link.in-my.bio
PrivacyTerms

Legal · Privacy

Privacy Policy

We run one server, keep one log, and set no cookies. This page explains the little that is collected when you open a page on link.in-my.bio, why it is collected, how long it is kept, and how to have it removed.

Last updated 26 July 2026

01Who is responsible

fyzno, a studio established in the Netherlands, operates link.in-my.bio and is the controller for the processing described here within the meaning of the General Data Protection Regulation (GDPR).

Privacy questions and requests: info@fyzno.com. There is no separate privacy desk. The same people who run the server answer the mail.

02What this policy covers

This policy applies to link.in-my.bio and every profile page served under it (link.in-my.bio/<name>). It does not cover fyzno.com, which has its own privacy policy. If you contacted us through the form there, that policy governs your message. It also does not cover any site you reach by clicking a link on one of our pages.

03Server logs

link.in-my.bio is served through nginx, and nginx writes an access log. This is the only personal data the site collects on its own. Per request it records:

  • your IP address (and, where a proxy is involved, the forwarded client IP);
  • the date and time of the request;
  • the requested URL, HTTP method, protocol and response status;
  • the number of bytes sent;
  • the referring URL, if your browser sent one;
  • your browser’s user-agent string.

The same IP address is held briefly in memory for rate limiting, so a single address cannot flood the server. Application error logs may contain the same request data when something breaks. Requests for static build assets are not logged at all.

Logs are read when something is broken or under attack. They are not profiled, not enriched, not cross-referenced with anything, and not used to identify or follow visitors.

04What we do not do

No cookies at all. link.in-my.biosets no cookies of any kind: not analytics, not advertising, not “essential” ones either. There is nothing to consent to, which is why you have never seen a banner here.

Also absent, by design:

  • no analytics or measurement of any kind;
  • no advertising, retargeting or conversion pixels;
  • no fingerprinting, session recording or heatmaps;
  • no accounts, logins, dashboards or profiles of visitors;
  • no fonts, scripts or stylesheets pulled from a third-party CDN. Typefaces are self-hosted at build time, so your browser never calls out to Google.

We never sell, rent, trade or otherwise share data with third parties. Not aggregated, not anonymised, not “with partners”. There is no third party in this system beyond the hosting provider that runs the machine.

05Content on profile pages

A profile page contains material supplied to us by the client, meaning the person or business whose page it is: a name, a photo, a biography, links, project descriptions, quotes, prices. We publish it because they asked us to and because publishing it is the entire service; it is stored on the server purely so it can be displayed. It is never used for anything else and never passed on.

The client decides what appears on their page and is responsible for having the right to publish it, including any photograph, testimonial or name of another person. If you appear on a page and want that changed or removed, write to info@fyzno.com. We will act on well-founded requests without waiting for the client’s agreement.

06Embeds and outbound links

A client may choose to include a YouTube or Spotify player on their page. Those are the only third-party components this site can load, and both are optional and uncommon:

  • YouTube players are embedded through youtube-nocookie.com, which does not store viewing cookies unless you press play.
  • Spotify players are loaded from Spotify and may set their own cookies and receive your IP address and user-agent under Spotify’s privacy policy.

The whole point of these pages is to send you somewhere else. The moment you follow a link, you are on someone else’s site under someone else’s policy, and we have no control over and no responsibility for what happens there.

07Legal bases

  • Server logs and rate limiting: legitimate interests, art. 6(1)(f) GDPR, for keeping the service available, secure and debuggable. The data is minimal, short-lived and never used to profile anyone.
  • Publishing profile content: performance of a contract, art. 6(1)(b) GDPR, with the client whose page it is.
  • Billing and tax records: legal obligation, art. 6(1)(c) GDPR. These are handled by fyzno outside this site.

Nothing here relies on consent, because nothing here needs it. There is no automated decision-making and no profiling.

08How long things are kept

  • Access and error logs: 30 days maximum, then rotated out and deleted.
  • Rate-limiting state: held in memory for seconds to minutes.
  • Profile content: for as long as the page is live, plus the backup cycle after it is taken down. Removal on request.
  • Backups: encrypted, rotating, overwritten within 30 days.

09Where the data is

Everything runs on our own server at OVHcloud, Gravelines (France), with encrypted backups held within the EU. There are no transfers of personal data outside the European Economic Area, and no US-based processors in the path. The hosting provider acts as a processor on our instructions under art. 28 GDPR.

10Disclosure

Log data is disclosed to no one. The only exceptions are ones we cannot refuse: a binding order from a competent authority or court in the Netherlands, or a legitimate abuse report where an IP address must be shared with a network operator to stop an attack. If we ever have to hand something over and are legally permitted to say so, we will say so.

11Security

HTTPS only, with HTTP redirected and modern TLS. Strict security headers, a restrictive referrer policy, per-IP rate and connection limits, non-standard request methods rejected outright, no upload endpoints, no forms, and no database of visitors to steal. The server is patched routinely and administrative access is limited to key-based authentication.

No system is perfect. If you find a weakness, mail support@fyzno.com before publishing it and we will fix it.

12Your rights

Under the GDPR you may request:

  • access to the personal data we hold about you;
  • rectification of anything inaccurate;
  • erasure;
  • restriction of processing;
  • portability, where it applies;
  • and you may object to processing based on legitimate interests.

Write to info@fyzno.com. We answer within one month. One honest limitation: server logs record an IP address and nothing else, so unless you can tell us the address and roughly when you visited, we usually cannot find your entries, and we will not collect more data from you just to go looking (art. 11 GDPR).

If you are not satisfied, you can lodge a complaint with the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl) or the supervisory authority where you live.

13Visitors outside the EU

We are established in the Netherlands and apply the GDPR standard to everyone, wherever you happen to be. We do not maintain separate, weaker practices for visitors from other regions, so there is nothing extra to opt out of.

For residents of California and other US states with comparable laws: we are a small European studio and do not meet the revenue or volume thresholds that make those laws apply to us. Even so, for the avoidance of doubt:

  • we do not sell personal information, and we do not share it for cross-context behavioural advertising, for money or for anything else;
  • we run no advertising, no analytics and no cookies, so there is nothing to opt out of;
  • because the site sets no cookies and runs no tracking, a Global Privacy Control signal is already satisfied by default;
  • we collect no sensitive personal information and offer no financial incentives;
  • the rights in section 12, including access and deletion, are offered to you on the same terms as to an EU visitor, without discrimination for exercising them.

The same applies to visitors in the UK, Switzerland, Brazil and elsewhere: one policy, one standard, one mailbox at info@fyzno.com.

14Children

The service is not aimed at children and we knowingly build pages only for people who can enter into a contract. If you believe a page contains a child’s personal data published without proper authority, tell us and we will take it down.

15Changes and contact

If what we collect ever changes, this page changes first and the date at the top moves with it. There is no mailing list to notify, which is rather the point.

Questions, requests or takedowns: info@fyzno.com. The commercial side of the service is covered by our Terms of Service.

© 2026 link.in-my.bioinfo@fyzno.com