Privacy Policy
Last updated:
This site is a personal portfolio. It sets no cookies, runs no advertising, and does no profiling. The only personal data it stores is the email address of people who deliberately create an account for the private area.
1. Who is responsible for your data
The data controller for this website is Stefanos Tzortzoglou, a private individual based in Uppsala, Sweden. This site is a personal portfolio, not a business: nothing is sold here and no company is behind it.
Contact for any privacy question or request: stefanos@tzortzoglou.eu.
Because the controller is established in Sweden, this policy is governed by the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) and the Swedish Data Protection Act (lag (2018:218) med kompletterande bestämmelser till EU:s dataskyddsförordning).
2. If you only browse the site
You do not need an account to read anything on the public pages, and you are not asked for any information. Three things still happen automatically, because that is how the web works:
2.1 Hosting logs
The site is hosted on GitHub Pages (GitHub, Inc., United States). To deliver and protect the pages, GitHub processes technical connection data including your IP address, the requested URL, and your browser's user-agent string. I have no access to these logs and cannot read them.
- Purpose: serving the site and protecting it from abuse.
- Legal basis: legitimate interests, Art. 6(1)(f) GDPR — running a functioning, secure website.
- Transfer outside the EEA: yes, to the United States, under GitHub's Data Protection Agreement and the EU Standard Contractual Clauses. See GitHub's privacy statement.
2.2 Analytics
Visitor statistics are collected with GoatCounter, a privacy-focused analytics service hosted in the EU. GoatCounter sets no cookies and does not build a persistent identifier or profile of you. It records the page you viewed, the referring page, and coarse technical details such as browser, operating system, screen size and country. It does not store your IP address.
- Purpose: understanding, in aggregate, which pages people find useful.
- Legal basis: your consent, Art. 6(1)(a) GDPR. Analytics does not load at all unless you accept it on the banner shown on your first visit, and you can withdraw that consent at any time — as easily as you gave it — from the Cookies & Local Storage page (Art. 7(3)).
- If you decline or ignore the banner: nothing is loaded, nothing is counted, and the site works exactly the same.
- More information: GoatCounter's privacy policy.
2.3 Third-party files loaded by your browser
Some fonts, icons and widgets are loaded directly from other providers rather than from this domain. When your browser fetches those files, it connects to those providers directly, and they necessarily receive your IP address, your user-agent, and the page you were on. This happens on page load, before you interact with anything. The full list is in the Cookies & Local Storage page.
I do not control what those providers do with that connection data. If you would rather not connect to them, a content-blocking browser extension will prevent the requests; the site remains readable, though some icons and the GitHub activity graph will not render.
3. If you create an account
A small part of this site (the private area) is personal content shared with specific people. Reaching it requires an account, which is approved manually by me. Creating one is entirely optional — nothing on the public site depends on it.
When you register, the following is stored:
| Data | Where it is stored | Why |
|---|---|---|
| Email address | Firebase Authentication and Cloud Firestore | To identify your account and let me recognise who is requesting access. |
| Password | Firebase Authentication only, stored as a salted hash | To let you sign in. I never see your password and cannot recover it. |
Account status (pending / approved) and creation timestamp |
Cloud Firestore | To run the manual approval step. |
- Purpose: restricting private personal content to people I have approved.
- Legal basis: your consent, Art. 6(1)(a) GDPR, given by ticking the consent box on the registration form. You may withdraw it at any time (see section 6); withdrawal does not affect processing already carried out.
- Processor: Google Ireland Limited (Firebase / Google Cloud). Data is stored on Google Cloud infrastructure and may be transferred outside the EEA under the EU Standard Contractual Clauses and Google's Data Processing Addendum.
- Retention: until you ask for deletion, or until the account is no longer needed — whichever comes first. Registrations left unapproved are deleted periodically.
What is never done with it: your email address is not used for marketing, not added to any mailing list, not sold, not shared with anyone, and not used for profiling or automated decision-making within the meaning of Art. 22 GDPR.
4. If you email me
Email sent to stefanos@tzortzoglou.eu is not delivered to a mailbox on this domain. It is relayed by my domain registrar's mail-forwarding service (Spaceship) to a personal Gmail mailbox (Google Ireland Limited), where it is read and answered. Both providers process the message in transit or at rest as part of delivering it.
Its contents, your address, and anything you choose to include are kept for as long as needed to deal with your message and to keep a record of the correspondence.
- Legal basis: legitimate interests, Art. 6(1)(f) GDPR — responding to someone who contacted me.
- Transfer outside the EEA: possible, under those providers' own standard contractual clauses.
- Sensitive information: ordinary email is not end-to-end encrypted. Please do not send anything confidential or sensitive to this address.
5. What is stored on your device
No cookies are set by this site. A small amount is written to your browser's local storage: your theme preference, your analytics choice, and — only if you log in — your session token. The full list, and how to change your analytics choice, are on the Cookies & Local Storage page.
6. Your rights
Under the GDPR you have the right to:
- Access — get a copy of the personal data held about you (Art. 15).
- Rectification — have inaccurate data corrected (Art. 16).
- Erasure — have your data deleted (Art. 17).
- Restriction — have processing limited (Art. 18).
- Portability — receive your data in a machine-readable format (Art. 20).
- Object — object to processing based on legitimate interests (Art. 21).
- Withdraw consent — at any time, where processing rests on consent (Art. 7(3)).
To exercise any of these, email stefanos@tzortzoglou.eu. There is no charge, and I will respond within one month. Deleting an account is a manual step and takes only a short message — you do not have to give a reason.
If you think your data has been handled improperly, you can complain to the Swedish supervisory authority, Integritetsskyddsmyndigheten (IMY) — imy.se — or to the authority in your own EU/EEA country.
7. Security
The site is served over HTTPS. Authentication and account data are handled by Firebase, and database rules restrict each account to reading only its own record; account approval can only be performed by me. Passwords are hashed by Firebase and are never visible to me. No system is perfectly secure, but the amount of personal data held here is deliberately kept to the minimum needed to run the approval gate.
8. Children
This site is not directed at children. Please do not register an account if you are under 16. If you believe a child has registered, email me and I will delete the account.
9. Changes to this policy
If the site starts doing something new with personal data — a contact form, a newsletter, embedded third-party media — this policy will be updated before that goes live, and the "last updated" date above will change.
Questions about this page? Email stefanos@tzortzoglou.eu.