Privacy policy
Last updated:
1. Data controller
COSTIN TUDOR PERSOANĂ FIZICĂ AUTORIZATĂ (sole trader, Romania)
Tax ID (CUI) 54625491 · Trade Register no. F2026023673001
Registered office: Str. Lucian Blaga nr. 32A, Sânpetru, Brașov County, 507190, Romania
Email: tudorcostinconsultant@gmail.com · Phone: +40 771 372 698
We are not required to appoint a Data Protection Officer. For any question about your data, write to the address above.
2. What we process, and why
a) Contact form
| What | Legal basis | Why |
|---|---|---|
| Name, email, phone (optional), preferred channel, message | Art. 6(1)(b) GDPR: steps prior to entering a contract, at your request | So we can reply |
Data is sent by email to the Operator and stored in a database so we can track the state of the conversation (unread / read / contacted).
b) Anti-bot protection
Cloudflare Turnstile processes technical data (IP address, browser signals) to distinguish humans from bots. Basis: Art. 6(1)(f), our legitimate interest in protecting the form from abuse.
c) Server logs and error reports
IP address, browser type, page accessed and time are recorded by the hosting infrastructure. Application errors are reported to Sentry (EU region) for diagnostics. Basis: Art. 6(1)(f), our legitimate interest in keeping the site working and secure.
d) Traffic statistics
We use an analytics service that sets no cookies and does not identify individuals. We do not build profiles and do not track visitors across sites.
3. What we do not do
- We do not sell or rent data.
- We do not use data for behavioural advertising.
- We make no automated decisions producing legal effects, and create no profiles.
- This site is not directed at people under 16 and we do not knowingly collect their data.
4. Who else has access
Providers processing data on our behalf, under contract:
| Provider | Role | Location |
|---|---|---|
| Hosting (VPS, EU) | infrastructure | EU |
| Cloudflare | DNS, anti-bot, statistics | EU / global |
| Resend | email delivery | USA, see §5 |
| Upstash | rate limiting | EU |
| Sentry | error reporting | EU |
| Neon | message database | EU |
We may disclose data to authorities where required by law.
5. Transfers outside the EEA
Email delivery (Resend) is provided by a United States entity. Transfers rely on the European Commission's Standard Contractual Clauses and/or the EU-US Data Privacy Framework. You may request information about these safeguards at our contact address.
Other providers are configured in the European Union region.
6. Retention
| Category | Period |
|---|---|
| Contact form messages | 24 months from the last status change, then deleted |
| Email correspondence | duration of the relationship plus 3 years |
| Server logs | maximum 12 months |
| Error reports | per Sentry policy, maximum 90 days |
If an engagement goes ahead, financial records are kept for the periods required by Romanian tax and accounting law.
7. Your rights
You have the right to: access · rectification · erasure · restriction · portability · object to processing based on legitimate interest · withdraw consent where processing relies on it.
Send your request to tudorcostinconsultant@gmail.com. We respond within 30 days.
If you are not satisfied, you may lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, Bucharest, 010336, dataprotection.ro, or with a competent court.
8. Security
The site runs exclusively over HTTPS. Access to the message database is restricted to the Operator, behind authentication. We apply reasonable technical and organisational measures, but no method of transmission over the internet is completely secure.
9. Changes
We will update this policy whenever the way we process data changes. The last update date appears at the top of this page.