Privacy policy — Pal-Think
How Pal-Think collects, uses and protects your data when you use its website and digital services.
Scope of this document
- This document describes what this site actually does with data: what is collected, where it is stored, who can reach it, and which of your requests we can carry out — and which we cannot yet. It was written from the code itself rather than from a template, and we update it whenever the system changes.
- We take the principles of the GDPR as our design reference — collecting less, naming the purpose, and the user's right to their own data — but we do not claim documented compliance with it: there is no formally appointed data protection officer, no approved processing register, and no self-service interface that carries out your requests automatically. The rights section below sets out the real mechanism behind each right.
- We do not sell your data or share it for commercial purposes
- The connection to this site is encrypted over HTTPS
- Access to form data is limited to administrator accounts
- No tracking script loads before you have explicitly agreed
What we collect
- What you type into the site's forms: your name and email address and, depending on the form, possibly your phone number, your organisation, the text of your message and a link to your CV if you added one.
- Your IP address, with every message: your IP address and browser details are stored attached to the message you sent — neither anonymised nor aggregated. Their purpose is to deal with automated messages and abuse. We state this plainly because an earlier version of this page described browsing data as “aggregated and anonymised”, which does not describe this case.
- Preferences saved in your browser: these stay on your device and never reach us — see the table below.
- Server logs: the server logs incoming requests as any web service does, for operational and diagnostic purposes.
How we use it
- We use what you send to answer your enquiry, process your application or register you for an event, and we send the newsletter only to those who confirmed their subscription through the confirmation email. We use your data for no other purpose, and we pass it to no one for marketing.
Third parties your data reaches
- Opening any page means your browser requests files from the servers listed below, and each request reveals your IP address and the page you came from to whoever runs that server. This is the list as it stands today:
- Images from images.unsplash.com: some publications carry cover images hosted at Unsplash rather than uploaded to our own servers, so your IP address reaches them when those pages are displayed. We are gradually replacing these with locally uploaded images.
- Typefaces: the site used to load the Cairo typeface from Google's servers on every page, so your IP address reached them on every visit. The font is now served directly from our own servers, and there is no longer any connection to an external font server.
Local storage and cookies
- The site sets no tracking cookies. The items below are saved in your browser's local storage; they stay on your device, are never sent to our servers, and you can clear all of them from your browser settings.
- Signing in to the admin panel uses a session cookie — it has nothing to do with browsing the public site and is never set for visitors.
- pt_cookie_ok — Remembers your choice on the cookie notice — Until you clear it from your browser
- pt_theme — Stores your dark/light mode preference — Until you clear it from your browser
- pt_bookmarks — The publications you saved to read later — Until you clear it from your browser
- pt_search_history — Your most recent searches within the site — Until you clear it from your browser
- pt_font_pct — Stores your font-size preference — Until you clear it from your browser
- pt_cms_cache:* — A local copy of the last content that loaded successfully, shown when the server cannot be reached — Until you clear it from your browser
How long we keep it
- There is at present no automatic deletion after a set period: messages sent through the forms remain in our database until we delete them, either at your request or in a periodic review. We say so plainly rather than claim an automated retention policy that does not exist. Preferences saved in your browser stay on your device until you clear them yourself.
Your rights, and how they are actually exercised
- Each right below states its mechanism outright. Most are carried out by hand over email rather than automatically through the site, and we aim to respond within thirty days.
- Right of access — Write to us and we will send you whatever is held under your name or email in the site's forms and newsletter lists. Carried out by hand — there is no self-service portal.
- Right to rectification — Tell us which detail is wrong and we will correct it. Carried out by hand from the admin panel.
- Right to erasure — Ask us to delete your messages or your subscription and we will delete them. Unsubscribing from the newsletter is immediate, through the link at the foot of every message. Deleting contact messages, however, is done by hand against the database — no tool in the admin panel deletes them, so it can take days.
- Right to a copy — We will send you what we hold as a text file. Prepared by hand on request — there is no export button.
Security
- The connection to this site is encrypted over HTTPS, administrator passwords are stored hashed rather than in plain text, and access to form data is limited to administrator accounts whose actions are written to an audit log. We claim no external security certification and no independent penetration test.
Contact us
- We have no formally appointed data protection officer; privacy requests reach the site team through these two channels: