Privacy Policy
Last updated: 3 May 2026
Introduction
SarmaLinux ("I", "me", or "my") is a personal technology studio operated by Sarma, based in the United Kingdom. This Privacy Policy explains how I collect, use, disclose, and safeguard your information when you visit sarmalinux.com or use my services. It applies alongside the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. If you do not agree with the terms of this policy, please do not use the site.
Data controller: Sarma
Contact: legal@sarmalinux.com
Information I Collect
Personal data you provide
When you use the contact form, the chatbot, or otherwise engage with my services, I may collect:
- Name
- Email address
- Company name (optional)
- Project details and messages you submit
- Budget and timeline information (optional, chatbot only)
Automatically collected data
When you visit the site, certain technical information is collected automatically:
- Browser type and version
- Operating system
- IP address (anonymised before storage by Vercel Analytics)
- Pages visited and approximate time on page
- Referring website
How I Use Your Information
- To respond to enquiries and provide requested services
- To follow up on project conversations initiated through the contact form or chatbot
- To send transactional emails related to your enquiry (via Resend)
- To understand how the site is used and improve it (via anonymised Vercel Analytics)
- To comply with legal obligations
The legal basis for processing personal data you submit voluntarily is legitimate interest (responding to your enquiry) or, where you have explicitly opted in, consent. Anonymised analytics data is processed on the basis of legitimate interest in improving the site.
The Chatbot
The site includes a chatbot at /api/chat. Conversations are routed to large language model providers, primarily Groq, with OpenRouter as a fallback, to generate responses. Messages you send are transmitted to these providers as part of the inference request and are subject to their data-processing terms. I do not store full conversation transcripts unless the chatbot identifies a genuine project enquiry (name, email, and a project summary are all present), at which point the lead and transcript are saved to Supabase and a notification email is sent to me via Resend. If you share personal data in the chat, it may be retained as part of that lead record. You can request deletion at any time, see the "Your rights" section below.
Email Communications
When you submit the contact form or the chatbot captures a lead, you will receive a confirmation email acknowledging your submission. Follow-up is limited to your enquiry. I do not send marketing emails without your explicit opt-in. You can opt out of any communication at any time by contacting me at legal@sarmalinux.com.
Cookies and Tracking
This site uses a minimal set of cookies and tracking technologies:
- Strictly necessary cookies: Required for the site to function (e.g. session management, security tokens). These cannot be opted out of.
- Vercel Analytics: Anonymised, aggregate page-view data collected by Vercel. No personally identifiable information is stored. IP addresses are anonymised before any data is recorded. This does not require consent under UK GDPR given the absence of personal data processing.
No third-party advertising, behavioural-tracking, or re-marketing cookies are used on this site. You can control browser cookies in your browser settings; disabling essential cookies may affect site functionality.
Third-Party Services and Data Processors
The following third-party services may receive or process your data as part of operating this site. Each has its own privacy policy which I encourage you to review.
- Supabase, database hosting for contact form submissions and chat leads. Data is stored in the EU region.
- Resend, transactional email delivery for contact confirmations and lead notifications.
- Vercel, site hosting, CDN, and anonymised analytics. Servers in the US and EU (data subject to Vercel's DPA).
- Cloudflare, DNS and network-level protection. Cloudflare may process request metadata (IP, headers) in transit. No personal data is stored by Cloudflare on my behalf.
- Cal.com, booking system used exclusively for admin scheduling. No public booking links are exposed on this site; visitors cannot book through sarmalinux.com.
- Groq / OpenRouter, large language model inference for the chatbot. Messages sent to the chatbot are transmitted to these providers to generate responses. See their respective privacy policies for details of their data handling.
Open Graph and Meta Tags
Pages on this site include Open Graph meta tags (title, description, and image) to control how links appear when shared on social platforms. These tags do not collect or transmit any user data.
Data Storage and Security
- Contact form submissions and chat leads are stored in a Supabase database with row-level security enabled
- All data in transit is encrypted via HTTPS/TLS
- Access to the database is restricted to the site backend and my personal admin account
- Data is retained only as long as necessary to fulfil the purpose for which it was collected, or as required by law
Your Rights Under UK GDPR
As a UK resident (or where UK GDPR otherwise applies), you have the following rights regarding your personal data:
- Access, request a copy of the personal data I hold about you
- Rectification, request correction of inaccurate or incomplete data
- Erasure, request deletion of your data ("right to be forgotten")
- Restriction, request that I restrict processing of your data
- Portability, receive your data in a structured, machine-readable format
- Objection, object to processing based on legitimate interest
To exercise any of these rights, email privacy@sarmalinux.com with the subject line "GDPR request". I will respond within one calendar month as required by UK GDPR. If you are not satisfied with my response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO).
Children's Privacy
This site and my services are not directed at individuals under the age of 18. I do not knowingly collect personal information from children. If you believe I have collected information from a child, please contact me immediately at legal@sarmalinux.com.
Changes to This Policy
I may update this privacy policy from time to time. Any changes will be reflected on this page with an updated date at the top. Continued use of the site after changes constitutes acceptance of the updated policy.
Contact
Questions about this Privacy Policy or my data practices:
Data subject requests (UK GDPR): privacy@sarmalinux.com
Policy and legal questions: legal@sarmalinux.com
Security disclosure: security@sarmalinux.com
General contact: hello@sarmalinux.com
Website: sarmalinux.com