Privacy & Compliance

This page covers what aifordbas.com collects, why, where it goes, & what rights you have over it, under United States law (including the California Consumer Privacy Act as amended by the CPRA) & international law (including the EU General Data Protection Regulation & UK GDPR). It also carries the site's terms of use. Effective date: 2026-08-13. The site is operated by Ward Minson; reach me at [email protected] for anything on this page.

What we collect

The contact form collects your name, email address, message, & two optional fields: company & SQL Server instance count. Submissions are stored in this site's database & delivered to our mailbox by email. That's the record we use to reply to you.

If you register an account, we store your username, email address, & password. Passwords are stored as argon2 hashes, never in plain text. Signing in sets one session cookie, WTM64_admin_session, marked HttpOnly & Secure; it exists to keep you signed in & for nothing else.

Like every website, our infrastructure keeps standard server logs that include IP addresses & requested URLs, used for security monitoring & troubleshooting. Your light/dark theme preference is kept in your browser's localStorage & never transmitted to us.

What we do not do

No analytics trackers. No advertising. No third-party marketing cookies. We do not sell personal information & we do not share it for cross-context behavioral advertising, as the CCPA/CPRA defines those terms. Because there is no sale or sharing to opt out of, Global Privacy Control signals are honored by default. Links to LinkedIn (the newsletter & group) leave this site; LinkedIn's own privacy policy governs what happens there.

Legal bases for processing (GDPR Article 6)

Contact form submissions: your consent, given by submitting the form (Article 6(1)(a)). Accounts: performance of a contract, the account you asked us to create (Article 6(1)(b)). Server logs & security monitoring: our legitimate interest in keeping the site running & secure (Article 6(1)(f)).

Where your data lives

This site is self-hosted in the United States. Cloudflare provides the CDN & TLS layer in front of it & processes traffic metadata, including IP addresses, as part of that service. If you visit from the EU, UK, or elsewhere, your data is transferred to & processed in the United States.

Retention

Contact submissions are kept for as long as the correspondence they belong to stays active, then as ordinary mailbox & database history. Account data is kept until you ask us to delete the account. Server logs rotate on a fixed schedule & are not archived long-term.

Your rights

Under the GDPR & UK GDPR you can request access to your personal data, rectification, erasure, restriction of processing, data portability, & you can object to processing based on legitimate interest. You also have the right to lodge a complaint with your supervisory authority.

Under the CCPA/CPRA, California residents can request to know what personal information we hold, request deletion, request correction, & will not receive discriminatory treatment for exercising any of these rights. Since we do not sell or share personal information, there is no opt-out to exercise.

To exercise any right, email [email protected] from the address the request concerns; that is also how we verify the request. We respond within 30 days for GDPR requests & 45 days for CCPA requests, the statutory windows.

Cookies

One cookie, WTM64_admin_session, set only when you sign in, strictly necessary for the session, & deleted when you sign out. Strictly necessary cookies do not require consent banners under the ePrivacy Directive, which is why you don't see one here.

Children

This site is written for working database administrators & is not directed at children. We do not knowingly collect personal information from children under 13 (COPPA) or under 16 (GDPR). If you believe a child has submitted data here, email us & we will delete it.

Security

Every page is served over TLS. Passwords are argon2-hashed. Access to the systems behind this site follows least privilege, the same standard applied in the SOC 2, NERC CIP, HIPAA, & PCI DSS environments described on the About page. Report a suspected vulnerability to [email protected] & you will get a human answer.

Terms of use

Content on this site is provided for information, as-is. Articles describe our environment & our results; your SQL Server estate is not our environment, & nothing here is professional advice for it. Test before you run anything in production.

Accounts are for legitimate use of this site's features. We may suspend or delete accounts used for abuse, spam, or attempts to compromise the service. You can delete your account at any time by emailing us.

These terms & this policy are governed by the laws of the State of Arkansas, United States. If we change this page, the change appears here with a new dated entry; we do not change it silently.

Change log

2026-08-13: first published.