1. Controller responsible for processing
The controller within the meaning of Regulation (EU) 2016/679 (“GDPR”) is the person or entity that determines the purposes and means of processing personal data in connection with this website.
Brand / website: MT Digital Studio
Legal operator: [FULL LEGAL NAME REQUIRED]
Legal form, if applicable: [E.G. SOLE TRADER / KLEINGEWERBE / OTHER]
Postal address: [STREET, POSTCODE, CITY, COUNTRY]
Email: contact@mihai-teleuca.com
Telephone: not published
If a data protection officer is legally required or voluntarily appointed, their contact information must be added here: [DATA PROTECTION OFFICER / NOT APPLICABLE].
2. Scope of this Privacy Policy
This Policy applies to personal data processed through or in connection with the MT Digital Studio website and related project communications. It is intended to cover, in particular, website visits, technical access logs, contact forms, project inquiries, communications by email, any future account area, locally stored interface preferences and administrative functions that may be introduced later.
“Personal data” means information relating to an identified or identifiable natural person. This may include obvious identifiers such as a name or email address, but may also include online identifiers, device information, IP addresses or combinations of information that can reasonably be linked to an individual.
This Policy does not automatically cover external websites, social networks, code repositories, payment providers, hosting dashboards or other third-party services that operate under their own privacy notices. Where the website links to a third-party service, users should review that provider’s privacy information separately.
3. Data-protection principles
The operator intends to process personal data in accordance with the core GDPR principles, including:
- Lawfulness, fairness and transparency: processing should have an appropriate legal basis and be explained in an understandable manner.
- Purpose limitation: information should be collected for specified and legitimate purposes rather than reused arbitrarily.
- Data minimisation: only information reasonably necessary for the relevant purpose should be requested or retained.
- Accuracy: reasonable steps should be taken to keep personal information accurate where accuracy matters.
- Storage limitation: data should not be retained indefinitely without a legitimate reason.
- Integrity and confidentiality: suitable technical and organisational measures should be used to protect information against unauthorised access, loss, alteration or disclosure.
- Accountability: the controller remains responsible for being able to demonstrate compliance where required.
4. Website hosting, server logs and technical access data
When a website is accessed, the hosting infrastructure ordinarily receives technical information required to deliver the requested content and maintain the security and reliability of the service. Depending on the final hosting provider, this may include the requesting IP address, date and time, requested URL or resource, referrer information, browser type, operating system, response status, transferred data volume and technical diagnostic information.
The final website must identify its actual hosting provider here: [HOSTING PROVIDER NAME, ADDRESS, PRIVACY LINK].
Purposes
- delivering website pages and assets;
- maintaining availability, stability and technical performance;
- detecting abuse, attacks, malware, unusual traffic or operational errors;
- troubleshooting and enforcing the security of the hosting environment;
- where necessary, establishing, exercising or defending legal claims.
Legal basis
Where technical processing is necessary to provide the website requested by a visitor, processing may be based on Article 6(1)(b) GDPR where relevant to requested pre-contractual services, and/or Article 6(1)(f) GDPR for the legitimate interest in securely operating and protecting the website. The appropriate basis depends on the actual relationship and processing operation.
Retention
Technical logs should be kept only for a period reasonably necessary for security and operations, unless longer retention is required to investigate a specific incident or comply with a legal obligation. Insert the host’s real log retention period here: [LOG RETENTION PERIOD].
5. Contact forms, project inquiries and direct communications
The Contact page may collect information submitted voluntarily by a visitor. Depending on the fields used at the time of submission, this may include name, email address, telephone number, requested service, approximate budget, preferred deadline, project title, free-text project details, source information, consent/acknowledgement information and a submission timestamp.
Purpose of processing
Contact information is processed to receive and organize inquiries, understand the requested project, communicate with the sender, prepare a proposal, answer questions, assess whether a collaboration is suitable and document business communications.
Legal basis
If an inquiry is made with the intention of entering into a contract or requesting a proposal, processing is generally intended to rely on Article 6(1)(b) GDPR for steps taken at the data subject’s request before entering into a contract. For general communications that are not pre-contractual, processing may be based on Article 6(1)(f) GDPR and the legitimate interest in responding to legitimate messages, maintaining business communications and protecting against abuse.
The checkbox in the current form is intended primarily to confirm that the user has been presented with the Privacy Policy. It should not be treated as the sole legal basis for all contact processing unless the final implementation and wording are specifically designed around consent under Article 6(1)(a) GDPR.
Required and optional data
Fields marked as required are necessary to process the request in the intended workflow. Optional information does not need to be supplied unless the user believes it is useful for understanding the project.
6. Communication and enquiry processing
When you send a project request or another message through the website, the information you provide is used to understand the request, respond to you, clarify requirements and, where appropriate, prepare or discuss a possible project.
Information that may be processed
Depending on what you choose to provide, this may include your name, email address, telephone number, selected service, approximate budget, preferred deadline, project title and the contents of your message.
Purpose
- responding to enquiries and project requests;
- understanding requirements and determining whether a project is a suitable fit;
- organising follow-up communication;
- protecting the contact function against misuse and automated spam;
- maintaining relevant business correspondence where necessary.
Contact information is not intended to be used for unrelated advertising simply because you sent an enquiry. Please do not include passwords, access tokens, payment-card information, identity documents or other unnecessary sensitive data in a general message.
7. User accounts and account security
If you create an account, the website may process information such as your name, email address, account role, verification status, account creation date and information required to keep you signed in securely.
Passwords and authentication
Passwords are not intended to be stored in readable form. They are protected using one-way password hashing. Account sessions are used so that authenticated users do not need to sign in again on every page.
Email verification and password recovery
Time-limited verification or password-recovery links may be sent when needed to activate an account or restore access. These links are designed to expire and should not be shared with other people.
Roles and administrator access
Some accounts may have additional permissions, such as administrator access for managing portfolio content. Permissions are assigned to the account and restricted to functions appropriate to that role.
You are responsible for keeping your password confidential and for informing us if you believe that another person has gained unauthorised access to your account.
8. Cookies, browser storage and preferences
The website uses a privacy-choice record so that your cookie and preference decision does not need to be requested on every page. Storage that is strictly necessary for account sessions, security or remembering your privacy choice may remain active where legally permitted.
Optional preferences
If you allow the Preferences category, the website may remember choices such as your selected visual theme and preferred website language. These settings are intended to improve convenience rather than to create an advertising profile.
Your choice
You can accept optional preferences, reject them or change your choice later through the Cookie settings control. Rejecting optional preferences does not prevent you from browsing the main public content of the website.
Advertising and behavioural tracking
The website does not currently use advertising cookies, cross-site behavioural tracking or marketing pixels. If this changes, the consent interface and this Privacy Policy will be updated before such technologies are activated where required.
9. Optional AI-assisted translation
The website may offer automated translation so that public website content can be viewed in another language. Translation is optional and can be started from the language selector.
The translation feature is designed to work with public interface wording only. Information entered into contact forms, passwords, private account details and other confidential user data are excluded from the translation workflow by design.
If Preferences are enabled, your selected language may be remembered so the website can offer the same language again on future visits. You can return to the original English version at any time.
Automated translations can contain linguistic, technical or contextual errors. For legally significant wording, the original English version should be treated as the reference version unless an officially reviewed translation is specifically provided.
10. Analytics, performance monitoring and tracking
The website does not currently use advertising analytics or behavioural profiling tools. Basic technical information may still be processed where necessary to operate, protect and troubleshoot the website.
If optional analytics are introduced later, the relevant purpose, legal basis, retention information and consent choices will be described before those tools are activated where required.
11. Security and confidentiality measures
The controller should use technical and organisational measures appropriate to the nature, scope, context and risks of the processing. Depending on the final infrastructure, measures may include HTTPS/TLS, access controls, strong unique credentials, multi-factor authentication, least-privilege administration, secure backups, software updates, secure hosting configuration, appropriate logging, input validation, anti-spam controls and procedures for responding to suspected security incidents.
No internet transmission or storage system can be guaranteed to be absolutely secure. The operator therefore cannot promise that a security incident is impossible, but should take reasonable measures and comply with applicable breach-notification duties where required.
Users should not submit passwords, payment card data, government identification documents, highly sensitive personal information or other unnecessary confidential data through the general contact form.
12. Recipients and categories of service providers
Personal data is shared only where there is a relevant purpose and an appropriate legal basis. Depending on the services actually used, recipients may include:
- website hosting, infrastructure, domain and security providers;
- email and communication service providers;
- technical service providers that support authentication, storage or website operation;
- professional advisers such as accountants, tax advisers or lawyers where necessary;
- public authorities or courts where disclosure is required by law.
Where a service provider processes personal data on our behalf, appropriate contractual and data-protection safeguards are used where required. Personal data is not sold to advertisers.
13. Transfers outside the European Economic Area
Some service providers may process information in, or make information accessible from, countries outside the European Economic Area. Where such a transfer involves personal data, appropriate safeguards must be used in accordance with Chapter V GDPR.
Depending on the provider and destination, safeguards may include an adequacy decision, Standard Contractual Clauses or another lawful transfer mechanism. The exact position depends on the services that are active when the website is publicly launched.
14. Data retention
Personal data should be retained only for as long as necessary for the relevant purpose, subject to statutory retention duties and legitimate needs such as the establishment, exercise or defence of legal claims.
| Data category | Indicative purpose | Retention approach to define before launch |
|---|---|---|
| Server logs | Security, delivery and diagnostics | [HOST’S ACTUAL LOG RETENTION] |
| Unsuccessful project inquiry | Responding and short-term follow-up | [E.G. 6–12 MONTHS, AFTER LEGAL REVIEW] |
| Customer correspondence | Contract management and evidence | As required for the contract, legal claims and statutory obligations |
| Invoices / tax records | Accounting and legal compliance | According to applicable German tax/accounting retention obligations |
| Account data | Providing account access | Until deletion plus any legally justified residual retention |
| Theme preference | Remembering user-selected appearance | Until browser storage is cleared or the preference is changed |
These periods are not final legal commitments. The controller must determine real periods based on the actual processing and legal obligations.
15. Legal bases under Article 6 GDPR
Depending on the activity, processing may rely on one or more of the following legal bases:
- Article 6(1)(a) GDPR — consent: where the user has freely given valid consent for a specific processing purpose.
- Article 6(1)(b) GDPR — contract / pre-contractual steps: where processing is necessary to perform a contract or take steps requested by the data subject before entering into a contract.
- Article 6(1)(c) GDPR — legal obligation: where processing is necessary to comply with a binding legal duty.
- Article 6(1)(f) GDPR — legitimate interests: where processing is necessary for a legitimate interest and that interest is not overridden by the individual’s rights and freedoms.
The controller must map each real processing operation to its correct legal basis. A generic reference to “consent” should not be used where the processing is actually required to answer a requested project inquiry or perform a contract.
16. Rights of data subjects
Subject to the conditions and limitations in the GDPR, individuals may have the following rights:
- Right of access: to obtain confirmation whether personal data is processed and, where applicable, receive access and related information.
- Right to rectification: to request correction of inaccurate personal data and completion of incomplete information.
- Right to erasure: to request deletion where the legal conditions are met.
- Right to restriction: to request restricted processing in circumstances specified by law.
- Right to data portability: in applicable cases, to receive data in a structured, commonly used and machine-readable format and/or have it transmitted to another controller.
- Right to object: where processing is based on Article 6(1)(e) or (f), the individual may have the right to object on grounds relating to their particular situation.
- Direct-marketing objection: if personal data is ever processed for direct marketing, the individual has the right to object at any time to such processing.
- Withdrawal of consent: where processing is based on consent, consent can generally be withdrawn for the future without affecting the lawfulness of processing before withdrawal.
Requests should be sent to [PRIVACY EMAIL]. The controller may need to verify the identity of a requester where there are reasonable doubts and should respond within the time limits required by applicable law.
17. Right to lodge a complaint with a supervisory authority
Individuals have the right to lodge a complaint with a competent data-protection supervisory authority if they believe that the processing of their personal data infringes the GDPR.
The relevant German authority depends on where the controller is established. Insert the competent authority before publication: [NAME, ADDRESS, WEBSITE OF COMPETENT LAND DATA PROTECTION AUTHORITY].
The right to complain does not prevent an individual from contacting the controller first so that a concern can be investigated directly.
18. Children and minors
This portfolio is directed toward professional, technical and project-related interactions and is not intentionally designed as a service for young children. The operator does not knowingly seek sensitive or unnecessary information from minors through the general contact form.
If the final account system or services are made available directly to minors, the controller must review the specific age, consent, contract-capacity and child-protection requirements applicable to the relevant service and jurisdiction.
19. Automated decision-making and profiling
The current website template does not intentionally make decisions producing legal effects or similarly significant effects about individuals based solely on automated processing. The contact workflow may automatically validate fields, detect obvious spam patterns, write form values to a spreadsheet and send notification emails, but those technical operations are not intended to constitute significant automated decision-making.
If scoring, automated rejection, AI-based applicant evaluation, behavioural profiling or similar functionality is introduced later, this section must be revised accordingly.
20. External links, GitHub, LinkedIn and third-party content
The website may contain links to third-party websites such as GitHub, LinkedIn, hosting providers, social platforms or project demos. Following an external link may result in data being processed by the destination provider under that provider’s own terms and privacy policy.
The current template uses ordinary links and does not intentionally embed third-party social widgets on this page. If embedded videos, maps, fonts, tracking scripts, external images or social widgets are introduced, the privacy implications must be reviewed before activation.
21. Changes to this Privacy Policy
This Policy may be updated when the website, services, providers, legal obligations or processing activities change. The date shown at the top of the page should be updated whenever substantive changes are made. Where required by law, individuals should receive additional notice or be asked for renewed consent before a materially different processing activity begins.
Users are encouraged to review the current version periodically, particularly before submitting new personal information.
22. Privacy contact
For privacy questions, data-subject requests or concerns about personal-data handling, contact:
Name: [CONTROLLER NAME]
Email: [PRIVACY EMAIL]
Postal address: [POSTAL ADDRESS]