Privacy Policy

9 min read

Privacy Policy

Last updated: 27.06.2026

This Privacy Policy explains how personal data is collected and processed when you visit danielstanica.com (the "Website"), subscribe to our newsletter, or contact us. It is drafted in accordance with Regulation (EU) 2016/679 ("GDPR"), Romanian Law no. 190/2018, and Romanian Law no. 506/2004 on e-privacy.

1. Data Controller

The controller of your personal data is:
Company name: MEDIADIGI INTELLIGENCE SRL

Registered office: Sos Berceni nr 17, Sector 4, Bucharest, Romania

EUID: ROONRC.J40/11676/2017

Email: hello[@]danielstanica[.]com

We have not appointed a Data Protection Officer, as we are not legally required to do so given the nature and scale of our processing. For any privacy matter, contact us at the email above.

2. What Data We Collect and Why

2.1 Website visits (technical data)

When you visit the Website, our hosting and security infrastructure (Cloudflare) automatically processes technical data: IP address, browser type and version, operating system, device type, referring URL, pages visited, and timestamps.

  • Purpose: delivering the Website, ensuring security (DDoS protection, abuse prevention), debugging, and performance optimization.
  • Legal basis: our legitimate interest (Art. 6(1)(f) GDPR) in operating a secure, functional website.
  • Retention: server and security logs are kept for a short period ([e.g., 30 days]) unless needed longer for security investigations.

2.2 Analytics

We use Cloudflare Web Analytics to understand aggregate Website usage.

This tool does not use cookies, and Analytics cookies are set only with your prior consent (Art. 6(1)(a) GDPR and Law 506/2004), which you can give or refuse via the cookie banner and withdraw at any time via [Cookie Settings].

2.3 Newsletter subscription

If you subscribe to our newsletter, we process your email address; the date, time, and IP address of your subscription; the version of the consent text you accepted; and subsequent engagement data strictly necessary for delivery (bounces, unsubscribes).

  • Purpose: sending you the newsletter you requested and proving valid consent (accountability, Art. 5(2) GDPR).
  • Legal basis: your consent (Art. 6(1)(a) GDPR; Art. 12 of Law 506/2004).
  • Withdrawal: you can unsubscribe at any time via the link in every email or by contacting us. Withdrawal does not affect the lawfulness of prior processing.
  • Retention: for as long as you remain subscribed. After unsubscribing, we retain minimal proof of your past consent and its withdrawal for [3 years] to defend against potential claims (Art. 6(1)(f) GDPR).

2.4 Contact forms and email correspondence

If you contact us via a form or email, we process the data you provide: name, email address, message content, and any information you choose to include.

  • Purpose: responding to your inquiry and any follow-up correspondence.
  • Legal basis: legitimate interest (Art. 6(1)(f) GDPR) in responding to correspondence; where your inquiry relates to a potential services contract, steps before entering a contract (Art. 6(1)(b) GDPR).
  • Retention: [2 years] from our last exchange, unless a longer period is required (e.g., correspondence relating to contracts or disputes).

Spam and abuse protection:

Our forms are protected by Cloudflare Turnstile, which analyzes technical signals from your browser to distinguish humans from bots, without tracking you across websites. Legal basis: legitimate interest (Art. 6(1)(f) GDPR) in preventing spam and abuse.

2.5 Interactive features

Interactive elements on the Website run locally in your browser. They do not collect personal data beyond the technical data described in Section 2.1.

2.6 Web fonts

All fonts used on the Website are hosted on our own infrastructure. Displaying them involves no connection to third-party font services and no transfer of your data.

2.7 Data we do not collect

We do not knowingly collect special categories of data (Art. 9 GDPR), and we do not perform profiling or automated decision-making producing legal or similarly significant effects on you (Art. 22 GDPR).

2.8 Is providing your data mandatory?

Providing personal data through the Website is never a statutory or contractual requirement. However, without an email address we cannot deliver the newsletter, and without contact details we cannot respond to your message.

If you choose not to provide data, the only consequence is that the corresponding feature will not be available to you. Browsing the Website itself requires no personal data beyond the technical data inherently processed as described in Section 2.1.

3. Where Your Data Comes From

We collect data directly from you (forms, newsletter signup, correspondence) or automatically from your device when you visit the Website. We do not purchase personal data from third parties, and we do not enrich your data from external sources.

4. Who Receives Your Data

We share personal data only with service providers ("processors") who help us operate the Website, under data processing agreements compliant with Art. 28 GDPR:

Provider

Role

Location

Cloudflare, Inc.

Hosting, CDN, security, edge infrastructure, media storage, email routing, Turnstile bot protection

USA / global network (EU data centers where possible)

[EMAIL DELIVERY PROVIDER, if any]

Newsletter delivery

[LOCATION]

[ANALYTICS PROVIDER]

Website analytics

[LOCATION]

We may also disclose data where required by law, to competent authorities, or to establish, exercise, or defend legal claims.

We do not sell personal data, and we do not share it with third parties for their own marketing purposes.

4.1 Embedded third-party content

Some pages embed content hosted by third parties (for example, videos, social media posts, or interactive widgets). When a page containing such an embed loads, your browser connects directly to the third party's servers, which receive your IP address and technical browser data and may set their own cookies. These third parties act as independent controllers of that processing; we do not control it.

  • Legal basis on our side: your consent (Art. 6(1)(a) GDPR and Law 506/2004), collected via the consent banner [and/or the click-to-load overlay on the embed itself].
  • We identify embedded providers in our [Cookie Policy] and recommend reviewing their privacy policies.

4.2 Content syndication and technical notifications

The Website uses plugins that syndicate our own published content to external platforms (e.g., the AT Protocol / Bluesky network) and send automated technical notifications about Website events to external endpoints. These flows carry our editorial content and technical event data, not visitor personal data. If any such integration were to process visitor personal data in the future, this Policy and the table above will be updated first.

5. International Transfers

Some providers (notably Cloudflare, Inc.) are established in the United States. Transfers to them rely on:

  • the European Commission's adequacy decision for the EU–US Data Privacy Framework, where the provider is certified; and/or
  • Standard Contractual Clauses (Commission Decision (EU) 2021/914), supplemented by technical measures such as encryption in transit and at rest.

Embedded third-party content (Section 4.1) may likewise involve transfers to the provider's country of establishment, under that provider's own safeguards. You may request a copy of the relevant safeguards by contacting us.

6. How Long We Keep Data

We keep personal data only as long as necessary for the purposes described above. Indicative periods are stated per category in Section 2. When data is no longer needed, it is deleted or irreversibly anonymized. Where legal obligations require longer retention (e.g., fiscal and accounting rules under Romanian law for contract-related records), those periods prevail.

Backups: deleted data may persist in encrypted backup copies until those backups are rotated, for a maximum of [30/60/90 days] after deletion. Backup copies are not used for any active processing and are restored only for disaster recovery.

7. Your Rights

Under the GDPR, you have the right to:

  • access your data (Art. 15);
  • rectify inaccurate data (Art. 16);
  • erase your data ("right to be forgotten", Art. 17);
  • restrict processing (Art. 18);
  • data portability (Art. 20);
  • withdraw consent at any time, where processing is based on consent, without affecting prior processing (Art. 7(3)).
Where we process your data based on legitimate interest (see Sections 2.1, 2.2, 2.3 in fine, 2.4), you have the right to object at any time, on grounds relating to your particular situation. Where personal data is processed for direct marketing purposes, you may object at any time, without giving any reason, and we will stop that processing immediately. To object, email us at hello[@]danielstanica[.]com. or use the unsubscribe link in any newsletter.

To exercise any right, contact us at hello[@]danielstanica[.]com. We will respond within one month (extendable by two further months for complex requests, with notice). We may ask for information necessary to confirm your identity. Exercising your rights is free of charge, except in cases of manifestly unfounded or excessive requests (Art. 12(5) GDPR).

8. Complaints

If you believe your data protection rights have been infringed, you may contact us for a resolution or lodge a complaint with the Romanian supervisory authority:

Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) B-dul G-ral Gheorghe Magheru 28-30, Sector 1, 010336 Bucharest, Romania www.dataprotection.ro | anspdcp@dataprotection.ro

You also have the right to an effective judicial remedy (Art. 79 GDPR). We would, however, appreciate the chance to address your concern directly first.

9. Security

We apply technical and organizational measures appropriate to the risk (Art. 32 GDPR), including: HTTPS/TLS encryption for all traffic, infrastructure-level security and DDoS protection via Cloudflare, access controls on administrative interfaces, sandboxed plugin architecture, and minimization of the data we collect in the first place. No internet transmission is ever completely secure; if a data breach likely to result in a high risk to your rights occurs, we will notify you and the ANSPDCP as required by Arts. 33–34 GDPR.

10. Children

The Website is not directed at children. We do not knowingly collect personal data from persons under 16 years of age (the age of digital consent in Romania under Law 190/2018). If you believe a minor has provided us with personal data, contact us, and we will delete it.

11. Cookies

Information about cookies and similar technologies, including any strictly necessary cookies set by the Website itself, cookies set by embedded third-party content, and how to give, refuse, or withdraw consent for non-essential cookies, is provided in our [Cookie Policy] and the consent banner shown on your first visit. Administrative session cookies used solely by the Website operator to manage the site are not set for regular visitors.

12. Our Social Media Profiles

We maintain profiles on third-party platforms (e.g., LinkedIn, X, Bluesky). When you visit or interact with those profiles, the respective platform processes your data as an independent controller (or, for certain page-insight statistics, as a joint controller) under its own privacy policy. This Privacy Policy does not govern processing performed by those platforms. If you contact us through such a platform, the correspondence rules in Section 2.4 apply to our side of the exchange.

13. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices, services, or legal requirements. The current version, with its "Last updated" date, is always available on this page. For material changes affecting newsletter subscribers, we may additionally notify you by email.

Version history:

  • 27.06.2026 — current version

14. Contact

MEDIADIGI INTELLIGENCE SRL

Email: hello[@]danielstanica[.]com

Address: Sos Berceni, 17, Sector 4, Bucharest, Romania