MaherNova Back to portfolio Cookie preferences
Last Updated: 9 September 2026

Privacy Notice

This notice explains how MaherNova handles personal data collected through the MaherNova website and related services.

Controller

Maher Aldndan, trading as MaherNova as a sole trader, is responsible for the personal data processed through this website.

Contact details:

  • Legal owner: Maher Aldndan (sole trader), trading as MaherNova
  • Contact email: maheraldndan@yahoo.co.uk
  • Business correspondence address: Belmont Row, Birmingham B4 7RQ, United Kingdom
  • ICO registration number, if applicable: To be confirmed

Personal Data We Collect

We may collect:

  • Contact details you send by email, including your name, email address, company, phone number, subject, and message.
  • Account details for authorised administrators, including email address, password hash, name, role, and authentication metadata.
  • Uploaded file metadata, including original filename, stored filename, file type, size, public URL, visibility, and uploader.
  • Claude demo messages that you submit through the website.
  • Technical information needed to operate and secure the website, such as server logs, request metadata, and security events.

How We Use Personal Data

We use personal data to:

  • Respond to enquiries and project requests.
  • Operate and secure the website and backend systems.
  • Provide the Claude demo and return AI-generated responses.
  • Manage authorised admin access.
  • Maintain project, blog, contact, and upload records.
  • Meet legal, accounting, security, and regulatory obligations.

Legal Bases

Depending on the context, we rely on:

  • Legitimate interests: responding to business enquiries, running the website, securing systems, and improving services.
  • Contract or steps before entering a contract: discussing and delivering requested work.
  • Consent: optional browser storage for Claude demo chat history and any future non-essential cookies or analytics.
  • Legal obligation: records needed for compliance, accounting, security, or regulatory purposes.

Claude Demo and Anthropic

If the Claude demo is enabled, your prompt and recent conversation context are sent to the MaherNova server and then to Anthropic so Claude can generate a response.

Do not submit passwords, payment details, health data, confidential client material, trade secrets, or any personal data that is not necessary for the demo.

Anthropic may process data as described in its own terms and privacy materials. Review Anthropic's policies before enabling the demo in production.

Browser Storage

The website saves your cookie preference in localStorage until changed or cleared. The admin dashboard uses an essential HttpOnly session cookie on the API host and keeps the chosen API address in localStorage. JavaScript cannot read the authentication cookie. Logout clears and revokes the session. Browser restoration may retain the cookie but cannot extend its signed expiry. See the Cookie and Storage Notice for exact names and controls.

With Accept All under notice version 3, the public portfolio sends a page-view event to the MaherNova API for an optional daily aggregate counter. The event contains only its type and consent version, not visitor identifiers, URLs, referrers or message content. No individual events are retained by this counter. Counts are per API process and reset on restart or on the next request after the UTC day changes. Hosting providers still process normal network metadata such as IP addresses. This measurement relies on consent; Cookie preferences lets you choose Essential Only to stop future events. Optional chat storage remains a separate choice.

API error records contain a generated request ID, status and a generic error category. Production application error logging omits raw exception stacks, request URLs, query strings, bodies, cookies and credentials. Infrastructure logging is configured separately by the operator.

The Claude demo can optionally remember recent chat turns in your browser using local storage. This is disabled unless you choose to remember the chat. You can clear stored chat history using the Clear Chat button or your browser settings.

Sharing Personal Data

We may share personal data with:

  • Hosting, database, email, security, and infrastructure providers.
  • Anthropic, if the Claude demo is enabled and you send a prompt.
  • Professional advisers or authorities where required by law.

Before launch, document all production processors, their locations, and their data processing terms.

International Transfers

Some providers may process personal data outside the UK. Before launch, confirm the transfer safeguards used by each provider, such as adequacy regulations, the UK International Data Transfer Agreement, or an approved addendum to standard contractual clauses.

Retention

Before launch, define exact retention periods. A practical starting point is:

  • Contact enquiries: up to 24 months after the last meaningful interaction.
  • Project/client records: for the contract period and then as required for legal/accounting purposes.
  • Admin accounts: while access is needed, then deleted or disabled promptly.
  • Uploaded files: while published or needed for service delivery.
  • Server/security logs: normally 30-180 days unless needed for investigation.
  • Claude demo chat in browser storage: treated as expired after 24 hours and removed on the next app read; data may remain on the device while the site is closed. Clear Chat, switching off Remember this chat, or browser settings removes it earlier.

Your Rights

Under UK data protection law, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal data. You may also have the right to withdraw consent where processing is based on consent.

To exercise your rights, email maheraldndan@yahoo.co.uk.

You also have the right to complain to the UK Information Commissioner's Office: https://ico.org.uk/

Security

We use technical and organisational measures intended to protect personal data. Before production launch, confirm HTTPS, access control, secure secrets management, backups, logging, vulnerability management, and processor security terms.

Updates

This notice should be reviewed before launch and whenever processing, providers, retention periods, or contact details change.