Who is responsible for your data

The controller for the purposes of the General Data Protection Regulation (EU) 2016/679 (“GDPR”) is the publisher of MariuszDuda.md, the independent editorial project operating at mariuszduda.md.

All privacy questions, access requests and deletion requests go to [email protected]. There is no separate data protection officer, because the scale of processing here does not require one under Article 37.

What is collected, and why

Data Where it comes from Purpose Legal basis Kept for
Session identifier (PHPSESSID cookie) Set by the site when you load a page Keeps the anti-forgery token for the contact form valid between page load and submission Strictly necessary — no consent required (Art. 6(1)(f); ePrivacy exemption) Deleted when you close the browser
Name, email address, optional company, optional budget, message Typed by you into the contact form Reading and answering your enquiry Your consent, given with the checkbox (Art. 6(1)(a)); pre-contractual steps where the enquiry is a business offer (Art. 6(1)(b)) 24 months from the last message in the thread
IP address, browser user agent, submission timestamp Recorded with contact form submissions Spam prevention, rate limiting and abuse investigation Legitimate interest in keeping the form usable (Art. 6(1)(f)) 24 months, alongside the enquiry
Server access logs (IP address, URL requested, user agent, timestamp, response code) Written automatically by the web server Security, error diagnosis and capacity planning Legitimate interest in operating the service securely (Art. 6(1)(f)) 30 days, then rotated out
Every category of personal data processed by this site, as of 20 August 2026.

Nothing else is collected. There is no account system, no newsletter, no comment system and no advertising identifier. See the cookie policy for the full cookie inventory.

Who else can see it

Personal data is never sold, rented or shared for anyone else’s marketing. It is shared only with the processors needed to run the site and deliver a reply:

  • The hosting provider — stores the site files and writes the server logs described above. Servers are located in the European Union.
  • Brevo — the SMTP provider that delivers contact form submissions to the editorial inbox. Brevo is established in France and processes the data within the EU.
  • A messaging relay — a copy of each enquiry notification is forwarded to a private messaging channel over the Telegram Bot API so that nothing is missed. Telegram operates outside the European Economic Area; that transfer relies on the safeguards in Article 46 GDPR. If you would rather your message did not pass through it, email the editorial address directly instead of using the form.

Data may also be disclosed where a law, a court order or a binding request from a competent authority requires it. If that happens and the law allows us to tell you, we will.

What is not done with your data

  • No profiling and no automated decision-making within the meaning of Article 22.
  • No behavioural advertising, retargeting or cross-site tracking.
  • No sale or exchange of personal data with third parties.
  • No marketing email. Your address is used to answer you, and then it stops being used.

Your rights

Under Articles 15 to 22 GDPR you can ask for access to the personal data held about you, correction of anything inaccurate, erasure, restriction of processing, and a copy of the data you provided in a portable format. You may object to processing based on legitimate interest, and where processing rests on consent you can withdraw that consent at any time without affecting what was lawful beforehand.

Send the request to [email protected] from the address you used to write in, or explain how the request relates to the data held. A reply follows within one month, extendable by two further months for complex requests, as Article 12(3) allows. Requests are free unless they are manifestly unfounded or excessive.

If you believe the data has been mishandled, you may complain to the data protection supervisory authority in the EU or EEA country where you live, work, or where the alleged infringement took place.

Security

The site is served over HTTPS with HTTP Strict Transport Security. A strict Content Security Policy, anti-forgery tokens and a submission rate limit are in place. Session cookies are marked HttpOnly, SameSite=Lax and, over HTTPS, Secure. No system is perfect, but personal data here is kept to a minimum precisely so that a breach would have little to take.

Children

This site is written for a general adult audience and is not directed at children. No data is knowingly collected from anyone under 16. If you believe a child has sent us personal data, write in and it will be deleted.

Changes to this policy

If analytics, advertising or any other processing is introduced later, this page is updated before the change goes live, the “last updated” date changes, and where the law requires consent, a consent mechanism appears first.

Privacy questions

Does this site use Google Analytics or any other tracker?

No. There is currently no analytics package, no tag manager, no advertising network and no third-party embed of any kind on the pages served here.

Do I need to accept a cookie banner?

No, because the only cookie set is the strictly necessary session cookie, which is exempt from the consent requirement. If a non-essential cookie is ever introduced, a consent banner will appear before it is set.

How do I get my enquiry deleted?

Email [email protected] and ask. The message and any associated metadata are deleted, and you get written confirmation.

Where is the data stored?

On servers in the European Union, apart from the enquiry notification copy relayed over the Telegram Bot API, which is covered by the Article 46 safeguards described above.