🔍
Start typing to search…
↑↓ Navigate
Enter Open
Esc Close
Legal Document

Privacy Policy

📅 Last updated: March 1, 2026 🔒 GDPR Aware
🔐
Your privacy matters to us
This policy explains exactly what data tonirulislam.tech collects, why we collect it, how it is used, and what rights you have over your personal information. We believe in full transparency — no hidden data harvesting, no selling your information, ever.
01

Who We Are

This Privacy Policy applies to tonirulislam.tech ("the Site"), a personal blog and portfolio owned and operated by Tonirul Islam, a Network Engineer and software builder based in West Bengal, India.

Tonirul Islam is also the founder of themedium.blog (a long-form publishing platform) and doccraftr.com (a browser-based PDF editor and converter). Each of those services operates under its own separate privacy policy.

ℹ️
If you have any questions about this policy or how we handle your data, please contact us at admin@tonirulislam.tech — we aim to respond within 2 business days.
02

What Data We Collect

We collect the minimum data necessary to operate the Site and provide the services you request. Here is a clear breakdown:

Newsletter subscriptions

  • First name (optional — used to personalise emails)
  • Email address (required)
  • Subscription date and verification status

Contact form submissions

  • First and last name
  • Email address
  • Subject and message content
  • Timestamp of submission

Comments

  • Display name
  • Email address (not publicly shown — used for moderation only)
  • Comment text and submission timestamp

Server & analytics logs

  • IP address (anonymised after 30 days)
  • Browser type and version
  • Pages visited and time on page
  • Referring URL
We do not collect: payment information, government IDs, biometric data, sensitive personal categories, or any data from users we know to be under 16 years of age.
03

How We Use Your Data

We use the data we collect only for the specific purposes described below. We never use your data for purposes beyond what is listed here without your explicit consent.

📨
Newsletter
Weekly updates, new article announcements, and occasional curated content. Unsubscribe anytime via the link in every email.
💬
Contact Form
Solely to respond to your message or inquiry. Your data is never added to a marketing list without explicit consent.
🗨️
Comments
To display your comment on the relevant article and notify you of replies if you opt in to notifications.
📊
Server Logs
To diagnose technical issues and understand aggregate traffic. Logs are never used to build individual user profiles.
🛡️
Security
To detect and prevent spam, fraud, bot traffic, and other malicious activity targeting the Site.
⚠️
We never sell, rent, or trade your personal data to advertisers, data brokers, or any other third parties — under any circumstances.
04

Legal Basis for Processing

Where applicable under the General Data Protection Regulation (GDPR) and India's Digital Personal Data Protection Act (DPDPA), we process your personal data on the following legal bases:

05

Cookies & Tracking

We use a small number of cookies to make the Site function correctly and to understand how it is used. We do not use advertising cookies or sell cookie data.

🍪
You can disable or delete cookies at any time through your browser settings. Disabling essential cookies may affect the Site's functionality. For full details, see our Cookie Policy →
06

Data Retention

We retain your personal data only for as long as necessary to fulfil the purpose for which it was collected, or as required by law.

📧 Newsletter subscribers
Until unsubscribed + 90 days purge window
Retained until you click unsubscribe. Unsubscribed records are permanently deleted within 90 days.
📝 Contact form submissions
12 months then permanently deleted
Stored solely to facilitate a reply. Automatically purged after 12 months with no archive copy kept.
🗨️ Comments
Indefinite or until deletion requested
Retained as part of the published article unless you request removal or content is moderated.
🖥️ Server logs
30 days (raw) anonymised data may be kept longer
Raw IP-level logs are deleted after 30 days. Anonymised aggregate statistics may be retained for long-term trend analysis.
📬
You may request early deletion of your data at any time — see Your Rights for how to submit a request.
07

Third Parties & Data Sharing

We do not sell or share your personal data with third parties for their own marketing purposes. We may share limited data with the following service providers strictly to operate the Site:

🏠
Hostinger
Hosting Provider
Infrastructure
Your data is stored on servers managed by Hostinger, subject to their own data processing agreement and EU-standard security measures.
📮
SMTP Mail
Email Delivery
Internal
Newsletter emails are sent via PHP's native mail() through our host's SMTP. No third-party email platforms (Mailchimp, SendGrid etc.) are used.
⚖️
Law Enforcement
Legal Obligation
If required
We may disclose data if required to do so by law, court order, or a valid governmental request. We will notify you where legally permitted to do so.
We do not use Facebook Pixel or any behavioural advertising networks on this Site. Google Analytics is used in anonymised form only.
08

Your Rights

Depending on your location, you may have the following rights regarding your personal data. We honour all reasonable requests regardless of your jurisdiction.

👁️
Right to Access
Request a copy of all personal data we hold about you.
✏️
Right to Rectification
Ask us to correct inaccurate or incomplete data.
🗑️
Right to Erasure
Request deletion of your personal data ("right to be forgotten").
⏸️
Right to Restrict
Ask us to limit how we process your data in certain circumstances.
📦
Right to Portability
Receive your data in a structured, machine-readable format.
🚫
Right to Object
Object to processing based on legitimate interests at any time.
📬
To exercise any of these rights, email admin@tonirulislam.tech. We will respond within 30 days. No fees apply for reasonable requests.
09

Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, alteration, or disclosure. These include:

  • HTTPS / TLS encryption for all data transmitted between your browser and our server
  • Passwords stored as bcrypt hashes — plain-text passwords are never stored
  • Database access restricted to application-level queries only; no direct external access
  • CSRF protection on all forms to prevent cross-site request forgery
  • Regular software updates and security patches applied to the server and CMS
⚠️
No method of transmission over the internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. Please use strong, unique passwords and report any suspected breaches to us immediately.
10

Children's Privacy

This Site is not directed at children under the age of 16. We do not knowingly collect personal data from anyone under 16. If you are a parent or guardian and believe your child has submitted personal data to us, please contact us immediately at admin@tonirulislam.tech and we will delete that data promptly.

11

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will update the "Last updated" date at the top of this page.

We encourage you to review this page periodically. Your continued use of the Site after any changes constitutes your acknowledgement of the updated policy.

12

Contact & Complaints

For any privacy-related questions, requests, or complaints, please contact us directly:

If you are located in the European Economic Area and believe we have not handled your data appropriately, you have the right to lodge a complaint with your local data protection supervisory authority. In India, complaints may be directed to the Data Protection Board under the DPDPA 2023.