Policy
Privacy Policy
What this site records when you read it, why it records it, how long it keeps it, and how to have it removed.
GetTechByte is a blog. You do not need an account to read it, there is nothing to sign up for, and it asks you for nothing. What it does do is keep a log of the requests it answers, so that its author can see which writing is being read and can turn away the traffic that is trying to break in. Nothing on these pages is loaded from anybody else’s server, and nothing about your visit is sent to one. There is no advertising on this site, so nothing here is chosen for you, sold about you, or shared with an ad network.
Who is responsible
This site is run by GetTechByte, from India. For anything in this policy — a question, a request to see what is held about you, or a complaint — write to info@gettechbyte.com.
In the language of the GDPR, that makes GetTechByte the data controller for this site. Under India’s Digital Personal Data Protection Act 2023 the equivalent term is data fiduciary, and the address above is where a grievance goes.
What is recorded when you read a page
The site keeps its own request log. It runs on this server, it involves no third party, and it sets no cookie — which is the entire reason it exists rather than a hosted analytics product. One row is written per page you open:
| What | Why |
|---|---|
The address of the page, and anything after the ? |
To count which posts are read. This includes what you typed into the site’s search box, since that is carried in the address. |
| The page you arrived from, if your browser sent one | To tell a search result from a shared link. |
| Your IP address | Used only to identify and block abusive or scanning traffic. |
| Your browser’s user-agent string, and the browser, operating system and device type read out of it | To know whether the site needs to work better on phones, and to tell a person apart from a crawler. |
| The HTTP method and the status the server answered with | To find broken links, and to see what an attempted break-in asked for. |
| A one-way hash of your IP address and user-agent | Used only to recognize a visit without retaining the original address. It cannot be used to recover your IP address and is not shared with anyone. |
No name, no email address, and no cookie is involved in any of that. The log cannot tell the author who you are; it can tell them that somebody using Firefox on Windows read three posts on Tuesday.
A few hundred bytes of JavaScript report the page load, because most pages are served straight off disk without the application ever running. It sends the page address, the query and the referrer, and nothing else. With JavaScript off, the page still works and the visit is simply not counted.
You can refuse this. Pressing Reject on the cookie notice stops your visits being counted — the script checks before it sends anything, and nothing else records the visit in its place. None of the above is then written about you at all. to change that either way; the link is in the footer of every page.
What is never collected
- No accounts, and no sign-up. There is nothing here to register for.
- No newsletter and no mailing list. Your email address is never asked for.
- No comment form and no contact form, so nothing you type is submitted anywhere.
- No payments, so no card or billing details.
- No advertising, so no ad network, no ad profile and no remarketing.
- Nothing is ever sold, rented or handed to a data broker.
Third parties
There are none. No analytics service, no advertising network, no comment platform, no font or script loaded from somebody else’s server, and no tag manager. Every file these pages ask your browser for comes from this domain. That is why the cookie notice asks you for nothing and offers no switches: there is genuinely nothing here you could refuse. It tells you what is set and gets out of the way. If that ever changes, it becomes a real choice with a real Reject button, and you will be asked again rather than held to having dismissed a notice.
Video embeds
Some posts embed a YouTube video. Those are loaded from
youtube-nocookie.com, Google’s privacy-enhanced player, which sets nothing until
you press play. Scrolling past a video does not tell YouTube anything about you; playing one does,
under Google’s policy rather than this one.
Why this is allowed
Under the GDPR and the UK GDPR, everything above needs a lawful basis. These are the ones relied on here:
- Legitimate interests for the site’s own request log. Knowing which posts are read is how the author decides what to write next, and refusing addresses that are probing for an unpatched admin panel is how the site stays up. The data is minimal, it is pseudonymous, it is not shared, and none of it is used to make a decision about any individual — which is the balance that makes this basis available.
- Legitimate interests for the session and anti-forgery cookies, which exist to stop a form on this site being submitted from somewhere else. These are exempt from the consent requirement because the site cannot be delivered securely without them.
Under India’s DPDP Act the framing differs — consent, or a legitimate use — but the practical answer is the same: nothing about you is sent to anyone, so there is nothing to consent to.
How long it is kept
| Record | Kept for |
|---|---|
| Ordinary page visits | 400 days |
| Crawler and bot requests | 60 days |
| Requests flagged as an attempted intrusion | 90 days |
A scheduled job runs every night. Nothing about a visit survives past 400 days.
Where your data goes
Nowhere. What the site records stays in its own database, on the server that answers these pages, and is deleted on the schedule above. There is no third-party analytics account, no ad network and no export.
Your rights
If you are in the EU or the UK, the GDPR gives you the right to ask what is held about you, to have it corrected, to have it deleted, to restrict or object to how it is used, to receive it in a portable form, and to withdraw consent at any time without that affecting what was done before you withdrew it. You can also complain to your national supervisory authority.
If you are in India, the DPDP Act 2023 gives you the right to access a summary of your data and what has been done with it, to have it corrected or erased, to nominate someone to exercise these rights on your behalf, and to have a grievance answered. Where a grievance is not resolved, the Data Protection Board of India is the next step.
One honest limitation, stated rather than buried. The log holds no name, no email address and no cookie. For the first 30 days your IP address is in it, so if you supply that address and a rough time, your rows can be found, shown to you or deleted. After 30 days the address is gone and what remains cannot be tied back to you by anyone, including the author — so from that point a request to find “your” rows cannot be answered at all. Under the GDPR this is the Article 11 position: where a controller genuinely cannot identify you, it is not required to collect more data in order to become able to. What can always be done, immediately and without asking anyone, is to stop the collection — which is what Reject on the cookie notice does.
If you are in California, there is nothing here to opt out of: the CCPA’s “sale” and “sharing” both turn on personal information moving for advertising, and this site carries none.
Children
This site is written for IT professionals and isn’t directed at children. We don’t knowingly collect data from children.
Security
The site is served over HTTPS, its cookies are marked HttpOnly and SameSite, it sends a Content Security Policy that stops injected script from posting anywhere off this domain, and the admin panel is rate limited against password guessing. No site can promise it will never be broken into; what this one can promise is that there is very little in it worth stealing.
Changes
When what the site collects changes, this page changes with it and the date at the top moves. A change to the cookie categories also resets the banner, so you will be asked again rather than held to an answer you gave about something else.
Contact
GetTechByte — info@gettechbyte.com. Questions about a post are welcome at the same address.