Personal Data Protection Information

This document describes possible approaches to handling user information when visiting this site, using its functions and sending messages through it. It covers what may be processed, the reasons for it, how long information may be held and what control users have. This is an independent project, and this document should not be taken as the official policy of the Jaya9 operator, which publishes its own.

Privacy and Data Handling Principles

Three principles underlie everything below.

PrincipleIn practice
TransparencyThe reasons for processing are stated rather than implied
Limited useInformation serves the purpose it was collected for
SecurityReasonable measures protect what is held
MinimisationWhat is not needed is not collected
No salePersonal information is not sold to anyone

None of that amounts to a promise of perfect security, because no operator of any website can honestly offer one.

Application of This Privacy Policy

Three categories of person may fall within this document.

  • Visitors who read pages and do nothing else
  • Users of account-related functions, where such functions apply
  • Anyone sending a message through a contact route

What each generates differs sharply. A reader opening a few pages produces technical data and nothing else. A person writing in provides whatever they chose to include. Where an account with a platform is involved, that platform applies its own policy to it, and this document does not replace it.

Types of Information We May Process

Categories below may be involved depending on what a person actually does. No reader profile is constructed from any of it.

Registration and Account Information

Where a registration or profile function exists, details supplied at that point may include a username or name, an email address, a phone number, a date of birth and a country of residence. The form presented at the time determines what is actually requested, and anything absent from it is not required.

Verification and Identity-Related Data

Confirming identity, age or ownership of a payment method may involve documents or supporting confirmation. Material of that sensitivity belongs only inside a secure interface built for it, never in an ordinary message, and any request for it through chat, email or a form should be treated as an attempt at fraud.

Payment and Transaction Records

Where payment functions apply, records may cover an amount, a currency, a date, an operation status, the method used and a transaction identifier. That is different from holding a full card number or the credentials of a payment account, which remain with the payment provider.

Information Gathered Automatically

Loading a website transmits technical detail without anybody typing it:

  • An IP address, used in general form rather than to identify a person
  • Device type and basic characteristics
  • Browser and operating system
  • Language preference
  • Pages opened and the time of a visit
  • The source that referred you

Approximate location inferred from an IP address describes a broad area. Knowing a visit came from Bangladesh is a different thing from knowing where somebody physically is, and technical data of this type does not establish the latter.

Reasons for Processing Personal Data

PurposeWhat it involves
Site operationMaking pages and functions work
User supportHandling and answering messages
SecurityDetecting misuse, fraud and abuse
Preventing violationsIdentifying activity that breaks the rules
ImprovementFixing faults and refining how pages behave

Each of those serves an operational need. None involves building advertising profiles or passing personal information onward for somebody else’s marketing.

Cookies and Similar Technologies

A cookie is a small stored file that lets a browser carry something from one page to the next. Three roles apply here. Session cookies hold a visit together and support any sign-in function, preference cookies remember settings such as language, and analytics cookies measure how pages perform and where problems appear.

Where analytics are used, an external provider handles the measurement under its own policy and terms. No specific provider is named here, since arrangements change and naming one that has been replaced would mislead rather than inform.

User Control Over Cookies

Control belongs to your browser, which allows stored cookies to be inspected, deleted and restricted by site. Private browsing usually discards them when a window closes, and settings apply per browser and per device rather than across all of them.

What changes if you block them:

  • Any sign-in or session function may behave inconsistently
  • Saved preferences reset at every visit
  • Analytics measurement stops, which affects nothing you experience

Blocking analytics costs a reader nothing. Blocking session cookies costs functionality, which is the trade-off worth understanding before changing everything at once.

Sharing Data With External Providers

Running a website involves outside companies for hosting, technical support, analytics and security. Where information reaches them, it should be limited to what each specific task requires.

No unconfirmed company is named here. What can be said is that any such provider processes what it receives under its own terms, outside this site’s control, and that rights you hold in relation to that information operate against them alongside us.

Legal Requests and Protection of Rights

Information may be disclosed where an authorised body makes a lawful request, where disclosure protects users, where fraud is under investigation, or where the rights and security of the site require it.

No absolute promise is offered that information will never reach authorities. Such a promise could not be kept by anyone, and offering it would be dishonest rather than reassuring.

Data Storage and Security Practices

Retention varies with the nature of the information and the purpose it serves. Technical and error logs are held for the period needed to investigate faults and then cycle out. Correspondence is kept while a matter is being handled and afterwards only where a reason exists.

Naming a period would mean inventing one, because it depends entirely on the systems holding the data.

Protection combines standard measures. An encrypted connection for traffic, access restricted to those who need it, updated software so known weaknesses are closed, and monitoring for unusual behaviour. Claiming absolute security would be untrue, so it is not claimed.

Managing Your Privacy Rights

Subject to circumstances and applicable requirements, several rights may be available, including access to information held, correction of anything inaccurate, deletion, restriction of processing and withdrawal of consent previously given.

These rights are not uniform in every situation, so a request is assessed against the circumstances rather than granted automatically.

Reviewing and Correcting Personal Details

Where a detail can be edited directly through available settings, that is the fastest route. Where it cannot, a request through the contact channel is the alternative, and establishing that a request comes from the right person forms part of handling it.

Requesting Personal Data Removal

Deletion can be requested. Some records may still be retained where security, fraud prevention, an unresolved dispute or a continuing obligation requires it, which means immediate erasure of everything is not something any site can honestly undertake.

Adjusting Consent Preferences

Where consent supported a particular use, such as optional messages or non-essential cookies, it can be withdrawn. Withdrawal operates from that point forward and does not undo processing already carried out on a lawful basis.

Requests go through the contact channel. Include the subject and a clear statement of what you want, and never include passwords, codes, documents or payment details, since none of it is needed and nobody legitimate will ask for it.