Skip to content
PhiloCyber logo

Privacy Policy

Last updated: September 2026

1. Who We Are

PhiloCyber is the personal website of Ricardo Prieto, based in Argentina. It brings together writing, talks and practical resources, with a focus on AI safety grounded in cybersecurity experience. Ricardo is not taking on new consulting engagements through this website.

This Privacy Policy explains what personal data we collect through this website, why we collect it, how we protect it, and the rights you have over it. For the purposes of applicable data protection law — including Argentina’s Personal Data Protection Law No. 25,326 and, where applicable, the EU General Data Protection Regulation (GDPR) — the data controller is Ricardo Prieto, reachable through our contact form.

2. What We Collect

We collect only the minimum information needed to operate this website and respond to you:

  • Contact form submissions: your name, email address, subject, and message. Submissions are screened by Cloudflare Turnstile (bot detection) and processed through the configured contact destinations: Supabase for storage and Resend for email notifications.
  • Email subscriptions: if you subscribe to our updates, we collect your email address and use it solely to send you the content you asked for.
  • Analytics data: pages visited and time spent on the site, used to understand readership and improve our content.
  • Technical information: browser and device type, collected to keep the site compatible and secure.
  • Cookies: used for site functionality, analytics, and remembering your preferences — never for advertising. See our Cookie Policy for details.

Interactive features such as quizzes run without registration and do not collect personal data.

3. How We Use Your Information

  • To respond to your questions, corrections and relevant research, professional or community correspondence.
  • To send you the updates or content you explicitly subscribed to.
  • To analyze readership and improve the website and its content.
  • To keep the website secure and prevent abuse (for example, bot screening on forms).

We do not sell, rent, or share your personal information with third parties for marketing purposes, and we do not build advertising profiles.

4. Third-Party Service Providers

A small number of service providers process data on our behalf to run this website:

  • Cloudflare: hosting, security, and Turnstile bot detection.
  • Supabase: database storage for contact submissions and site analytics.
  • Resend: transactional email delivery for contact form notifications.

Each provider processes data under its own privacy policy and contractual safeguards, and only for the purposes described above.

5. International Data Transfers

PhiloCyber is based in Argentina, a jurisdiction whose data protection regime the European Commission has recognized as providing an adequate level of protection. Some of the service providers listed above process data in the United States or other countries; where required, such transfers are covered by the providers’ own adequacy mechanisms and safeguards. If you are in the EU or EEA, your data benefits from the protections described in this policy wherever it is processed.

6. How We Protect Data

Security is our profession, and we hold ourselves to the standard we advise others to meet:

  • Encryption: data is encrypted in transit (TLS) and at rest.
  • Least-privilege access: access to personal data is restricted and controlled.
  • Ongoing review: we regularly review and update our safeguards against unauthorized access or disclosure.

For client engagements performed under contract, the practice applies stricter controls as a matter of principle: isolated per-client environments, a strict AI-tooling rule (no client data is ever sent to public AI services without prior written approval — private or local tooling is the default), and deletion of engagement evidence within 90 days of delivery, with certified deletion on request. These principles are described here for transparency; the specific obligations for each engagement are defined in the applicable service agreement.

7. Data Retention

  • Contact inquiries: kept for as long as needed to handle your request and a reasonable follow-up period, then deleted.
  • Subscriptions: kept until you unsubscribe, which you can do at any time.
  • Client engagement data: governed by the applicable service agreement; by default, engagement evidence is deleted within 90 days of delivery.

8. Your Rights

You have control over your personal data. Depending on your jurisdiction, your rights include:

  • Access: request a copy of the personal data we hold about you.
  • Rectification: ask us to correct inaccurate or incomplete information.
  • Deletion: request that we remove your personal data from our systems.
  • Objection and opt-out: object to processing, disable cookies via your browser settings, or unsubscribe from communications.
  • Withdrawal of consent: revoke your consent to data collection at any time by contacting us.

Under Argentine Law No. 25,326, you may exercise your right of access free of charge at intervals of no less than six months, unless you demonstrate a legitimate interest (Art. 14(3)). The Agencia de Acceso a la Información Pública (AAIP), as the enforcement authority, is empowered to receive complaints and reports of non-compliance. If you are in the EU or EEA, you also have the right to lodge a complaint with your local supervisory authority under the GDPR.

To exercise any of these rights, contact us as described in Section 10.

9. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for operational, legal, or regulatory reasons. Any changes will be posted on this page with an updated revision date.

10. Contact Us

If you have questions, concerns, or requests about this Privacy Policy or our data practices, reach out through our contact form or email us at info@philocyber.com. We respond promptly and transparently to all inquiries.

Privacy Policy | PhiloCyber