Privacy Policy
How we collect, use and protect your personal data, in line with the General Data Protection Regulation (GDPR).
1. Data controller
This website (ramiz.no) is operated by Ramiz Safdar AS, which is the data controller for the personal data processed through the site.
2. What data we collect
We process data you provide yourself, technical data for operation and security, and optional visitor statistics when you consent:
- Contact form: name, email address, phone number and the content of your message.
- Technical data: IP address, browser type and timestamp, logged by our hosting provider for security and operational purposes.
- Browser storage: your language preference and your cookie choice (see the cookie policy).
We do not use cookies for analytics, tracking or marketing.
If you choose “Allow statistics”, we use Vercel Web Analytics for aggregated visitor statistics without analytics cookies. We measure public page views and clicks on the contact button in the menu. URL parameters, form contents and previews are excluded from this measurement. You can withdraw consent using “Cookie settings” in the footer.
3. Purpose and legal basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Responding to contact form enquiries | Consent / legitimate interest (Art. 6(1)(a)/(f)) |
| Operating, securing and debugging the site | Legitimate interest (Art. 6(1)(f)) |
| Optional visitor statistics | Consent (Art. 6(1)(a)) |
| Meeting legal obligations | Legal obligation (Art. 6(1)(c)) |
4. Processors and sharing
We never sell personal data. Data is only shared with providers who process it on our behalf under a data processing agreement:
- Supabase · database and storage of form submissions.
- Vercel · website hosting and operation, plus optional visitor statistics.
Some providers may process data outside the EU/EEA. In such cases the transfer is safeguarded by the EU Standard Contractual Clauses (SCC) or equivalent guarantees.
5. Retention
Contact form enquiries are kept for as long as necessary to follow up, and deleted once no longer relevant. Technical logs are deleted on a rolling basis after a short period.
6. Your rights
Under the GDPR you have the right to:
- request access to the data we hold about you,
- request correction of inaccurate data,
- request erasure (the "right to be forgotten"),
- request restriction of processing,
- object to the processing,
- request data portability, and
- withdraw consent at any time.
To exercise your rights, contact us at ramiz@ramiz.no.
7. Complaint to the supervisory authority
If you believe we process your personal data in breach of the rules, you may lodge a complaint with the Norwegian Data Protection Authority, Datatilsynet.
8. Security
We use technical and organisational measures to protect personal data against unauthorised access, alteration and deletion, including encrypted transmission (HTTPS) and access control.
9. Changes
We may update this policy when needed. The current version is always available on this page, with the updated date shown at the top.