Privacy

Last updated: 2026-04-02

This privacy notice explains how personal data may be processed when you visit SheafofThoughts (the “Site”). It is written for the current configuration of the Site as a static personal blog without comments, contact forms, newsletters, analytics, advertising, or social-media widgets.

1. Controller

The controller of the processing connected with this Site is the person who operates sheafofthoughts.org.

  • Controller: Davide D'Angelo
  • Contact email for privacy requests: sheafofthoughts.huddling989@passmail.com

2. Categories of personal data

When you browse the Site, the following categories of personal data may be processed:

  1. Technical connection and request data, such as IP address, date and time of the request, requested resource, browser and device metadata, referrer, and similar HTTP or server-log information.
  2. Security and operational data generated by the hosting infrastructure to deliver the Site, prevent abuse, and maintain service integrity.
  3. Data you voluntarily provide only if you contact the Site owner directly outside the Site, for example by sending an email to the published contact address.

The Site is intended not to collect comments, account data, form submissions, newsletter sign-ups, or first-party analytics data.

3. Purposes of processing

Personal data may be processed for the following purposes:

  • delivering the Site and its content;
  • ensuring security, integrity, abuse prevention, and troubleshooting;
  • maintaining the availability and technical operation of the Site;
  • replying to communications that you voluntarily send directly to the Site owner.

5. Cookies and similar technologies

The Site is intended to operate without first-party analytics cookies, profiling cookies, advertising cookies, or comment widgets.

To the best of the current configuration, the Site itself does not intentionally set non-essential tracking tools. However, the hosting provider may process technical information and may use cookies or similar technologies insofar as necessary for infrastructure delivery, security, and service operation.

If analytics, embeds, external interactive widgets, advertising, or similar tools are added later, this notice and the technical configuration should be reviewed again, and consent requirements may change.

6. Hosting provider and recipients

The Site is hosted through GitHub Pages / GitHub. According to GitHub’s documentation, when a GitHub Pages site is visited, the visitor’s IP address is logged and stored for security purposes.

Personal data may therefore be processed by:

  • GitHub / GitHub Pages, as hosting and infrastructure provider;
  • technical service providers involved in secure content delivery, network protection, and related infrastructure support where applicable;
  • public authorities or other recipients where disclosure is required by law.

7. International transfers

Because the Site uses GitHub infrastructure, personal data may be processed outside the European Economic Area, including in the United States.

GitHub states in its privacy documentation that it may transfer personal data from the EU/EEA, UK, and Switzerland outside those jurisdictions and that it relies on the transfer mechanisms and safeguards described in its own privacy documentation.

8. Retention

The Site owner does not intend to maintain a separate visitor database.

Personal data is kept only for as long as necessary for the purposes described above and, in practice, may be retained according to the operational policies of the hosting provider.

In particular:

  • technical and security log data are retained according to the hosting provider’s operational and security practices;
  • emails or other direct communications sent to the Site owner may be retained for as long as reasonably necessary to handle the correspondence and any related follow-up.

9. Whether provision of data is mandatory

Some technical processing is necessary in order to access the Site.

If you choose to contact the Site owner directly, you necessarily provide the data contained in your communication.

10. Your rights

Subject to the conditions and limits laid down by the GDPR, you may request:

  • access to your personal data;
  • rectification of inaccurate data;
  • erasure of data;
  • restriction of processing;
  • objection to processing based on legitimate interests;
  • data portability, where applicable.

Where processing is based on consent, you may also withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.

To exercise your rights in relation to processing controlled by the Site owner, use the contact details indicated in Section 1.

11. Complaint to a supervisory authority

You have the right to lodge a complaint with a competent supervisory authority. For individuals in Italy, this includes the Garante per la protezione dei dati personali.

12. Automated decision-making

The Site does not intentionally carry out automated decision-making or profiling producing legal or similarly significant effects on visitors.

13. Changes to this notice

This notice may be updated if the Site changes, especially if analytics, forms, comments, newsletters, embeds, or other third-party tools are added.