Your information
A small amount of data.
A specific purpose.
You can read this personal portfolio without an account. Optional analytics stays off unless you accept it. CV requests are reviewed personally.
Who to contact
I’m Aranda Tuduwage, responsible for this portfolio. For privacy questions, access, correction, deletion or an objection to processing, email aranda.tuduwage@gmail.com. This portfolio is separate from GradPlan and does not create a GradPlan account.
Requesting my CV
When the service is enabled, I use your email address to send a verification code, review your request and email an approved copy of my CV. You may optionally supply your name, company and reason. Email verification confirms control of that mailbox; it does not prove your identity, employer or the accuracy of your description. These details are not used for marketing.
The request database stores encrypted contact details and the timestamps and states needed for this process. A verified request generates an email notification to me. I sign in to an owner-only admin on my computer to review it. Verification alone never releases the CV. Approval pins a particular recipient and document version; the PDF is then sent as an attachment. My CV stays on my computer until I approve sending it. Provider acceptance does not guarantee inbox delivery, and an emailed document can be copied or forwarded.
I process request information to respond to your enquiry and protect the service, based on my legitimate interests in professional correspondence and security. If delivery is unavailable, the form says so and you can contact me directly. Requests awaiting review expire after seven days; I aim to get back to you as soon as possible, though response times can vary.
Security and essential processing
The service temporarily processes source network addresses for abuse prevention. The application stores secret-protected email/source fingerprints and counters, not raw IP addresses. These identifiers can still be personal data. Codes are protected in storage, expire after ten minutes, allow five attempts and have a minimum sixty-second resend interval. No public download session is issued.
Cloudflare necessarily processes network data when serving the site. Application request logging is disabled by default. Codes, private keys, email bodies and the CV are excluded from application logs and public assets. Security processing is separate from analytics consent.
Optional analytics
When enabled and with your affirmative consent, this site records a small set of page views, selected-project clicks, GradPlan screenshot opens, Approach views and CV-request button clicks. A random first-party identifier lasts thirty minutes to deduplicate interactions. These are pseudonymous consenting sessions, not exact unique people. Marked controlled-test sessions are shown separately and excluded from visitor activity figures.
Events contain an allowlisted page or item and a broad source category. They exclude form text, requester email, precise location, full URLs, query strings, fragments, raw IP addresses and private routes. Browsing activity is not joined to CV request records. There is no advertising, fingerprinting, session replay, company identification or email open/click tracking. Bot and owner filtering is imperfect.
You can reject or withdraw analytics in Cookie settings at any time. Withdrawal stops collection and clears the optional identifier. Essential functions continue. Existing aggregate counts cannot identify which count was yours.
Retention
Unused verification codes expire after ten minutes; unverified request details are removed after twenty-four hours. Pending review expires after seven days. Identifying request records, decisions and delivery attempts are removed ninety days after closure. Unresolved delivery operations stop retrying after twenty-three hours and enter that retention period without claiming delivery.
Short-lived analytics identifiers and deduplication events expire after thirty minutes; aggregated counts are retained for at most 365 days. Security counters expire with their hourly or daily window; minimised general security/audit records are retained for up to fourteen days. Non-identifying email budget totals cover the recent monthly allowance. Automatic cleanup runs in bounded batches every five minutes when the service is active; outages or a backlog can delay deletion, but expired material cannot authorise access.
Application deletion does not immediately remove provider backups or copies in mailboxes. Cloudflare D1 Free provides a recovery history of up to seven days. Resend’s Free plan lists thirty-day provider data retention. My notification mailbox and a recipient’s mailbox have their own retention, and correspondence may remain there until deleted. Contact me to request deletion of related correspondence where possible.
Services and international processing
Cloudflare Workers and D1 provide hosting, the request database and consenting analytics. Resend processes email addresses, verification messages, my owner notifications and, only after approval, the CV attachment. Google’s Gmail receives my owner notifications. Squarespace remains the domain registrar. Their infrastructure and subprocessors may process data outside the UK; I do not promise UK-only storage.
Cloudflare and Resend publish data processing terms with international-transfer safeguards, including contractual clauses where applicable. See Cloudflare’s data processing terms and Resend’s data processing terms. These descriptions do not constitute a legal or security certification.
Your choices and other features
You can browse without optional analytics and leave the CV form at any point. Depending on the circumstances, you may have rights to access, correct, erase, restrict or object to processing and to withdraw consent. Contact me above; you may also raise a concern with the UK Information Commissioner’s Office.
The illustrative RICE calculator runs in your browser and does not transmit its inputs. The gallery shows historical screenshots with demo data. External links and direct email use the other service’s own privacy practices.