Privacy Policy AWS-hosted
Effective date: 13 October 2025 · Last updated: 13 October 2025
1. Introduction
This policy explains how Ahmed Eisa collects, uses, and safeguards information when you visit ah-eisa.com (the "Site"). The Site is a static website hosted on Amazon Web Services (AWS) S3 and distributed through Amazon CloudFront. No personal data is collected beyond what you voluntarily provide via the contact form or what is technically necessary for security and analytics.
2. What I collect & why
| Source | Data | Purpose & legal basis |
|---|---|---|
| Contact form | Name, email, message | Reply to your enquiry (consent - GDPR Art. 6(1)(a)) |
| AWS CloudFront logs | IP, browser, URI, timestamp | Security & error debugging (legitimate interest - GDPR Art. 6(1)(f)) |
| Cloudflare Web Analytics | Page views, device type (no cookies or cross-site tracking) | Aggregated usage stats (legitimate interest) |
3. AWS data handling
- Hosting: Files stored in an AWS S3 bucket with AES-256 encryption and block-public-access enabled. CloudFront serves all pages over TLS 1.3.
- Logs: CloudFront access logs kept 30 days, encrypted at rest, then auto-deleted. Contain only standard HTTP fields (IP, user-agent, URI).
- Region: Logs stored in Europe (London) to reduce data-transfer impact for EU visitors.
- Sub-processors: Amazon Web Services EMEA SARL (Luxembourg) under GDPR's shared-responsibility model (details).
4. Cookies & trackers
No advertising or profiling cookies are used. Cloudflare Web Analytics is cookie-less and does not collect unique identifiers. CloudFront uses only standard HTTP headers. No third-party pixels or tracking scripts are embedded on this Site.
5. Your rights (GDPR & UAE PDPL)
You may request access, rectification, erasure, restriction, or portability of your personal data, or object to processing. Contact [email protected] - responses are provided within 30 days.
6. Data retention
- Contact-form emails - 12 months (unless a business relationship is established)
- CloudFront logs - 30 days (auto-purged)
- Cloudflare analytics - aggregated after 26 months
7. Security measures
- HTTPS everywhere (TLS 1.3, HSTS, OCSP stapling)
- S3 bucket policies deny all non-CloudFront requests
- IAM least-privilege access (one admin identity only)
- Regular AWS Security Hub reviews
8. Third-party services
Besides AWS and Cloudflare, no other providers receive data from this Site. No embedded trackers, social-media pixels, or external analytics scripts are present.
9. Changes to this policy
Updates will appear on this page with a revised "Last updated" date. Material changes will be summarised at the top for 30 days.
10. Contact
Data controller: Ahmed Eisa, Abu Dhabi, UAE
[email protected] ·
LinkedIn
This document is for transparency only and does not constitute legal advice.