Scope

This policy applies to the public website at mahlis.com and its private administrator area. Product prototypes may require separate privacy documentation before they collect or process information.

The public website is not a patient portal and should not be used to submit patient records or urgent clinical information.

Contact-form information

When a visitor submits the contact form, Mahlis collects the supplied name, email address, subject, message, submission time and review status. This information is used to read, organize and respond to the request.

The form uses a short-lived, non-reversible rate-limit identifier to reduce automated abuse. The raw network address is not stored in the contact submission.

Visitors should not submit passwords, payment-card information, patient records or other sensitive personal information through the contact form.

Optional analytics

Analytics are optional and run only after a visitor selects “Allow analytics.” Mahlis records daily aggregate page views, an approved operating-system category and whether a new consented visit occurred.

Operating systems are grouped as Windows, Linux, Android, iOS, macOS or Other. Mahlis does not retain the complete user-agent string in the analytics database.

The analytics design does not store advertising identifiers or build individual visitor profiles.

Cookies

Essential cookies

Essential cookies support security controls, cross-site request forgery protection and authenticated administrator sessions. They are not used for advertising.

Optional analytics cookies

The analytics-consent cookie records the visitor’s choice. When analytics are allowed, a short-lived visit cookie helps avoid counting every page view as a new visit. The visit token is not stored in the analytics database.

Selecting “Essential only” prevents optional analytics from running and removes the analytics visit cookie.

Browser storage

Local storage

The website may use local storage only to remember the visible cookie-banner state. It must not store administrator credentials, contact messages or sensitive personal information there.

Session storage

Session storage may hold temporary interface state that disappears when the browser session ends. Authentication authority remains on the server and is not established by session storage.

IndexedDB

The current Mahlis website does not use IndexedDB. A future feature must receive a privacy and security review before IndexedDB is used for persistent information.

Browser cache

Public pages may be cached briefly for performance. Administrator, contact-submission and other sensitive responses are delivered with instructions that prevent browser and intermediary caching.

Administrator accounts

Authorized administrator records include a name, email address, password hash, account status and security audit timestamps. Passwords are processed using a one-way password derivation function and are not stored as readable text.

Administrator session tokens are generated securely. Only a hash of the active token is stored in the database. Sessions expire and can be revoked.

Security measures

Measures include secure and HttpOnly cookies in production, SameSite cookie restrictions, CSRF protection, session expiration, login throttling, parameterized database queries, content sanitization, security response headers and restricted caching.

No internet service can guarantee absolute security. Mahlis reviews controls according to the information and functions actually in use.

Retention

Contact requests are retained while they are needed for review, response and reasonable operational records. Short-lived rate-limit records are automatically eligible for deletion after their security purpose has passed.

Aggregate analytics may be retained to understand long-term public interest because they do not contain a complete user-agent string or an individual visitor profile.

Sharing

Mahlis does not sell contact-form information or analytics data. Information may be disclosed when required by applicable law or when necessary to protect the security and lawful operation of the service.

Your choices

Visitors may decline optional analytics, remove website cookies through browser controls or contact Mahlis about a submitted request. Removing essential cookies may end an administrator session or require a new security token.

Policy changes

This policy may be updated when website functions or information practices change. The effective date at the top of this page will be revised when a new policy is published.

Contact Mahlis

Questions about this policy can be submitted through the Mahlis contact form.