Privacy
Last updated 16 September 2026
This site is one person's. It sells three things and runs a few games. It collects as little as it can get away with, and this page says exactly what that is rather than describing a policy in general terms.
Who is asking
Christopher Sisamos, in Cyprus, is the data controller for everything on sisamos.net and its subdomains: research.sisamos.net, newrome.sisamos.net, gg.sisamos.net, cv.sisamos.net and portfolio.sisamos.net.
Write to chris@sisamos.net about anything on this page. There is no data protection officer, because at this size the law does not require one and inventing a role nobody fills would be worse than saying so.
What is collected, and why
- Your email address
- When you buy something. It is how the thing you bought reaches you, how Stripe sends your receipt, and how you get back in if you lose access. It is not added to any mailing list, and nothing else is sent to it. Legal basis: performing the contract you entered into.
- Your card details
- Never seen by this site. The payment form is Stripe's own, running inside a frame Stripe serves; the card number is typed into their page, not this one, and never touches this site's servers. What is kept here is the identifier of the payment and a short reference code.
- Files and text you send for a project review
- The files you attach, the brief you write, and the answer to the one question asked afterwards. They are stored privately, read to do the work you paid for, and are not shown to anyone else or used to train anything. Legal basis: performing the contract.
- A cookie called
__session - Set once, after you buy the book, so that newrome.sisamos.net knows you may read it. It holds a random string and nothing else: no name, no address, nothing readable. It is necessary for the thing you asked for, which is why there is no banner asking permission for it. It lasts a year, and clearing your cookies removes it. You can get back in with your email and your reference code.
- Your IP address, briefly
- Every request to a server anywhere carries one. Here it is used to count requests per address so that the payment and recovery endpoints cannot be hammered, and it lives in memory for minutes rather than being stored. Google's hosting keeps its own request logs. Legal basis: legitimate interest in keeping the site working.
- On gg.sisamos.net only: a player name and scores
- The arcade keeps a leaderboard. The name on it is the one you type, and choosing a name that is not yours is entirely reasonable. Play is signed in anonymously, which means a random identifier in your browser and no account.
- Visitor statistics, but only if you say yes
- sisamos.net can count visits with Google Analytics. It is off until
you press Allow on the notice at the bottom of the page: until
then the measurement script is never even downloaded, so nothing is sent
anywhere. If you do allow it, your IP address is shortened by Google
before it is recorded, and advertising and personalisation stay off
regardless. Your answer is remembered in a cookie called
sisamos_analytics_consentfor six months, and you can change it by clearing your cookies. Legal basis: your consent, which you can withdraw.
What is not collected: no advertising or tracking pixels, no profiling, no selling anything to anyone, and no automated decisions made about you. Measurement is limited to the single counter above, and it only runs if you turn it on.
Who else sees it
Three companies, each doing one job:
- Stripe takes the payment and is the only party that handles your card. They are a controller in their own right for the payment, under their own privacy policy.
- Google hosts the site, the database and the stored files, through Firebase and Google Cloud. The servers used are in the European Union.
- Google Fonts serves the typefaces. Loading a page here makes your browser fetch fonts from Google, which means Google sees that request and the address it came from. This is said plainly because it is easy to leave out.
- Google Analytics, and only if you allowed it, as described above.
Nobody else. Nothing is sold, rented, or shared for marketing.
How long it is kept
- Purchase records for as long as you might need to get back into what you bought, and as long as tax law requires a record of the sale, which in Cyprus is six years.
- Review files and briefs until the review is delivered and a reasonable period after, in case you come back with a question. Ask and they will be deleted sooner.
- Access records for the book until you ask for them to go, or the purchase is refunded.
What you can ask for
Under the GDPR you may ask for a copy of what is held about you, ask for it to be corrected, ask for it to be deleted, ask for it in a portable form, or object to a use of it. There is no form and no process: send an email and it gets done, normally within a few days and always within a month.
One honest caveat. Deleting the record of your purchase deletes the thing that proves you bought it, so access goes with it. You will be told that before anything is deleted rather than after.
If you think this has gone wrong and writing here has not fixed it, you can complain to the Office of the Commissioner for Personal Data Protection in Cyprus, or to the authority where you live.
Children
Nothing here is aimed at children, and nothing sold here is for them. No age is asked for, and none is inferred.
If this page changes
The date at the top changes with it. A change that affects what is collected or who sees it will be said in the text rather than slipped in.
See also the terms of sale. Questions to chris@sisamos.net.