At a glance
- No cookiesNothing is stored in your browser
- No trackingNo analytics, adverts or third-party scripts
- No formsNo accounts, logins or comments
- 90 daysRequest logs are deleted automatically
andy.boura.uk is my personal site: a profile page and a page about the companies I have invested in. It is static: plain files served over HTTPS, with no server code and no database.
Privacy
I, Andy Boura, am responsible for the personal data this site handles, acting as an individual and not trading.
What is collected
No cookies, analytics, adverts or third-party content. Like almost every website, the site keeps a log of the requests it answers, including your IP address, the time, the page requested, the page that linked to it and your browser type. The logs are private and are deleted automatically after 90 days.
How it is used
Only to keep the site working and secure, and to investigate errors, abuse and attacks. The lawful basis is my legitimate interest in running a secure website. Nothing is sold, used for advertising or used to profile visitors, and individual IP addresses are not copied out of the logs.
Who else is involved
Amazon Web Services hosts the site and stores the logs on my behalf, in the United States, under its data processing terms. Links to other sites, such as LinkedIn, X and the companies on the investments page, take you to services with their own privacy terms; nothing is sent to them unless you follow a link.
If you email me
Mail to the trust centre address below is received by Amazon Web Services, checked for spam and viruses, and forwarded to my own mailbox, which Google hosts. Amazon holds its copy in the United States and deletes it automatically after 7 days. Google stores the forwarded copy in its data centres, which may be outside the UK, under its own data processing terms. The lawful basis is my legitimate interest in reading and answering mail you choose to send.
Your rights
You can ask for a copy of data about you, ask me to correct it if it is wrong, ask me to delete it, ask me to restrict how it is used, or object to its use.
Before acting on a request I will ask you to show that the data is yours, so that no one can obtain or delete someone else's. For request logs, that means showing you control the IP address concerned, for example by opening a link I send you from that connection, and telling me roughly when you visited, within the last 90 days. For mail, it means writing to me from the email address concerned.
Complaints
If you are unhappy with how your data has been handled, please tell me first, at BouraUk+trustcentre@designed.online. I will acknowledge your complaint within 30 days and look into it without undue delay. You can also complain to the Information Commissioner's Office at ico.org.uk.
Changes to this notice
This notice may be updated from time to time. The date it was last reviewed is at the foot of the page.
Security
The site is deliberately simple, so there is little to attack: no server code, no database, no logins and nothing to upload.
How a page reaches you
- Your browserHTTPS only, modern TLS
- Delivery networkAdds strict security headers to every response
- Private storageReadable only by the delivery network
How a change goes live
- CodeSite and infrastructure defined as code
- ReviewPull request and automated checks
- StagingChecked on a test copy first
- ProductionShort-lived, narrowly scoped deploy access
In the browser
The page loads only its own files. Security headers tell your browser to use HTTPS, refuse framing and content sniffing, keep other sites' windows apart, and turn off features the page does not need, such as the camera, microphone and location.
Controls behind the scenes
- Access: least-privilege, role-based access control. Interactive access always requires multi-factor authentication, and automated deploys use short-lived credentials, issued only to this site's own repository and limited to its own storage. Each role's purpose and permissions are tracked and recorded.
- Change: every change, to the site or to the hosting, is made in code, reviewed through a pull request with automated checks, and checked on staging before it goes live; earlier versions are kept, so a change can be rolled back.
- Monitoring: account activity is recorded in a tamper-evident audit trail kept for a year, and threat detection, configuration recording and access analysis report anything unexpected.
- Testing: Dependabot watches the site's libraries and its build tools and proposes updates; every change to the hosting is checked against AWS security rules before it can deploy; and after every deploy an automated test confirms the security headers are in place.
- Logs: request logs cannot be deleted early by anyone; only their 90-day expiry removes them.
Keeping up to date
The site's two libraries are pinned to exact versions and monitored for advisories. I aim to fix known vulnerabilities in them within these times, though as a private individual it may sometimes take longer:
| Severity | Target | At the latest |
|---|---|---|
| Critical | 1 day | 7 days |
| High | 14 days | 30 days |
| Medium | 90 days | 6 months |
| Low | Next routine update | 12 months |
Assessment
The site and its hosting are self-assessed against the OWASP Application Security Verification Standard 5.0, with a mapping to the OWASP Top 10, and kept up to date as things change.
Reporting a vulnerability
If you find a security problem, please email BouraUk+trustcentre@designed.online with enough detail to reproduce it. I aim to acknowledge reports within 5 working days and to fix confirmed problems within the times above, though as a private individual it may sometimes take longer. I do not offer a bug bounty.
In scope
- andy.boura.uk
- staging.andy.boura.uk
- Testing that reads only what the site serves to everyone
Not permitted
- Denial of service, load or flood testing, or anything that slows the site for others
- Automated scanning at volume
- Social engineering, phishing or contacting anyone other than me
- Physical attacks, or attacks on hosting providers or other customers
- Accessing, changing or keeping anyone else's data
- Publishing details before the problem is fixed, or 90 days after your report, whichever comes first
If you keep to these rules and act in good faith, I will not pursue legal action against you for your research. This policy is also linked from the site's security.txt.
Legal
Who runs this site
andy.boura.uk is run by Andy Boura as a private individual, not trading. It is not a business, sells nothing, and is not operated by or for any employer.
Licences
| What | Licence |
|---|---|
| The site's content | Copyright Andy Boura, all rights reserved |
| Start Bootstrap Grayscale theme | Apache 2.0, published as LICENSE.txt |
| Bootstrap 5 | MIT |
| Font Awesome Free 7 | Icons CC BY 4.0, fonts SIL OFL 1.1, code MIT |
Company names and logos on the site, including LinkedIn and X, are trademarks of their owners, used only to identify them.
Governing law
These terms and any dispute about the site are governed by the law of England and Wales.
Contact
For privacy requests and security reports, email BouraUk+trustcentre@designed.online.
For anything else, find me on X or LinkedIn.