Data controller
Davide D’IgnazioEmail: dignazio90@gmail.com
This email address may be used for privacy-related requests and to exercise data protection rights.
Privacy
This policy explains how personal data is handled by the DavDev portfolio in the configuration intended for its first public release.
Last updated: 10 August 2026
This email address may be used for privacy-related requests and to exercise data protection rights.
The website is designed to collect as little data as possible. It does not provide:
Normal communication between a browser and a server may still involve technical information such as:
This technical data may appear in infrastructure logs and is used only to operate the website and protect its security and integrity. It is not used to build visitor profiles.
The legal basis is the controller’s legitimate interest in maintaining the availability and security of the service under Article 6(1)(f) GDPR.
In its current configuration, the Laravel application itself:
The public Laravel application is stateless: normal public pages do not create Laravel session cookies, CSRF cookies, server-side session files or an application visitor database.
The homepage loader uses only browser-native navigation-type and referrer signals and does not store data in the browser.
Laravel Cloud routes incoming traffic through a managed edge network backed by Cloudflare. Cloudflare may set strictly necessary security cookies, including __cf_bm, to detect and manage automated or malicious traffic and protect the service.
These infrastructure security cookies are not set by the Laravel application and are not used by DavDev for advertising, analytics or profiling.
No consent banner is displayed because, in its current configuration, the site does not use non-essential cookies or tracking technologies requiring consent. This position will be reassessed if future functionality changes.
The website is hosted on Laravel Cloud, a managed Laravel hosting and infrastructure platform, with application compute in EU Central (Frankfurt / eu-central-1), Germany, European Union.
Laravel Cloud runs application compute on AWS infrastructure and routes incoming HTTP traffic through its Cloudflare-backed edge network before requests reach the application.
Laravel Cloud automatically generates access logs for incoming application requests. These logs may contain the IP address, request method and path, user agent, response status, country, request duration, bytes sent and related technical metadata.
The current release does not use:
Under the current Laravel Cloud Starter plan, logs and metrics are retained for up to one day and may be deleted earlier if the plan’s storage quota is reached.
The website does not contain a contact form. The contact action opens the visitor’s configured email client through a standard mailto:dignazio90@gmail.com link.
The portfolio server does not receive or store the message. Simply visiting the portfolio does not contact Google.
If a visitor voluntarily emails dignazio90@gmail.com, the information supplied in the communication may be processed, including their email address, name, message content and any attachments. Email is handled through Gmail, a service provided by Google.
The applicable legal bases are:
Emails are retained for the time needed to handle the request and any follow-up. Longer periods may apply if a professional relationship develops, or where legal obligations or the establishment, exercise or defence of legal claims require it. No fixed period is imposed independently of those circumstances.
Links to GitHub, LinkedIn and any public repositories currently exposed are ordinary external hyperlinks.
Viewing the portfolio does not automatically contact those services. Interaction with the third party and the related transfer of data begin only when the visitor chooses to follow the external link.
Laravel Cloud application logs and access logs follow the Starter plan retention described above: up to one day, with possible earlier deletion if the plan’s storage quota is reached.
The website does not retain visitor profiles, browsing histories, user databases or persistent visitor identifiers.
Email communications follow the separate retention criteria described in the email contact section.
Technical data needed to operate the website may be processed by Laravel Cloud as the managed platform provider. Application compute is located in EU Central (Frankfurt), while incoming HTTP traffic may pass through Laravel Cloud’s globally distributed Cloudflare-backed edge network before reaching the application.
Personal data is not sold or disclosed for advertising, marketing or profiling purposes.
If a visitor voluntarily contacts the controller through Gmail, Google’s infrastructure and the applicable data processing arrangements may apply.
Where provided by the GDPR, data subjects may exercise the following rights:
Requests may be sent to dignazio90@gmail.com.
Data subjects also have the right to lodge a complaint with the competent supervisory authority, including the Italian Garante per la protezione dei dati personali, under Article 77 GDPR.
The website does not carry out automated decision-making.
This policy may be updated if the website’s functionality, infrastructure or processing activities change. The last-updated date shown on the page identifies the version currently in effect.