Legal
Privacy Policy
This is a personal website. It does not track you, advertise to you, or share your data with third parties.
Who we are
This website is operated by Santosh Pandit as a personal website. The data controller is Santosh Pandit, London, United Kingdom. Contact: contact@santoshpandit.com.
This policy applies to the website santoshpandit.com and any subdomains. It does not cover third-party websites linked from this site.
What data we collect
This website collects the minimum data necessary to serve web pages. Specifically:
- Server access logs. Like all web servers, the server that hosts this site records standard access log entries: IP address, date and time, URL requested, HTTP status code, browser and operating system identifier (user agent). These logs are retained for a maximum of 30 days for security monitoring purposes and are then deleted automatically.
- Email enquiries. If you contact us by email, we retain your email address and the content of your message for the purposes of responding to your enquiry. We do not add you to any mailing list. We do not share your email with third parties.
We do not use analytics platforms (Google Analytics, Plausible, Fathom or similar). We do not use advertising networks. We do not use social media tracking pixels. We do not deploy any third-party JavaScript beyond the fonts served from this server.
Cookies
This website does not set cookies. Please see our Cookies Policy for full details.
Legal basis for processing
Under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, we process personal data on the following legal bases:
- Legitimate interests — server access logs, for security monitoring and server maintenance.
- Performance of a contract / taking steps to enter a contract — email enquiry data, where the enquiry relates to a professional engagement.
- Consent — where you have voluntarily contacted us with personal information and there is no other applicable basis.
Your rights
Under the UK GDPR, you have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate personal data.
- Request erasure of your personal data (the right to be forgotten), where applicable.
- Object to processing based on legitimate interests.
- Data portability, where applicable.
- Lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
To exercise any of these rights, contact us at contact@santoshpandit.com.
Data retention
Server access logs: 30 days. Email enquiry data: retained for as long as necessary to respond to the enquiry and manage any subsequent engagement, and deleted when no longer required. We do not retain personal data for longer than necessary for the stated purpose.
Third-party services
This website is served from infrastructure operated under the ZTZT.dev zero-trust architecture. No third-party hosting providers, content delivery networks or cloud platforms with their own data processing terms are involved in serving this site.
Links to third-party websites (LinkedIn, external publications, partner organisations) are provided for reference. We have no control over and accept no responsibility for the privacy practices of those websites.
Changes to this policy
We may update this policy from time to time. The current version is always available at this URL. Material changes will be noted with an updated date below.
Last updated
April 2026.