Shibaji Debnath

System Architect | Mentor

Transparency & Compliance

Privacy Policy & Data Architecture

An engineering-first disclosure of telemetry handling, zero cross-site tracker usage, and advisory communication governance.

Effective: September 2026 Scope: shibajidebnath.com

1 Core Privacy Philosophy

As a technical consultancy and engineering portfolio (shibajidebnath.com), data governance is treated as an architectural requirement rather than a legal afterthought. We strictly uphold a minimal-ingestion model: we only process technical and communication data strictly necessary to review advisory briefs, run system diagnostic courses, and defend the server perimeter against automated brute-force attacks.

2 Data Ingestion Matrix

The following matrix specifies every piece of telemetry captured through this platform:

Data Point Origin / Channel Purpose Retention
Name & Email Advisory Contact Form Responding to consultation briefs Active engagement duration
Client IP Address HTTP Server Headers Rate limiting (5 req / 10 min) & anti-DDoS Rotated every 24 hours
CSRF Session Token HTTPOnly Secure Cookie Mitigating Cross-Site Request Forgery Destroyed on browser exit
Project Context Consultation Form Box Evaluating system architecture bottlenecks Archived after NDA/SOW sign-off

3 Cookies & Local Storage Usage

Unlike marketing-heavy portals, this site does not deploy behavioral profiling cookies. We only maintain:

  • Cryptographic Anti-CSRF Token: Issued by the PHP session layer with SameSite=Strict; Secure; HttpOnly parameters, preventing malicious third parties from forging consultation messages.
  • Local Theme State: A single key in your browser's localStorage (theme: "dark" | "light") to remember your lighting preferences between sessions without notifying remote servers.

4 Third-Party Integrations & CDN Isolation

Course trailers and technical demonstrations are embedded using YouTube's privacy-enhanced embed gateway. When you play a video, Google services may capture functional streaming telemetry subject to standard Google privacy terms. No visitor identification data from contact submissions or courses is shared with external analytics vendors.

5 Data Retention & Erasure Rights

In strict accordance with global data protection standards (including GDPR Article 17 and Indian DPDP guidelines), you hold the permanent right to request full audits or permanent deletion of any communication history exchanged with our technical mailboxes.

6. Direct Data Protection Requests

To request an immediate purge of your consultation records or discuss technical NDA boundaries, reach out directly to the principal:

imshibaji@gmail.com Direct review by Shibaji Debnath (< 24h)