logologo
HomeSkillsCareerPortfolioBlogContacts
Resume
01Home02Skills03Career04Portfolio05Blog06Contacts
Language
Resume

Privacy Policy

Learn how we collect, use, and protect your personal data when you visit our website.

Last updated: 18 August 2026

Privacy Policy

Introduction

This Privacy Policy explains how Cristian Di Carlo ("I", "me") processes limited information when you visit this website or access its private content management system.

For questions regarding privacy or the processing of your data, contact:

okazakee@proton.me

Data Controller

Cristian Di Carlo
okazakee@proton.me

Data Processed

Website Infrastructure

This website is hosted on Vercel.

As part of normal website delivery, security and infrastructure operation, Vercel may process technical request information such as IP addresses, browser and device information, request URLs, timestamps and other HTTP metadata.

This data is processed according to Vercel's own infrastructure, privacy and data-processing policies.

Performance Monitoring

Vercel Speed Insights is used to monitor website performance and Core Web Vitals.

Performance monitoring may include technical metrics related to page loading, browser, device and network conditions. It is used only to understand and improve the technical performance of the website.

Analytics

This website uses a self-hosted instance of Umami for privacy-focused analytics.

Umami does not use tracking cookies or cross-site tracking. It records information such as page views, referrer URLs, browser, operating system, device type and approximate geographic information.

The visitor's IP address may be used transiently to derive anonymous session or location information, but the IP address itself is not stored as an analytics record.

The analytics instance is self-hosted and the collected analytics data remains under my control.

CMS Authentication and Access Control

Access to the CMS is restricted to explicitly authorized users. Public self-registration is disabled.

Depending on the authentication method, the following information may be processed:

Email and password authentication

  • Email address
  • Authentication credentials managed by Supabase
  • Display name
  • Optional profile avatar

Passwords are handled by Supabase authentication and are not stored by this website in plain text.

GitHub OAuth

When GitHub OAuth is used, the CMS may receive:

  • Email address
  • GitHub username
  • Display name
  • GitHub profile avatar URL

GitHub processes the OAuth authentication request according to its own privacy policy.

CMS allowlist

The CMS maintains an internal allowlist used exclusively for access control.

An allowlist record may contain:

  • Email address and/or GitHub username
  • Assigned CMS role

The allowlist is not publicly accessible and is used only by trusted server-side authorization logic.

Login Security and Rate Limiting

To protect the CMS login system from automated abuse, rate limiting is applied independently to the requesting IP address and login email.

Before persistence, both values are transformed into SHA-256 hashes. The raw IP address and raw email address are not stored in the rate-limiter database table.

The rate-limiter stores only the hashed identifier, attempt counters, timing information and temporary lockout state.

Successful authentication clears the corresponding rate-limit buckets. Stale rate-limit records are also subject to automated scheduled cleanup.

This information is used exclusively for authentication security and abuse prevention.

Cookies

Theme Preferences

Two functional cookies are used to remember the selected appearance:

CookiePurposeExpiry
themeModeStores the selected theme mode (light, dark or automatic)365 days
resolvedThemeStores the resolved theme used during server-side rendering365 days

These cookies are used only to remember a preference explicitly selected by the user.

Authentication Cookies

When an authorized user logs into the CMS, Supabase authentication uses session cookies to maintain the authenticated session.

These cookies are used exclusively for authentication and session management and are not used for advertising or cross-site tracking.

Purposes and Legal Basis

Data is processed only where necessary for the following purposes:

ProcessingPurposeLegal basis
Website infrastructureDelivering, operating and securing the websiteLegitimate interests, Art. 6(1)(f) GDPR
Performance monitoringDiagnosing and improving website performanceLegitimate interests, Art. 6(1)(f) GDPR
Privacy-focused analyticsUnderstanding aggregate website usageLegitimate interests, Art. 6(1)(f) GDPR
CMS authentication and access controlOperating and securing the private CMSLegitimate interests, Art. 6(1)(f) GDPR
Login rate limitingPreventing abuse and unauthorized access attemptsLegitimate interests, Art. 6(1)(f) GDPR

Service Providers and International Data Transfers

Supabase

Supabase provides database, storage and authentication infrastructure.

The Supabase project used by this website is deployed in the Central Europe (Zurich) region.

Switzerland is recognized by the European Commission as providing an adequate level of protection for personal data under Article 45 GDPR.

Supabase may also use subprocessors according to its own privacy policy and data-processing terms.

Vercel

Vercel provides website hosting and performance infrastructure.

Vercel is based in the United States and may process information outside the EU/EEA. Where required, Vercel provides international data-transfer mechanisms including Standard Contractual Clauses.

GitHub

GitHub processes authentication information when an authorized CMS user chooses GitHub OAuth.

GitHub's processing is governed by its own privacy policy and OAuth terms.

Umami

Website analytics are processed by a self-hosted Umami instance rather than a third-party analytics service.

Data Retention

  • Self-hosted Umami analytics are retained until manually deleted or until the configured retention policy is changed.
  • Vercel infrastructure and performance data are retained according to Vercel's applicable retention policies.
  • CMS profile and access-control data are retained while CMS access remains active or until the relevant records are removed.
  • Rate-limiter records are temporary security records. Successful authentication removes the relevant buckets and stale records are subject to scheduled cleanup.
  • Theme preference cookies expire after 365 days unless removed earlier by the user.
  • Authentication session data is retained according to the active Supabase session configuration and is invalidated when the session ends or the user signs out.

Account Deletion

Authorized CMS users may request or initiate removal of their CMS access.

The current account-removal flow removes the user's CMS allowlist entry and website profile and terminates the active session.

For requests concerning any remaining authentication or stored data, contact:

okazakee@proton.me

Your Rights

Under the GDPR, where applicable, you may have the right to:

  • Access your personal data
  • Correct inaccurate personal data
  • Request erasure
  • Restrict processing
  • Object to processing
  • Request data portability
  • Lodge a complaint with the competent supervisory authority

To exercise any applicable right, contact:

okazakee@proton.me

Changes to This Policy

This Privacy Policy may be updated when the website, CMS, infrastructure or data-processing practices change.

The latest version will always be published on this page.

Made with ❤️ by Okazakee | Source Code
•CMS•Privacy Policy