Legal
Privacy Policy
Last Updated: April 7, 2026 · Effective Immediately
1. Introduction
Welcome to iktiarshovo.com (“Website”), operated by Iktiar Shovo (“we,” “us,” or “our”). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our Website and interact with our AI assistant, θ (Theta).
We are committed to protecting your privacy and complying with applicable data protection laws, including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and the UK Data Protection Act 2018.
2. Information We Collect
We may collect the following types of information:
- Voluntarily Provided Information: Name, email address, phone number, and project details that you submit through our contact form or θ (Theta) AI chat widget.
- Automatically Collected Data: Browser type, operating system, IP address (anonymized), referring URL, pages visited, and session duration via privacy-focused analytics.
- Chat Interaction Data: Messages exchanged with our θ (Theta) AI assistant for the purpose of providing accurate service responses and lead management.
🔒 3. AI Data Handling & Zero-Trust Security
We take the security of your data extremely seriously. Our AI system, θ (Theta), operates under a strict Zero-Trust Security Architecture:
- No AI Training on Private Data: Our AI models (θ Theta) do NOT train on private client conversations. Chat interactions are processed in real-time for response generation only and are not fed back into any machine learning training pipeline.
- GDPR & CCPA Compliance: We fully comply with the General Data Protection Regulation (GDPR) for EU/UK residents and the California Consumer Privacy Act (CCPA) for California residents. You have the right to access, rectify, delete, or export your personal data at any time.
- We Never Sell Your Data: Under no circumstances do we sell, rent, or trade your personal information to third parties. Period.
- Secure Database Architecture: All databases are locked behind strict Firebase Admin SDK server-side authentication. Client-side access to any database is strictly prohibited. No public-facing database endpoints exist.
- API Key Protection: All API keys, service credentials, and third-party integrations (Groq, Gemini, Telegram, Google Sheets) are stored exclusively in server-side environment variables and are never exposed to the client browser.
- Anti-Prompt Injection: θ (Theta) includes built-in security protocols to resist prompt injection, role-override attacks, and data exfiltration attempts. The AI will refuse any request that attempts to bypass its security rules.
- Chat Data Retention: Lead data (name, email, phone) submitted through the chat widget is stored securely in our protected database for business contact purposes only. Chat conversation content is ephemeral and is not stored permanently on our servers.
4. How We Use Your Information
We use collected information exclusively for:
- Responding to your inquiries and providing service quotations
- Managing client leads and business communications
- Improving our website functionality and user experience
- Sending notifications about your project (only if you opt in)
- Complying with legal obligations
5. Third-Party Services
Our system integrates with the following third-party services for operational purposes:
- Groq (Primary AI Engine): Processes chat messages for real-time AI responses. Subject to Groq's privacy policy.
- Google Gemini (Fallback AI Engine): Used as a backup AI processor when the primary engine is unavailable. Subject to Google's privacy policy.
- Firebase (Google Cloud): Secure database for lead storage. All access is server-side only via Admin SDK.
- Telegram Bot API: Used to send lead notifications to our business Telegram channel. No user data is stored on Telegram.
- Google Sheets API: Used for CRM lead synchronization. Access is restricted via OAuth 2.0 service accounts.
- Vercel: Website hosting platform with enterprise-grade security and HTTPS encryption.
6. Your Rights (GDPR & CCPA)
Under GDPR and CCPA, you have the following rights:
- Right to Access: Request a copy of all personal data we hold about you.
- Right to Rectification: Request corrections to inaccurate data.
- Right to Erasure: Request complete deletion of your personal data (“Right to be Forgotten”).
- Right to Data Portability: Receive your data in a structured, machine-readable format.
- Right to Object: Object to processing of your data for specific purposes.
- Right to Withdraw Consent: Withdraw any previously given consent at any time.
- Right to Non-Discrimination (CCPA): We will not discriminate against you for exercising your privacy rights.
To exercise any of these rights, please contact us at: [email protected]
7. Cookies & Tracking
Our website uses minimal cookies necessary for site functionality. We do not use advertising cookies or invasive tracking technologies. Any analytics data collected is anonymized and aggregated.
8. Children's Privacy
Our services are not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us immediately and we will delete it.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated “Last Updated” date. We encourage you to review this policy periodically.
10. Contact Us
If you have any questions or concerns about this Privacy Policy or our data practices, please contact us: