Privacy policy.
This policy covers the provael.com website. It is written to meet the EU GDPR and India’s Digital Personal Data Protection (DPDP) Act. Effective 26 July 2026.
Who we are
Provael, maintained by Sattyam Jain (India). Contact:[email protected].
What we collect
- Analytics. When analytics is enabled on a deployment we use cookieless, privacy-first analytics (Plausible, and optionally PostHog in memory-only mode). These do not use cookies or cross-site identifiers and do not build a profile of you. Because they are cookieless, we do not show a consent banner. This deployment ships no analytics script at all.
- Repository lookup. The site reads the project’s star count and latest release from GitHub’s public API. That request sends your IP address and browser user-agent to GitHub; no cookie is set and we store nothing from it.
- Email you send us. If you email us or book a call, we process the contact details and message you provide to respond.
- Booking. If you book an assessment call, our scheduling processor (Cal.com) processes the details you enter to arrange the meeting.
We do not collect special-category data, and we do not sell personal data.
Legal basis (GDPR)
- Legitimate interest for aggregate, cookieless analytics that cannot identify you.
- Steps to enter into / perform a contract for assessment enquiries and bookings.
Subprocessors
- Cloudflare - hosting and content delivery.
- GitHub (Microsoft, United States) - the public source repository, and the star / release lookup described above.
- Analytics (Plausible / PostHog) - not enabled on this deployment. If either is switched on, it is listed here with the endpoint it sends to.
- Cal.com - assessment-call scheduling (loaded only when you choose to book).
Retention
Analytics are aggregate and not tied to you. Emails and enquiry records are kept only as long as needed to respond and to meet legal obligations, then deleted.
Your rights
Under the GDPR and the DPDP Act you may request access, correction, erasure, restriction, portability, or object to processing, and you may withdraw consent. Email [email protected] and we will respond within the statutory timeframe. EU/EEA users may also complain to their supervisory authority.
International transfers
We are based in India and use processors in multiple regions. India is not currently the subject of an EU adequacy decision, so where personal data of EU or UK data subjects is transferred to India we rely on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum), supported by a transfer-impact assessment of the destination’s laws and safeguards. Such data is processed in line with both the GDPR and India’s Digital Personal Data Protection Act, 2023 (DPDP Act). Where a processor stores data within the EEA or UK, no such transfer arises.
Some processors are outside the EEA or UK. GitHub (Microsoft) is United States based, so the repository lookup described above involves a transfer to the US, made under the transfer mechanism that processor publishes for EU/UK data. Analytics endpoints are set per deployment, so the processing region is whichever the host named in the subprocessor list above implies - it is not guaranteed to be the EEA.
EU/UK representative
Provael is a small, non-EU open-source project. We will appoint a GDPR Article 27 representative in the EU (and a corresponding representative under the UK GDPR) if and when our processing of EU or UK personal data reaches a level that requires one. Until then, EU and UK data subjects may exercise their rights and raise any concern directly with us at [email protected], and may also complain to their local supervisory authority.
Changes
We will update this page as our processing changes and revise the effective date.
Provael is built and maintained by one person. That is a real dependency for anything you rely on, so it is stated here rather than left to the About page: the tool is Apache-2.0 and forkable, every result is reproducible from a committed recipe, and no evidence you already hold stops being valid if this project does. What a single maintainer cannot offer is a service level, and none is published for that reason.
These are standard terms provided in good faith and are not a substitute for legal advice.