Legal · Privacy
Privacy Policy
This site runs on as little personal data as it can: first-party analytics with hashed identifiers, Google Analytics for aggregate audience measurement, and no advertising networks or data brokers. This policy sets out exactly what is collected, why it is collected, how long it is kept, who else can see it, and what you can ask us to do about it.
Effective 5 August 2026 · Version 1.0 · Applies to https://mrvictor.dev and its sub-pages
Who we are and how to reach us
This website, mrvictor.dev, is owned and operated by Laxtic Software Services, the trading name under which Victor Ezeigwe carries on business as an independent software developer and consultant. In this policy “we”, “us” and “our” mean Laxtic Software Services; “you” means any person who visits the site or sends us information through it.
For the purposes of Nigerian, European, United Kingdom and Californian data protection law, Laxtic Software Services is the data controller the party that decides why and how your personal information is processed.
- Controller: Laxtic Software Services (Victor Ezeigwe, sole proprietor)
- Base of operations: Lagos, Nigeria we work fully remotely and serve clients worldwide
- Privacy contact: [email protected] this address reaches Victor Ezeigwe directly and is the single point of contact for every request, question or complaint described in this policy
- Website: https://mrvictor.dev
We have not appointed an external data protection officer. Given the scale and nature of the processing described below, one is not required; enquiries go to the address above and are answered personally.
Scope of this policy
This policy covers the personal information we process through this website and the application programming interface that serves it: the contact form, the newsletter subscription form, and the first-party analytics that count page views and clicks.
It does not cover:
- Third-party services you are handed off to. Booking a call through Calendly, completing a purchase on an external checkout page, or opening one of our social profiles takes you onto someone else’s platform, governed by their privacy policy and not by ours. Section 11 of our Terms of Service says the same thing about their terms.
- Client engagements. Once a consulting or development engagement is signed, the processing of any data inside that project is governed by the written agreement for that engagement including, where required, a separate data processing agreement and not by this website policy.
- Ordinary correspondence. If you email us directly rather than using the form, that message lives in our mailbox and is handled under the same principles, but it is not processed by this website.
The information we collect
We collect only what a specific feature needs in order to work. There is no hidden collection, no fingerprinting, and no enrichment of your data from outside sources.
3.1 The contact form
When you submit the contact form either on the contact page or in the contact section of the home page we receive and store:
- Your name, as you type it
- Your email address, so that a reply can reach you
- A subject line, if you provide one (optional)
- Your message, and anything you choose to put in it please do not send passwords, payment details, government identifiers or other sensitive information through a web form
- A SHA-256 hash of your IP address and your browser’s user-agent string, recorded with the submission purely to detect and rate-limit abuse of the form
3.2 The newsletter
If you subscribe to the newsletter we store your email address and the source of the subscription (for example, “website”), together with the date it was created and whether it is currently active.
Please note one thing plainly: we do not currently operate double opt-in. No confirmation email is sent to verify that the address belongs to you submitting the form is what subscribes it. This means you should only enter your own address. Every issue we send carries a way to unsubscribe, and an unsubscribe request sent to [email protected] is honoured promptly and without question.
3.3 First-party analytics
We count how the site is used so that we know which work is worth continuing. The analytics are written by us, stored on our own server, and never shared. For each event - a page view, a link click, a social click, a product click, a form submission we record:
- The event type and, where relevant, which item it refers to (for example, which project card was clicked)
- The path on this site where it happened
- The referring URL, if your browser sent one
- Your browser’s user-agent string (browser and operating system family)
- A SHA-256 hash of your IP address a one-way fingerprint used to tell two visits apart and to spot abuse. We do not store the address itself, and the hash cannot be reversed back into it by us
Our first-party analytics use no cookie and no local storage identifier, and there is no session recording, no heatmap and no advertising pixel. The one third-party measurement tool on the site is Google Analytics 4, described in section 5 used for aggregate audience measurement only, never joined to anything you submit through a form.
3.4 Scheduling a call
Where a booking link is published on the site, scheduling is handled by Calendly. Selecting that link takes you to Calendly’s own service, where the name, email address, time zone and any answers you give to their booking questions are collected by Calendly and shared back with us so that the meeting can happen. Their handling of that data is governed by Calendly’s privacy notice.
3.5 Purchases
Digital products and courses sold through this site are fulfilled by external checkout processors. Clicking a purchase link sends you to that processor’s hosted checkout page. No card number, CVV, bank detail or other payment credential is ever entered on, passed through, or stored by mrvictor.dev. The processor collects what it needs to take the payment and deliver the file, applies its own privacy policy, and reports back to us only the commercial outcome that a sale occurred, and the customer email address needed to support the purchase.
3.6 Hosting and server logs
The pages you are reading are static files delivered by Firebase Hosting (Google). The content of the site is fetched from an application programming interface we run ourselves on a virtual private server. Both keep ordinary technical request logs - including IP address, timestamp, requested path, response code and user agent for security, capacity and abuse-prevention purposes. These are infrastructure logs, separate from the analytics described in 3.3.
3.7 What we never collect
- Payment card or bank account details of any kind
- Government identifiers, passport numbers or national identity numbers
- Special categories of data health, biometrics, genetics, race or ethnic origin, political opinions, religious beliefs, trade union membership, sex life or sexual orientation. We do not ask for any of it, and you should not volunteer it
- Precise geolocation from your device
- Contacts, calendars, files or anything else from your device
Why we process your information, and our legal bases
Every item above exists for one narrow reason. Where the General Data Protection Regulation, the UK GDPR or the Nigeria Data Protection Act asks us to name a lawful basis, it is named here.
- Contact form submissions to read your enquiry, reply to it, and keep a record of the conversation. Basis: performance of a contract or steps taken at your request before entering one where you are enquiring about an engagement, and legitimate interests (responding to correspondence addressed to us) otherwise.
- Hashed IP and user agent on submissions to rate-limit, detect automated abuse, and keep the form usable. Basis: legitimate interests in the security and availability of our own service.
- Newsletter address to send you the newsletter you asked for. Basis: consent, given by submitting the form, and withdrawable at any time.
- Analytics events to understand which pages, projects and products are actually of interest, in aggregate. Basis: legitimate interests in measuring and improving our own website. Because no information is stored on or read from your device, no cookie consent is required for this processing.
- Server and hosting logs to keep the site up and to investigate faults and attacks. Basis: legitimate interests in security and service continuity.
- Purchase records reported back by a checkout processor to fulfil the order, provide support and keep the accounting records the law requires. Basis: performance of a contract and compliance with a legal obligation.
Where we rely on legitimate interests we have considered whether those interests are overridden by your rights and freedoms, and concluded they are not: the data involved is minimal, pseudonymised where practical, never sold, never combined into a profile of you, and used only to run and improve a personal professional website. You can object to that processing at any time see section 11.
How long we keep information
We keep personal information only for as long as it is doing a job, then delete it. Our standard periods are:
- Contact form submissions for the life of the enquiry and up to 24 months after our last correspondence, so that we can pick up a conversation that resumes. Deleted sooner on request.
- Newsletter subscriptions until you unsubscribe or ask for deletion. An unsubscribed record is deactivated immediately and purged within 12 months.
- Analytics events raw event rows for up to 24 months, after which they are deleted. Aggregate counts that contain no identifier of any kind may be kept indefinitely.
- Server and hosting logs typically 30 to 90 days, depending on the provider’s own rotation.
- Purchase and accounting records for as long as tax and accounting law requires us to retain them, which in Nigeria is generally six years from the end of the relevant financial year.
Backups are kept on a rolling basis and expire on their own schedule; a deletion request is applied to live systems immediately and works its way out of backups as they rotate.
Service providers and sub-processors
We keep the supply chain deliberately short. The following parties may process personal information on our behalf or in connection with this site. Each is bound by its own terms and privacy commitments, and none of them is permitted to use your data for their own marketing on our instruction.
- Google Firebase Hosting. Serves the static website and its content delivery network; processes request metadata including IP address. See the Firebase privacy and security notice and the Google Privacy Policy.
- Our infrastructure provider. A virtual private server hosts the application programming interface and the PostgreSQL database holding contact submissions, subscribers and analytics events. The provider has no application-level access to that data and acts only as an infrastructure processor.
- Calendly. Scheduling, where a booking link is offered. See Calendly’s privacy notice.
- External checkout processors. Payment collection and digital delivery for products and courses. The processor handling a given item is identified on its own checkout page before you pay, and its privacy policy and terms apply to that transaction. Examples of the kind of processor used include Gumroad, Lemon Squeezy, Paystack and Stripe.
- Our email provider. Carries correspondence and newsletter issues to and from us.
We do not sell personal information, we do not rent or trade mailing lists, and we do not share your data with advertising networks, data brokers or analytics vendors. If we ever engage a new processor that materially changes this picture, this section is updated before the change takes effect.
International transfers
We are based in Nigeria and our providers operate globally, so personal information associated with this site may be stored or processed in Nigeria, the United States, the European Union or elsewhere, depending on the provider and the region its infrastructure serves.
Where personal data is transferred out of the European Economic Area or the United Kingdom, we rely on the transfer mechanisms our providers have put in place principally Standard Contractual Clauses (with the UK Addendum where applicable) and, where a provider is certified, the EU–US Data Privacy Framework and its UK extension. Where personal data is transferred out of Nigeria, we do so on the bases permitted by the Nigeria Data Protection Act principally an adequate level of protection in the destination, appropriate contractual safeguards, or the necessity of the transfer for the performance of a contract with you.
You may request details of the specific safeguard applying to a given transfer by writing to [email protected].
When we disclose information
Your information leaves our systems in only four circumstances:
- To the service providers listed in section 7, to the extent each one needs it to perform its function.
- When the law requires it a valid court order, subpoena, regulatory demand or other lawful process. We assess every such request, comply only to the extent we must, and tell you unless we are legally prohibited from doing so.
- To protect rights and safety where disclosure is necessary to investigate fraud or abuse, enforce our Terms of Service, or protect the security of our systems or the rights of others.
- In a business transfer if the business is ever sold, merged or reorganised, records may transfer to the successor, who would remain bound by this policy or give you notice of a replacement before anything changes.
Beyond these, we do not disclose your information to anyone. In particular we do not sell it, and we do not share it for cross-context behavioural advertising.
How we protect information
No system is perfectly secure, but the measures here are proportionate to the small amount of data involved and are applied consistently:
- Encryption in transit. The website, the administrative portal and the application programming interface are served exclusively over HTTPS with modern TLS.
- Pseudonymisation by default. IP addresses are never written to the database in the clear only a SHA-256 hash is stored, for contact submissions and for analytics alike.
- Hardened administrative access. The portal that can read contact submissions and subscribers is protected by a password hashed with argon2id and by mandatory time-based two-factor authentication. Sessions use short-lived access tokens with rotating refresh tokens, and repeated failed logins lock the account.
- Least privilege. Administrative interfaces to the database and server are restricted to the operator; automation keys are individually issued, scoped and revocable.
- Abuse controls. Public write endpoints (contact, subscribe, analytics) are rate-limited per address, and standard security headers are applied to every response.
- Nothing sensitive to lose. The single most effective control is that we do not hold payment credentials, identity documents or special-category data at all.
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within the period the law requires 72 hours under the GDPR and the UK GDPR and notify affected individuals directly where the risk to them is high.
Your rights and how to exercise them
Wherever you are, we will honour the following requests in respect of the personal information we hold about you:
- Access a copy of the personal information we hold about you, and an explanation of what we do with it.
- Correction rectification of anything inaccurate or incomplete.
- Deletion erasure of your information where we no longer have a legitimate reason to keep it.
- Objection to processing we carry out on the basis of legitimate interests, including our analytics.
- Restriction a pause on processing while a dispute about accuracy or legitimacy is resolved.
- Portability the information you gave us, in a structured, commonly used, machine-readable format, sent to you or directly to another controller where technically feasible.
- Withdrawal of consent for the newsletter, at any time, without affecting anything sent before you withdrew it.
- Complaint to us, and to your data protection authority.
How to make a request
Email [email protected] with “Privacy request” in the subject line and tell us what you want done. There is no form to fill in and no fee. We will acknowledge promptly and respond within 30 days, extending only where a request is genuinely complex and telling you if we do. If we cannot verify that the request comes from the person the data belongs to, we may ask a limited follow-up question usually just replying from the address concerned before acting.
If we refuse a request we will explain why, and tell you how to challenge that decision.
Nigeria NDPR and the Nigeria Data Protection Act
As a Nigerian business we process personal data in accordance with the Nigeria Data Protection Regulation 2019 (NDPR) and the Nigeria Data Protection Act 2023 (NDPA), and we observe their governing principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; and integrity, confidentiality and accountability.
Under the NDPA you have the rights set out in section 11 above, exercisable through the same channel. You also have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC) if you believe your data has been mishandled. We would ask that you raise it with us first most issues are a misunderstanding we can resolve the same week but you are not obliged to.
We do not process personal data at a scale that requires the appointment of a Data Protection Officer under the NDPA, and we are not a data controller of major importance. Should that change, we will register and appoint as required and update this policy.
European Economic Area and United Kingdom GDPR
If you are in the European Economic Area or the United Kingdom, the General Data Protection Regulation or the UK GDPR applies to our processing of your personal data. The controller is Laxtic Software Services, identified in section 1. The categories of data, purposes and lawful bases are set out in sections 3 and 4; retention in section 6; recipients in section 7; and transfers in section 8.
Your rights under those regulations are the rights listed in section 11 access (Article 15), rectification (16), erasure (17), restriction (18), portability (20), objection (21) and withdrawal of consent (7(3)). You also have the right to lodge a complaint with your national supervisory authority, or with the Information Commissioner’s Office in the United Kingdom.
Representative. We have not appointed a representative under Article 27. Our processing of EEA and UK personal data is occasional, is limited to the categories described in section 3, includes no special categories of data and no criminal offence data, and is unlikely to result in a risk to the rights and freedoms of individuals. If the nature or scale of our processing changes so that a representative is required, we will appoint one and name them here.
Consequences of not providing data. Everything on this site is optional. You can read every page without giving us anything. Declining to complete the contact form simply means we have no way to reply; declining to subscribe means you do not receive the newsletter. Nothing else is withheld from you.
California CCPA and CPRA
If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act gives you specific rights, and requires us to describe our practices in its own vocabulary.
Categories of personal information collected in the last twelve months:
- Identifiers name, email address, and a hashed internet protocol address (collected through the contact form, the newsletter form and analytics; from you directly and from your browser).
- Internet or other electronic network activity information pages viewed, items clicked, referring URL and user-agent string (collected through our first-party analytics).
- Commercial information the fact that a purchase of a digital product or course occurred, reported back to us by the external checkout processor.
We collect these for the business purposes described in section 4, retain them for the periods in section 6, and disclose them only as described in sections 7 and 9. We do not collect sensitive personal information as the CPRA defines it.
We do not sell personal information, and we do not share it for cross-context behavioural advertising and we have not done so in the preceding twelve months, including in respect of anyone we know to be under sixteen.
Your California rights: to know what we collect, use and disclose; to delete personal information we hold about you; to correct inaccurate personal information; to opt out of sale or sharing (inapplicable here, as we do neither); to limit the use of sensitive personal information (inapplicable, as we collect none); and to be free from discrimination for exercising any of them. We offer no financial incentives in exchange for personal information.
Exercise any of these by emailing [email protected]. An authorised agent may act for you if they provide written permission signed by you, and we may ask you to confirm the authority directly.
Children’s privacy
This site is a professional portfolio and a business site. It is not directed at children, and it is not intended for use by anyone under the age of sixteen. We do not knowingly collect personal information from children.
If you are a parent or guardian and believe a child has provided us with personal information through the contact form or the newsletter, email [email protected] and we will delete the record promptly and confirm when it is done.
Third-party links and embedded content
This site links out constantly to code repositories, articles, social profiles, course platforms, checkout pages and scheduling tools. Once you follow one of those links you are on a service we do not operate and cannot control. Their collection practices are theirs, their cookies are theirs, and this policy stops at our boundary.
We choose the services we link to carefully and name the significant ones in section 7, but we encourage you to read the privacy policy of any third-party service before giving it your data.
Automated decision-making and profiling
We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you, and we do not build behavioural profiles of visitors. Analytics are counted and read in aggregate; they are not used to score, categorise or target any individual.
Changes to this policy
As the site changes, this policy changes with it. The current version is always the one published at mrvictor.dev/privacy, and the effective date at the top of the page tells you when it took effect.
For material changes a new category of data, a new purpose, a new processor that meaningfully alters where your data goes we will update the effective date and, where the change affects information you have already given us and we have a way to reach you, tell you directly. Continuing to use the site after a change takes effect means the updated policy applies to you.
Contact and complaints
Questions, requests and complaints about privacy all go to the same place, and are read by the person who built the site:
- Email: [email protected]
- Post: Laxtic Software Services, Lagos, Nigeria a postal address is available on request for formal service
- Contact form: mrvictor.dev/contact
If you are not satisfied with how we have handled a matter, you may complain to your data protection authority: the Nigeria Data Protection Commission in Nigeria, your national supervisory authority in the European Economic Area, the Information Commissioner’s Office in the United Kingdom, or the California Privacy Protection Agency or Attorney General in California.
The companion document to this one is our Terms of Service, which governs your use of this site and anything you buy through it.