Privacy Policy

PRIVACY POLICY

Last updated: 5 September 2026

  1. WHO IS RESPONSIBLE

Securing.AI is my personal website. I am Marin Ivezic, and I am the data controller for the personal data described here. In this policy, “I”, “me” and “my” mean Marin Ivezic. “You” means anyone who visits the Site or contacts me through it. “the Site” means the website published at securing.ai. “GDPR” means the General Data Protection Regulation, Regulation (EU) 2016/679.

Write to me about anything in this policy at [CONFIRM privacy contact email]. No data protection officer has been appointed, and the GDPR does not require one here.

  1. WHAT THIS SITE DOES, AND WHAT IT DOES NOT DO

The Site publishes articles on AI security, AI safety and AI privacy, and it sells nothing. No advertising, sponsored posts or paid links appear anywhere on it.

Personal data collected through the Site stays with me and with the processors named in section 5. I have never sold, rented or traded it, and I build no advertising or marketing profiles. No decision about you is made by automated means, and I do not profile you within the meaning of Article 22 of the GDPR. Nothing collected here is used to train a machine learning model, and I supply it to no one for that purpose.

  1. WHAT I COLLECT

3.1 What you send me

The Site has one contact form, at securing.ai/contact/. That form asks for your first name, last name, email address and message. Everything else you write is up to you. If you send me an email instead of using the form, I hold whatever that email contains.

Supplying this data is voluntary. No law and no contract between us requires it. If you choose not to supply it, I cannot reply to you, and nothing else follows.

3.2 What is collected automatically

Every request your browser makes to the Site is recorded by my hosting provider and by the content delivery network in front of it. Each record contains your IP address, the date and time of the request, the page or file requested, the response code, the referring page where your browser sends one, and your browser’s user agent string.

These records exist before any consent question arises. A server cannot answer a request without knowing where to send the answer. I use the records to deliver pages, to diagnose faults, and to identify and block automated abuse.

3.3 Cookies and similar technologies

Some cookies are needed for the Site to work at all, including the one that records your cookie choice, and those are set without asking you. The ePrivacy Directive, as implemented in national law, permits strictly necessary storage on that basis.

Every other cookie or similar technology is set only after you accept it. iubenda operates the consent banner, and you can change or withdraw your choice at any time through it.

securing.ai/cookie-policy/ holds the current list of cookies, what each one does, and how long each one lasts. That list comes from a scan of the Site and stays more current than this policy. Where the two disagree, the cookie policy is correct.

3.4 Analytics

I use [CONFIRM analytics provider] to count visits and to see which articles are read. That tells me which subjects to write about next. It does not tell me who you are, and I make no attempt to identify individual readers.

Analytics runs only if you accept analytics cookies. Decline the banner, or ignore it, and no analytics data about your visit is collected.

3.5 Comments

Comments are closed on the Site. I will update this policy before opening them.

  1. WHY I PROCESS IT, AND ON WHAT LEGAL BASIS
  • Delivering and protecting the Site, using the server and CDN records, on the basis of legitimate interests under Article 6(1)(f) of the GDPR. My interest is in keeping the Site available, correct and resistant to attack. That interest does not override your right to read privately, and the records are held briefly and never used to build a picture of any individual.
  • Answering you, using contact form submissions and email, on the basis of legitimate interests under Article 6(1)(f). My interest is in replying to people who write to me, which is the reason they wrote.
  • Counting visits, using analytics, on the basis of your consent under Article 6(1)(a), given through the banner.
  • Recording your cookie choice, on the basis of a legal obligation under Article 6(1)(c). I must be able to demonstrate that consent was given, and I must remember your answer, and the banner therefore does not ask again on every page.
  1. WHO ELSE SEES IT

These organisations process personal data on my behalf, under written terms that restrict them to my instructions.

  • [CONFIRM hosting provider], which stores the Site’s files and database and keeps the server logs.
  • Cloudflare, Inc., which serves the Site through its network, protects it against attack, and obscures email addresses published on it.
  • iubenda S.r.l., which operates the consent banner and stores the record of your consent.
  • WPForms, which runs the contact form. Submissions are stored in the Site’s database and emailed to me.
  • [CONFIRM email provider], which delivers and stores messages sent to me.
  • [CONFIRM analytics provider], which processes the analytics data described in section 3.4.

Two other parties receive data on their own account. Author photographs come from Gravatar, operated by Automattic Inc., so your browser requests those images directly and Automattic receives your IP address. Any site you click through to from an article receives whatever your browser tells it, under its own policy.

Beyond this, I disclose personal data to no one. A court or a competent authority could compel disclosure. I would comply, and I would tell you unless the law forbade it.

  1. TRANSFERS OUTSIDE THE EEA

Some of the organisations named above are established in the United States or process data there.

Where the recipient is certified under the EU-US Data Privacy Framework, the transfer relies on the European Commission’s adequacy decision of 10 July 2023. That decision remains in force: the General Court upheld it on 3 September 2025, and an appeal against that judgment is pending before the Court of Justice as Case C-703/25 P.

Where the recipient is not certified, the transfer relies on the European Commission’s standard contractual clauses.

  1. HOW LONG I KEEP IT
  • Server and CDN records, for [CONFIRM retention period, typically 30 to 90 days], after which they are deleted automatically.
  • Contact form submissions and email correspondence, until the exchange ends and then for up to two years, in case someone reopens the thread. After that I delete them.
  • Consent records, for as long as your consent lasts and then for as long as I might need to demonstrate that you gave it.
  • Analytics data, for [CONFIRM retention period set in the analytics tool].
  1. YOUR RIGHTS

If the GDPR applies to you, you have the right to:

  • ask what personal data I hold about you and get a copy of it (Article 15);
  • have inaccurate data corrected (Article 16);
  • have data erased (Article 17);
  • have processing restricted while a dispute is resolved (Article 18);
  • receive data you gave me in a portable format, where you gave consent and the processing is automated (Article 20);
  • object to processing based on legitimate interests, including everything in section 4 that relies on Article 6(1)(f) (Article 21); and
  • withdraw consent at any time, without affecting anything done before you withdrew it (Article 7(3)).

To exercise any of these, write to me at [CONFIRM privacy contact email]. I will answer within one month. A complex request may take two further months, and I will tell you within the first month if that happens. I will not charge you, and I will not ask you to justify the request.

If you think I have handled your data unlawfully, complain to the data protection authority in your country of residence or workplace in the EU or the UK. You may also complain to my own supervisory authority, [CONFIRM supervisory authority and link]. Writing to me first is usually quicker.

If you are a California resident: I do not sell or share personal information as those terms are defined in the California Consumer Privacy Act, and I have not done so in the past twelve months.

  1. SECURITY

The Site is served over HTTPS. Administrative access requires multi-factor authentication. Software is patched on a schedule, and the network in front of the Site filters attack traffic.

Every website can be broken into, and this one is no exception. What I can tell you is how little there is to take: no accounts, no payments, no reader profiles, and nothing about you beyond what you typed into a contact form.

  1. CHILDREN

The Site is not directed at children. I do not knowingly collect personal data from anyone under 16. If you believe a child has sent me personal data, write to me and I will delete it.

  1. CHANGES

I will update this policy when what I do changes, and I will change the date at the top. Where a change affects you materially, I will say what changed.

  1. RELATED PAGES

Cookie Policy: securing.ai/cookie-policy/
Terms and Conditions: securing.ai/terms-and-conditions/
AI Use and Editorial Integrity: securing.ai/ai-use-editorial-integrity-statement/

The legal position stated here was checked against the GDPR and the ePrivacy Directive as in force on 5 September 2026. The Digital Omnibus proposal published on 19 November 2025 would move cookie consent rules into the GDPR. That proposal has not been adopted as at 5 September 2026, and this policy states the law as it stands.