Trust Centre

Privacy, security and legal information for andy.boura.uk

This site is run by Andy Boura as a private individual, not trading. It is not run by, or on behalf of, any employer or company. Views on it are my own, not my employer's, and nothing on it is investment advice.

At a glance

  • No cookiesNothing is stored in your browser
  • No trackingNo analytics, adverts or third-party scripts
  • No formsNo accounts, logins or comments
  • 90 daysRequest logs are deleted automatically

andy.boura.uk is my personal site: a profile page and a page about the companies I have invested in. It is static: plain files served over HTTPS, with no server code and no database.

Privacy

I, Andy Boura, am responsible for the personal data this site handles, acting as an individual and not trading.

What is collected

No cookies, analytics, adverts or third-party content. Like almost every website, the site keeps a log of the requests it answers, including your IP address, the time, the page requested, the page that linked to it and your browser type. The logs are private and are deleted automatically after 90 days.

How it is used

Only to keep the site working and secure, and to investigate errors, abuse and attacks. The lawful basis is my legitimate interest in running a secure website. Nothing is sold, used for advertising or used to profile visitors, and individual IP addresses are not copied out of the logs.

Who else is involved

Amazon Web Services hosts the site and stores the logs on my behalf, in the United States, under its data processing terms. Links to other sites, such as LinkedIn, X and the companies on the investments page, take you to services with their own privacy terms; nothing is sent to them unless you follow a link.

If you email me

Mail to the trust centre address below is received by Amazon Web Services, checked for spam and viruses, and forwarded to my own mailbox, which Google hosts. Amazon holds its copy in the United States and deletes it automatically after 7 days. Google stores the forwarded copy in its data centres, which may be outside the UK, under its own data processing terms. The lawful basis is my legitimate interest in reading and answering mail you choose to send.

Your rights

You can ask for a copy of data about you, ask me to correct it if it is wrong, ask me to delete it, ask me to restrict how it is used, or object to its use.

Before acting on a request I will ask you to show that the data is yours, so that no one can obtain or delete someone else's. For request logs, that means showing you control the IP address concerned, for example by opening a link I send you from that connection, and telling me roughly when you visited, within the last 90 days. For mail, it means writing to me from the email address concerned.

Complaints

If you are unhappy with how your data has been handled, please tell me first, at BouraUk+trustcentre@designed.online. I will acknowledge your complaint within 30 days and look into it without undue delay. You can also complain to the Information Commissioner's Office at ico.org.uk.

Changes to this notice

This notice may be updated from time to time. The date it was last reviewed is at the foot of the page.

Security

The site is deliberately simple, so there is little to attack: no server code, no database, no logins and nothing to upload.

How a page reaches you

  • Your browserHTTPS only, modern TLS
  • Delivery networkAdds strict security headers to every response
  • Private storageReadable only by the delivery network

How a change goes live

  • CodeSite and infrastructure defined as code
  • ReviewPull request and automated checks
  • StagingChecked on a test copy first
  • ProductionShort-lived, narrowly scoped deploy access

In the browser

The page loads only its own files. Security headers tell your browser to use HTTPS, refuse framing and content sniffing, keep other sites' windows apart, and turn off features the page does not need, such as the camera, microphone and location.

Controls behind the scenes

  • Access: least-privilege, role-based access control. Interactive access always requires multi-factor authentication, and automated deploys use short-lived credentials, issued only to this site's own repository and limited to its own storage. Each role's purpose and permissions are tracked and recorded.
  • Change: every change, to the site or to the hosting, is made in code, reviewed through a pull request with automated checks, and checked on staging before it goes live; earlier versions are kept, so a change can be rolled back.
  • Monitoring: account activity is recorded in a tamper-evident audit trail kept for a year, and threat detection, configuration recording and access analysis report anything unexpected.
  • Testing: Dependabot watches the site's libraries and its build tools and proposes updates; every change to the hosting is checked against AWS security rules before it can deploy; and after every deploy an automated test confirms the security headers are in place.
  • Logs: request logs cannot be deleted early by anyone; only their 90-day expiry removes them.

Keeping up to date

The site's two libraries are pinned to exact versions and monitored for advisories. I aim to fix known vulnerabilities in them within these times, though as a private individual it may sometimes take longer:

SeverityTargetAt the latest
Critical1 day7 days
High14 days30 days
Medium90 days6 months
LowNext routine update12 months

Assessment

The site and its hosting are self-assessed against the OWASP Application Security Verification Standard 5.0, with a mapping to the OWASP Top 10, and kept up to date as things change.

Reporting a vulnerability

If you find a security problem, please email BouraUk+trustcentre@designed.online with enough detail to reproduce it. I aim to acknowledge reports within 5 working days and to fix confirmed problems within the times above, though as a private individual it may sometimes take longer. I do not offer a bug bounty.

In scope

  • andy.boura.uk
  • staging.andy.boura.uk
  • Testing that reads only what the site serves to everyone

Not permitted

  • Denial of service, load or flood testing, or anything that slows the site for others
  • Automated scanning at volume
  • Social engineering, phishing or contacting anyone other than me
  • Physical attacks, or attacks on hosting providers or other customers
  • Accessing, changing or keeping anyone else's data
  • Publishing details before the problem is fixed, or 90 days after your report, whichever comes first

If you keep to these rules and act in good faith, I will not pursue legal action against you for your research. This policy is also linked from the site's security.txt.

Contact

For privacy requests and security reports, email BouraUk+trustcentre@designed.online.

For anything else, find me on X or LinkedIn.