Privacy Policy
What data this site collects, why, and how to have it removed.
This is the personal site of Dmitry Zatulovskiy. There is no advertising here, no analytics counters, and no data sold to anyone. The only place where you share anything about yourself is the contact form. Below is exactly what it collects, why, how long it is kept, and how to have it removed.
The data controller is Dmitry Zatulovskiy, owner of grafsoul.com. For anything in this document, reach me through the form on the contact page.
What is collected
When you submit the form on the contact page, the server and the site's database receive exactly what you typed:
- your name, as you gave it;
- your email address, so a reply can reach you;
- the message text;
- the language of the page you wrote from, and the time of sending.
Separately, the site briefly sees your IP address — it arrives with any request on the internet. It is held in the server's memory for no longer than fifteen minutes and for one purpose only: to limit how many messages come from one address and to block spam bots. It is never written to the database and never included in the email.
On what basis, and why
The legal basis for processing is your consent. The form cannot be sent without ticking the consent box; that tick is the consent. The processing has a single purpose — to read your message and answer it. The data is used for nothing else.
Consent is voluntary, and you may withdraw it at any time — write to me and the exchange, along with your data, will be deleted.
Who the data is shared with
I forward your data to no one by hand. But for the email to arrive and the site to run, two external services are in the chain:
- Resend — the email service that delivers your message to my inbox. Your name, email and message pass through it.
- The hosting provider — the company whose servers run the site and the database where the message is stored.
Both services process data under their own policies and may store it on servers outside your country. Beyond them, the data goes nowhere: no ad networks, no analytics platforms, no partners — simply because none of those exist on this site.
How long the data is kept
A message stays in the database as long as it is useful: once the conversation is over, the record is deleted. There is deliberately no fixed number of days — so that a needed exchange is not lost and an unneeded one is not kept. On your request I delete it right away, with no follow-up questions.
Cookies and browser storage
There are currently no advertising or analytics cookies on the site. Your browser stores only the strictly necessary things, without which the site would not work as intended:
- the colour theme you picked, light or dark — kept in localStorage and never sent anywhere;
- your answer to the cookie banner — so it is not shown again;
- a session cookie for signing in — which appears only for me, in the site's admin panel.
If analytics is ever added to the site, it will not start until you agree to it in the cookie banner. You can manage and withdraw that choice in the same place you gave it. Until you consent, no counters load at all — this is built into how the site works, not a promise on paper.
Your rights
Regarding your data, you may:
- request a copy of what is held about you;
- correct an inaccuracy;
- ask for deletion;
- withdraw your consent to processing;
- complain to the data-protection authority in your country if you believe your data was mishandled.
To exercise any of these, write through the form on the contact page. I answer personally, usually within a few days.
Security and children
The site runs only over a secure connection (HTTPS), and access to the admin panel and the database is password-protected. No protection online is absolute, but reasonable measures are in place. The site is not aimed at children and does not knowingly collect their data.
Changes
If the rules change, a new version and a new update date will appear here; material changes are worth re-reading. Current version dated 24 July 2026.