Privacy

What this site processes

This is a technical template reflecting the application’s default behavior. The owner must complete the marked details and obtain legal advice appropriate to their jurisdiction.

Controller and contact

OWNER_NAME_AND_POSTAL_ADDRESS — TO BE COMPLETED

PRIVACY_CONTACT — TO BE COMPLETED

Public website and hosting

The public profile is delivered by Vercel. As with ordinary web hosting, Vercel may process request metadata such as IP address, timestamp, requested resource, user agent, and operational logs. Complete the legal basis, retention, and processor details for the actual deployment.

Necessary access session

If you use NFC or exchange an application code, this site stores a necessary HttpOnly cookie named __Host-access. It contains an opaque random session secret, not contact or CV data. The server stores only a keyed digest and scoped grants with expiry/revocation state.

Codes, NFC, and security events

Application codes are not stored in plaintext. NFC verification uses authenticated dynamic tag data and a counter. Minimal events such as successful redemption, rejection category, revocation, or replay rejection may be recorded without raw codes, session secrets, AES keys, private contact fields, or CV content.

Abuse prevention

Repeated failed code attempts can create a temporary rate-limit record. An IP-derived value, if available, is transformed with a rotating keyed HMAC before storage; the plaintext IP is not placed in the application database. Records expire automatically and are used only to protect the access form.

Supabase

Protected contact information, CV content, access metadata, and a private PDF are stored in the configured Supabase region. Supabase provides PostgreSQL, owner authentication, and private object storage. Complete the deployment-specific processor, region, retention, and transfer information.

Tracking and external links

No advertising analytics, pixels, or behavioral tracking scripts are included by default. External professional links are opened only when selected; their providers then process the request under their own terms.

Retention and rights

RETENTION_PERIODS_AND_DATA_SUBJECT_RIGHTS_PROCESS — TO BE COMPLETED. The default design supports expiry and revocation of tokens, sessions, grants, rate-limit records, and minimal audit events.

Last technical template update: 17 August 2026. This page is not legal advice.