Last updated: August 31, 2026
This Privacy Policy Agreement (hereinafter referred to as "the Agreement") is entered into as of May 6, 2025, by and between VitalyBook.com, the personal author website managed by Vitaly Kirkpatrick (formerly published as Vitaly Magidov) (hereinafter referred to as "VitalyBook.com," "we," "us," or "our"), and all users, visitors, and contributors accessing or interacting with the website (hereinafter referred to as "Users," "you," or "your"). This Agreement sets forth the terms and conditions governing the collection, use, storage, and protection of personal and non-personal data on VitalyBook.com, in accordance with applicable U.S. (including CCPA), European (GDPR), and other international privacy regulations. By accessing or using VitalyBook.com, you acknowledge and agree to the practices described herein.1.1 Users have the following rights regarding their personal information collected and processed by VitalyBook.com: (a) Right to Access: Request confirmation of whether personal data is being processed and obtain a copy of such data. (b) Right to Rectification: Request correction of inaccurate or incomplete personal data. (c) Right to Erasure (Right to be Forgotten): Request deletion of personal data under certain circumstances. (d) Right to Restriction of Processing: Request limitation of processing of personal data in specific situations. (e) Right to Object to Processing: Object to processing of personal data based on legitimate interests or for direct marketing purposes. (f) Right to Data Portability: Receive personal data in a structured, commonly used, and machine-readable format and transmit it to another controller, where technically feasible.
2.1 Users may request access to their personal data by contacting VitalyBook.com via the contact form on the website or by email at [email protected]. 2.2 Users must provide sufficient information to verify their identity, including full name, email address, and any other information necessary for verification. 2.3 VitalyBook.com will provide the requested data in an electronic format (such as PDF or CSV). 2.4 VitalyBook.com may refuse repetitive, manifestly unfounded, or excessive requests, as permitted by law.
3.1 Users may request correction of inaccurate or incomplete personal data by emailing [email protected] with "Data Correction Request" in the subject line. 3.2 Users must specify the data to be corrected, the proposed correction, and provide supporting documentation if necessary. 3.3 VitalyBook.com will implement valid corrections within 30 days of receiving the request.
4.1 Users may request deletion of their personal data by emailing [email protected] with "Data Deletion Request" in the subject line. 4.2 Data will be deleted if: (a) It is no longer necessary for the purposes for which it was collected. (b) The user withdraws consent and there is no other legal ground for processing. (c) The data has been unlawfully processed. 4.3 VitalyBook.com may retain data where required by law or for the establishment, exercise, or defense of legal claims. 4.4 Deletion requests will be completed within 30 days of receiving a valid request. 4.5 Data shared with third-party services (such as Google Analytics) will be anonymized where possible; complete removal may be subject to the third party’s policies.
5.1 Users may request restriction of processing by emailing [email protected] with "Data Restriction Request" in the subject line. 5.2 Restriction may be requested if: (a) The accuracy of the data is contested. (b) Processing is unlawful and the user opposes erasure. (c) VitalyBook.com no longer needs the data, but the user requires it for legal claims. (d) The user has objected to processing pending verification of legitimate grounds. 5.3 While processing is restricted, VitalyBook.com will store the data but not process it further except as permitted by law.
6.1 Users may object to processing of their data based on legitimate interests or for direct marketing by emailing [email protected] with "Objection to Processing" in the subject line. 6.2 Upon receiving a valid objection, VitalyBook.com will cease processing the data for the relevant purposes, unless there are compelling legitimate grounds or legal requirements to continue.
7.1 Users may request their personal data in a structured, commonly used, and machine-readable format by emailing [email protected] with "Data Portability Request" in the subject line. 7.2 Data portability applies only to data provided by the user and processed by automated means, where technically feasible. 7.3 VitalyBook.com will provide the data in a format such as CSV or JSON within 30 days of receiving a valid request.
8.1 Users may exercise any of the above rights by contacting VitalyBook.com at [email protected] or via the contact form on the website. 8.2 Users should clearly state the right they wish to exercise and provide sufficient information for verification.
9.1 VitalyBook.com will verify the identity of users before fulfilling any request related to personal data. 9.2 Users may be asked to provide additional information to confirm their identity. 9.3 No information will be disclosed, corrected, or deleted without proper verification.
10.1 VitalyBook.com will respond to user requests within 30 days of receipt, as required by applicable law. 10.2 If additional time is required due to complexity or volume of requests, users will be notified of the extension and the reasons for the delay.
11.1 Exercising these rights is free of charge. 11.2 VitalyBook.com may charge a reasonable fee for repetitive, manifestly unfounded, or excessive requests, as permitted by law. Users will be informed of any applicable fees before processing the request.
12.1 Certain rights may be limited or denied where VitalyBook.com is legally required to retain data, where fulfilling the request would adversely affect the rights and freedoms of others, or where technical feasibility prevents compliance. 12.2 Users will be informed of the reasons for any denial or limitation of their request.
13.1 Where processing is based on user consent (such as newsletter subscriptions), users may withdraw consent at any time by using the unsubscribe link in emails or by contacting [email protected]. 13.2 Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
1.1. Contact Form Submissions: Names, email addresses, and messages submitted via the website contact form. 1.2. Newsletter Subscribers: Email addresses collected for the purpose of distributing newsletters and updates. 1.3. User Comments: Names, email addresses (if provided), and comment content posted on blog posts or other interactive sections. 1.4. Account Data (if applicable): Usernames, passwords (or password hashes), and profile information associated with user accounts. 1.5. Analytics Data: Pseudonymized or anonymized IP addresses, browser types, device information, and website usage data collected through analytics tools such as Google Analytics. 1.6. Transaction Data (if applicable): Order details, shipping addresses, and payment information related to purchases made directly through the website.
2.1. Contact Form Submissions: Retain for 12 months from the date of submission. 2.2. Newsletter Subscribers: Retain email addresses until the subscriber unsubscribes from the newsletter. 2.3. User Comments: Retain indefinitely or until the user requests removal, unless legal obligations require otherwise. 2.4. Account Data (if applicable): Retain as long as the account remains active. If an account is inactive for 24 months, notify the user and provide an option to reactivate. If no response is received, delete the account and associated data. 2.5. Analytics Data: Retain user-level data for 14 months in accordance with analytics provider settings. Retain aggregated, anonymized data indefinitely for statistical purposes. 2.6. Transaction Data (if applicable): Retain for seven years to comply with accounting and tax regulations. Anonymize or pseudonymize after this period.
3.1. User Request: Delete personal data promptly upon a valid user request, unless retention is required by law. 3.2. Unsubscription: Remove email addresses from the newsletter list immediately upon unsubscription. 3.3. Inactivity: Delete inactive account data after 24 months of inactivity, following notification to the user. 3.4. Data Minimization: Regularly review and delete data that is no longer necessary for the purposes for which it was collected. 3.5. Legal Obligations: Retain data for longer periods if required to comply with legal obligations, such as tax laws or court orders.
4.1. Data retention practices comply with applicable laws, including the California Consumer Privacy Act (CCPA), the General Data Protection Regulation (GDPR), and other relevant international data protection laws. 4.2. Honor user rights regarding data access, rectification, erasure, restriction of processing, data portability, and objection, as required by applicable law.
5.1. Anonymize or pseudonymize identifying information in analytics data to protect user privacy. 5.2. Retain anonymized data indefinitely for statistical and analytical purposes.
6.1. Users may request deletion of their personal data at any time by contacting the website owner via the contact details provided on the website. 6.2. Verify the identity of the requester before processing any deletion request. 6.3. Respond to deletion requests within the timeframes required by applicable law.
7.1. Review this data retention policy periodically to ensure ongoing compliance with legal requirements and to reflect changes in business practices. 7.2. Update this policy as necessary and notify users of any material changes in accordance with the Privacy Policy.
1.1. VitalyBook.com implements spam filtering to protect against malicious emails and form submissions. 1.2. The website uses firewall protection to prevent unauthorized access to servers and data. 1.3. All website traffic is encrypted using Secure Socket Layer (SSL) technology (HTTPS), with a valid and up-to-date SSL certificate. 1.4. Regular malware scans are conducted on the website and server to detect and remove malicious software. 1.5. A Web Application Firewall (WAF) is in place to protect against common web exploits.
2.1. All data transmitted between users’ browsers and VitalyBook.com servers is encrypted using SSL/TLS protocols. 2.2. Personal data stored on servers or third-party services is encrypted at rest using strong encryption algorithms, such as AES-256. 2.3. Encryption keys are securely managed and stored, with access limited to authorized personnel only.
3.1. Access to personal data is granted only to individuals who require it to perform their specific duties, following the principle of least privilege. 3.2. All user accounts with access to personal data must use strong, unique passwords. 3.3. Multi-factor authentication (MFA) is required for all administrative accounts and accounts with access to sensitive personal data. 3.4. Regular access reviews are conducted to ensure permissions are appropriate and unauthorized access is revoked promptly.
4.1. Vulnerability scans are performed regularly on the website and server to identify security weaknesses. 4.2. Periodic penetration testing is conducted to assess the effectiveness of security measures. 4.3. Secure code review practices are implemented to identify and address security vulnerabilities in website code.
5.1. VitalyBook.com maintains an incident response plan to address security incidents and data breaches. 5.2. Procedures are in place for identifying and reporting security incidents. 5.3. Steps are defined for containing the impact of security incidents, including isolating affected systems. 5.4. Processes are established for eradicating the cause of incidents and restoring systems to normal operation. 5.5. Procedures exist for recovering lost or compromised data. 5.6. Affected users and regulatory authorities are notified of data breaches as required by applicable laws, including CCPA and GDPR.
6.1. Individuals handling personal data receive regular training on data protection principles and privacy. 6.2. Employees are educated on security policies and procedures. 6.3. Training includes phishing awareness and secure password management practices.
7.1. Third-party service providers are assessed for appropriate security measures to protect personal data. 7.2. Data processing agreements are in place with third-party vendors, outlining security responsibilities and data protection obligations. 7.3. The security practices of third-party vendors are monitored regularly to ensure adequate controls are maintained.
8.1. The website is hosted on secure data centers with restricted physical access. 8.2. Physical access controls limit entry to server rooms or data centers. 8.3. Surveillance systems monitor physical access to infrastructure.
9.1. Security updates for server operating systems are installed regularly. 9.2. Applications, including content management systems and plugins, are kept up-to-date with the latest security patches. 9.3. Automated updates are enabled where possible to ensure prompt application of security patches.
10.1. Website data, including personal data, is backed up frequently to minimize data loss. 10.2. Backups are stored securely in a location separate from the primary server. 10.3. Backups are tested regularly to ensure successful restoration.
