Privacy Policy
authorasfia.com · free.authorasfia.com
This Privacy Policy explains how Asfia Bint Abdullah, trading as Author Asfia (“we”, “us”, or “our”), collects, uses, stores, and protects your personal data when you visit our websites or sign up to receive communications from us.
We are committed to protecting your privacy in accordance with the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR), and applicable data protection laws in the UAE and India.
1. Who We Are
Data Controller: Asfia Bint Abdullah (Author Asfia)
Website: authorasfia.com and free.authorasfia.com
Contact email: mail@authorasfia.com
2. What Data We Collect
When you sign up to receive our free eBook or any other communication, we collect:
- First name — to personalise communications sent to you
- Email address — to deliver the eBook and send follow-up emails
- Consent record — the date, time, and method by which you gave consent
- Basic usage data — such as whether you opened or clicked links in our emails (collected automatically by our email platform)
We do not collect payment information, sensitive personal data, or data from children under the age of 16.
3. How We Use Your Data
We use your personal data for the following purposes:
- To deliver the free eBook you requested
- To send you related Islamic parenting content, book updates, and occasional offers from Author Asfia
- To personalise our communications using your first name
- To monitor email engagement (open rates, click rates) to improve our content
- To comply with our legal obligations
4. Legal Basis for Processing
We process your personal data on the following legal bases under UK/EU GDPR:
- Consent (Article 6(1)(a)): You gave us explicit consent by ticking the consent checkbox on our sign-up form. You may withdraw this consent at any time by clicking the unsubscribe link in any email we send you.
- Legitimate interests (Article 6(1)(f)): Where we have a legitimate interest in communicating with existing contacts about directly related products and services.
5. How We Store and Protect Your Data
Your data is stored securely using the following platforms:
- Systeme.io — our email marketing and CRM platform (data stored on EU-based servers)
- Hostinger — our web hosting provider
Both platforms implement industry-standard security measures including encryption in transit (SSL/TLS) and at rest. We do not store your personal data on our own servers beyond what is necessary to process your form submission.
6. How Long We Keep Your Data
- We retain your data for as long as you remain subscribed to our mailing list
- If you unsubscribe, your email address is suppressed from future mailings. You may request full deletion at any time (see Section 8)
- Consent records are retained for up to 3 years for legal compliance purposes
7. Who We Share Your Data With
We do not sell, rent, or share your personal data with third parties for their own marketing purposes.
We share your data only with the following service providers, who process it on our behalf:
- Systeme.io — email delivery and list management
- Hostinger — website hosting and form processing
All third-party processors are contractually bound to protect your data and may not use it for any purpose beyond providing services to us.
8. Your Rights
Depending on your location, you have the following rights regarding your personal data:
Under UK/EU GDPR
- Right of access — request a copy of the data we hold about you
- Right to rectification — request correction of inaccurate data
- Right to erasure — request deletion of your data (“right to be forgotten”)
- Right to restrict processing — request that we limit how we use your data
- Right to data portability — receive your data in a portable format
- Right to object — object to processing based on legitimate interests
- Right to withdraw consent — withdraw consent at any time without affecting prior processing
Under UAE Federal Decree-Law No. 45 of 2021
- Right to be informed about how your data is used
- Right to access, correct, and request deletion of your personal data
- Right to withdraw consent at any time
Under India’s Digital Personal Data Protection Act 2023 (DPDPA)
- Right to access information about your personal data
- Right to correction and erasure
- Right to grievance redressal
- Right to withdraw consent
9. Cookies
Our sign-up page (free.authorasfia.com) does not currently use tracking cookies or analytics scripts. Our main website (authorasfia.com) may use basic cookies for functionality purposes.
We do not use advertising cookies, retargeting pixels, or third-party tracking on our sign-up page.
10. International Data Transfers
Your data may be processed outside your country of residence. When this occurs, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) where required under GDPR.
11. Children’s Privacy
Our services are directed at adults. We do not knowingly collect personal data from children under the age of 16. If you believe we have inadvertently collected data from a child, please contact us immediately at mail@authorasfia.com and we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date at the top of this page. Continued use of our services after any changes constitutes acceptance of the updated policy. For significant changes, we will notify subscribers by email.
13. How to Unsubscribe
You can unsubscribe from our mailing list at any time by:
- Clicking the unsubscribe link at the bottom of any email we send you
- Emailing us directly at mail@authorasfia.com with “Unsubscribe” in the subject line
We will process your unsubscribe request immediately. You may still receive one further email if one was already scheduled at the time of your request.
14. Complaints
If you are unhappy with how we handle your data, you have the right to lodge a complaint with the relevant supervisory authority:
- UK: Information Commissioner’s Office (ICO) — ico.org.uk
- EU: Your local Data Protection Authority
- UAE: UAE Data Office — uaedataoffice.gov.ae
- India: Data Protection Board of India (once operational)
We would, however, appreciate the opportunity to address your concerns before you contact a regulator. Please email us first at mail@authorasfia.com.
15. Contact Us
For any questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact:
