Updesh Shrivastava
|

Privacy Policy

Last updated: April 2026 · Impressum

1. Controller (Data Responsible Person)

The controller responsible for data processing on this website within the meaning of the EU General Data Protection Regulation (GDPR) is:

Updesh Shrivastava

Am Europakanal 40, 91056 Erlangen, Germany

Email: [email protected]

This website is operated as a private, non-commercial portfolio by a private individual. No Data Protection Officer (DPO) is required or appointed, as none is mandated under GDPR Art. 37 for private individuals not conducting large-scale processing.

2. What Data We Collect and Why

2.1 Hosting and Access Logs

This website is hosted by Vercel (Frankfurt, Germany — EU region eu-central-1 / fra1). When you visit the site, Vercel automatically records standard server log data: your IP address, browser type, operating system, requested URL, HTTP status code, and timestamp.

This processing is technically unavoidable for serving a website. The operator does not create or store server log files separately. Data is held by Vercel per their standard retention policy (typically up to 30 days).

Legal basis: GDPR Art. 6(1)(f) — legitimate interest in operating a technically secure, functional website.

2.2 Contact Form

When you submit the contact form at /contact, the following is collected and stored in a Supabase database located in Paris, France (EU West region):

This data is used solely to respond to your enquiry and is not shared with third parties.

Legal basis: GDPR Art. 6(1)(b) — necessary to respond to your request (pre-contractual measures); alternatively Art. 6(1)(f) — legitimate interest in maintaining communication. Retention: Contact messages are retained until the enquiry is fully resolved, then deleted within 6 months, unless legal obligations require longer retention.

2.3 Newsletter Subscription

When you enter your email in the subscription form in the page footer, your email address is stored in a Supabase database in Paris, France (EU West region).

Your email is collected to send you occasional updates about new articles and projects on this site. No emails are currently being sent actively; your address is stored for use when a newsletter is launched.

Legal basis: GDPR Art. 6(1)(a) — your explicit consent given via the subscription form. Withdrawal of consent: You may unsubscribe at any time by emailing [email protected] with the subject "Unsubscribe". Withdrawal does not affect the lawfulness of any processing prior to withdrawal.

2.4 Admin Authentication

The admin panel (/admin) uses Supabase Authentication for the website operator's own login. A session token is stored in the operator's browser only during an active admin session. This section does not affect or collect data from public website visitors.

2.5 Article View Counts

Blog posts maintain an anonymous integer view counter. Only the count is incremented — no visitor identity, IP address, or personal data is associated with a view.

3. Data Processors

We use the following GDPR-compliant processors. All data processing takes place within the European Union — no personal data is transferred to third countries.

ProcessorData centrePurpose
Vercel Inc.Frankfurt, Germany (eu-central-1)Website hosting, CDN, page serving
Supabase Inc.Paris, France (eu-west-3)Contact messages, newsletter emails, blog posts

Data Processing Agreements (DPAs) are in place with both processors. Since both providers operate the relevant infrastructure inside the EU, no Standard Contractual Clauses (SCCs) for third-country transfers are required for the data processing activities described in this policy.

4. Cookies

This website does not use tracking cookies, analytics cookies, or advertising cookies. No cookie consent banner is displayed because no non-essential cookies are set for public visitors.

The admin panel sets a strictly necessary session cookie during the operator's authenticated session only. This cookie is automatically deleted when the session ends or the operator logs out.

5. AI-Curated Content (AI News Section)

The /ai-news section aggregates articles from public RSS feeds published by third-party media (TechCrunch, The Verge, VentureBeat, MIT Tech Review, Wired, OpenAI, DeepMind, Hacker News, arXiv). A scheduled server-side job uses Claude AI (Anthropic) to score and categorise articles for relevance.

  • No personal data from website visitors is used in or sent to the AI system
  • The AI processes only article titles and text excerpts from third-party RSS feeds
  • The AI does not generate editorial content — it only scores and categorises existing articles
  • Every article links directly to its original publisher, who bears editorial responsibility
  • Anthropic does not receive personal data from this website's visitors as part of this integration

Some articles and written content on this site may have been prepared or revised with AI assistance. All published content is reviewed by the operator before publication. Users are encouraged to verify important information at the original source. The operator accepts no liability for errors or omissions in AI-curated or AI-assisted content.

6. Analytics and Tracking

This website does not use Google Analytics, Meta Pixel, or any other third-party analytics or tracking service. No data is collected for advertising, profiling, or behavioural analytics purposes.

7. Your Rights Under the GDPR

If we process personal data about you, you have the following rights. To exercise any of them, email [email protected]. We will respond within one month (GDPR Art. 12).

Art. 15
Right of access: You can request a copy of the personal data we hold about you.
Art. 16
Right to rectification: You can ask us to correct inaccurate data or complete incomplete data.
Art. 17
Right to erasure: You can ask us to delete your personal data ("right to be forgotten"), subject to legal retention obligations.
Art. 18
Right to restriction: You can ask us to restrict processing in certain circumstances.
Art. 20
Right to data portability: You can request your data in a structured, machine-readable format.
Art. 21
Right to object: You can object to processing based on legitimate interests (Art. 6(1)(f)).
Art. 7(3)
Right to withdraw consent: Where processing is based on consent (newsletter), you may withdraw it at any time without affecting the lawfulness of prior processing.

8. Right to Lodge a Complaint

You have the right to lodge a complaint with the competent data protection supervisory authority. For Bavaria, this is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)

Promenade 27, 91522 Ansbach, Germany

www.lda.bayern.de

9. Changes to This Policy

This privacy policy may be updated to reflect changes in data processing practices or legal requirements. The date at the top of this page shows when it was last revised. Continued use of this website after changes constitutes acceptance of the updated policy.

Impressum · Last updated: April 2026