Data Governance & Privacy
Privacy Policy
1. Overview & Privacy-First Philosophy
Your privacy, autonomy, and security are non-negotiable. This Privacy Policy governs how data is handled across Gaurav Portfolio. The architecture operates on strict data minimization principles: only the minimum information necessary to facilitate professional communication is collected, with zero third-party data tracking, zero cookie profiling, and zero monetization of personal information.
2. Absolute Right to Anonymity & Confidential Inquiries
Every visitor and prospective collaborator has the full, unrestricted right to maintain complete anonymity:
- Default Anonymous Role: The contact form defaults to the "Anonymous / Confidential" identity to ensure no visitor is pressured into declaring a specific role.
- Pseudonyms & Private Relays: You may submit inquiries using an alias, pseudonym, or privacy-relayed email address (such as Apple Relay or SimpleLogin).
- Zero Telemetry Correlation: Inbound contact messages are strictly segregated from user-agent fingerprints and external analytics data.
3. Bot Mitigation & Ephemeral Cloudflare Turnstile Evaluation
To protect public endpoints against automated spam and DDoS attacks, the system utilizes Cloudflare Turnstile:
- Cookie-Free Evaluation: Turnstile evaluates browser telemetry ephemerally during submission without setting persistent cross-site tracking cookies.
- Server-Side Token Validation: Tokens are validated instantaneously via server-to-server TLS calls and discarded immediately following verification.
4. Transactional Communications & Brevo Delivery Gateway
All transactional communications, verification passcodes, and mandatory legal announcements are routed through an enterprise Brevo server pipeline:
- Authenticated Domain: Official communications originate strictly from the verified primary identity
gauravpatil.site. - Official Senders:
hello@gauravpatil.site(Direct contact & automated receipts)security@gauravpatil.site(Security alerts, authentication verification & push audit logs)help@gauravpatil.site(Support & assistance)no-reply@gauravpatil.site(System OTPs & mandatory legal update announcements)- Strict Non-Marketing Standard: Submitting an inquiry or authenticating will never enroll you in promotional campaigns or marketing distributions.
Mandatory Legal Update Broadcasts & Strict No-Unsubscribe Standard
Email addresses provided through Contact Form submissions, Assistant/Live Chat OTP authentication, or direct inquiries are retained securely in cloud databases. These addresses receive mandatory service announcements whenever the public Terms of Service or Privacy Policy are amended. Because these notices represent vital legal disclosures required for platform transparency and governance (and never commercial marketing), they do not include marketing unsubscribe links and cannot be opted out of, even through third-party automated email client features (such as Google/Gmail automatic 1-click unsubscribe headers).
5. Data Security, Storage & Deletion Rights
Inquiries are stored in encrypted cloud databases (Firebase Firestore / Realtime Database in region asia-southeast1) with atomic lead tracking. You retain the right under GDPR, CCPA, and international privacy standards to:
- Request a copy of any communication history associated with your email.
- Request permanent, atomic deletion of all submitted contact records and message drafts.
6. Personal Assistant (Beta) & AI Safety Architecture
Why Gaurav Assistant Was Created
The Personal Assistant was conceived and engineered as an intelligent interactive portfolio navigator designed to elevate how recruiters, hiring managers, engineering leaders, and potential clients explore Gaurav Patil's work. Instead of manually parsing static resume bullets, visitors can receive real-time answers concerning deep case studies, technical specializations, engineering philosophy, and live architectural demonstrations.
Custom Mail Domain Support & Verified Communication Channels
All visitor interactions, assistant support inquiries, and transactional communications are backed by a dedicated, enterprise-grade Brevo email delivery pipeline configured with strict SPF, DKIM, and DMARC authentication records. Official communication originating from this portfolio is bound to the primary authenticated domain gauravpatil.site:
gaurav@gauravpatil.site— Direct professional contact, engineering consulting engagements, and formal controller correspondence.hello@gauravpatil.site— Direct portfolio contact, visitor inquiries, developer collaboration, and automated inquiry receipts.help@gauravpatil.site— Assistant technical assistance, bug reports, user feedback, and portfolio navigation support.security@gauravpatil.site— Security disclosures, vulnerability reports, 2FA OTP codes, and authentication alerts.no-reply@gauravpatil.site— Non-interactive automated notifications, system passcodes, and security verifications only.
Live Chat Notification Privacy & 4-Hour Session Security
- Direct Message Routing: When you send a message in Live Chat, it is streamed immediately if Gaurav is connected. When away, the automated system triggers an instantaneous notification email to Gaurav's personal inbox with your message transcript and 1-click reply routing.
- Zero Plaintext OTP Storage: 6-digit verification codes are hashed using salted HMAC-SHA256 before storage and destroyed immediately upon successful authentication or after 5 minutes.
- Encrypted 4-Hour Session Token: Verified sessions are stored in an encrypted
httpOnly,SameSite=Laxcookie valid for 4 hours. You can close and return to the portfolio anytime during this period without re-verifying. - 1-Click Sign-Out & Detachment: You may revoke your session token at any time by clicking Sign out in the chat header, which atomically clears your session cookie and closes live streams across all browser tabs.
Data Protection, Ephemeral Processing & Anonymity
- Ephemeral Session Processing: Assistant interactions are evaluated in-memory strictly for real-time guidance during your active session.
- Zero Third-Party Training or Data Selling: A 100% data integrity guarantee is maintained: queries and live messages are never sold, rented, monetized, or fed into public generative model training pools.
- No Persistent Tracking: The assistant functions completely without tracking cookies, behavioral tracking scripts, or persistent fingerprinting.
- Active Beta Guardrails: Automated rate-limiting and input sanitization protect against malicious exploitation while maintaining zero layout shift (
CLS = 0) across desktop and mobile devices.
7. WhatsApp Recruiter Data Portability & Self-Service Export (GDPR Art. 20)
In full compliance with GDPR Article 20 (Right to Data Portability) and the California Consumer Privacy Act (CCPA), visitors and recruiters interacting with Gaurav Patil via the official WhatsApp Business channel maintain absolute ownership of their communication records:
- Instant ZIP Archive: Typing
/exportmydatain WhatsApp immediately triggers the server to compile an encrypted in-memory ZIP package containing your complete records with zero wait time. - Visual HTML Log: Includes a standalone, beautifully styled Dark Luxury HTML transcript featuring verified timestamps, speaker badges, and Gaurav Portfolio branding readable offline on any browser.
- GDPR Certificate: Every export includes an official Data Portability Certificate detailing exact UTC generation timestamps, session identifiers, compliance guarantees, and SHA-256 integrity verification.
How to Export Your WhatsApp Chat Data (2 Simple Steps)
- In your active WhatsApp conversation with Gaurav Patil, send:
/exportmydata(or/export). - The automated system will immediately confirm with a generation notice, followed by a cryptographically signed HMAC download link (strictly valid for 10 minutes). Tap the link to download your
.ziparchive directly to your device.
GDPR Article 17: Right to Immediate Erasure (STOP Command)
You maintain full sovereignty over your information. At any point, simply reply STOP to WhatsApp. The server immediately unsubscribes your number and permanently erases all message documents and session data from the database in an atomic transaction.
8. Administrative Subsystem Privacy Governance
The administrative panel (/admin/*) maintains a strictly isolated data governance architecture. Administrative authentication is restricted to authorized Superadmins via Google OAuth 2.0 PKCE. 2FA One-Time Passcodes are stored in salted HMAC-SHA256 hashed representations, and security IP verification challenges operate under an immutable 15-minute TTL. Sign-out triggers a complete 5-step detachment that clears all cookies, tokens, and browser session storage. Detailed administrative privacy protocols are documented in the Administrator Privacy Policy.
9. Contact & Data Requests
For formal privacy inquiries, data deletion requests, or direct professional communication:
- Direct Professional & Controller Inquiries: gaurav@gauravpatil.site *(Reserved strictly for professional proposals, consulting contracts, and data controller requests)*
- General Inquiries: hello@gauravpatil.site
© 2026 Gaurav Portfolio. All rights reserved.