Privacy Policy
Last Updated: September 9, 2026
Effective Date: September 9, 2026
1. Introduction
Welcome to ruinelson.com. This Privacy Policy explains how we handle information when you visit our website. We are committed to protecting your privacy and being transparent about our data practices.
This is a personal website owned and operated by Rui Nelson M. Carneiro ("we", "us", "our"). We respect your privacy and are dedicated to protecting any personal data you may choose to share with us.
Contact for Data Protection Matters:
Email: [email protected]
Location: Porto, Portugal
2. Our Commitment to Minimal Data Collection
We believe in privacy by design. This website:
- Does not use tracking cookies
- Does not use analytics services
- Does not engage in behavioral tracking
- Does not share data with third parties for marketing
- Only collects data you explicitly provide
3. Information We Collect
3.1 Information You Provide Directly
We only collect personal data when you voluntarily provide it through:
- Contact Form Submissions: When you use our feedback form, we collect the message content you choose to share, and your email address if you choose to provide one
Providing an email address is optional. You may submit a message anonymously, in which case no personal data identifying you is stored alongside it. Please note the two consequences: we have no way of replying to you, and the self-service tool described in Section 8 cannot find your message, because it identifies your messages by the email address you submitted them with.
3.2 Information Collected Automatically
We do not collect any information about you automatically. Our web server keeps operational access logs, but they are deliberately stripped of everything that could identify or fingerprint a visitor: they record only the timestamp, the HTTP method, the requested path, the response status and the response size. No IP address, no browser user agent, no referrer and no query string is ever written to them.
However, please note:
Cloudflare: All traffic to this website reaches us through Cloudflare, which acts as our reverse proxy and network edge: the connection between your browser and Cloudflare terminates on Cloudflare's infrastructure, and Cloudflare then forwards the request to our server over an outbound-only tunnel. Cloudflare also provides caching, DDoS protection and bot mitigation. In this role Cloudflare may automatically collect and process:
- IP addresses (for security and routing purposes)
- Basic technical information (browser type, operating system)
- Security-related cookies (strictly necessary for protection against attacks)
We do not receive your IP address from Cloudflare: the client IP headers Cloudflare adds are explicitly discarded at our proxy before the request reaches any of our own services.
These are essential technical cookies that ensure the website functions securely and efficiently. They are not used for tracking or advertising purposes.
Cloudflare Turnstile: We use Cloudflare Turnstile for bot protection on our feedback form. This service may set strictly necessary cookies to verify you are human and protect against automated abuse.
4. Legal Basis for Processing
Under the General Data Protection Regulation (GDPR), we process your personal data based on:
- Consent (Article 6(1)(a) GDPR): When you voluntarily submit information through our contact form, you consent to us processing this data to respond to your inquiry
- Legitimate Interests (Article 6(1)(f) GDPR): We have a legitimate interest in responding to genuine inquiries and maintaining the security of our website
5. How We Use Your Information
Your personal data is used exclusively for:
- Responding to your questions, feedback, or inquiries
- Addressing any issues or suggestions you raise
- Protecting our website from security threats (via Cloudflare)
We will never use your data for:
- Marketing or promotional purposes
- Sale of your data, or transfer to any third party for that third party's own purposes
- Profiling or automated decision-making
- Any purpose other than responding to your direct communication
Where a service provider handles your data on our behalf, it does so strictly on our instructions and solely to make the service work, never for its own purposes. See Section 10.
6. Data Storage and Security
6.1 Storage Location
- Form submission data is stored on secure servers located in Germany (European Union member state)
- We do not store your data in personal email accounts or local systems
6.2 Security Measures
We implement comprehensive security measures including:
- All communications encrypted in transit with TLS
- Virtualization and containerization
- Firewall protection
- Asymmetric encryption for administrative access
- Regular vulnerability monitoring
- Penetration testing
- Bot detection and prevention
6.3 Data Retention
- All personal data from form submissions is automatically deleted no later than 31 days after receipt. A scheduled job sweeps the database several times a day and removes every message older than 30 days
- When you request access to your own messages (see Section 8), a temporary session is created that holds your email address and the time the session started. It expires 4 hours after it is created, and expired sessions are erased by a job that runs every 5 minutes
- We do not retain data beyond what is necessary to address your inquiry
7. Your Data Protection Rights
Under the GDPR, you have the following rights:
7.1 Right of Access (Article 15 GDPR)
You can request confirmation of whether we process your personal data and obtain a copy of such data.
7.2 Right to Rectification (Article 16 GDPR)
You can request correction of inaccurate personal data or completion of incomplete data.
7.3 Right to Erasure - "Right to be Forgotten" (Article 17 GDPR)
You can request deletion of your personal data when:
- The data is no longer necessary for the original purpose
- You withdraw consent
- You object to the processing
- The data has been unlawfully processed
7.4 Right to Restrict Processing (Article 18 GDPR)
You can request that we limit how we use your personal data under certain circumstances.
7.5 Right to Data Portability (Article 20 GDPR)
You can request to receive your personal data in a structured, commonly used, and machine-readable format.
7.6 Right to Object (Article 21 GDPR)
You can object to processing based on legitimate interests or for direct marketing purposes.
7.7 Right to Withdraw Consent
Where processing is based on consent, you can withdraw this consent at any time without affecting the lawfulness of processing before withdrawal.
8. Exercising Your Rights
To exercise any of your data protection rights:
- Use our dedicated tool: Visit our feedback editor for immediate action. It sends a temporary access code to your email address and then lets you read, correct or delete the messages you submitted with that address. Messages you submitted anonymously carry no email address, so this tool cannot locate them
- Contact us directly: Email [email protected]
We will respond to your request within one month as required by GDPR. This period may be extended by two additional months for complex requests, in which case we will inform you of the delay and reasons.
All rights can be exercised free of charge. However, we may charge a reasonable fee or refuse to act on requests that are manifestly unfounded, excessive, or repetitive.
9. Cookies and Similar Technologies
9.1 Our Cookie Policy
This website sets no cookies of its own, and uses no cookies at all for tracking, analytics or advertising. The only cookies you may receive are the strictly necessary security cookies described below, which are set by Cloudflare.
We also do not use browser storage as a substitute for cookies: the feedback editor keeps your access code in memory only, so closing or reloading the page discards it.
9.2 Strictly Necessary Technical Cookies
Cloudflare Security Cookies:
__cf_bm(Bot Management): Distinguishes between humans and bots, expires after 30 minutescf_clearance(Challenge Passage): Set when you pass a security challenge, so you are not challenged again on every request
These cookies:
- Contain a token that is unique to your visit, used to remember that a security check has already been passed. This token is not linked to your identity and is not used to build any profile of you
- Are scoped to this website and cannot track you across other websites
- Are essential for protection against DDoS attacks and malicious bots
- Are short-lived, and their lifetime is set by Cloudflare rather than by us
- Do not require consent under EU law as they are strictly necessary for security
9.3 Managing Technical Cookies
While these cookies are essential for website functionality, most modern browsers allow you to:
- View all cookies stored
- Delete specific cookies
- Block all cookies (note: this may affect website functionality)
10. Third-Party Services
10.1 Cloudflare
We use Cloudflare services solely for security and performance. Cloudflare processes data according to their privacy policy: cloudflare.com/privacypolicy/
Cloudflare is certified under the EU-U.S. Data Privacy Framework and implements appropriate safeguards for international data transfers.
10.2 Sweego
When you request an access code to manage your own messages, we send that email through Sweego, an email delivery provider based in France. Sweego receives your email address and the access code solely in order to deliver that one message; it does not receive the content of your feedback. Sweego acts as our processor under a data processing agreement, and processes the data within the European Union. Their privacy policy: sweego.io/privacy-policy/
10.3 External Links
This website may contain links to external websites. We are not responsible for the privacy practices of these external sites. We encourage you to read the privacy policies of any website you visit.
11. Automated Decision Making and Profiling
We do not engage in any form of automated decision making or profiling. Specifically:
- No Automated Processing: All inquiries are reviewed and responded to personally by a human
- No Profiling: We do not create profiles based on your behavior, preferences, or characteristics
- No Algorithm-Based Decisions: We do not use algorithms or automated systems to make decisions that would affect you
- No Predictive Analysis: We do not analyze your data to predict future behavior or preferences
- No Scoring Systems: We do not assign scores or ratings to users based on any criteria
Your interactions with this website are straightforward: you contact us, we respond personally, and then we delete your data. There are no hidden automated processes analyzing or categorizing you.
12. International Data Transfers
Our servers are located in Germany, and our email provider processes data in France, both within the EU. The only provider that may process data outside the EU is Cloudflare, which operates a global network. All such transfers are protected by:
- Standard Contractual Clauses approved by the European Commission
- Adequate safeguards as required by GDPR Article 46
- Cloudflare's compliance with EU data protection standards
13. Children's Privacy
This website is not directed at, and may not be used by, anyone under 18 years of age, as set out in our Terms of Use. We do not knowingly collect personal data from minors. If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately at [email protected].
14. Data Breach Notification
In the unlikely event of a personal data breach that poses a high risk to your rights and freedoms, we will:
- Notify you without undue delay
- Describe the nature of the breach
- Communicate the measures taken to address the breach
- Comply with all GDPR breach notification requirements
15. Supervisory Authority
You have the right to lodge a complaint with a supervisory authority. For Portuguese residents, the relevant authority is:
Comissão Nacional de Proteção de Dados (CNPD)
- Address: Avenida D. Carlos I, Nº 134 – 1º; 1200-651 Lisboa
- Phone: +351 213 928 400
- Privacy Line: +351 213 930 039
- Email: [email protected]
- Website: www.cnpd.pt
EU residents may also contact their local data protection authority.
16. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our practices or for legal, technical, or operational reasons. When we make changes:
- The "Last Updated" date at the top will be revised
- For significant changes, we may provide additional notice on our website
- Continued use of our website after changes constitutes acceptance of the updated policy
We encourage you to review this Privacy Policy periodically.
17. Accessibility
We strive to make this Privacy Policy accessible to all users. If you need this information in an alternative format due to disability, please contact us at [email protected].
18. Contact Information
For any questions, concerns, or requests regarding this Privacy Policy or our data practices:
Data Protection Contact:
Email: [email protected]
Name: Rui Nelson M. Carneiro
Location: Porto, Portugal
We aim to resolve any privacy concerns promptly and transparently.
This Privacy Policy is provided in English as the primary language of this website. In case of any disputes, the interpretation of this policy shall be based on European Union data protection law, particularly the General Data Protection Regulation (EU) 2016/679.