Privacy Policy
Last updated: 7 July 2026
This privacy policy explains how I process personal data when you interact with the dev-portfolio application, its APIs, and connected services.
The application offers multilingual content (English, German, Turkish) and is primarily intended for clients located in Germany, the EU, and Türkiye. Wherever possible we align with the EU General Data Protection Regulation (GDPR) and applicable German law.
1. Controller
Ali Ramazan Yildirim, Hebelstraße 1, 77880 Sasbach, Deutschland, email: info@arytechsolutions.com, phone: +49 151 67145187, acts as the controller for all processing described here.
For EU/EEA residents, you may also address requests to our German correspondence address upon request; we will reply within statutory timelines.
2. Personal Data We Process
We only process data that you actively provide or that is technically required to operate this portfolio.
- Contact details (name, email address, message content) submitted through the contact form at /api/contact; stored with timestamp and rate-limiter metadata in our MongoDB database.
- Customer records created via the admin area (/api/admin/customers): first and last name, company, postal address, phone number, email, referral codes, project notes, pricing, discountRate, finalPrice, referralCount, and timestamps.
- Referral programme transactions saved through ReferralTransaction records, including referrerCode, discountRate (3/6/9%), referral level, and the linked customer ID.
- Bank details (IBAN, account holder) submitted via the customer portal for referral reward payouts; the IBAN is stored encrypted (AES-256-GCM) and displayed only in masked form.
- Invoice information produced with the invoice generator (InvoiceService), such as invoice number, deliverables, project descriptions, VAT calculations, and payment references.
- Authentication data for administrators (email, hashed password, session token stored as the httpOnly cookie "admin-auth-token").
- Technical metadata such as IP address (retained briefly by the rate limiter key), browser headers, and server logs required to secure the service.
3. Purposes and Legal Bases
- Responding to contact requests and preparing proposals (Art. 6(1)(b) GDPR).
- Administering customer accounts, referral rewards, and project deliverables (Art. 6(1)(b) and 6(1)(f) GDPR).
- Generating invoices and meeting statutory bookkeeping duties (Art. 6(1)(c) GDPR).
- Delivering referral notifications and reminders via email using nodemailer (legitimate interest, Art. 6(1)(f) GDPR); you can opt out at any time via the unsubscribe link in each referral email.
- Processing referral reward payouts including your bank details (Art. 6(1)(b) GDPR); retaining payment records under Art. 6(1)(c) GDPR in conjunction with § 147 AO and § 257 HGB.
- Mitigating abuse, enforcing rate limits, and defending our systems (legitimate interest, Art. 6(1)(f) GDPR).
- Complying with legal obligations or requests from authorities (Art. 6(1)(c) GDPR).
4. Retention
- Contact enquiries are kept for up to 12 months after completion, unless a further contract arises.
- Customer and referral data remain for the duration of our business relationship plus up to 3 years for limitation periods, unless bookkeeping law requires longer storage.
- Invoice-related information is retained for 8 years in line with German commercial and tax retention rules.
- Payout bank details (IBAN) are deleted after the final payout or at the latest when the business relationship ends; payout-related accounting records are retained for 8 years (§ 147 AO).
- Rate-limiter entries containing IP-based keys automatically expire within the configured window (60 seconds) and are then deleted.
- Server and security logs are purged within 90 days unless they form part of an incident investigation.
5. Recipients and Processors
- Hosting and deployment providers used for the live portfolio (e.g. Vercel or comparable cloud platforms).
- Database hosting with MongoDB Atlas or another provider defined by the environment variable MONGODB_URI.
- Email transmission via Gmail SMTP or, in development, Ethereal test accounts operated by nodemailer.
- Cloudflare R2 for media storage and asset delivery (CDN) when you upload images through /api/upload.
- Payment service providers (e.g. banks, PayPal) if you remit invoice amounts using the listed methods.
- Professional advisors or authorities where legally required.
6. International Transfers
Data may be processed in Turkey, the EU/EEA, and other jurisdictions where our processors operate (notably the United States for Cloudflare and Gmail).
When transferring outside the EU/EEA we rely on appropriate safeguards such as Standard Contractual Clauses or equivalent guarantees provided by the respective service provider.
7. Security
- Encrypted transport (HTTPS) for public endpoints and admin interfaces.
- Scoped administrative access protected by JWTs and httpOnly cookies.
- Rate limiting and IP throttling implemented via mongoRateLimiter to curb abuse.
- Field-level encryption (AES-256-GCM) for bank details, with the encryption key held outside the database in environment configuration.
- Regular dependency maintenance and monitoring of server logs for anomalies.
8. Your Rights
- Access to your personal data (Art. 15 GDPR).
- Rectification of inaccurate data (Art. 16 GDPR).
- Erasure (Art. 17 GDPR) and restriction (Art. 18 GDPR) within statutory limits.
- Portability for data you provided to us (Art. 20 GDPR).
- Objection to processing based on legitimate interests (Art. 21 GDPR).
- Withdrawal of consent with effect for the future, where processing relies on consent.
- Right to lodge a complaint with a supervisory authority, especially in Germany (LfDI Baden-Württemberg) or your local authority.
9. Exercising Your Rights
Please contact us using the details below. We may ask for proof of identity to protect your data. Responses are provided without undue delay and within the deadlines set by law.
10. Client Projects and Partner Logo Showcase
As part of my professional portfolio service, I showcase projects I have developed for clients and display partner logos in the partners section of my website.
This showcase serves as a reference for potential clients to understand the quality and scope of my work, and to demonstrate professional relationships with established partners.
- Project Showcase: With explicit written consent from each client, I display project details including descriptions, technologies used, screenshots, and project outcomes. Client names and company information are only displayed when expressly permitted.
- Partner Logos: Partner company logos are displayed in the partners section only after obtaining explicit permission through a written agreement or contract clause. Logos are used solely for the purpose of demonstrating professional collaborations.
- Client Control: Clients retain the right to request removal or modification of their project information or logos at any time by contacting me directly. Such requests will be processed within 7 business days.
- Confidential Information: No confidential business information, proprietary code, or sensitive data is ever published without explicit written authorization. All showcase materials undergo client review and approval before publication.
- Legal Basis: These showcase activities are conducted under Art. 6(1)(a) GDPR (consent) and Art. 6(1)(f) GDPR (legitimate interest in presenting professional work), with client consent always taking precedence.
11. Updates
We will update this privacy policy whenever our services or legal obligations change. The current version is always available at /privacy.
Contact for privacy requests
- Ali Ramazan Yildirim
- Address: Hebelstraße 1, 77880 Sasbach, Germany
- Email: info@arytechsolutions.com
- Phone: +49 151 67145187
If the translations differ, the English version prevails. Local consumer protections remain unaffected.