This policy describes how personal data collected through nixit.io is handled, in accordance with Regulation (EU) 2016/679 (GDPR).
Data controller
The controller is the company identified in the footer of this site. For any request relating to your personal data, use the contact form.
What we collect
Data submitted through the contact form. When you complete the form we collect your name, email address, company name if you provide one, and the content of your message. This is delivered to us by email so we can reply.
Aggregate technical data. We use Cloudflare Web Analytics, which measures traffic without cookies, without device fingerprinting and without collecting data that identifies individual visitors. We do not build profiles and do not track users across sites.
Security logs. The Cloudflare infrastructure serving this site retains technical logs, including IP addresses, for a limited period to protect against abuse and attacks.
What we do not use
This site uses no tracking cookies, advertising pixels or behavioural marketing tools. That is why you are not shown a cookie consent banner: there is nothing to ask you to consent to.
Legal basis and purpose
Contact form data is processed on the basis of our legitimate interest in responding to business enquiries and, where applicable, in order to enter into a contract. It is used solely to correspond with you about your enquiry. We do not sell it, rent it, or use it for unsolicited marketing.
Spam protection
The contact form is protected by Cloudflare Turnstile, a CAPTCHA alternative that does not track users or collect personal data for advertising purposes.
Retention
Messages received through the form are retained in our correspondence for as long as there is a legitimate business interest, and no longer than three years after the last interaction, unless a longer period is required by law.
Recipients and transfers
Data is processed by our infrastructure providers: Cloudflare, for serving this site and spam protection, and Google Workspace, for email. Both provide contractual safeguards for international data transfers as required under GDPR.
Your rights
Under GDPR you have the right of access, rectification, erasure, restriction of processing, objection and data portability. To exercise any of these, send us a request through the contact form. We respond within one month.
If you believe your rights have been infringed, you may lodge a complaint with the Romanian supervisory authority ANSPDCP at dataprotection.ro, or with the supervisory authority in your own EU member state.
Changes
Any change to this policy is published on this page, with the last updated date shown below.