Privacy Policy
Transparency about how I collect, process and protect personal data when you visit this website or contact me.
Data controller
In accordance with the General Data Protection Regulation (GDPR) and Spanish Organic Law 3/2018 of 5 December on Personal Data Protection and Guarantee of Digital Rights (LOPDGDD), the following information identifies the data controller responsible for personal data processed through this website:
Mihai Dobre's professional activity includes web development, WordPress, WooCommerce, bespoke software, business automation and artificial intelligence integration.
This website is intended to present the professional services offered, publish content related to those services and facilitate contact between prospective clients and the controller.
Purposes of processing
Personal data collected through this website may be processed for the following purposes:
- Responding to enquiries submitted through the website.
- Preparing and sending quotations and commercial proposals.
- Providing contracted services.
- Managing and coordinating ongoing projects.
- Providing technical support related to services supplied.
- Issuing and managing invoices.
- Complying with applicable legal obligations.
- Protecting the website and preventing fraud or abuse.
- Analysing the origin of enquiries and the effectiveness of acquisition activities.
- Obtaining website usage statistics only where the user has consented to analytics cookies.
- Improving the website and its content where appropriate.
Categories of personal data
Only data necessary for the purposes described above is processed. This may be provided voluntarily by the user or generated through use of the website:
- First and last name.
- Company name, where voluntarily provided.
- Email address.
- Telephone number, where voluntarily provided.
- Message or project description.
- Billing information where a commercial relationship is established.
- Technical data generated through use of the website, such as IP address, browser and User-Agent.
- Attribution and origin data, such as landing page, referrer and UTM parameters (source, medium, campaign, term and content), where available.
Special categories of personal data, such as health information, political opinions, religion or sexual orientation, are not intentionally collected.
Legal basis for processing
Personal data is processed on the following legal bases under the General Data Protection Regulation (GDPR):
Consent — Article 6(1)(a) GDPR
When you submit the contact form, you authorise the processing of your data for the purpose of handling and responding to your enquiry. Consent may be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal.
Performance of a contract — Article 6(1)(b) GDPR
Processing necessary for providing contracted services, managing projects, providing technical support and handling billing is based on the performance of the relevant contract.
Compliance with legal obligations — Article 6(1)(c) GDPR
Data may be processed where necessary to comply with applicable legal obligations, including tax and accounting obligations arising from the professional activity.
Legitimate interests — Article 6(1)(f) GDPR
Website security, fraud prevention and improvements to the browsing experience may rely on legitimate interests where those interests are not overridden by the user's rights and freedoms.
Data retention
Personal data is retained only for as long as necessary for the purposes for which it was collected and in accordance with applicable legal and contractual obligations:
- Enquiry data is retained while the enquiry is being handled and for as long as necessary to maintain the commercial relationship.
- Billing data is retained for the period required by applicable tax and accounting legislation.
- Technical data generated through browsing is retained in accordance with the Cookie Policy.
Data is securely deleted when it is no longer required for the purpose for which it was collected, unless a legal retention obligation applies.
Recipients and service providers
To provide services and operate this website, personal data may be processed by service providers necessary for the relevant activity. Depending on the particular service and circumstances, these may include:
Web hosting
Hosting and infrastructure services necessary to operate the website.
Email services
Email services used to manage communications arising from enquiries.
Web analytics
Tools used to obtain aggregated information about website usage.
Security services
Services used for website protection, monitoring and abuse prevention.
Payment providers, where applicable
Payment platforms used where a payment forms part of a contracted service.
Automation platforms
Process automation tools used in managing professional activity.
Artificial intelligence providers, where applicable
AI services that may support certain technical tasks in accordance with the AI Transparency Policy.
This does not mean that all of these providers are used simultaneously or permanently. The services used may change over time. Where a provider acts as a data processor, access to and processing of personal data takes place under the controller's instructions and the safeguards required by applicable law. Where a third party processes data for its own purposes, that processing is also governed by the third party's own terms and privacy policies.
International data transfers
Certain technology providers may process data from countries outside the European Economic Area. Where an international transfer of personal data takes place, an appropriate mechanism recognised under the GDPR will be used, such as an adequacy decision by the European Commission, Standard Contractual Clauses or another valid safeguard provided for by applicable law. The specific mechanism depends on the providers and services actually used at the relevant time.
Artificial intelligence
Artificial intelligence may be used to support certain technical tasks, in accordance with this website's AI Transparency Policy.
Personal data or confidential client information is not entered into public artificial intelligence tools without an appropriate legal basis or the relevant authorisation.
Content, code, documentation or solutions supported by artificial intelligence are personally reviewed and validated before delivery or deployment to production.
More information is available in the AI Transparency Policy.
Your data protection rights
As a data subject, you have the right to:
- Access your personal data and obtain information about what data is processed and for what purpose.
- Rectify inaccurate or incomplete personal data.
- Request deletion of your personal data where it is no longer necessary for the purpose for which it was collected.
- Request restriction of processing in certain circumstances.
- Object to the processing of your personal data in certain circumstances.
- Request data portability in a structured and commonly used format.
- Withdraw your consent at any time without affecting the lawfulness of processing carried out before withdrawal.
To exercise any of these rights, you can contact me using the contact form or by emailing the address shown at the end of this policy. Requests will normally be answered within one month of receipt.
If you believe that your personal data has not been processed correctly, you have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD): https://www.aepd.es/.
Cookies and similar technologies
This website uses cookies and storage technologies required to remember user preferences and maintain certain technical functions. Google Analytics cookies are activated only after the user has provided consent. SessionStorage may also be used temporarily to retain attribution information such as landing page, referring website and UTM parameters during the session.
Detailed information about the cookies used, their purpose and how to manage them is available in the Cookie Policy.
Security measures
Appropriate technical and organisational measures are applied according to the nature of the services in order to protect personal data against unauthorised access, alteration, disclosure or destruction.
- Encrypted communications using HTTPS throughout the website.
- Restricted access to systems where personal data is stored.
- Strong passwords and authentication for administration systems.
- Anti-spam measures on the contact form.
- Periodic evaluation of infrastructure security.
No method of transmitting or storing data is completely secure. Appropriate safeguards are applied, but absolute security cannot be guaranteed in every circumstance.
Changes to this policy
This Privacy Policy may be updated periodically to reflect changes in data processing activities, services or applicable legislation. The date of the most recent update appears at the beginning of this page. You should review this policy from time to time to remain informed about how your personal data is protected.
Contact
If you have any questions about this Privacy Policy or the processing of your personal data, you can contact me directly.