Protocol / 01
Who controls your information
This website is operated by Rahib Azam, based in Dhaka, Bangladesh. In this policy, “I,” “me,” and “my” refer to Rahib Azam, and “you” refers to a visitor, person making an inquiry, or client whose relationship began through this website.
I determine how personal information submitted through the website is used for my professional activities and am the controller of that information where applicable. Service providers may also process information on my behalf or independently under their own terms.
This policy covers information processed through the website and inquiries or professional relationships that originate through it.
Protocol / 02
Information I collect
I may collect the following information when you choose to provide it:
- Identity and contact details, such as your name, email address, phone number, company, and preferred contact method.
- Project details, including the service you need, requirements, budget range, timeline, availability, and problems you want help solving.
- Messages, follow-up correspondence, proposals, scheduling details, statements of work, attachments, invoices, and other records connected to an inquiry or engagement.
Please do not submit sensitive personal information that is not necessary for me to understand or respond to your inquiry.
When the relevant services are enabled, technical information may be collected automatically, including an IP address, browser and device information, operating system, screen characteristics, approximate location, referral source, pages viewed, interactions, timestamps, session data, cookie identifiers, analytics identifiers, and information needed to operate or secure the website.
Protocol / 03
How and why I use information
I use personal information only for defined professional, operational, analytical, security, and legal purposes, including to:
- Read and respond to messages, evaluate potential work, discuss scope, availability, pricing, and prepare proposals.
- Provide agreed services, communicate about a project, exchange materials, maintain records, handle invoices or payments, and resolve questions or disputes.
- Maintain accurate CRM and professional relationship records.
- Operate, secure, diagnose, and improve the website and understand aggregate usage when analytics is enabled.
- Comply with legal, tax, accounting, fraud-prevention, and record-keeping obligations.
For people in the European Economic Area or United Kingdom, the legal basis depends on the context: consent for optional tracking or marketing; steps requested before entering a contract; performance of a contract; compliance with legal obligations; or legitimate interests such as responding to professional inquiries, maintaining business records, securing the site, and improving its operation. I do not rely on legitimate interests where your rights and freedoms override those interests.
Protocol / 04
Service providers and disclosures
Depending on which site and business features are active, information may be processed by:
I may also disclose information to professional advisers, public authorities, or other parties where reasonably necessary to comply with law, protect rights or security, establish or defend legal claims, or complete an authorized business transaction. I do not permit service providers to use personal information for unrelated purposes merely because they provide a service to me.
Protocol / 06
How long I keep information
I keep personal information only for as long as reasonably necessary for the purpose for which it was collected, including legal, accounting, security, and dispute-resolution needs. My default retention targets are:
| Record | Default period |
|---|---|
| Inquiries that do not become projects | Up to 24 months after the last interaction |
| Client, project, contract, invoice, and tax records | Generally 7 years after the engagement ends, or longer if law requires |
| General CRM relationship records | Up to 3 years after the last meaningful interaction |
| Security and diagnostic logs | Generally up to 12 months |
| Analytics information | According to the disclosed provider setting; targeted not to exceed 14 months |
| Consent and opt-out records | As long as needed to demonstrate or honor your choice |
Information may be deleted sooner when it is no longer needed or when a valid request applies. It may be retained longer where necessary to meet a legal obligation, preserve evidence, prevent fraud, or establish, exercise, or defend legal claims.
Protocol / 07
Your privacy rights
Depending on where you live and the law that applies, you may have the right to request:
- Confirmation of whether I process your personal information and access to a copy.
- Correction of incomplete or inaccurate information.
- Deletion, restriction, or objection to certain processing.
- Portability of information you provided in a usable format.
- Withdrawal of consent at any time, without affecting earlier lawful processing.
- A complaint to the data-protection authority where you live or work.
These rights may be subject to legal exceptions. I may ask for reasonable information to verify your identity and will respond within the timeframe required by applicable law. I do not charge for ordinary requests unless the law permits a fee for requests that are manifestly unfounded, excessive, or repetitive.
Where applicable, these protections include rights under the GDPR, UK GDPR, relevant Bangladesh privacy law, and qualifying U.S. state privacy laws. California residents may request the categories and specific pieces of personal information collected, correction, deletion, and information about disclosures. I do not sell or share personal information for cross-context behavioral advertising and will not discriminate against you for exercising a privacy right.
Protocol / 08
International data transfers
I operate from Bangladesh. If you contact me from another country, your information may be received and processed in Bangladesh and in countries where service providers operate. Those countries may have different privacy protections from your own.
Where transfer restrictions apply, I and relevant providers will use an appropriate legal mechanism or safeguard, such as approved contractual clauses, an adequacy decision, or another mechanism permitted by law. You may ask for more information about safeguards relevant to your data.
Protocol / 09
Email, advertising, and data sales
Submitting an inquiry does not automatically subscribe you to marketing. I may reply to your message, discuss a requested project, send scheduling information, or continue a professional conversation. I am not currently using the website to operate an automated marketing list.
If marketing email is introduced, it will use an appropriate legal basis, identify the sender, include a valid postal address and an easy unsubscribe method where required, and honor opt-out requests within the applicable timeframe. Service and relationship messages may still be sent when needed to perform an agreement or respond to you.
I do not currently use visitor data for advertising or remarketing, and I do not sell personal information. This policy and the site’s controls will be updated before those practices change.
Protocol / 10
Payments
If a project is agreed, payment may be handled through Payoneer. Payment details submitted through Payoneer are processed by Payoneer under its own terms and privacy practices; I do not receive or store your full card or bank credentials.
I may receive transaction details needed for business and accounting, such as your name, company, currency, amount, transaction reference, payment status, date, invoice information, and other information connected to the transaction.
Protocol / 11
Security, children, and automated decisions
I use reasonable technical and organizational safeguards intended to reduce the risk of unauthorized access, disclosure, alteration, loss, or misuse. No online service or storage system can be guaranteed completely secure. If a qualifying incident occurs, I will take appropriate containment and notification steps required by law.
This professional portfolio is not directed to children under 18, and I do not knowingly collect personal information from children through it. If you believe a child has submitted information, please contact me so I can review and delete it where appropriate.
I do not use personal information collected through this website to make decisions that produce legal or similarly significant effects solely through automated processing.
Protocol / 12
Third-party links and social media
The website may link to social networks, client sites, project resources, scheduling services, or other third-party websites. Those services determine their own data practices. Their privacy policies apply when you visit or interact with them, and this policy does not control what they collect or how they use it.
Information you post publicly or send through a third-party social platform is also subject to that platform’s settings and privacy practices.
Protocol / 13
Changes and privacy requests
I may update this policy when the website, providers, legal obligations, or processing practices change. The “Last updated” date will identify the current version. Material changes will be presented clearly where appropriate rather than treated as though they had always been part of this policy.
To ask a question or request access, correction, deletion, restriction, portability, or another privacy action, email rahib.azam18@gmail.com with the subject line “Privacy Request.” Please include enough information for me to understand the request and identify the relevant records, but do not send unnecessary sensitive information.
The short version
I limit collection to what supports the website, inquiries, and professional work. I do not sell your information. If you want to know what I hold or ask me to delete it, contact me.
A privacy request should be straightforward.
Send the request and I’ll respond within the period required by applicable law.