Legal
Privacy Notice
Last updated: June 2026
1. Who we are
This website is operated by Abhishek Bansiwal, a data privacy and protection consultant based in Dublin, Ireland. For the purposes of the GDPR (Regulation (EU) 2016/679) and the Irish Data Protection Acts 1988–2018, Abhishek Bansiwal is the data controller for personal data collected through this website.
Contact: abhishek.adv@yahoo.com
2. What personal data we collect and why
2a. Contact form
When you submit the contact form on this website, we collect your name, email address, company information, and the message you provide. This data is processed to respond to your enquiry and assess whether our services are relevant to your situation. The legal basis is Article 6(1)(b) GDPR (processing necessary for steps prior to entering a contract at your request).
Contact form submissions are processed via Web3Forms (web3forms.com), which forwards your submission to our email inbox. We retain contact form data for up to 12 months, after which it is deleted.
2b. Booking a call
When you book a call through our scheduling link, we collect your name, email address, the meeting time you select, and any notes you choose to add. This data is processed to schedule and hold the call. The legal basis is Article 6(1)(b) GDPR (processing necessary for steps prior to entering a contract at your request).
Scheduling is provided by Cal.com via its EU-hosted service (Cal.eu), with booking data stored and processed within the European Union. Booking details also appear in our calendar and email as a necessary part of holding the meeting. We retain booking records for up to 12 months after the call, after which they are deleted unless we have entered an engagement.
2c. Newsletter
Our newsletter, Where Is My Privacy?, is published on Substack. If you subscribe, your email address (and any profile information you give Substack) is processed by Substack Inc., a US company, to deliver the newsletter on our behalf. The legal basis is Article 6(1)(a) GDPR (consent) — you can withdraw it at any time by unsubscribing via the link in any issue.
Substack processes subscriber data in the United States; the safeguards Substack applies to international transfers are described in Substack's privacy notice. Our newsletter page also embeds a Substack signup widget — see the cookies section below.
2d. Website analytics
This website uses Vercel Web Analytics, a privacy-first analytics tool. Vercel Analytics does not use cookies and does not store any persistent identifiers on your device. It collects aggregated, anonymised data about page views, referring URLs, device types, and geographic regions (country level only). No individual visitor is tracked across sessions or across sites.
The legal basis for this processing is Article 6(1)(f) GDPR (legitimate interest) — specifically, understanding how visitors engage with the website to improve its content and usability. This processing does not trigger ePrivacy consent obligations as no cookies or trackers are placed on your device.
2e. Hosting and server logs
This website is hosted by Vercel Inc. To deliver pages to your browser, Vercel necessarily processes your IP address and standard request metadata, and keeps short-lived technical logs for security and reliability. The legal basis is Article 6(1)(f) GDPR (legitimate interest in operating a secure, functioning website).
3. Cookies and local storage
This website does not set any first-party cookies, and Vercel Analytics operates without cookies. One value is stored in your browser's local storage: a flag recording that you dismissed the analytics notice banner, so it does not reappear on every visit. It contains no personal data, is never transmitted anywhere, and is strictly necessary to honour your dismissal — you can clear it at any time via your browser settings.
The newsletter page embeds a Substack signup widget inside a frame. When that page loads, Substack may set its own third-party cookies within the widget, governed by Substack's privacy notice. No other page on this site loads third-party embeds.
The contact form uses a honeypot field for spam prevention — no cookies are set and no tracking takes place when you submit it. A complete inventory of every cookie and storage item, and why no consent banner is required, is in our Cookie Policy.
4. Who we share your data with
We share personal data only with the following processors:
- Vercel Inc. (website hosting and analytics) — data processed in the US under the EU-US Data Privacy Framework
- Web3Forms (contact form delivery) — submissions are forwarded to our email and not retained by the service as a data store
- Cal.com (call scheduling via its EU-hosted Cal.eu service) — booking data stored and processed within the EU
- Substack Inc.(newsletter delivery and subscriber management) — data processed in the US; see Substack's privacy notice for its transfer safeguards
We do not sell, rent, or share your personal data with any third party for marketing purposes.
5. How long we keep your data
- Contact form enquiries: 12 months from the date of submission
- Call bookings: 12 months after the call, unless an engagement follows
- Newsletter subscriptions: until you unsubscribe
- Analytics data: aggregated and anonymised — no individual records retained
6. Your rights under GDPR
As a data subject, you have the following rights:
- Right of access (Art. 15) — request a copy of personal data we hold about you
- Right to rectification (Art. 16) — request correction of inaccurate data
- Right to erasure (Art. 17) — request deletion of your data
- Right to restriction (Art. 18) — request restricted processing
- Right to object (Art. 21) — object to processing based on legitimate interest
- Right to data portability (Art. 20) — receive your data in a structured format
To exercise any of these rights, contact us at abhishek.adv@yahoo.com. We will respond within one calendar month.
7. Right to lodge a complaint
If you believe your data has been processed unlawfully, or that we have failed to comply with your rights, you have the right to lodge a complaint with the Irish supervisory authority:
Data Protection Commission (DPC)
21 Fitzwilliam Square South, Dublin 2, D02 RD28
www.dataprotection.ie
8. Changes to this notice
We may update this privacy notice from time to time. The date at the top of the page reflects when it was last revised. Material changes will be noted with a revised date.
9. Legal disclaimer
The services provided through this website are compliance consulting services. Nothing on this website constitutes legal advice. For legal advice specific to your situation, please consult a qualified solicitor.