Legal
Privacy policy
What is collected when you visit this site, why, how long it is kept, and what you can ask to have done with it. Written to be read rather than to be ticked off.
Last updated: 31 August 2026
In short
This site has no accounts and sells nothing online. It has one form, for requesting a free demo. Form data is sent only when you press “Send request”; analytics starts only if you accept the “Analytics” category.
There are three ways I end up with data about you. First: you submit the demo form. Second: you email, message me on WhatsApp or call. Third: you agree to analytics, and Google and Microsoft measure how the site is used.
The rest of this page explains each situation, plus what you can ask to happen to your data at any point.
Who is responsible for your data
The data controller, in the sense of the General Data Protection Regulation (GDPR), is the business behind this site.
- Registered name
- Ungureanu Remo Mihail Persoană Fizică Autorizată
- Legal form
- Persoană Fizică Autorizată (PFA)
- Trade register number
- F2026040293008
- Tax identification code
- 55435177
- Registered address
- Str. Maica Teofana nr. 17, bl. M, ap. 2, Sector 1, București
- TVA
- Neplătitor de TVA
For anything to do with your data, write to info@thesitefactory.ro. You get me, not a department.
I have not appointed a Data Protection Officer and am not required to: I do not monitor people on a large scale and I do not process special categories of data.
What is collected
Four categories of data, explained directly.
What you submit through the demo form. The form asks for your name, the type of business and a phone or WhatsApp number. You may optionally add your current website and project details. Netlify Forms processes the submission and makes it available to me so I can reply.
What you send me directly. If you email, message me on WhatsApp or call, I have the address or number you wrote from and whatever you told me. Usually: your business name, what you do, and the site you have now.
What the analytics tools see, if you agree. Which pages you open, how far you scroll, what you click, what kind of device you are on, and roughly which country you are in. That is data about how the site is used, not about who you are, and it never reaches me in a form that would let me recognise you.
What the server logs. The site is hosted by Netlify, and as with every site on the internet the server that delivers the pages keeps brief technical logs: IP address, time of request, page requested. They are needed for the site to work and to be protected from abuse. I do not use them for anything else and do not look at them unless something breaks.
What is NOT collected: the form does not ask for your home address, payment details, national ID or other sensitive data. There is no account, basket or newsletter. There is no profiling and no automated decision-making about you.
Your language choice and your answer to the cookie banner are saved in your browser's local storage. They are not cookies, they are never transmitted, and nothing but your own browser can read them. Details are in the cookie policy.
Why I process it, and on what legal basis
The GDPR requires a basis for every kind of processing. Here are mine.
| What | Why | Legal basis |
|---|---|---|
| Your demo request, message and contact details | So I can reply, and so we can prepare the project if we work together | Steps taken at your request before entering a contract: Art. 6(1)(b) |
| Google Analytics and Microsoft Clarity | So I can see which pages get read, where people give up and what needs fixing | Your consent: Art. 6(1)(a). Withdrawn as easily as it is given. |
| Server technical logs | So the site works, is delivered correctly and is protected from abuse | Legitimate interest in running a working, secure site: Art. 6(1)(f) |
| Invoices and accounting records | To comply with Romanian tax and accounting law | Legal obligation: Art. 6(1)(c) |
If you object to the processing based on legitimate interest, write to me and I will tell you exactly what I am weighing and why, or stop.
How long it is kept
- Demo requests, messages and conversations: as long as the conversation still has a point. If we never work together, I delete them within two years at most.
- Financial records: as long as Romanian accounting and tax law requires. I am not free to delete these earlier.
- Google Analytics: according to the retention setting on the property. User-level and event-level data is deleted automatically when that period expires.
- Microsoft Clarity: session recordings are kept for roughly 30 days, then deleted.
- Server logs: short periods, set by Netlify.
- Your cookie choice: in your browser, until you change it or clear your browsing data.
Who else sees it
I do not sell data and I do not hand it to anyone for marketing. There are, however, companies that process data on my behalf, because without them the site would not work.
| Who | For what | When |
|---|---|---|
| Google Ireland Limited | Google Analytics 4: aggregate statistics about how the site is used | Only after you accept the "Analytics" category |
| Microsoft Ireland Operations Limited | Microsoft Clarity: interaction heatmaps and anonymised recordings | Only after you accept the "Analytics" category |
| Netlify, Inc. | Site hosting, technical logs and processing submissions sent through the demo form | On every visit and when you submit the form |
| Email and WhatsApp (Meta) | Carrying the messages you send me | Only if you write to me |
| Accountant | Invoices and records, as required by law | Only if we become client and supplier |
I may be required to disclose data to authorities where the law demands it. It has not happened so far.
Transfers outside the European Union
The analytics contracts are with the European entities: Google Ireland Limited and Microsoft Ireland Operations Limited. Some processing may nonetheless reach their parent companies in the United States. Netlify, Inc., which hosts the site, is a US company.
In each case the transfer rests on the Standard Contractual Clauses approved by the European Commission, included in the data processing agreement signed with each of them. Google and Microsoft additionally rely on the EU–US Data Privacy Framework, under the adequacy decision of July 2023.
Refusing the “Analytics” category stops transfers to Google and Microsoft completely. Hosting and form processing through Netlify cannot be refused in the same way: without hosting the page cannot reach you, and without form processing the request cannot reach me. You can instead choose not to submit the form and use email or WhatsApp.
How consent works
On your first visit a small banner appears in the corner. Until you choose, no analytics tool is loaded: no Google or Microsoft script, no cookies, no request to their servers at all. Consent is prior, not assumed.
"Accept all" and "Only necessary" sit next to each other, at the same size, one click apart. Refusing has to be as easy as agreeing.
If your browser sends a Global Privacy Control or Do Not Track signal, I read it as a refusal and do not show you the banner at all. You have already said no.
I also use Google Consent Mode v2, which means Google's tools are told the state of your consent explicitly rather than inferring it from silence.
How to withdraw your consent
At the bottom of every page there is a "Cookie settings" button. Open it, switch analytics off, and save.
The page reloads immediately afterwards. That is not a bug: a script that is already running cannot be stopped any other way, and "withdraw at any time" would mean nothing if you kept being measured until you happened to navigate.
Withdrawing does not affect processing that was lawful before it, but from that moment on it stops completely.
Your rights
The GDPR gives you concrete rights. All of them are exercised by writing to me.
- Access: find out what data I hold about you, and get a copy.
- Rectification: have anything wrong or incomplete corrected.
- Erasure: have it deleted, where no legal duty requires me to keep it.
- Restriction: have processing paused, with the data kept, while something is resolved.
- Portability: receive your data in a format someone else can read.
- Objection: object to processing based on legitimate interest.
- Withdrawal of consent: at any time, without having to explain why.
Write to info@thesitefactory.ro and you get an answer within 30 days at the latest (in practice much sooner). There is no charge. I may ask you to confirm it is really you if the request comes from an address I do not recognise.
If you are not satisfied with my answer, you have the right to complain to the supervisory authority: the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul General Gheorghe Magheru 28–30, Sector 1, Bucharest, dataprotection.ro. Please try me first, though.
Security
The site is served over HTTPS only and sends security headers that restrict what is allowed to load in the page. It has no database, account system or admin panel. The only form is processed by Netlify Forms and protected by an invisible anti-spam field.
Your messages arrive in my email or WhatsApp, protected the way any serious personal account should be: unique passwords and two-factor authentication.
No measure is perfect. If a breach ever occurs that could affect your rights, you will be told and the authority will be notified, within the deadlines the law sets.
Changes
If what is collected changes, or who it is shared with, I update this page and the date at the top. For changes that affect consent, the banner asks again. Consent given for one thing is not recycled for another.
Contact
Any question about your data, however small, has an answer. No formal wording is needed and you do not have to cite articles.
- info@thesitefactory.ro