Skip to content
Rafael Aslanian
Legal

Privacy notice

Last updated 28 August 2026

This notice covers personal data collected through this website. It is written to meet the UK GDPR and the Data Protection Act 2018.

The short version: if you send the enquiry form, I collect what you type. When you have arrived from an advert, what I collect also includes the campaign and click information that was in the link you followed, so I can tell whether the advert produced a real enquiry. Separately, the site counts visits using self-hosted software that sets no cookies and stores no IP address. If your browser sends a Do Not Track signal, it is not counted at all.

This site also records how pages are used — mouse movement, clicks, scrolling — and replays those sessions to me so I can see where the page is confusing. That runs by default and it sets two cookies. You can switch it off at any time using the Cookies link in the footer of every page, and it stays off.

Everything you type into the enquiry form is masked in those recordings and is never sent to the recording provider.

1. Who is responsible

The controller for personal data collected through this site is Rafael Aslanian, a sole trader established in England, trading from 222 Worple Road, London SW20 8RH, United Kingdom. You can reach me through the contact form, or in writing at that address.

Microsoft provides the session-recording tool described below. It acts as a controller in its own right for the data it collects, not only as my processor. That is Microsoft's own characterisation and it means Microsoft's privacy statement applies to that data alongside this notice.

2. What the enquiry form collects

When you send the enquiry form I collect the answers you give: your name, work email address, the clinic or business name, the website or repository address you supply, what you describe as the problem, and when you would want it done. Four further questions are optional and clearly marked as such. They are the type of work, what happens if it is unresolved, a budget band and whether you can approve the work.

My server also records the IP address the submission came from and the time it arrived. Those two are used to rate-limit the form and to identify abuse, and for nothing else.

Please do not put patient details, medical information or anything else about a third party into the form. Nothing here asks for it, and it is not something I need in order to reply.

3. Advertising click and campaign information

If you arrive through an advert, the site records limited campaign and click information contained in the landing-page URL so I can tell whether the advert led to an enquiry. This may include Google click identifiers such as GCLID, GBRAID or WBRAID and UTM campaign parameters, along with the page you landed on and, where your browser sends it, the address of the site you came from.

That information is held in your browser's memory for the length of the visit and is submitted only if you go on to send the form. If you have not turned off optional storage in the footer, it is also kept in your browser's local storage under a single key so that an enquiry sent on a later visit can still be matched to the advert that brought you. That entry holds only the campaign information described above, never anything you typed, and it is deleted automatically after ninety days. Turning off optional storage deletes it immediately and stops it being written again; the click identifier is still read for the visit you are on. If you never send the form, nothing is submitted at all. The click identifier is removed from the address bar as soon as it has been read, and it is never placed in a cookie, because a cookie would attach it to every request your browser makes.

The lawful basis is legitimate interests. Measuring whether paid advertising produces genuine enquiries is a basic and expected part of running a business. It is limited to the campaign information the advertising platform itself put in the link, and it tells me nothing about you that the enquiry does not.

4. What is sent back to Google

Where an enquiry came from Google Ads, I may send Google the relevant click identifier, conversion name and conversion time so the enquiry can be attributed to the advert. Where a project is won I may also send its value. I do not send Google the contents of your message for this purpose, and I do not send your name, your email address or your website.

The conversion name says only which stage an enquiry reached — for example that it was a qualified enquiry, or that a proposal was sent. Google receives that label and the click identifier it already issued; it does not receive the enquiry.

Google Ireland Limited and Google LLC act as controllers for the advertising data they hold. This processing is also on the basis of legitimate interests in measuring advertising.

5. Two different things, treated differently

This site measures two things, and they are not in the same category, so they are not handled the same way.

Counting visits is described below. It runs without asking, on the basis of legitimate interests. It uses no cookies, stores no IP address, is self-hosted rather than a third-party analytics account, and is not combined with data from any other website. It is the electronic equivalent of knowing how many people came through the door. If your browser sends a Do Not Track signal, nothing is collected from you at all — that is the opt-out, and it needs no dialogue box.

Recording your session is the other, and it is the more intrusive of the two: it involves a third party and it sets cookies. It runs by default rather than waiting to be asked. If you would rather it did not, the Cookies link in the footer of every page switches it off, and that choice is remembered.

Your choice is stored in your browser's local storage under a single key so that it is remembered on every page. That one entry contains nothing but the answer and the date you gave it, and is not linked to the advertising information above.

Switching it off stops further recording and tells Microsoft to delete the cookies it set. It does not delete recordings already taken — see the section on that below.

6. Umami — visit statistics

This site uses Umami to count visits. It is a self-hosted installation running on my own Railway service in the European Union, not a third-party analytics account. So the data is not shared with an analytics company and is not combined with data from any other website. The lawful basis is legitimate interests. Knowing how many people reach a page, and which of them came from an advert, is a basic and expected part of running a business, and none of it identifies you.

For each page view Umami receives: the page path and any campaign parameters on it, the address of the referring site, the page title, your browser's language, your screen size, and your browser, operating system, device type and country as derived from the request. It does not use cookies. It does not store your IP address. Instead the visit is grouped into a session using a value calculated from your IP address, your browser identification and a salt that changes every month, so sessions cannot be linked across months.

The advertising click identifiers described in section 3 are deliberately removed before anything is sent to Umami, so no Google click identifier reaches it. The campaign parameters — source, medium, campaign, term and content — are kept, because knowing which campaign produced a visit is the point.

The tracker checks your browser's local storage for one entry, named umami.disabled, which exists so that particular browsers can be excluded from the count. Nothing on this site writes that entry, and reading it tells the tracker nothing about you.

It honours Do Not Track. If your browser sends that signal, no visit of yours is counted. That is the opt-out, and unlike a banner it applies to every site you visit rather than only this one. If you would prefer to be excluded from the count some other way, ask me and I will arrange it.

7. Microsoft Clarity — session recordings and heatmaps

This site uses Microsoft Clarity to record how pages are used, and to build heatmaps showing where visitors click and how far they scroll. It runs by default. The Cookies link in the footer of every page switches it off.

A recording captures the structure of the page and how you moved through it: mouse movement, clicks, scrolling, selections, the fact that a field was interacted with, page and script errors, and how quickly the page performed. Microsoft assigns an identifier to your browser so that several pages in one visit can be replayed together.

The enquiry form is masked in its entirety. Everything inside it is replaced before it leaves your browser and is never uploaded to Microsoft. That includes what you type, the labels, the help text, any error messages and the confirmation shown afterwards. Text entered into any input is masked by Microsoft in every mode and cannot be revealed. No page on this site asks Clarity to unmask anything.

Microsoft is told which page type you are on and which offer it carries. It is never sent your name, your email address, your website, your message, your budget answer, an advertising click identifier or any identifier I hold for you. Clarity's ability to link a session to a named person is not used at all.

Clarity sets two first-party cookies: _clck, which lasts one year and holds the identifier for your browser, and _clsk, which lasts one day and joins several page views into one recording. It also uses one session-storage entry, _cltk, to identify the browser tab. Microsoft states that it uses your IP address to work out your approximate location and does not store the address itself.

Data is shared with Microsoft as a recipient and is stored on Microsoft Azure, which involves a transfer outside the UK. Microsoft's advertising-related sharing is switched off on this site: the setting that would allow it is refused on every request.

Microsoft honours the Global Privacy Control signal, and will not start if your browser sends it. It does not respond to Do Not Track.

8. Who else sees your data

Your enquiry is delivered to my inbox, and the confirmation is delivered to you, by Resend, an email delivery provider acting as my processor. It is processed on servers that may be outside the UK, including in the United States. Those transfers are covered by the UK International Data Transfer Addendum to the European Commission's standard contractual clauses.

The site and the Umami installation are hosted by Railway, and the site is served through Cloudflare. Both process request data including IP addresses in order to serve the page, as my processors.

Microsoft receives the session-recording data described above, and Google receives the conversion information described above, only where those apply.

I do not sell personal data, and I do not share it with anyone for their own marketing.

9. How long it is kept

Enquiries are held in my email account and in a private record on my own server for as long as there is a live business reason to keep them. Enquiries that do not lead to an engagement, and the advertising click information stored with them, are deleted within 24 months.

Where an enquiry becomes an engagement, the correspondence is kept for the duration of the engagement and for six years afterwards. Six years is the period in which a contract claim can be brought and the period business records must be retained for tax purposes.

Umami is self-hosted and has no automatic expiry. Visit statistics are therefore deleted manually, and I review and clear data older than 14 months. If you would like that done sooner, ask.

Clarity's retention is set by Microsoft and cannot be changed by me. Microsoft states that session recordings are kept for 30 days, that a small sample of recordings and the heatmap click data are kept for nine months, and that data is then deleted from its servers including backups.

Server rate-limit records hold an IP address in memory for one minute and are not written to permanent storage.

Your session-recording choice is kept in your own browser for six months and is not held by me at all.

10. Your rights

Under the UK GDPR you have the right to:

  • ask for a copy of the personal data I hold about you
  • ask me to correct it if it is wrong
  • ask me to erase it
  • ask me to restrict how I use it
  • object to processing carried out on the basis of legitimate interests, which includes the advertising measurement in sections 3 and 4
  • withdraw your agreement to session recording at any time, using the link in the footer
  • object to the visit counting described above, which is on legitimate interests
  • ask for a copy in a portable format

11. One limit worth stating plainly

I can delete your enquiry, the advertising information stored with it and your entry in the visit statistics, and I will if you ask.

Microsoft Clarity does not offer a way to delete the data of one individual. Its own documentation says the only way to remove a person's data is to delete the entire project. So if you ask me to erase a Clarity recording, what I can do is stop further recording for you, ask Microsoft to remove its cookies from your browser, and — if you want it — delete the whole Clarity project. That last step removes everyone's data including yours. Recordings are in any case deleted by Microsoft after 30 days.

You should know that before agreeing, which is why it is written here rather than left for you to discover.

12. Making a request or a complaint

To exercise any of those rights, contact me. I will respond within one month. There is no charge unless a request is manifestly unfounded or excessive.

If you are not satisfied with how I have handled your data, you can complain to the Information Commissioner's Office at ico.org.uk, or on 0303 123 1113. I would appreciate the chance to put it right first.

13. Security

It is served over HTTPS with a content security policy and a strict referrer policy, so the address of a page you visited is not passed to other sites in full. Enquiries are validated and rate-limited on the server, and every value submitted is checked against a fixed set of rules before it is stored.

Access to the inbox that receives enquiries is protected by a strong unique password and two-factor authentication. Enquiries can also be read through a password-protected page on this site, which is available only to me. That page is excluded from search engines, never cached, and does not exist at all unless a password is configured. Sessions expire after eight hours and repeated failed attempts are rate-limited.

No system is perfectly secure. If a breach occurs that is likely to risk your rights and freedoms, I will notify the Information Commissioner's Office within 72 hours and tell you where the law requires it.

14. Changes

If this notice changes, the revised version appears here with a new date at the top.

Ask before you sign or subscribe, not after. Get in touch