Privacy Policy

Primary privacy page for the English-language site. German version: /datenschutz.

1. Controller

Ilyas El Hallaoui

Friedhofstraße 59, 65428 Rüsselsheim am Main, Germany

Email: ilyas.elhallaoui@gmail.com

2. What data I collect

When you browse this website, I do not intentionally collect personal data beyond what is technically necessary to serve the site and protect it.

If you sign up for the newsletter or request a free resource, I collect your email address. No name, phone number, postal address, or payment data is requested through these signup forms.

Technical request data may also be processed by the hosting and email infrastructure, such as IP address, timestamp, browser information, and log data needed to deliver the site, confirm signups, and secure the service.

3. Why I process your data

Your email address may be used to:

  • send you the free resource you requested
  • send you newsletter emails, new blog posts, and occasional updates about my content and work
  • document and verify your signup through double opt-in
  • handle unsubscribe requests and keep the mailing list compliant

I do not sell your personal data. I do not share it with unrelated third parties for their own advertising.

4. Legal basis

The legal basis for newsletter and free-resource email delivery is your consent under Article 6(1)(a) GDPR.

Signups should run through a double opt-in process. That means you submit your email address, receive a confirmation email, and must actively confirm before being added to the list.

You can withdraw your consent at any time, for example via the unsubscribe link in an email or by contacting me at ilyas.elhallaoui@gmail.com.

Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

5. Email provider: Brevo

For the newsletter, I use Brevo (Sendinblue SAS), a service provider based in Paris, France, to organize, manage, and analyze newsletter delivery.

The data submitted for newsletter signup, such as your email address and any optional first-name field used in a specific form, is stored on Brevo's servers in the EU. Brevo processes this data to operate the mailing list, manage double opt-in confirmations, and send the emails you requested or consented to receive.

I have concluded a Data Processing Agreement (DPA) with Brevo in accordance with Article 28 GDPR. This agreement is intended to ensure that Brevo processes personal data strictly on my instructions and in compliance with EU data protection law.

Brevo privacy policy: brevo.com/legal/privacypolicy/

Brevo's GDPR sign-up guidance emphasizes clear consent language, a privacy-policy link, and double opt-in as proof of consent: Brevo GDPR-compliant sign-up form guidance.

6. Hosting: Cloudflare Pages

This website is hosted on Cloudflare Pages by Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA.

When pages are requested, technical data such as IP address, browser information, request timestamps, and logs may be processed for delivery, stability, and security.

Cloudflare privacy policy: cloudflare.com/privacypolicy/

7. Retention period

Your email address is stored for as long as you remain subscribed. If you unsubscribe, your email address should be removed from the active mailing list without undue delay, subject to any limited retention needed to document compliance or handle disputes.

8. Your rights

Under the GDPR, you may have the right to:

  • access your personal data
  • request correction of inaccurate data
  • request deletion of your data
  • request restriction of processing
  • receive your data in a portable format where applicable
  • object to processing in certain cases
  • withdraw consent at any time where processing is based on consent

To exercise these rights, contact: ilyas.elhallaoui@gmail.com

9. Complaint to a supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority. If this site is operated from Hesse, Germany, the competent authority is the Hessian Commissioner for Data Protection and Freedom of Information: datenschutz.hessen.de.

10. Cookies and analytics

This site does not currently use analytics tools such as Google Analytics and does not intentionally use advertising or tracking cookies.

If embedded third-party forms or services are added later, this policy should be updated to match the live implementation.

11. Transparency note

GDPR transparency requires clear and plain language and informed consent. The European Commission states that consent must be freely given, informed, specific, explicit, and withdrawable: European Commission guidance on valid consent.

Last updated: April 17, 2026