01 Who I am
This website is the personal portfolio of Ravi Sharma, an independent contract embedded systems and firmware engineer based in India. For the purposes of the EU/UK General Data Protection Regulation (GDPR) and India's Digital Personal Data Protection Act, 2023 (DPDP Act), I act as the data controller for the information collected through this site.
You can reach me about anything in this policy at the email address in the Contact section.
02 Data I collect
I only collect what's needed to respond to you and run this site. Depending on how you use it, that may include:
- Inquiry form data — your name, email address, company (optional), and the contents of your message.
- Newsletter signup — your email address, plus a timestamp and consent record proving you opted in.
- Chatbot conversations — any messages you type into the AI assistant on this site.
- Technical data — IP address, browser type, and approximate location, collected automatically in server logs for security and diagnostics.
- Consent metadata — the source, date, and time of any consent you give, stored for compliance records.
I never knowingly collect sensitive data. Please don't share confidential, financial, health, or other sensitive information through the contact form or chatbot.
03 Why I collect it & legal basis
Under the GDPR, every use of your data needs a lawful basis. Mine are:
- Consent — for sending you the newsletter. You opt in explicitly and can withdraw at any time.
- Legitimate interest / steps toward a contract — for responding to inquiries you send me, so we can discuss potential work.
- Legitimate interest — for keeping server logs to protect the site against abuse and to fix technical problems.
Under the DPDP Act, processing is based on the consent and notice you receive when you submit your information.
04 How I use your data
- To read and reply to inquiries about contract work.
- To send newsletter emails, if you've opted in.
- To answer your questions through the AI chatbot.
- To maintain the security, stability, and performance of the site.
- To keep records that demonstrate legal compliance.
No selling, no ad-targeting. I never sell your data, and I don't use it for third-party advertising. Outreach is always reviewed by a human before any contact is made — nothing is sent automatically.
05 Third parties who process data
Running this site relies on a few trusted service providers, who process data on my behalf:
- Hostease — web hosting. Stores form submissions and server logs on its infrastructure.
- Google (Gemini API) — powers the AI chatbot. Messages you send to the chatbot are processed by Google to generate replies.
- Google Fonts — serves the typefaces used on this site, which may involve your browser contacting Google's servers.
- Email delivery — confirmation and newsletter emails are sent via my hosting provider's mail service.
Each provider has its own privacy practices. I share only what's necessary for each to do its job.
06 International data transfers
I'm based in India and work with clients in the US, Europe, the UK, and India. This means your data may be processed in, or transferred to, countries outside your own — including India and the United States. Where data is transferred out of the EU/UK, I rely on appropriate safeguards such as my service providers' standard contractual clauses. By contacting me or subscribing, you understand your data may be handled in these locations.
07 How long I keep it
- Inquiries — kept while we're in contact and for a reasonable period afterward (up to 24 months) in case you return, then deleted.
- Newsletter data — kept until you unsubscribe, after which your email is removed from the active list.
- Chatbot conversations — not retained long-term by me beyond transient processing; Google's retention is governed by its own terms.
- Server logs — rotated and deleted on a rolling short-term basis.
08 Your rights
Whether you're covered by the GDPR, the UK GDPR, or India's DPDP Act, you have the right to:
- Access the personal data I hold about you.
- Correct data that's inaccurate or incomplete.
- Erase your data ("right to be forgotten").
- Withdraw consent at any time, for example by unsubscribing.
- Restrict or object to certain processing.
- Data portability — receive your data in a portable format.
- Lodge a complaint with your local data protection authority (such as the ICO in the UK, or the Data Protection Board in India).
To exercise any of these, just email me — see Contact. I'll respond within the timeframe required by law.
10 How I protect your data
I take reasonable technical and organizational measures to keep your data safe, including encrypted connections (HTTPS), access controls, hardened sessions, and audit logging on administrative systems. No method of transmission over the internet is completely secure, but I work to protect your information and review my practices regularly.
11 Changes to this policy
I may update this policy as my site or legal obligations evolve. The "last updated" date at the top always reflects the current version. Significant changes will be made clear on this page.
12 Contact
Questions about this policy or a request about your data? Get in touch and I'll be glad to help.
Email me →