Skip to content
Pavlo Kostenko

Privacy

What this site processes, why, on what legal basis, for how long, and who else can see it.

Who is responsible

The controller of any personal data processed through this site isPavlo Kostenko, a private individual resident in Limassol, Cyprus, acting in a personal capacity. This blog is not operated by my employer and sells nothing. Contact: hi@pavlokostenko.com.

Cyprus is an EU member state, so the processing falls under Regulation (EU) 2016/679 (GDPR) and Cyprus Law 125(I)/2018. No data protection officer has been appointed and none is required: Article 37 GDPR reserves that obligation for public authorities, for large-scale systematic monitoring, and for large-scale processing of special category data. None of that happens here.

What is processed

Server and network logs. The site is hosted on Cloudflare, so every request passes through its network and is recorded there: the IP address it came from, the timestamp, the URL, the response status, the browser user agent, and the referring page if your browser sends one. An IP address is personal data under GDPR. I run no logging of my own, export nothing, and never try to connect a log line to a person.

Aggregate audience statistics. Cloudflare Web Analytics is switched on, and it is deliberately blind in one direction: the measurement script is not served to visitors from the European Union at all. If you are reading this from an EU country, nothing on this page measures you. Everywhere else it loads and records the page viewed, the referring site, approximate country, browser family, and how quickly the page rendered. It sets no cookie, writes no identifier to your device, and builds no profile: what comes back to me are counts, and I cannot tell one returning reader from two new ones.

Correspondence. If you write tohi@pavlokostenko.com, I receive your address, whatever you put in the message, and the headers your mail server attaches. That is the only channel here that collects anything from you: there is no contact form, no comment section, and no subscription field.

Legal basis for each

Logs rest on legitimate interests, Article 6(1)(f) GDPR: keeping the site available and not trivially abused, which means serving the correct page, absorbing hostile traffic, and diagnosing failures. Recital 49 recognizes network security as exactly such an interest. Weighed against it, the data is produced by your request rather than asked of you, is never enriched, feeds no profile and no advertising, stays with the host, and is short-lived. Nothing here overrides your rights.

Correspondence rests on the same basis: I have a legitimate interest in reading and answering mail sent to me. Where the message is itself a data protection request, handling it is also a legal obligation under Articles 12 to 22.

Aggregate statistics rest on Article 6(1)(f) as well. The interest is plain enough to state without dressing it up: knowing whether any of this is read is what keeps me writing it. The weight on your side is light by construction, because the tool is cookieless, what it produces are counts rather than records about people, and the readers to whom EU law gives the strongest protection are excluded from measurement outright instead of being asked to dismiss a banner.

Consent, Article 6(1)(a), appears nowhere above, because nothing here is done on the strength of it. It will become the basis for the newsletter, when the newsletter exists, and for nothing else.

Why there is no cookie banner

This is a legal conclusion, not an omission. Article 5(3) of the ePrivacy Directive (2002/58/EC, as transposed in Cyprus) requires consent for storing information on your terminal equipment or gaining access to information already stored there. On the current implementation nothing here does either to a reader in the European Union: no cookie is set, nothing is written to local or session storage, no service worker is registered, and the one measurement script this site uses is not served to EU visitors at all. Typefaces come from this domain and the share icons are ordinary links, so no outside party learns you were here unless you click through to it.

Two qualifications, because the flat version of that sentence would be the wrong shape. Outside the EU the Cloudflare measurement script does load; it stores nothing on your device, but it runs. And Cloudflare attaches a network error reporting policy to every response, which your browser keeps for a week and uses to report failed connections back to Cloudflare. Neither one collects anything I could use to identify you, neither exists to follow you anywhere, and the toggle for the second is not offered on this plan. Both are still more than nothing, so I would rather name them than claim a purity the code does not have.

Server logs fall outside Article 5(3) altogether: they are created by the host receiving your request, not by anything on your machine, hence legitimate interests. A consent banner would change none of the above, which is why there is not one.

Who else can see this

Cloudflare hosts the files, stands in front of every request as the network provider, operates the email routing for the address on this page, and runs the audience measurement, so it holds both the server logs and the visit counts. Googlereceives correspondence: mail sent tohi@pavlokostenko.com is forwarded by Cloudflare Email Routing to a private Gmail mailbox. Anything you send me therefore passes through Cloudflare and comes to rest on Google infrastructure. Both publish their own terms:Cloudflare andGoogle.

Both operate inside and outside the European Economic Area and publish data processing terms covering accounts such as mine. Transfers out of the EEA rely on the safeguards those providers maintain, currently the European Commission's standard contractual clauses and, for their US entities, the EU-US Data Privacy Framework where applicable. A provider can change its mechanism at any time, so the linked documentation governs rather than my summary.

Nobody else: no advertising network, no data broker, no analytics vendor beyond the one named, no mailing list provider. A third party would receive data only under a binding legal obligation.

How long it is kept

Logs are retained by Cloudflare on its own schedule and I keep no copy. The criterion is not a number I chose: on the plan this site runs, log export is not available to me at all, so the period is the one Cloudflare's documentation sets for the services in use, and I have no means of extending it. Aggregate statistics are held by Cloudflare for the period its Web Analytics documentation states; what it holds are counts, not records about you. Correspondence is kept while there is a reason to keep it: routine mail is deleted within 24 months, while a message recording a legal position, such as a rights request and my answer, is held as long as needed to show it was handled properly.

Your rights

Depending on the circumstances and on the basis for the processing, Articles 15 to 22 GDPR give you the right to obtain access to the personal data I hold about you, to have it corrected or erased, to have its processing restricted, to receive data you provided in a portable form, and to object to processing based on legitimate interests. That last one is real here: if you object to my keeping our correspondence, I will delete it unless I can show compelling grounds to keep it, which will rarely be the case.

Send any request to hi@pavlokostenko.com. There are no accounts here, so email is the only route. I will answer within one month, and will say so if the complexity of the request requires the two month extension permitted by Article 12(3). One limit, stated plainly because Article 11 GDPR allows it: I cannot identify you from server logs, and will not collect more data for the sole purpose of answering requests about them. Correspondence is different, and requests about it will be fulfilled.

You have the right to lodge a complaint with my supervisory authority, theOffice of the Commissioner for Personal Data Protectionof Cyprus, and under Article 77 equally with the authority of the EU member state where you live or work. Telling me first is welcome but not required.

Children, decisions, profiling

This site is not directed to children: the subject matter is professional, nothing is marketed to anyone, and no data is knowingly collected from a person under 16. There is no automated decision-making and no profiling either. Every reader gets the same static pages, and no decision within the meaning of Article 22 GDPR is made about anyone.

Readers in the UK and California

For UK readers the same processing is governed by the UK GDPR and the Data Protection Act 2018, every right above applies on the same terms, and complaints go to the Information Commissioner's Office. No UK representative is appointed under Article 27 UK GDPR, which binds controllers offering goods or services in the UK or monitoring behavior there. Nothing is sold here, and counting page views without building a profile is not, as I read it, monitoring within the meaning of that provision. That is my assessment of the site as it stands, and it would be revisited if what the site does changed.

The CCPA, as amended by the CPRA, binds businesses crossing thresholds of revenue or data volume. On its current activities and scale this site does not cross them, so I do not consider myself a "business" under it. The substance matters more: I do not sell personal information, do not share it for cross-context behavioral advertising, and run no advertising. A "Do Not Sell or Share My Personal Information" request would change nothing here, because there is nothing to stop.

Changes, and the newsletter that does not exist yet

A newsletter is planned. Today there is no form, no list, no email provider, and no address stored anywhere for that purpose. On the day a field asking for an email appears, this page will already name the provider, the consent mechanism, how long the address is kept, and how to unsubscribe.

The same rule covers every other change: a new processor, a new category of data, or a new purpose appears here before it goes live, not after. There is no mailing list on which to notify anyone, so the date below is the notice. Until you have read such an update here, treat any page claiming to collect data for this site as not mine.

Last updated 2026-08-23.