Corbin Floyd ← Back to the site
Privacy Policy

Privacy Policy

Effective 16 August 2026  ·  Last updated 16 August 2026

This Privacy Policy describes how information is collected, used, disclosed and retained in connection with the website located at corbinfloyd.com, and describes the rights available to individuals with respect to that information.

1. Scope and Application

This Privacy Policy (the “Policy”) governs the collection, use, storage, disclosure and other processing of information obtained through the website located at the domain corbinfloyd.com, including all subpaths and subdomains thereof (collectively, the “Site”). By accessing or otherwise interacting with the Site, you acknowledge that you have read and understood the practices described in this Policy.

This Policy does not apply to any third-party website, platform, application, or service that may be linked to or referenced from the Site, including but not limited to professional networking platforms, code hosting platforms, and career services platforms. Such third parties maintain their own privacy practices, over which the Site exercises no control and for which it accepts no responsibility.

The Site is a personal portfolio operated by an individual. It does not offer goods or services for sale, does not process payments, does not maintain user accounts, and does not permit user registration or authentication of any kind.

2. Identity of the Controller

For purposes of the General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”), the UK General Data Protection Regulation, and analogous frameworks, the controller of personal data processed through the Site is Corbin Floyd, an individual residing in the State of Florida, United States of America, contactable at the address set out in Section 21 of this Policy.

No data protection officer has been appointed, no such appointment being required under Article 37 of the GDPR given the nature, scope, context and purposes of the processing described herein. No representative has been designated pursuant to Article 27 of the GDPR.

3. Definitions

For the purposes of this Policy, the following terms have the meanings ascribed to them below:

4. Categories of Information Collected

The Site operates a first-party measurement mechanism consisting of a small inline script served as part of the Site's markup. The script transmits Event Records to a first-party endpoint on the Site's own domain. No information is transmitted to any third-party measurement, advertising, or data-brokerage service. The categories of information comprised in an Event Record are enumerated below.

4.1 Information transmitted by the browser script

Table 1 — Client-transmitted attributes
AttributeDescription
Page pathThe path and fragment identifier of the page or section viewed (for example, /#proof-files).
Referring URLThe value of document.referrer, where the browser supplies one, indicating the page from which you navigated.
Query stringThe query component of the request URL, where present.
Screen dimensionsThe width and height of the device screen in CSS pixels.
Time zoneThe IANA time zone identifier reported by the browser's internationalisation API.
LanguageThe primary language preference reported by the browser.
Automated-browsing indicatorsStandard browser-exposed properties used to distinguish ordinary browsing from automated traffic.
Engagement durationElapsed time, in milliseconds, between page load and the transmission of the Event Record.
Scroll depthThe greatest proportion of the document scrolled, expressed as a percentage.
Interaction countA count of pointer interactions registered on the document.
Session identifierA pseudorandom value generated in the browser and retained in session storage for the duration of the browsing tab.

4.2 Information derived at the network edge

The following attributes are not transmitted by the browser script but are derived from the network characteristics of the request by the Site's infrastructure provider and appended to the Event Record:

Table 2 — Network-derived attributes
AttributeDescription
Approximate locationCountry, region or state, city, and postal code, inferred from network address. Such inference is approximate and is frequently inaccurate, particularly where a virtual private network, corporate proxy, or mobile carrier network is used.
Network operatorThe autonomous system number and the registered name of the organisation operating the network from which the request originated (for example, an internet service provider, a university, or an employer's corporate network).
User agent stringThe User-Agent header supplied by the browser, identifying browser and operating system.
Pseudonymised network addressAn irreversible pseudonymised value derived from the network (IP) address. The address itself is never stored. See Section 4.3.

4.3 Treatment of network addresses

The Site does not record, store, or log network (IP) addresses in plain form. Upon receipt of a request, the network address is subjected to an irreversible, keyed cryptographic transformation, and the plaintext address is discarded without being written to persistent storage. The key material used in that transformation is held as an encrypted secret and is not present in any published artefact.

The resulting value constitutes pseudonymised data within the meaning of Article 4(5) of the GDPR. It permits requests originating from the same network to be correlated with one another but does not permit the underlying network address to be recovered. Rotation or replacement of the key material irreversibly severs the correlation between previously stored values and any subsequently collected data.

5. Information Not Collected

For the avoidance of doubt, the Site does not collect, request, generate, purchase, or otherwise obtain any of the following:

6. Cookies and Local Storage

The Site sets first-party cookies only. It does not set, permit, or participate in the setting of third-party cookies, and it does not employ pixel tags, web beacons, clear GIFs, device fingerprinting services, or cross-site tracking technologies operated by any third party.

Table 3 — Cookies and storage set on a visitor's browser
TypePurposeDuration
First-party cookie Holds an opaque identifier permitting repeat visits from the same browser to be counted as a single visitor rather than as one visitor per page load. The identifier carries no name, contact detail, or other information about you, and is not shared with anyone. Up to 400 days
Session storage entry Holds a short-lived identifier used to group the activity of a single browsing session. Cleared when the browser tab is closed

Administrative cookies used solely by the operator to access internal tooling are never set on a visitor's browser and are outside the scope of the table above.

All cookies described above are set with the Secure, HttpOnly and SameSite=Lax attributes, which respectively confine transmission to encrypted connections, prevent the value from being read by client-side script, and prevent the cookie from being sent with cross-site requests. Actual cookie lifetime may be shortened by your browser: several browsers cap cookie lifetimes irrespective of the expiry requested by the server.

No consent banner is presented. The controller's assessment is that the cookies described above are strictly necessary or, in the alternative, are deployed on the basis of the legitimate interests described in Section 8, and that the processing presents a low risk to the rights and freedoms of data subjects given its first-party, non-commercial, non-advertising character. You may nonetheless refuse or delete these cookies at any time as described in Section 17.

7. Purposes of Processing

Information collected through the Site is processed exclusively for the following purposes:

  1. To determine whether the Site is being viewed by human beings, and in particular whether it is being viewed by prospective employers, recruiters, collaborators, or academic institutions, the Site being maintained by its operator for the purpose of seeking professional opportunities;
  2. To distinguish human visitors from automated traffic, including search engine crawlers, monitoring services, link-preview fetchers, vulnerability scanners, and scraping tools;
  3. To exclude the controller's own visits from measurement, so that the controller's activity does not distort the measurement of genuine interest;
  4. To understand which sections of the Site attract attention, in order to inform the Site's content and structure;
  5. To generate summary notifications to the controller when a visit occurs;
  6. To maintain the security, availability and integrity of the Site, and to detect and mitigate abusive or anomalous traffic.

Information collected through the Site is not used for advertising, behavioural targeting, audience segmentation, retargeting, lead generation, credit assessment, insurance underwriting, employment screening of visitors, or any form of automated decision-making producing legal or similarly significant effects concerning any individual.

8. Legal Bases for Processing

Where the GDPR or the UK GDPR applies to the processing described in this Policy, that processing is carried out on the basis of the controller's legitimate interests pursuant to Article 6(1)(f), namely the legitimate interest of an individual job-seeker in understanding whether and by whom their professional portfolio is being read, and the legitimate interest in maintaining the security and integrity of the Site.

The controller has considered the interests, rights and freedoms of data subjects and has concluded that such interests are not overridden, having regard to: the pseudonymised character of the data; the absence of any advertising, commercial exploitation, or onward disclosure; the absence of any special categories of data; the limited and proportionate scope of collection; and the availability of straightforward means to prevent collection entirely, as described in Section 17. You may object to this processing at any time as described in Section 14.

9. Automated Filtering and Classification

Information collected through the Site is subject to automated evaluation for the purposes described in Section 7. That evaluation categorises traffic as human or automated and forms a general impression of whether a visitor may be acting in a professional or recruiting capacity. The specific signals and thresholds applied are not published, disclosure of which would defeat the anti-automation purpose they serve.

The evaluation produces no output other than a categorisation displayed on internal tooling accessible only to the controller. It does not produce legal effects concerning any data subject, does not similarly significantly affect any data subject, and does not constitute automated decision-making within the meaning of Article 22 of the GDPR. No output of that evaluation is disclosed to any third party.

Geographic attributes are not used to identify or to exclude any particular individual, such attributes being unreliable for that purpose.

10. Disclosure and Sub-Processors

The controller does not sell, rent, lease, licence, trade, or otherwise disclose information collected through the Site to any third party for monetary or other valuable consideration, and does not share such information for cross-context behavioural advertising. No advertising network, data broker, analytics vendor, marketing platform, or social media platform receives information collected through the Site.

Information is processed by the following sub-processor:

Table 4 — Sub-processors
EntityFunctionCategories processed
Cloudflare, Inc. Content delivery, edge computation, database storage, and transactional mail delivery. The Site's pages, its measurement endpoint, its stored Event Records, and its notification messages are all served, executed, stored, and transmitted using Cloudflare infrastructure. All categories described in Section 4

Cloudflare, Inc. additionally processes request metadata in its own capacity as a network and security provider, in accordance with its own privacy practices, over which the controller exercises no control. Information regarding those practices is published by Cloudflare, Inc.

The controller may further disclose information where required to do so by applicable law, regulation, legal process, subpoena, court order, or governmental request; where necessary to establish, exercise or defend legal claims; or where necessary to investigate or prevent fraud, abuse, or threats to the security of the Site or to the rights or safety of any person.

11. International Transfers

The Site's infrastructure is operated on a globally distributed network. Requests are ordinarily served from the point of presence nearest to the requesting network, and stored records are held in the United States. Accordingly, information collected from data subjects located in the European Economic Area, the United Kingdom, or Switzerland is transferred to and stored in the United States.

Such transfers are effected in reliance upon the standard contractual clauses adopted by the European Commission and, where applicable, the United Kingdom International Data Transfer Addendum, as incorporated into the controller's agreement with the sub-processor identified in Section 10. Given the pseudonymised character of the data and the absence of special categories of data, the controller assesses the residual risk arising from such transfers to be low.

12. Data Retention

Event Records are retained for so long as the Site remains in operation and the purposes described in Section 7 continue to apply. No fixed automated deletion schedule is presently implemented, and Event Records should therefore be understood to be retained indefinitely unless and until deleted. The controller may delete Event Records, in whole or in part, at any time and without notice, and does so periodically in the ordinary course.

Records are deleted in their entirety upon a verified request made pursuant to Section 14. Replacement of the key material described in Section 4.3, which may occur at any time, irreversibly severs the correlation between all previously stored values and any subsequently collected data.

13. Information Security

The controller implements technical and organisational measures appropriate to the risk presented by the processing, including: transmission of all traffic over encrypted connections; storage of network addresses in irreversible pseudonymised form only; storage of key material and credentials as encrypted secrets held outside the Site's source code; access controls restricting internal tooling to the controller alone; and the restrictive cookie attributes described in Section 6. Further particulars of those measures are withheld, their disclosure being liable to undermine their effectiveness.

No method of transmission over the internet and no method of electronic storage is entirely secure. While the controller endeavours to protect information by commercially reasonable means, absolute security cannot be guaranteed, and no warranty to that effect is given.

14. Rights of Data Subjects

Subject to applicable law and to the limitations described below, you may be entitled to exercise the following rights in respect of Personal Data relating to you:

Limitation arising from pseudonymisation. The Site does not collect any identifier by which a data subject may be identified by name or contact details. In consequence, and as contemplated by Article 11 of the GDPR, the controller is ordinarily unable to identify the data subject to whom a given Event Record relates and may be unable to comply with a request under this Section unless you supply additional information sufficient to permit identification of the relevant records. Requests should therefore specify, so far as you are able, the approximate date and time of your visit and the network from which it was made.

No fee is charged for the exercise of these rights. Requests are ordinarily responded to within thirty days.

15. United States Privacy Notices

The following disclosures are provided for residents of States having enacted comprehensive consumer privacy legislation, including California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon and Montana.

Categories of personal information collected. In the twelve months preceding the effective date of this Policy, the Site has collected the categories described in Section 4, which correspond to the statutory categories of internet or other electronic network activity information and, in respect of approximate location, identifiers.

Sale and sharing. The controller has not sold personal information and has not shared personal information for cross-context behavioural advertising in the twelve months preceding the effective date of this Policy, and does not do so. Because no sale or sharing occurs, no “Do Not Sell or Share My Personal Information” mechanism is provided.

Sensitive personal information. The controller does not collect or process sensitive personal information as that term is defined under applicable State law.

Non-discrimination. The controller does not discriminate against any consumer for exercising any right conferred by applicable State privacy law.

Authorised agents. Requests may be submitted by an authorised agent on your behalf, subject to verification of the agent's authority.

16. Do Not Track and Global Privacy Control

The Site does not presently detect or respond to the DNT request header or to the Global Privacy Control signal. No uniform industry standard governs the interpretation of the DNT header. The Global Privacy Control signal operates, under applicable State law, to communicate an opt-out of the sale or sharing of personal information; as set out in Section 15, no such sale or sharing occurs, with the result that the signal has no operative effect in respect of the Site.

17. How to Prevent Collection

The measurement mechanism described in Section 4 depends entirely upon the execution of JavaScript in your browser. Collection may therefore be prevented completely by any of the following means:

No feature of the Site is degraded, withheld, or made conditional upon permitting measurement.

18. Children's Privacy

The Site is directed to a professional audience and is not directed to children. The controller does not knowingly collect personal information from any child under the age of thirteen, nor, where the GDPR applies, from any child under the age of sixteen. Should the controller become aware that information relating to such a child has been collected, that information will be deleted promptly. A parent or guardian who believes that such information may have been collected is invited to make contact as set out in Section 21.

19. Third-Party Links

The Site contains hyperlinks to third-party websites and platforms, including professional networking, code hosting, and career services platforms. Activation of such a hyperlink causes your browser to transmit a request to the operator of the destination site, which may collect information concerning you in accordance with its own practices. The controller does not transmit any information concerning you to such operators and is not responsible for their practices. You are encouraged to review the privacy policy of any destination site.

20. Amendments

This Policy may be amended from time to time in order to reflect changes to the Site, to the practices described herein, or to applicable legal requirements. Any amended Policy takes effect upon publication at this address, and the effective date and version number appearing at the head of this Policy will be updated accordingly. Material amendments will be reflected by an increment to the major version number. Your continued use of the Site following publication of an amended Policy constitutes acknowledgement of the amended Policy.

21. Contact

Enquiries concerning this Policy, and requests to exercise any right described in Section 14 or Section 15, may be addressed to the controller by electronic mail at thecorbinfloyd@gmail.com. Please mark your communication for the attention of “Privacy” and include sufficient particulars to permit the identification of the records to which your request relates.