Privacy Policy

Last updated: 9 April 2026

1. Who I Am

This website is operated by Paul Jacobs, sole trader, based on the Isle of Wight, United Kingdom.

Paul Jacobs is the data controller for personal data collected through this website. For the purposes of this policy, “I”, “me” and “my” refer to Paul Jacobs.

Contact: contact@pauljacobs.dev

2. Legal Framework

This policy is written in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. If you are based in the European Union, the EU GDPR may also apply to your data.

I am registered with the Information Commissioner’s Office (ICO). My ICO registration number is: ZC088609.

3. What Data I Collect and Why

Contact form enquiries

Data collected: Name, email address, subject, and message content.

Purpose: To respond to your enquiry.

Lawful basis: Legitimate interest (Article 6(1)(f) UK GDPR) — I have a legitimate interest in responding to business enquiries sent to me voluntarily.

Retention: Enquiry emails are retained for up to 12 months, then deleted. I do not store contact form submissions in a database.

Website analytics

Data collected: Anonymised usage data including pages visited, time on site, browser type, approximate location (country/city), and device type. Google Analytics 4 does not collect your full IP address.

Purpose: To understand how visitors use the site so I can improve it.

Lawful basis: Consent (Article 6(1)(a) UK GDPR) — analytics only load if you click “Accept” on the cookie banner.

Retention: Google Analytics data is retained for 14 months, as configured in my GA4 account.

Third party: Google Ireland Limited. Google acts as a data processor under a Data Processing Agreement. See Google’s Privacy Policy.

Technical / server data

Data collected: IP address, browser type, referring URL, and timestamps — collected automatically by the web server.

Purpose: Security, fraud prevention, and diagnosing technical problems.

Lawful basis: Legitimate interest (Article 6(1)(f) UK GDPR).

Retention: Server logs are retained for 30 days and then automatically overwritten.

4. Where Your Data Is Stored

This website is hosted by Fasthosts Internet Ltd, a UK-based hosting provider. All data collected through this website is stored on servers located in the United Kingdom.

I do not transfer your personal data outside the UK, with the exception of analytics data processed by Google (see Section 3). Google’s standard contractual clauses and adequacy decisions provide the appropriate safeguards for any such transfer.

5. Cookies

I use two categories of cookies on this website:

Strictly necessary cookies

These are required for the website to function (for example, the CSRF security token used on the contact form). They are set automatically and do not require your consent.

Analytics cookies (Google Analytics 4)

These are only set if you click “Accept” on the cookie banner. You can decline at any time by clicking “Decline” on the banner or by clearing your browser cookies and reloading the page.

Your cookie preference is stored in your browser’s local storage. It does not expire automatically — to change your preference, clear your browser data or local storage for this site.

6. Third-Party Services

This website loads resources from the following third-party providers. Each may process your IP address as part of delivering their service:

Service Provider Purpose
Google Analytics 4 Google Ireland Ltd Website analytics (consent only)
Tailwind CSS CDN Tailwind Labs / Cloudflare Stylesheet delivery
Alpine.js jsDelivr Interactive UI components
AOS (animations) unpkg / Cloudflare Scroll animations
Lucide Icons unpkg / Cloudflare Icon library

I am in the process of self-hosting all non-analytics third-party scripts to eliminate external data transfers for non-consenting visitors.

7. How I Protect Your Data

  • This website is served over HTTPS (TLS encryption in transit)
  • Personal data from contact form submissions is transmitted directly to my private email inbox and is not stored in any database on this website
  • Application logs do not contain personal data
  • Hosting is on UK infrastructure (Fasthosts) with physical security controls

8. Your Rights Under UK GDPR

You have the following rights in relation to your personal data:

  • Right of access — You can request a copy of the personal data I hold about you.
  • Right to rectification — You can ask me to correct inaccurate data.
  • Right to erasure — You can ask me to delete your personal data where there is no compelling reason for me to keep it.
  • Right to restriction — You can ask me to restrict processing of your data in certain circumstances.
  • Right to object — You can object to processing based on legitimate interest.
  • Right to withdraw consent — Where processing is based on consent (e.g. analytics cookies), you can withdraw consent at any time by declining cookies.

To exercise any of these rights, email me at contact@pauljacobs.dev. I will respond within 30 days.

9. Right to Complain

If you are unhappy with how I have handled your personal data, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection:

I would appreciate the opportunity to address your concerns before you contact the ICO, so please get in touch with me first.

10. Changes to This Policy

I may update this privacy policy from time to time. The “Last updated” date at the top of this page reflects when changes were last made. Continued use of the website after changes are posted constitutes acceptance of the updated policy.