Legal
Privacy Statement
Effective 3 August 2026
1.Who we are
Brixa Web is operated by David Dumitrescu, acting as data controller. As a small, one-person studio, there's no separate Data Protection Officer, for any privacy question or request, write directly to BrixaWeb@outlook.com and it reaches the person actually handling your data.
In plain terms: David Dumitrescu is who's responsible for your data, no DPO needed at this size, just write in directly.
2.What we collect
We collect what's needed to talk to you and build your site: contact details you give us (name, email, phone), the content and materials you supply for your project, our written communications, billing details for invoicing, and privacy-respecting, aggregate analytics on how this site is used. We don't use ad trackers, and we never sell your data, to anyone, for any reason.
In plain terms: Just what's needed to talk to you and do the work, no ad trackers, and your data is never sold.
3.Purpose & legal basis
Every use of your data rests on one of these legal grounds:
| Purpose | Legal basis |
|---|---|
| Responding to enquiries | Pre-contractual steps: Art. 6(1)(b) |
| Delivering your project | Performance of a contract: Art. 6(1)(b) |
| Invoicing | Legal obligation: Art. 6(1)(c) |
| Analytics, portfolio display & client updates | Legitimate interest: Art. 6(1)(f), opt-out available |
In plain terms: Each thing we do with your data has a specific legal reason behind it, nothing is collected 'just in case.'
4.Processors
We work with a small set of processors to run this business: a hosting provider, an email provider, WhatsApp/Meta for messaging if you reach out that way, a payment processor for invoicing (we never see or store card numbers, that happens entirely on the processor's side), an accountant for bookkeeping, and relevant authorities where the law requires disclosure.
In plain terms: A handful of trusted processors keep things running, and card numbers never pass through our hands at all.
5.International transfers
Some processors we use may store or process data outside the EU/EEA, including in the United States. Where that happens, we rely on the EU-US Data Privacy Framework or Standard Contractual Clauses to keep your data protected to an equivalent standard, wherever it physically sits.
In plain terms: If data leaves the EU, it travels under DPF or SCC safeguards, same protection, different address.
6.Retention
We keep enquiry details for 12 months if nothing further develops. Project files are kept for the life of the project plus 24 months afterward, in case you need something re-sent or rebuilt. Invoices are kept for 10 years, as Romanian law requires. Analytics data is kept only in aggregate, non-identifying form.
In plain terms: Nothing sits around forever, enquiries and project files have a clock, invoices follow the law, and analytics stay anonymous.
7.GDPR rights
You have the right to access, correct, delete, restrict, or port your personal data, and to object to processing based on legitimate interest. To exercise any of these, write to BrixaWeb@outlook.com. We aim to respond within 30 days. If you're not satisfied with how a request is handled, you can lodge a complaint with Romania's data protection authority, ANSPDCP, at dataprotection.ro.
In plain terms: Your data, your call: access, fix, delete, or object any time, 30-day response, ANSPDCP as backstop.
8.Cookies
This site uses only functional cookies needed for it to work, plus cookieless analytics that doesn't track you individually or across other sites. Because nothing here identifies you or requires consent under the ePrivacy rules, there's no cookie banner, there's simply nothing invasive to consent to.
In plain terms: No tracking cookies, no banner needed, the analytics here can't identify you.
9.Security
The site runs over HTTPS everywhere, and its static-first architecture keeps the attack surface small by design, there's less to break into because there's less running. Hosting infrastructure is reputable and maintained by its provider. We collect only the data we actually need, keep it in versioned, restorable backups, and welcome responsible disclosure if you ever spot a security issue, reach out to BrixaWeb@outlook.com.
In plain terms: HTTPS everywhere, a small attack surface by design, and an open door if you find a problem.
10.Changes & contact
We may update this statement as the business or the law changes; the effective date at the top always reflects the current version. Questions or requests about your data go to BrixaWeb@outlook.com.
In plain terms: Updates happen; the date at the top tells you which version you're reading. Questions to BrixaWeb@outlook.com.