Skip to main content

PRIVACY

How your details are handled

This is a personal professional site. It exists to publish a verified public record and to receive direct inquiries. Nothing here profiles visitors.

Who is responsible

Edwin Mata is the controller for the personal data described here. Questions, objections and requests can be sent to edwin@brickken.com, or through the contact form on this site.

What the contact form collects

The form asks for a name, an email address, an organization or publication, an optional date or timeframe, and the context of the request. Those details are used for one purpose only: to read the inquiry and reply.

Alongside the message, limited security metadata is processed: a one-way digest of the connection the request came from, a one-way digest of the email address, an attempt count, a status flag and an expiry time.

The message is delivered privately by email and is not written to a database on this site. Once it arrives, it lives in an ordinary email inbox and is kept only for as long as the conversation is relevant.

Why it is processed, and on what basis

The inquiry itself is processed to respond to the contact you requested and to take any steps you asked for before a possible engagement. Where an inquiry leads towards an agreement, that is the performance of pre-contractual steps at your request.

The security metadata is processed on the basis of a legitimate interest in keeping a small personal contact form usable: preventing automated abuse, duplicated submissions and flooding. It is the least data that achieves that.

What is stored to prevent abuse

Anti-abuse counters hold only one-way cryptographic digests, a count, a status and an expiry timestamp. A digest cannot be reversed into an address or an IP address. No name, message text, organization, raw email address, raw IP address, recipient or sender address is ever written to the database.

Every counter is set to expire no later than 24 hours after the window it belongs to begins. An expired counter stops being valid at that moment and is no longer counted or acted on. Removal of the expired row itself happens on a routine purge and on the next request that touches the store, so a short interval can pass between a counter becoming invalid and the row being physically deleted.

Who processes data on this site's behalf

Lovable hosts the site, serves the pages and runs the server code. Supabase provides the short-lived anti-abuse database described above. Resend relays inquiry messages so a recipient address never appears in the browser, and the business email service used by the recipient receives and stores the delivered message. All act as processors on documented instructions and are not used to profile visitors.

These providers may process data outside the country you are in, including in the United States. Where that happens, transfers rely on the safeguards those providers make available, such as the European Commission's standard contractual clauses and, where applicable, an approved adequacy framework.

How long it is kept

Correspondence is kept only while the conversation, engagement or record-keeping reason for it remains relevant, then deleted. Anti-abuse counters expire within 24 hours as described above.

A relayed message also passes through the email provider's own systems and the recipient's business email service, which apply their own retention periods. Those periods are set by those providers and are not restated here.

Analytics, tracking and video

This site deliberately installs no marketing or behavioral analytics, no advertising pixel, no third-party tracker, no profiling or tracking cookie, no marketing list and no automated decision-making, and no inquiry is ever added to a mailing list. The hosting provider may process standard operational request logs and produce aggregate traffic statistics from them under its own terms, as any web host does; that processing is operational rather than a marketing analytics product, and it is not used to build a profile of you.

One exception is deliberate: when you choose to open a video on this site, the video provider is contacted at that moment so it can be played, and it will see the request. The video provider is not contacted until you make that choice. Page images, including the still frames shown before a video is opened, and the site's fonts are all served from this site, so before you deliberately open a video the page does not contact a separate font or video content delivery network. The hosting provider still handles the request itself, as described above.

Your rights

Subject to the applicable law, you can ask for access to the personal data held about you, ask for it to be corrected or erased, ask for processing to be restricted, object to processing carried out on the basis of a legitimate interest, and, where the processing is based on a contract or consent and carried out by automated means, ask for portability.

Requests are actioned directly and free of charge. You also have the right to lodge a complaint with your local data protection supervisory authority.

Return to the contact form