Privacy & Legal Information
A transparent look at how data is securely routed, processed, and protected on this platform in strict compliance with Swiss and European standards.
Welcome to mukiraz.ch. This Privacy Policy explains how personal data is processed when you visit this website or use the cybersecurity services provided here.
As a cybersecurity professional based in Switzerland, data protection and confidentiality are embedded into the core of my operations. This policy applies to all visitors of mukiraz.ch and recipients of my services, including Shift-Left Security, Penetration Testing, Source Code Analysis, Cybersecurity Trainings, Cybersecurity Audits, and Secure Website Development.
This website and its underlying technical infrastructure have been intentionally designed with a minimalist and secure-by-default architecture to minimize data collection and fully respect your digital privacy.
1. Introduction & Scope
Welcome to mukiraz.ch. This Privacy Policy explains how personal data is processed when you visit this website or use the cybersecurity services provided here.
As a cybersecurity professional based in Switzerland, data protection and confidentiality are embedded into the core of my operations. This policy applies to all visitors of mukiraz.ch and recipients of my services, including Shift-Left Security, Penetration Testing, Source Code Analysis, Cybersecurity Trainings, Cybersecurity Audits, and Secure Website Development. This website and its underlying technical infrastructure have been intentionally designed with a minimalist and secure-by-default architecture to minimize data collection and fully respect your digital privacy.
2. Legal Framework & Jurisdictions
The processing of personal data on mukiraz.ch is governed by strict data protection laws, operating under two primary regulatory pillars depending on your geographical location:
- 2.1. Swiss Federal Act on Data Protection (nFADP): As the primary law governing this infrastructure, all data processing operations strictly adhere to the revised Swiss Data Protection Act, ensuring high-level privacy controls for all users.
- 2.2. EU General Data Protection Regulation (GDPR): For users accessing this platform or receiving services from within the European Economic Area (EEA), data is handled in full compliance with the statutory mandates of the GDPR (specifically under Article 6(1)(f) regarding legitimate interests for secure communications).
3. Data Controller
The data controller responsible for the collection, storage, and processing of personal data on this platform is:
Murat Ugur Kiraz Furkastrasse 18 3904, Naters Valais, Switzerland Official Contact Email: contact@mukiraz.ch Any inquiries, data access requests, or deletion notices regarding your personal information can be submitted directly to the controller via the secure email address listed above.
4. What Data I Collect & How I Process It
In alignment with the principle of data minimisation, this platform explicitly avoids keeping a persistent database of your communications. I process data strictly through two operational channels:
- 4.1. Secure Contact Form: When you use my contact form, I collect your Name, Work E-mail, Company / Product name, and the specific message detailing your challenge. This information is processed strictly in-memory during transmission and is instantly dispatched to my secure Swiss-based email infrastructure. No record of this message is ever stored on the web application server's database.
- 4.2. Server Log Files & Technical Metadata: To maintain the security, availability, and stability of my secure infrastructure, the server automatically collects temporary technical logs. This includes truncated/anonymized IP addresses, browser types, and access timestamps. These logs are stored strictly for operational security and intrusion detection, and are automatically purged after a short rotation period.
5. Purpose and Technical Flow of Data Processing
Any data submitted or collected via this platform is processed exclusively for the purpose of initiating a secure professional collaboration and evaluating technical requests.
The technical processing of your data follows a secure-by-design routing model: information entered into the contact form is captured temporarily in-memory by my web application hosted on Exoscale (Zürich, Switzerland) and is immediately routed via secure protocols to my encrypted ProtonMail infrastructure (contact@mukiraz.ch). No data from this form is persistently stored or written to a database on the web server. Your input is evaluated solely to facilitate professional communications regarding my core offerings—including Shift-Left Security, Penetration Testing, Source Code Analysis, Cybersecurity Trainings, Audits, and Secure Website Development. I do not engage in tracking, profiling, or commercial analytics. Your information is handled with military-grade discretion and is never shared, rented, or sold to third parties.
6. Data Storage & Hosting Infrastructure
All web application services, technical backend processes, and temporary system logs are hosted within a highly secure enterprise infrastructure provided by Exoscale, located physically in Zürich, Switzerland. Any communication initiated through the web form is directly transmitted over encrypted TLS channels into my secure, end-to-end encrypted mail server managed by Proton AG (Geneva, Switzerland). No data leaves Swiss jurisdiction during the automated hosting and transmission processes.
To ensure the absolute integrity and confidentiality of the transmission environment, the underlying virtual infrastructure has been programmatically hardened using Automated Ansible Configuration. This deployment rigorously enforces the CIS (Center for Internet Security) Benchmarks configuration standards, systematically reducing the server's attack surface through strict access controls, kernel hardening, and cryptographic policy enforcement before any application code is executed.
7. Data Retention & Secure Deletion Policy
I adhere to strict data retention limits to avoid unnecessary data accumulation:
- Server Infrastructure Logs: Temporary technical metadata and network logs collected for firewall protection and intrusion detection are retained for a maximum period of 30 days, after which they are automatically and permanently overwritten by the server configuration.
- Non-Contractual Inquiries: Contact form messages that do not mature into a formal business engagement are permanently deleted from my encrypted ProtonMail archive within 6 months.
- Contractual Correspondence: In the event of a successful professional collaboration, business-related correspondence and scope definitions are archived by me for 10 years, strictly in accordance with statutory Swiss commercial retention obligations (Art. 958f Swiss Code of Obligations).
8. Use of Cookies & Analytics
This website uses cookies to guarantee network security, deliver a seamless user experience, and analyze platform performance. Cookies are categorized as follows:
- Strictly Necessary Cookies (Django Infrastructure): I use built-in Django security features including csrftoken (to protect form submissions against Cross-Site Request Forgery) and sessionid (to securely identify user connections). These are essential for the operation of the site and do not track personal behavior.
- Performance & Analytics Cookies (Google Analytics & Heatmaps): With your explicit consent, I utilize Google Analytics and behavior-mapping (heatmap) tools to optimize SEO and improve content engagement. These scripts only activate if you click 'Accept' on the consent banner. Your IP address is anonymized before processing, and this data is never linked to your personal identity.
9. Your Rights
Under both the Swiss nFADP and EU GDPR, you possess specific legal rights regarding the personal data processed on this platform. You may exercise these rights at any time, completely free of charge:
- Right to Access & Portability: You have the right to request a copy of any technical metadata or communication details I hold about you in a structured, commonly used format.
- Right to Rectification: You can request the immediate correction of inaccurate or incomplete personal information.
- Right to Deletion (Right to Be Forgotten): You may demand that I permanently erase your data from my temporary server logs or secure ProtonMail archive, provided it does not conflict with statutory Swiss commercial storage obligations.
- Right to Withdraw Consent: Since performance and analytics cookies (Google Analytics & Heatmaps) are entirely based on your active choice, you have the right to withdraw your consent at any time via the cookie settings.
10. Contact for Data Protection Queries
If you wish to exercise your rights, submit a data deletion request, or ask any technical questions regarding how your privacy is protected on this infrastructure, you can reach out directly to me:
Murat Ugur Kiraz Data Protection & Security Operations Email: contact@mukiraz.ch To maintain the absolute confidentiality of our communication, I strongly encourage you to send your data protection requests using encrypted channels, such as my end-to-end encrypted form, or via the secure OpenPGP, Signal, or Threema protocols listed on my contact page.
Questions about privacy?
You can contact me directly at any time.