Privacy Policy
How this website collects, uses, and protects your personal data.
Contents
- 1. Controller
- 2. Contact Details for Privacy Questions
- 3. Hosting and Delivery of the Website
- 4. Server Log Files
- 5. Necessary Technical Cookies and Local Storage
- 6. Contact Form
- 7. Work With Me Requests, Applications, and Scheduling a Call
- 8. Website Studio and Administrator Access
- 9. Media and External Content
- 10. Scheduling and Calendar Integration ("Book a Call")
- 11. Payment Processing
- 12. Data Processors and Recipients
- 13. Transfers Outside the EU/EEA
- 14. Retention and Deletion
- 15. Backups
- 16. Legal Bases
- 17. Rights of Data Subjects
- 18. Right to Complain to a Supervisory Authority
- 19. Security Measures
- 20. Changes to This Privacy Policy
- 21. Effective Date and Last Updated Date
1. Controller
The controller responsible for the processing of personal data described in this Privacy Policy is:
Thi Bich Lien Nguyen
This page is maintained for nguyenthibichlien.com, a personal website.
2. Contact Details for Privacy Questions
If you have a question about this Privacy Policy or about how your data is handled, you can reach the controller at:
support@build2teach.com
This is deliberately kept separate from the public Contact form, since a fixed address is more reliable for formal privacy requests.
3. Hosting and Delivery of the Website
This website is hosted on a server operated by Hetzner Online GmbH, located in Nuremberg, Germany (European Union), behind a Traefik reverse proxy. No content delivery network (CDN) is used - every request is served directly from this server. Uploaded media (images and video files) is stored on the same server and served by the application itself; static assets (CSS, JavaScript, fonts) are served by the application via WhiteNoise. All fonts used on this website are hosted locally and are never requested from a third-party font service.
Because hosting takes place within the EU/EEA, no international data transfer occurs through hosting itself.
4. Server Log Files
Like most websites, the web server, reverse proxy, and application record technical information for requests, which may include the requesting device's IP address, the date and time of the request, the requested page or resource, the referring page (if any), the browser/operating system (user agent string), and the HTTP status code returned. These logs are used only to operate, secure, and troubleshoot the website - they are not combined with any other dataset to identify individual visitors, and are not used for analytics or marketing.
No fixed, application-specific retention period is currently configured for these logs; they persist under the underlying infrastructure's own default behaviour until rotated or removed through routine system maintenance, rather than on a defined schedule set by this website.
5. Necessary Technical Cookies and Local Storage
This website uses only strictly necessary cookies required for it to function - no analytics, advertising, or marketing cookies are set, and no cookie consent banner is shown, because none is required for technology that is strictly necessary. See the separate Cookie Information page for the full list.
6. Contact Form
If you use the Contact form, the information you submit (name, email address, topic, and message) is stored in the website's database so that your enquiry can be reviewed. Unless your submission is automatically identified as spam, it is also emailed to the site operator, using your email address as the reply-to address so a reply reaches you directly. You do not receive an automatic acknowledgement email for a Contact form submission. This information is not used for any purpose beyond handling your enquiry.
7. Work With Me Requests, Applications, and Scheduling a Call
If you submit a general request, apply for a published offering, or request a call through the "Work With Me" or scheduling pages, the information you provide (such as your name, email address, background, goals, or requested time) is stored in the website's database and emailed to the site operator so your request can be reviewed. If you apply to an offering or request a call, you also receive a short confirmation email acknowledging receipt - this confirmation does not repeat your own submitted message back to you. This information is used to assess and respond to your request, and to prepare a proposal or agreement where relevant; it is not used for marketing, and you are never automatically subscribed to any mailing list by submitting a request.
Where a request is tied to scheduling a call, this website's own scheduling feature is used to record the request; whether that feature is currently connected to an external calendar provider is described in Section 10 below.
8. Website Studio and Administrator Access
The site operator manages content through an authenticated administration area ("Website Studio"). Logging in sets a session cookie so the operator stays authenticated - this applies only to the operator, not to public visitors. See the Cookie Information page for details.
9. Media and External Content
Images and video uploaded to this site are hosted on the same server as the website itself, as described in Section 3. Where a page includes an embedded video from YouTube or Vimeo, the embed is not loaded automatically - it only loads, and only then contacts that provider, once you actively click to play it.
10. Scheduling and Calendar Integration ("Book a Call")
This website's scheduling feature always stores your request (name, email, topic, and requested time) in this website's own database first. Whether a corresponding calendar event is also created through an external Microsoft Graph/Outlook calendar integration depends on whether that integration is currently configured - at present, it is not, so no scheduling data is currently transmitted to Microsoft. If that integration is enabled in the future, only the event subject (built from your name) and the topic you provided would be sent to create the calendar event - never your email address - and this policy will be updated, and a new version published, before that happens.
11. Payment Processing
This website uses Stripe for certain payment-related functionality, but that functionality is only used internally by the site operator, as part of a separately agreed engagement - there is currently no public checkout or payment flow on this website that a visitor can initiate directly. If that changes in the future, this policy will be updated, and a new version published, before a public payment flow is introduced.
12. Data Processors and Recipients
The following third parties are currently involved in operating this website:
| Provider | Role | Location |
|---|---|---|
| Hetzner Online GmbH | Web hosting, and automated infrastructure-level backups | Germany (EU) |
| Google (Google Workspace) | Sends outgoing notification emails (Contact, Work With Me, scheduling) on the operator's behalf, and hosts the mailbox that receives them | Provider is a global company; the specific data-region configuration of this mailbox has not been separately confirmed |
No analytics provider, advertising network, or other third-party processor is currently used. Microsoft (calendar integration) and Stripe (payment processing) exist as capabilities in this website's software, but neither currently receives data through any public, visitor-facing part of this website - see Sections 10 and 11. This section will be updated, and a new version of this policy published, if that changes.
13. Transfers Outside the EU/EEA
Hosting and day-to-day operation of this website take place within the EU/EEA (Germany). However, outgoing notification emails (Section 6, 7) are sent through Google Workspace, a globally operated email service - this website has not separately confirmed the specific data-region configuration of the Google Workspace account used, so it does not claim that email-related processing stays entirely within the EU/EEA. No other current processing (Microsoft calendar integration, Stripe payments) transfers personal data internationally today, since neither is currently active in a way that reaches a public visitor - see Sections 10 and 11.
14. Retention and Deletion
- Server logs: see Section 4 - no fixed retention period is currently configured.
- Contact, Work With Me, and scheduling records: currently kept indefinitely as an operational record; a defined retention/deletion period has not yet been decided. This is an open operational decision, not an automated deletion policy implemented by this website.
- Backups: see Section 15 - no automated deletion schedule is described here for backups either.
No automated deletion is currently performed for any of the above.
15. Backups
Two backup mechanisms currently exist for this website's data: an automated backup feature provided by the hosting infrastructure (Hetzner), and occasional manual database backups taken directly by the site operator. This page does not itemise the exact schedule, retention window, or encryption configuration of either mechanism.
16. Legal Bases
Where the General Data Protection Regulation (GDPR) applies, personal data described in this policy is processed on the following bases:
- Server log files: legitimate interest in operating a secure, reliable website (Art. 6(1)(f) GDPR).
- Contact form, Work With Me requests, applications, and scheduling requests: performance of steps taken at your request prior to entering into an agreement, or legitimate interest in responding to your enquiry (Art. 6(1)(b)/(f) GDPR).
- Website Studio session cookie: legitimate interest in securing administrative access (Art. 6(1)(f) GDPR) - this applies only to the site operator.
17. Rights of Data Subjects
Subject to applicable law, you may have the right to request access to, correction of, deletion of, or restriction on the processing of your personal data, and to object to processing based on legitimate interest. To exercise any of these rights, use the contact details in Section 2.
18. Right to Complain to a Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU/EEA member state of your habitual residence, place of work, or the place of the alleged infringement.
19. Security Measures
This website uses HTTPS to encrypt data in transit, and administrative access to Website Studio requires authentication. Beyond these measures, no specific claim is made here about additional technical safeguards; further detail is an operational matter outside the scope of this policy.
20. Changes to This Privacy Policy
This Privacy Policy may be updated from time to time, for example as the website's functionality changes - including when a currently-inactive feature (such as the calendar integration or a public payment flow) is switched on. The "last updated" date shown at the top of this page always reflects the most recent version. Earlier published versions are retained internally rather than discarded when a new version is published.
21. Effective Date and Last Updated Date
This policy's effective date and last-updated date are shown at the top of this page, next to the title.