Last updated 21 September 2026
Who is responsible for your data
The data controller is Voican Ioana PFA (Persoană Fizică Autorizată (PFA)), trading as Creative Vision, registered in Cluj-Napoca, Romania.
Registered address: Cluj-Napoca, Cluj County, Romania.
For anything in this notice, including requests to access or delete your data, use the contact form at /contact, or message the studio on Facebook at https://www.facebook.com/perfectionlogo. No data protection officer has been appointed, as the scale of processing does not require one under Article 37 GDPR.
What is collected, and why
Only three categories of personal data are processed, and none of them are used for profiling, advertising or automated decision-making.
- Contact form submissions
- Your name, email address, subject line and the content of your message. Collected so an enquiry can be read and answered. The message is stored on this site's own server and read there; no email is sent by this website, to you or to anyone else. Legal basis: Article 6(1)(b) GDPR, steps taken at your request prior to entering into a contract; where your message is not about a potential engagement, Article 6(1)(f), the legitimate interest in responding to correspondence.
- Server and access logs
- Your IP address, the time of the request, the page requested, the HTTP status and your browser's user-agent string. Recorded automatically by the web server. Legal basis: Article 6(1)(f) GDPR, the legitimate interest in keeping the site secure, diagnosing faults and detecting abuse.
- Administration account data
- A username, a hashed password and an audit record of sign-ins and content changes. This concerns only the site owner, not visitors. Legal basis: Article 6(1)(f) GDPR, securing access to the content management area.
What is not collected
There is no analytics, no advertising network, no social media pixel and no cross-site tracking of any kind on this website.
Typefaces are compiled into the site at build time and served from this domain, so loading a page does not disclose your visit to a font provider.
How long data is kept
- Contact messages
- Deleted automatically 365 days after they are received. Messages that lead to an engagement are retained for as long as the working relationship requires, and afterwards for the period Romanian accounting and tax law requires records to be kept.
- Server logs
- Rotated and deleted after approximately 30 days.
- Security audit records
- Sign-in and content-change records are retained for up to 12 months.
Who else can see it
Your data is never sold, rented or traded. It is shared only with the service providers needed to run the site, each of which acts as a processor under a data processing agreement:
- The hosting provider that operates the server on which this site runs.
- Cloudflare, which provides the content delivery network and the object storage holding the portfolio images. Cloudflare may process your IP address for security and delivery purposes.
Transfers outside the European Economic Area
The server and the database are located within the European Union. Some providers, Cloudflare in particular, operate a global network and may process data outside the EEA. Where that happens, the transfer relies on the European Commission's Standard Contractual Clauses or an adequacy decision, as provided for in Chapter V GDPR.
Your rights
Under Articles 15 to 22 GDPR you have the right to:
- Obtain confirmation of whether your data is being processed, and a copy of it (access).
- Have inaccurate data corrected (rectification).
- Have your data deleted where there is no overriding reason to keep it (erasure).
- Have processing restricted while a dispute about it is resolved.
- Receive your data in a structured, machine-readable format, or have it sent to another controller (portability).
- Object to processing carried out on the basis of legitimate interest.
- Withdraw consent at any time, where processing is based on consent.
Making a request or a complaint
Send any request through the contact form at /contact or by message on Facebook at https://www.facebook.com/perfectionlogo. You will receive a reply within one month, as required by Article 12(3) GDPR. Identity verification may be requested where there is reasonable doubt about who is making the request.
If you believe your data has been mishandled you may lodge a complaint with the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), B-dul G-ral. Gheorghe Magheru nr. 28-30, Sector 1, 010336 București, www.dataprotection.ro. You may also bring a claim before the competent Romanian courts.
Security
The site is served exclusively over HTTPS. Passwords are stored only as salted hashes, never in a recoverable form. Administrative access is protected by rate limiting and audit logging, and sign-in sessions use HttpOnly, SameSite-restricted cookies.
No system is perfectly secure. In the event of a personal data breach likely to result in a risk to your rights, affected individuals and the ANSPDCP will be notified as required by Articles 33 and 34 GDPR.
Changes to this notice
This notice was last updated on 21 September 2026. Any material change will be reflected in that date, and a revised notice will be published on this page.
