Privacy Policy
Last updated: 31 July 2026
This policy explains what happens to your data when you visit aminrj.com, subscribe to the newsletter, or book a call.
The data controller is Amine Raji. For any question about this policy or to exercise your rights, contact [email protected].
The short version
This site does not use advertising, does not sell data, does not set tracking cookies of its own, and does not build profiles of visitors. Analytics are aggregate and cookieless. The only personal data I hold directly is the email address of newsletter subscribers and whatever you choose to tell me when you get in touch.
What is collected, and why
Reading the site
Analytics are provided by GoatCounter, a privacy-focused, open-source service. It sets no cookies and does not track you across websites. It records the page requested, referrer, browser and screen size, and a country-level location derived from your IP address. The IP address itself is not stored — GoatCounter uses it transiently to derive location and to generate a daily-rotating, salted hash for counting unique visits, then discards it.
Legal basis: legitimate interest (Art. 6(1)(f) GDPR) in understanding which articles are read. No cookies are set, so no consent banner is required.
The site is hosted on Netlify and served through Cloudflare. Both process server request logs, including IP addresses, for delivery, security, and abuse prevention.
Some page assets are loaded from third-party hosts: the Bootstrap stylesheet from the jsDelivr CDN, typefaces from Google Fonts, and the profile image from Twitter’s image host. Requesting those files exposes your IP address to those providers, as is the case with any third-party asset on any website.
Subscribing to the newsletter
Newsletter signup forms are embedded from Beehiiv, which operates the AI Security Intelligence newsletter. When you subscribe, Beehiiv receives and stores your email address and, if you provide them, any other details on the form. Beehiiv records standard email engagement metrics such as opens and link clicks, and the embedded form may set cookies under the beehiiv.com domain.
Your email is used to send the newsletter. Nothing else. It is not sold, rented, or shared. You can unsubscribe from the link at the bottom of every issue, which removes you immediately.
Legal basis: consent (Art. 6(1)(a) GDPR), withdrawable at any time. See the Beehiiv Privacy Policy.
Booking a call
Call scheduling runs through Calendly. When you book, Calendly collects your name, email address, and anything you enter in the booking form, and shares it with me so I can prepare for and attend the call.
Anything you tell me during a security review is treated as confidential and is not published, shared, or used in writing without your explicit permission. Where a discussion informs my public research, it is generalized so that no client, system, or organization is identifiable. I am happy to sign an NDA beforehand.
Legal basis: your request to take steps prior to entering into a contract (Art. 6(1)(b) GDPR). See the Calendly Privacy Notice.
Emailing me
If you email me, I keep the message and your address for as long as needed to handle your enquiry and any resulting engagement. Email is not encrypted end-to-end in transit by default; please don’t send credentials, keys, or live vulnerability details by email. If you need a secure channel for sensitive material, ask and I’ll arrange one.
Downloading a resource
The field guide and checklists download directly, with no form and no email required. A download is recorded only as an anonymous aggregate event in GoatCounter.
Cookies
This site sets no cookies of its own. It stores a single value in your browser’s local storage to remember your light/dark theme preference. That value never leaves your device.
Embedded third-party content — the Beehiiv subscribe form, and Calendly if you open a booking — may set its own cookies under its own domain, governed by its own policy.
Retention
- Newsletter subscribers: until you unsubscribe, then removed from the active list
- Analytics: aggregate, non-identifying counts, retained indefinitely
- Email and call correspondence: for the duration of the enquiry or engagement, and up to 24 months afterwards
- Confidential client material: returned or deleted on request, and in any case per the terms of any signed NDA
Your rights
Under the GDPR you have the right to access, correct, delete, export, or restrict processing of your personal data, and to object to processing based on legitimate interest. Where processing rests on consent, you can withdraw it at any time without affecting what came before.
Email [email protected] and I will respond within 30 days. If you believe your data has been mishandled, you may also lodge a complaint with your national supervisory authority — in Sweden, IMY.
International transfers
Beehiiv, Calendly, Netlify, and Cloudflare are US-based providers, so some data is processed outside the EEA. Each relies on Standard Contractual Clauses and/or the EU–US Data Privacy Framework for those transfers.
Changes
Material changes to this policy will be reflected in the “last updated” date above.