses nothing to Google or anyone else.
- No database. Nothing you submit is stored by the website; form submissions are relayed to me by email and nowhere else.
- Everything stays in the EU. The server is in Frankfurt, Germany, and all data is stored and processed within the European Union — none of it is transferred outside.
- Client materials are deleted no later than one business week after final payment. Only my own copy of the report is kept.
- Never sold, never shared. Your information is not disclosed to third parties, in whole or in part, for any purpose other than delivering the service described here.
01Who is responsible
The controller of personal data processed through this website is Kanstantsin Vaitsakhouski, an independent consultant trading as kvdd.eu, providing technical due diligence and feasibility assessments for AI and computer-vision systems.
Contact for any privacy matter, including requests to exercise your rights: kanstantsin@kvdd.eu. I answer these personally. No data protection officer is appointed, as the scale and nature of the processing does not require one.
02Scope
This policy covers the website at kvdd.eu (including its subpages), the request and intake forms it hosts, and correspondence and materials exchanged during an engagement. It does not cover third-party websites that may be linked from here; if you follow a link elsewhere, that site's own policy applies.
03What is collected, why, and on what legal basis
There are only three situations in which any personal data is processed at all.
a. Simply visiting the website
The web server records a standard technical log entry for each request: your IP address, the time, the page requested, the HTTP status, and the browser's user-agent string. This is the ordinary operation of a web server, not analytics — it is not linked to you, not profiled, and not used to build any picture of your behaviour. It exists so that the site can be kept secure and working.
These logs are automatically rotated and deleted after 14 days. Beyond this, the website itself keeps nothing: no cookies, no local storage, no session identifiers, no analytics or advertising scripts, no social plugins, and no third-party fonts or embeds.
b. Sending a request or completing the intake questionnaire
If you use a form on this site, I receive what you chose to put in it — typically your name, email address, company, role, and your description of the decision, system or problem at hand, along with any reference links you add. The intake questionnaire additionally records your answers about the engagement, and your NDA and authorisation selections.
This information is used for one purpose: to understand and answer your request, and to scope the work if it proceeds. It is relayed to me by email and is not stored in any database, ranked, enriched, or used for marketing. You are also sent a copy of your own submission, for your records.
To keep the form from being abused, the service applies a rate limit per IP address and a hidden anti-bot field. The IP address used for rate limiting is held transiently in memory and is not written to any store or attached to your message.
Providing this information is entirely voluntary. It is not a statutory requirement and you are under no contractual obligation to supply it. The practical consequence is the only one: your name, a working email address and some description of what you need are necessary for me to reply at all, and to scope the work if it proceeds. Withhold them and I simply cannot respond — nothing else follows from it.
Please do not send confidential material through the form. It exists to scope the work; a short description is enough at that stage. If an NDA should be in place before you share anything meaningful, say so on the first step of the questionnaire and no details are transmitted.
c. During an engagement
If we work together, you may send me documents, data, code, model artefacts or other materials so that I can assess them. These may contain personal data, and in some fields may contain special categories of data. What is shared, and on what terms, is agreed between us in advance and governed by the NDA and the engagement terms.
Where I act as your processor, that relationship is put on a written footing: a data processing agreement satisfying Article 28(3) GDPR is concluded alongside the NDA, setting out the subject matter and duration of the processing, its nature and purpose, the categories of data and data subjects, and my obligations — to process only on your documented instructions, to keep the data confidential, to apply appropriate security, to engage no further processor without your authorisation, to assist you with data-subject requests and security obligations, and to delete the material at the end of the engagement. I am happy to sign yours or to provide one.
Some materials — medical images being the obvious case — may contain special categories of personal data within the meaning of Article 9 GDPR. Establishing a lawful basis for those categories, and for disclosing them to me, remains yours as controller; I process them solely for the purpose of the assessment you commissioned and for no other purpose. Where the material can be anonymised or pseudonymised without damaging the assessment, that is always the better course, and I will say so.
05Who else is involved
The practice is deliberately small, and so is the list of companies that can technically touch your information. There are two, both bound by their own data processing terms:
| Provider | Role | What it can see |
|---|---|---|
| DigitalOcean | Server hosting for kvdd.eu | The server and its logs. Located in Frankfurt, Germany (EU). |
| Zoho Corporation (ZeptoMail) |
Transactional email delivery and mailbox for kanstantsin@kvdd.eu | The content of messages sent to and from the site, as any email provider necessarily does. Operated on EU data-residency infrastructure. |
That is the complete list. There are no analytics vendors, no CRM, no marketing platform, no advertising networks, no chat widgets, and no AI service that receives your submissions. Your information is never sold, rented, or shared for anyone else's purposes.
Beyond these, information may be disclosed only where I am legally compelled to do so — for instance by a binding order from a competent authority — or where it is necessary to establish, exercise or defend a legal claim.
06Where your data is processed
All personal data processed in connection with this website and with engagements is stored and processed within the European Union.
The server is located in Frankfurt, Germany. Email for kvdd.eu is operated on EU data-residency infrastructure. The assessment work itself is carried out within the EU.
No personal data is transferred to a third country or to an international organisation outside the European Union or the EEA. As there is no such transfer, the Chapter V GDPR transfer mechanisms — adequacy decisions, standard contractual clauses, binding corporate rules — are not engaged.
Were this ever to change, this policy would be updated before the change took effect, and anyone with an active engagement would be told directly rather than left to notice.
07How long anything is kept
| What | Kept for |
|---|---|
| Server access logs | 14 days, then deleted automatically. |
| Rate-limiting IP data | Transient, in memory only. Not persisted. |
| Enquiries that do not become engagements | Only as long as needed to deal with the enquiry, then deleted. |
| Client materials from an engagement | Deleted no later than one business week after final payment for that engagement. |
| My copy of the delivered report | Kept as a professional record of the work performed, for no longer than the limitation period applicable to claims arising out of the engagement, after which it is deleted. Destroyed earlier on request. |
| Invoices and accounting records | As required by applicable tax and accounting law. |
If you would prefer that my copy of the report be destroyed as well, ask, and it will be.
08Confidentiality
Everything about a client is treated as confidential: their identity, their contact details, their business, their projects, their technology and their direction. I do not name clients, do not publish case studies about identifiable engagements, and do not use anyone's work as a reference without their explicit permission. Where I write publicly about technical patterns, the material is general and is not drawn from any identifiable client's system.
An NDA is signed before any substantive materials change hands — yours, or a mutual one I provide. Confidentiality obligations survive the end of the engagement and are not time-limited by this policy.
09Security
The measures in place are proportionate to a practice of this size and to the sensitivity of what is handled:
- All traffic is served over HTTPS (TLS), with HTTP redirected to HTTPS.
- No database exists, so there is no store of submissions to breach.
- Form input is sanitised on the server; submitted links are neutralised rather than made clickable, and dangerous URL schemes are rejected.
- Credentials for the email service are held in a root-only file on the server and are not present in the site's source code or its public repository.
- Access to the server is by SSH key only.
- Client materials are deleted on the schedule set out above rather than accumulating indefinitely.
No system is perfectly secure, and I would rather say so than imply otherwise. If you become aware of a vulnerability in this site, please tell me at kanstantsin@kvdd.eu — it will be taken seriously and fixed.
10Your rights
Under the GDPR you have the right to:
- Access (Art. 15) — obtain confirmation of whether I hold personal data about you, and a copy of it.
- Rectification (Art. 16) — have inaccurate data corrected, or incomplete data completed.
- Erasure (Art. 17) — have your data deleted where there is no overriding reason to keep it.
- Restriction (Art. 18) — require that processing be paused while a dispute is resolved.
- Portability (Art. 20) — receive data you provided in a structured, commonly used, machine-readable format, and have it sent to another controller where technically feasible.
- Withdraw consent (Art. 7(3)) — where processing rests on consent, withdraw it at any time, without affecting what was lawful beforehand.
Your right to object (Article 21 GDPR). Separately from the rights above, and brought to your attention explicitly: where processing is based on my legitimate interests — which here means the server logs and the handling of business correspondence — you have the right to object at any time, on grounds relating to your particular situation. If you object, I must stop processing that data unless I can demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or the processing is needed to establish, exercise or defend legal claims. To object, write to kanstantsin@kvdd.eu. No direct marketing is carried out from this site, so there is nothing here to object to on that ground.
To exercise any right, email kanstantsin@kvdd.eu. There is no charge. I will respond within one month of receiving the request; where a request is particularly complex, or where several have been made, that period may be extended by a further two months, in which case I will tell you about the extension and the reason for it within the first month. In practice, given how little is held, these are usually answered in a day or two.
Where I have reasonable doubts about who is making a request, I may ask for information needed to confirm your identity before acting on it. This is a protection for you, not an obstacle: it prevents someone else obtaining your data by asking for it.
11Complaints
If you believe your data has been handled improperly, please raise it with me first — it is usually the fastest route to a fix. You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU or EEA country where you live, where you work, or where the alleged infringement took place. Exercising that right does not depend on contacting me first.
12Automated decision-making
There is none. No automated decision-making or profiling with legal or similarly significant effects takes place. Engagements are assessed and written by a person — that is the entire point of the service.
13Changes to this policy
If this policy changes, the version number and date at the top of the page change with it. Material changes affecting an active engagement will be communicated to you directly rather than left for you to discover.
14Contact
Questions about this policy, your data, or anything above: kanstantsin@kvdd.eu.