Skip to main content
BRIXA
AboutServicesContact us

Legal

Privacy Statement

Effective 3 August 2026

1.Who we are

Brixa Web is operated by [CONFIRM LEGAL ENTITY], who acts as the data controller for the personal data described in this statement. As a small, one-person studio, there's no separate Data Protection Officer — for any privacy question or request, write directly to [CONFIRM EMAIL] and it reaches the person actually handling your data.

In plain terms — [CONFIRM LEGAL ENTITY] is who's responsible for your data — no DPO needed at this size, just write in directly.

2.What we collect

I collect what's needed to talk to you and build your site: contact details you give me (name, email, phone), the content and materials you supply for your project, our written communications, billing details for invoicing, and privacy-respecting, aggregate analytics on how this site is used. I don't use ad trackers, and I never sell your data — to anyone, for any reason.

In plain terms — Just what's needed to talk to you and do the work — no ad trackers, and your data is never sold.

3.Purpose & legal basis

Every use of your data rests on one of these legal grounds:

PurposeLegal basis
Responding to enquiriesPre-contractual steps — Art. 6(1)(b)
Delivering your projectPerformance of a contract — Art. 6(1)(b)
InvoicingLegal obligation — Art. 6(1)(c)
Analytics, portfolio display & client updatesLegitimate interest — Art. 6(1)(f), opt-out available

In plain terms — Each thing I do with your data has a specific legal reason behind it — nothing is collected 'just in case.'

4.Processors

I work with a small set of processors to run this business: a hosting provider, an email provider, WhatsApp/Meta for messaging if you reach out that way, a payment processor for invoicing (I never see or store card numbers — that happens entirely on the processor's side), an accountant for bookkeeping, and relevant authorities where the law requires disclosure.

In plain terms — A handful of trusted processors keep things running — and card numbers never pass through my hands at all.

5.International transfers

Some processors I use may store or process data outside the EU/EEA, including in the United States. Where that happens, I rely on the EU-US Data Privacy Framework or Standard Contractual Clauses to keep your data protected to an equivalent standard, wherever it physically sits.

In plain terms — If data leaves the EU, it travels under DPF or SCC safeguards — same protection, different address.

6.Retention

I keep enquiry details for 12 months if nothing further develops. Project files are kept for the life of the project plus 24 months afterward, in case you need something re-sent or rebuilt. Invoices are kept for 10 years, as Romanian law requires. Analytics data is kept only in aggregate, non-identifying form.

In plain terms — Nothing sits around forever — enquiries and project files have a clock, invoices follow the law, and analytics stay anonymous.

7.GDPR rights

You have the right to access, correct, delete, restrict, or port your personal data, and to object to processing based on legitimate interest. To exercise any of these, write to [CONFIRM EMAIL]. I aim to respond within 30 days. If you're not satisfied with how a request is handled, you can lodge a complaint with Romania's data protection authority, ANSPDCP, at dataprotection.ro.

In plain terms — Your data, your call — access, fix, delete, or object any time, 30-day response, ANSPDCP as backstop.

8.Cookies

This site uses only functional cookies needed for it to work, plus cookieless analytics that doesn't track you individually or across other sites. Because nothing here identifies you or requires consent under the ePrivacy rules, there's no cookie banner — there's simply nothing invasive to consent to.

In plain terms — No tracking cookies, no banner needed — the analytics here can't identify you.

9.Security

The site runs over HTTPS everywhere, and its static-first architecture keeps the attack surface small by design — there's less to break into because there's less running. Hosting infrastructure is reputable and maintained by its provider. I collect only the data I actually need, keep it in versioned, restorable backups, and welcome responsible disclosure if you ever spot a security issue — reach out to [CONFIRM EMAIL].

In plain terms — HTTPS everywhere, a small attack surface by design, and an open door if you find a problem.

10.Changes & contact

I may update this statement as the business or the law changes; the effective date at the top always reflects the current version. Questions or requests about your data go to [CONFIRM EMAIL].

In plain terms — Updates happen; the date at the top tells you which version you're reading. Questions to [CONFIRM EMAIL].

BRIXA
[CONFIRM PHONE][CONFIRM EMAIL]
Privacy StatementDisclaimerTerms of UseComplaint Procedure

© Brixa Web 2026

Every site we ship is SSL-encrypted.