Privacy Policy
Updated:
This policy explains what happens to personal data in connection with pydepth.com. It is written to the standard of Regulation (EU) 2016/679 (the GDPR) and applies to every visitor, wherever they are.
1. Controller
PyDepth, operating the website pydepth.com, decides why and how the data described below is processed and is the controller for the purposes of Article 4(7) GDPR.
Contact: contact@pydepth.com. Postal contact details are available on request. No data protection officer has been appointed; Article 37 GDPR does not require one for processing of this scope.
2. What is processed
2.1 Server and edge log data
The site is a static site served by Cloudflare Pages. Delivering a page necessarily involves processing your IP address, the requested URL, the response status, the referrer, the user-agent string and a timestamp. This is inherent in the HTTP protocol and cannot be switched off without ceasing to serve the site.
2.2 Email correspondence
If you write to the contact address, your address, the content of your message and its metadata are processed in order to answer it.
2.3 What is not processed
There is no analytics or measurement service of any kind. There is no account system, no newsletter, no comment system, no advertising, no cross-site tracking, no profiling and no fingerprinting.
No third-party request is made at any point. Fonts, styles, scripts and images are served from this site’s own origin; there are no embeds, no frames and no tag manager. Loading a page here contacts nobody but the server that sent it.
3. Legal bases
| Processing | Purpose | Article 6(1) GDPR |
|---|---|---|
| Server and edge logs | Delivering the site; security and abuse prevention | (f) legitimate interests |
| Email correspondence | Answering the message you sent | (f) legitimate interests, or (b) where a request precedes an agreement |
| Theme preference in local storage | Remembering your light or dark choice | Not personal data; stored only in your browser |
Where legitimate interests are relied on, the balancing test under Article 6(1)(f) is recorded as follows: the interest is delivering a publication and keeping it available; the data is the minimum the HTTP protocol requires, is not combined with anything else, and no identifier is created from it. You may object at any time under Article 21 — see section 8.
4. Retention
Cloudflare’s edge logs are retained under Cloudflare’s own retention schedule, which is measured in days rather than months, and are not exported, copied or archived by this site. No other record of a visit exists anywhere. Email is kept as long as the correspondence is live and deleted when it is not.
5. Recipients
Cloudflare, Inc. acts as a processor for hosting and content delivery, under a data processing agreement incorporating the Standard Contractual Clauses. The email provider handling the contact address acts as a processor for correspondence. There are no other recipients. Nothing is sold, shared for advertising, or disclosed except where a legal obligation requires it.
6. Transfers outside the EEA
Cloudflare operates a global network and the delivery of a page may take place outside the European Economic Area, including in the United States. Such transfers are made on the basis of the Standard Contractual Clauses adopted by the European Commission under Article 46(2)(c) GDPR, together with the supplementary measures set out in Cloudflare’s own transfer documentation.
7. Cookies and local storage
This site sets no cookies at all. The only thing written to your browser is a single local storage key recording whether you chose the light or the dark theme, which is strictly necessary to provide the display you asked for and never leaves your device. The Cookie Policy sets this out in full, including why no consent banner is shown.
8. Your rights
Under Articles 15 to 22 GDPR you have the right of access, rectification, erasure, restriction of processing, data portability, and objection to processing based on legitimate interests. Requests go to contact@pydepth.com and are answered within one month.
Note honestly that for log data there is usually nothing to return: without an identifier, a request for access cannot be matched to a visit. This is a consequence of the data minimisation the site practises, not a refusal.
9. Complaints
You may lodge a complaint with a supervisory authority under Article 77 GDPR, in the Member State of your residence, place of work, or the place of the alleged infringement.
10. Automated decision-making
There is none, within the meaning of Article 22 GDPR. Nothing here profiles you or makes a decision about you.
11. Changes
Material changes are reflected in the date at the top of this page. Because the site keeps no mailing list, there is no way to notify you individually; the dated page is the record.