DEV MIZAN / PRIVACY
Privacy policy.
This explains exactly what this website records, why it is held, and how to have it removed. It describes what the system actually does, not what a template says it might.
Last updated 23 September 2026Who is responsible
Dev Mizan (“I”, “me”) operates devmizan.org and decides how the information described here is used. For anything in this policy, contact hellomizanur247@gmail.com.
What you send through the enquiry form
When you complete the consultation form, the following is stored: your name, business name, email address, website, industry, country, the service you are interested in, your type of business, the problem you describe, the tools you currently use, the work you would like automated, your budget range and your timeline.
This is used to assess whether I can help, to prepare for a conversation and to reply to you. It is never displayed publicly, sold, or added to a marketing list.
How your enquiry is assessed
Each enquiry is scored automatically against fixed rules — for example how clearly the problem is described, whether a budget and timeline are given, and how closely it matches the work I do. The reasoning behind every score is recorded and visible to me.
When an AI service is connected, the text of your enquiry may also be sent to it to produce a written summary and suggested questions. No automated step decides on its own to reject an enquiry or change its status. A person reads every enquiry and makes every decision.
Visit measurement
On the home page, the insight articles and the /start/ page, the site records a page path, a broad referral category such as Google, LinkedIn or Instagram, and a random identifier held in your browser’s session storage for the length of that visit.
That identifier is discarded when you close the tab. It is not a cookie, it is not linked to you, and it is not shared. There are no advertising pixels, no third-party analytics services and no cross-site tracking on this website. The purpose is only to count how many visits each piece of content produces.
If you send an enquiry, I may follow up about it. Every message is written or reviewed and explicitly approved by me before it is sent — nothing is sent automatically on a schedule without that approval.
Follow-up stops as soon as you reply, ask to stop, or use the unsubscribe link in any message. Unsubscribing records your email address specifically so that it is not contacted again.
Booking a consultation
A booking link is private to you and unguessable. Booking records the meeting time you choose. When a calendar service is connected, the meeting is also created in my business calendar so the time is reserved. Your enquiry details are used to prepare for the call.
Client accounts and the portal
If you are given access to the client portal, sign-in is operated by Supabase, a managed authentication provider. Your password is handled entirely by that provider — it is never stored in my database and never reaches my servers in readable form.
The portal shows only what has been deliberately shared with you: your own projects, and where enabled, approved proposals and meeting dates. Internal notes, scores, commercial figures and other clients’ information are never sent to the portal.
Where information is held
Enquiries, messages, meetings, proposals and project records are held in the application’s own database on hosting I control. Connected services receive only what their function requires: an AI provider receives enquiry text when analysis runs, an email provider receives the message being sent, a calendar provider receives meeting times, and an authentication provider holds portal credentials.
How long it is kept
Enquiries and related records are kept while there is a realistic prospect of working together, and afterwards for as long as needed for business and accounting records. Records for completed client work are kept for the period required by law. You can ask for earlier deletion at any time.
Your choices
You can ask for a copy of what is held about you, ask for it to be corrected, ask for it to be deleted, or ask that I stop contacting you. Email hellomizanur247@gmail.com and say what you would like.
Deletion is handled manually. You will get confirmation once it is done.
Security
Enquiry data is written using parameterised database queries, repeated submissions from the same address are limited, and administrative and client areas are authorised on the server for every request rather than trusting anything the browser sends. Contact details are kept out of browser storage and application request logs. No system is perfect, and no guarantee of absolute security can honestly be given.
Changes
If this policy changes, the date above changes with it. Material changes affecting people who have already sent an enquiry will be communicated directly.
This policy describes the system's real behaviour. Before publishing, have it checked against the data-protection law that applies where you and your clients are based, and add your trading name, registered address and, where required, a data-protection contact.