01 / Responsibility
Who handles your data?
Alec Waumans, based in Belgium, is responsible for the personal data processed through The World of Kyra, a personal engineering portfolio.
For any privacy request, write to Kyra.developpeur@gmail.com.
The learning shop is not open for sales. The site does not currently collect payments or customer accounts.
02 / Collection and use
Only what the exchange needs.
Contact messages
The form collects your name, email address and message. These fields are required to use it: without them, your message cannot be sent. They are used to read your enquiry, respond and follow up on the discussion. Please avoid sending sensitive information or information about other people that is not needed.
Ordinary correspondence relies on my legitimate interest in receiving and responding to enquiries about my work (GDPR Article 6(1)(f)). Where you request steps towards a contract, processing necessary for those steps may instead rely on Article 6(1)(b). Your details are not sold or added to a marketing list.
Security and spam prevention
The website processes an IP address and temporary submission counters to limit abuse. Technical logs may include the date, requested page, response status, IP address and browser information. Their purpose is to keep the site available and investigate errors or attacks, based on the legitimate interest in protecting the service and its visitors.
Links are not allowed in the name or message, even a single link. A local filter checks for links and common spam patterns before any email is sent, without opening those links. A blocked submission is not sent; its text stays in the form so you can correct it or contact me directly. The filter can make mistakes and cannot stop every kind of spam. It does not profile you or make decisions with legal or similarly significant effects.
The site checks the email address format and the domain’s ability to receive email through DNS. It then emails you a six-digit code, valid for ten minutes with up to five attempts. Alec receives your message only after successful confirmation. An acknowledgement in the language of the form is then sent automatically after the message has been accepted by the outgoing mail service. The code checks access to the mailbox; it does not establish your formal identity or guarantee that a message is legitimate.
Requests are limited to five per minute and twenty per hour per IP address, shared by both languages. Code requests are also limited to three per fifteen minutes for the same recipient; equivalent Gmail addresses using dots or a plus suffix share this limit.
03 / Recipients and transfers
The services involved.
- Scaleway
Hosts the website on a server in Paris, France. Hosting involves processing the technical data needed to serve and secure the site.
- Cloudflare
Manages the domain’s DNS records in DNS-only mode. In this configuration, it answers DNS queries but does not proxy the website’s HTTP traffic or the contact form.
- Google / Gmail
Gmail sends verification codes, confirmed contact messages and automatic acknowledgements. Contact correspondence is received and managed in a personal Gmail mailbox used by Alec. Google processes data under its consumer privacy policy; this mailbox is not presented as a Google Workspace service with a business data-processing agreement.
The email-domain check uses the DNS resolver configured on the server. Only the domain is queried, not your full email address or message. No external email-validation API is used.
Access to correspondence is intended for Alec and the services required to deliver and store it. Provider operations can involve processing outside the European Economic Area. A server in Paris does not mean all data stays in France.
Google describes its transfer mechanisms, including adequacy decisions where applicable and standard contractual clauses, in its data-transfer framework. You can contact me to request information about the safeguards applicable to your data.
04 / Retention periods
A defined retention policy.
The periods below are the rules adopted for this portfolio. Daily retention routines are active for the site’s new dedicated server logs. Mailbox cleanup is not yet active, and older logs and backup copies still need review. Emails may remain beyond the stated periods until that work is done; their automatic deletion is not currently guaranteed. You can request deletion by email.
- Correspondence and automatic emails
- The adopted mailbox rule covers contact messages, replies, verification-code emails and acknowledgements: 365 days after the last received or sent message in the conversation, then moved to Trash during cleanup. A monthly manual review may add up to one month; an activated daily routine normally acts within 24 hours. Gmail keeps trashed messages for up to another 30 days before deletion. A code expiring after ten minutes does not delete its email from Gmail or the recipient’s mailbox.
- Website technical logs
- A maximum target of 30 days for routine logs, with daily rotation and cleanup. Separate provider logs and backup copies must be covered by their own verified settings.
- Pending confirmation
- For up to ten minutes, Redis stores keyed fingerprints of the submitted fields, the session token and the code, plus an attempt counter. It does not store the message text or readable code. The record is removed earlier when used or cancelled. Failed attempts do not extend its expiry. The original text remains in your form during confirmation.
- Temporary anti-abuse data
- IP submission counters expire with their rate-limit window of one minute or one hour. Recipient limits use a keyed fingerprint of the address and request timestamps; their record expires fifteen minutes after its last update. Form contents are not archived in a website database. The spam filter does not store rejected messages.
A specific legal obligation or the handling of a dispute may justify keeping limited information longer. The reason, scope and review date must be recorded; this is not a blanket exception for keeping every message. Provider backup deletion follows their applicable policies.
06 / Your choices
Access, correct, delete.
Depending on the applicable conditions, you can request access, correction, deletion or restriction of your personal data. You can object to processing based on legitimate interests. Data portability applies where its legal conditions are met, notably for automated processing based on consent or a contract. If a future use relies on consent, you can withdraw it without affecting the lawfulness of earlier processing.
Send your request to Kyra.developpeur@gmail.com. I normally respond within one month. If an extension is permitted because of the complexity or number of requests, I will tell you within that first month. Additional identity information will only be requested where needed to avoid disclosing data to the wrong person.
You can also lodge a complaint with the Belgian Data Protection Authority or your competent supervisory authority. Contact the Belgian authority
This notice will be updated if the service providers, uses of data or features of the portfolio change, including before any shop opens.