Last updated: 3 August 2026
This policy explains what personal data is collected through the website georgianamanolache.ro, why it is collected, how long it is kept, and what rights you have in relation to it. It is drafted in accordance with Regulation (EU) 2016/679 (GDPR), Romanian Law no. 190/2018, and Directive 2002/58/EC (“ePrivacy”).
Who is the controller of your data
The controller who decides how and why your personal data is processed on this site is:
- Name: Georgiana Manolache (operating under the personal brand “Georgiana Manolache”)
- Legal form: natural person (authorised sole trader, PFA)
- Website: https://www.georgianamanolache.ro
- Contact email for any matter regarding your data: contact@georgianamanolache.ro
For any question about this policy or about your data, write to me at contact@georgianamanolache.ro. I will reply within 30 days at the latest, in accordance with Article 12(3) GDPR.
What data I collect and in which situations
I collect data only in the situations described below. I do not buy, sell, or exchange personal data with third parties for marketing purposes.
1. When you fill in the contact form
If you use the contact form, I collect:
- name (so I know how to address you)
- email address (so I can reply)
- the content of your message
- any other information you choose to include in your message
2. When you leave a comment on a blog article
If you comment on an article, I collect:
- the name you choose to display
- your email address (not published)
- the content of the comment
- the IP address and browser type (for spam detection)
Approved comments and the displayed name are public and visible to all visitors.
3. When you browse the site (cookies and similar technologies)
The site uses cookies and analytics tools to understand how it is used and to optimise it. Full details are in the “Cookies and analytics tools” section below. A separate Cookie Policy page will be published together with the activation of the cookie consent banner.
4. Data automatically collected by the server that hosts the site
The hosting provider (ROMARG SRL, with servers in Romania) automatically collects minimal technical information in log files: the IP address from which you access the site, the browser type, the date and time of access, the pages visited, and the referring page. These logs are used solely for the technical operation of the site, the detection of security incidents, and the prevention of abuse.
5. When you use a free scanner
We record usage statistics: the address of the checked website, the approximate location of the request (country and city, determined locally, without sending your IP address to third parties) and a pseudonymized technical identifier (obtained through an irreversible hash of the IP address and a browser identifier), used to estimate the number of distinct users. The purpose is to understand how the tool is used and to improve it, on the basis of legitimate interest (Article 6(1)(f) GDPR). The raw IP address is not stored. Aggregate location and website statistics remain anonymous, and the pseudonymized identifiers are automatically deleted after 6 months.
The free website security scanner delivers its result by email, so I ask for your address. I use it to send you the report you asked for or, if I cannot confirm that the checked website is yours, the instructions for proving it. The legal basis is the performance of the service you requested (Article 6(1)(b) GDPR), not consent: without an address there is nowhere to send the result. The address stays in the delivery queue for 12 months, so that I can resend the report on request and answer a later question, after which it is deleted automatically and the record remains without a person in it. The online version of the report sits at a secret, non-indexed address for at most 30 days, then it is deleted automatically.
Below the form there is a separate, unticked box through which you can ask to receive occasional tips by email. Ticking it is not a condition of delivery: the report is sent either way. If you do tick it, the legal basis is your consent (Article 6(1)(a) GDPR and Article 12 of Romanian Law no. 506/2004), and as proof I keep the exact wording you saw, the date and the IP address at that moment. You can unsubscribe at any time from a link in every email, and inactive contacts are deleted automatically after 36 months.
If the checked website publishes a security contact address in the standardised security.txt file, the full report is also sent to that address, regardless of who requested the check. I do this because that is the place the website itself designates for reporting security problems, and the person who can fix them needs to know about them. The legal basis is legitimate interest (Article 6(1)(f) GDPR). The email states where the address was taken from and contains no commercial offer. The address is not kept after sending, with a single exception: if you reply asking not to receive such reports, I keep it precisely so that I can honour that request, and I do not write to you again. I send at most 3 such notifications to the same website within 24 hours.
6. When you buy the digital book
When you buy the book in digital format (PDF or EPUB), I process the order and billing data needed (your email address, billing details, and your confirmation that you agree to immediate delivery).
In addition, as a measure against unauthorised copying, each copy I deliver to you is personalised with your name, your email address and the order number, discreetly, on your copy: in the page footer for the PDF, on a licence page for the EPUB, and in the file information. This way, if a copy ends up shared publicly, it can be traced back to the order it came from, which discourages unauthorised sharing. I rely on my legitimate interest in protecting my digital product (Art. 6(1)(f) GDPR).
For this I do not ask for or add any new data beyond what you give me at purchase, and I do not use this information for any other purpose. I do not disclose it to anyone for their own purposes; the copy is sent to you by email through my email provider, which acts as a processor and does not use it for its own purposes. The personalised copy is generated at the moment of delivery and I do not keep it on the server after I have sent it to you. You can object to this processing by writing to me at contact@georgianamanolache.ro.
Why I collect the data (purposes) and on what legal basis
Each piece of personal data is processed for a clear purpose and on a precise legal basis, in accordance with Article 6 GDPR:
| What data | What I use it for | Legal basis |
|---|---|---|
| Name, email, message from the contact form | To reply to the message you sent and, if you ask about services, to discuss a possible collaboration | Pre-contractual steps taken at your request (Art. 6(1)(b) GDPR) or legitimate interest in replying to your request (Art. 6(1)(f) GDPR), depending on the nature of the message |
| Name, email, blog comment | To moderate, publish, and reply to comments | Your consent, expressed through a clear affirmative action by completing and submitting the comment form, Art. 6(1)(a) GDPR |
| IP and browser (for comments) | To detect spam and keep the comments section safe | Legitimate interest in preventing abuse, Art. 6(1)(f) GDPR |
| Web analytics data (GA4) | To understand how the site is used and to improve it | Your consent via the cookie banner, Art. 6(1)(a) GDPR |
| Marketing data (Meta Pixel) | To measure campaign effectiveness and, optionally, for remarketing | Your consent via the cookie banner, Art. 6(1)(a) GDPR |
| Server logs | For technical operation and security | Legitimate interest and legal security obligation, Art. 6(1)(c) and (f) GDPR |
| Name, email and order number, printed on the book copy delivered | To discourage unauthorised copying and to identify the source of a copy shared publicly | Legitimate interest in protecting my own digital product, Art. 6(1)(f) GDPR |
How long I keep your data
I keep data only for as long as is necessary for the purpose for which it was collected:
| Data category | Retention period |
|---|---|
| Messages from the contact form | 12 months from the last communication, then deleted. If you become a client, the data is kept for the duration of the contract plus the period required by tax law (5 years for financial and accounting documents, under Romanian Accounting Law no. 82/1991, as amended by Law no. 36/2023) |
| Blog comments | For as long as the article exists. On request, they are deleted immediately |
| Server logs | A limited period set by the hosting provider (usually up to 30 days) |
| Web analytics data (GA4) | Maximum 14 months (standard Google Analytics 4 setting) |
| Marketing data (Meta Pixel) | Maximum 180 days (standard Meta setting) |
| Email address from the free security scanner form | 12 months in the delivery queue, so that I can resend the report on request and answer a later question. After that the address is deleted automatically and the record remains without a person in it |
| Online version of the report, at the secret address sent by email | At most 30 days for the free security report. At most 12 months for purchased reports, matching the link in the email. After that it is deleted automatically |
| The copy of your purchased report, kept on the delivery server | At most 12 months, so that on a future purchase I can show you what changed since your previous report. After that it is deleted automatically |
| Scanner usage statistics | The aggregate statistics (date, tool, checked website, country and city) are kept, but they are anonymous. The pseudonymised technical identifier is deleted automatically after 6 months. The raw IP address is not stored at all |
| Email address on the tips list, if you ticked the box | Until you unsubscribe. If you stop interacting, the contact is deleted automatically after 36 months |
| Order and invoicing data (purchased reports, digital book) | The period required by tax law, currently 5 years for accounting documents (Romanian Accounting Law no. 82/1991, as amended by Law no. 36/2023) |
After these periods expire, the data is irreversibly deleted or anonymised.
Who I share the data with (processors)
To make the site work, I use services from external providers, which may process some of your data strictly to deliver their service to me. These providers act as “processors” and are contractually bound to comply with the GDPR.
| Provider | What data it processes | Server location |
|---|---|---|
| ROMARG SRL (hosting) | Site files, database, server logs | Romania (EU) |
| Google LLC (Google Analytics 4, Google Tag Manager, Google Search Console) | Browsing data, session identifiers | USA and Google regional centres, including the EU |
| Meta Platforms Ireland Ltd. (Meta Pixel) | Browsing and conversion events | Ireland (EU) and USA |
| Brevo (Sendinblue SAS) | Name and email address | France (EU) |
| Hetzner Online GmbH | Order data and technical data | Germany (EU) |
| Cloudflare, Inc. | Technical connection data (including IP address) | USA (standard contractual clauses) |
| Payment processor (Revolut) | Data needed to process the payment (not card details) | EU |
I do not share your data with anyone else, except in situations where the law requires me to (for example, at the request of a competent authority, through an official act).
International data transfers
Google LLC is based in the USA, and Meta Platforms Ireland Ltd. is based in Ireland (EU) but transfers data to its parent entity Meta Platforms, Inc. (USA) for processing. The transfer of data to the USA is covered by the EU-US Data Privacy Framework, recognised as adequate by the European Commission through Implementing Decision (EU) 2023/1795 of 10 July 2023, and by the Standard Contractual Clauses adopted by the European Commission through Implementing Decision (EU) 2021/914.
Cookies and analytics tools
The site will use the following categories of cookies, with the following default settings:
- Strictly necessary cookies: active automatically, without consent (Art. 5(3) of the ePrivacy Directive permits them)
- Analytics cookies (Google Analytics 4 via Google Tag Manager): active only after explicit consent through the cookie banner
- Marketing cookies (Meta Pixel): active only after explicit consent through the cookie banner
You can withdraw your consent at any time from the cookie banner settings displayed on the site, or by deleting cookies from your browser. Full details and the list of all cookies will be available on the separate Cookie Policy page, published together with the consent banner.
Your rights under the GDPR
Under Regulation (EU) 2016/679, you have the following rights in relation to your personal data:
- The right to information (Art. 13-14): to receive clear information about how your data is processed, which this policy provides.
- The right of access (Art. 15): to receive a copy of the data I hold about you.
- The right to rectification (Art. 16): to correct inaccurate or incomplete data.
- The right to erasure (Art. 17, the “right to be forgotten”): to request the deletion of your data, except in situations where a law requires me to keep it (e.g. accounting documents).
- The right to restriction of processing (Art. 18): to request the limitation of processing in certain situations.
- The right to data portability (Art. 20): to receive your data in a structured, commonly used, and machine-readable format.
- The right to object (Art. 21): to object to processing based on legitimate interest.
- The right not to be subject to automated decision-making (Art. 22): I do not use automated profiling with legal effects on you.
- The right to withdraw your consent at any time (Art. 7(3)), without the withdrawal affecting the lawfulness of processing carried out beforehand.
To exercise any of these rights, write to me at contact@georgianamanolache.ro. I will reply within 30 days at the latest (this period may be extended by a further 60 days for complex requests, in which case I will notify you within the first 30 days).
How to delete your data: detailed procedure
The right to erasure (Art. 17 GDPR) is one of your most important rights. Here is how you can exercise it, step by step.
1. How to send the request
- Email to contact@georgianamanolache.ro
- Recommended subject: “Request to delete personal data”
- What the message should include:
- the name used when sending the message or comment
- the email address used
- optional: the category of data you want deleted (for example “all data”, “only the blog comments”, “the message sent via the form on date X”)
- To prevent fraudulent deletions, I may ask you for additional confirmation from the email address I have on record.
2. What happens after you send the request
- You receive an acknowledgement of receipt within a maximum of 7 working days
- I verify your identity and determine which data can be deleted immediately and which must be kept on legal grounds
- The actual deletion is carried out within a maximum of 30 calendar days from the validation of the request
- You receive a confirmation email upon completion, with the exact date of deletion
3. What is deleted
- The contact form messages associated with your email address
- The comments published on the blog and the associated data (displayed name, email, IP)
- The web analytics data associated with your identifiers, if it can be technically isolated
- Any other identifiable personal data I hold about you
4. What remains and why
- Rotating site backups: the hosting provider keeps automatic backups for a limited period set by the provider. After this period expires, the deleted data also disappears from the backups. It cannot be manually removed from the provider’s backups.
- Technical logs: server logs are kept by the hosting provider for a limited period, for security and technical diagnostics, in accordance with its retention policy.
- Financial and accounting documents: if you were a client and requested paid services from me, the invoices and accounting documents are kept for 5 years, under Romanian Accounting Law no. 82/1991 as amended by Law no. 36/2023. This legal obligation cannot be overridden by an erasure request.
- Correspondence with legal value: signed contracts, official complaints, or communications related to active legal disputes remain until they are resolved.
5. If the request cannot be fully fulfilled
I send you a written reply within a maximum of 30 days, explaining what was deleted, what was not, and the legal basis that prevents complete deletion. You have the right to challenge this reply with the ANSPDCP (see the next section).
6. The request is free of charge
I do not charge a fee for the first request. For manifestly unfounded or excessive requests (for example, unjustified repeated ones), I may charge a reasonable fee for administrative costs or refuse the request, in accordance with Art. 12(5) GDPR.
The right to lodge a complaint with the ANSPDCP
If you are not satisfied with the way your data is processed and consider that your rights are being infringed, you have the right to lodge a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP), the Romanian data protection authority:
- Address: B-dul G-ral. Gheorghe Magheru 28-30, sector 1, Bucharest
- Phone: +40.318.059.211
- Email: anspdcp@dataprotection.ro
- Website: www.dataprotection.ro
I do, however, encourage you to contact me first, at contact@georgianamanolache.ro. I try to resolve any concern amicably.
Data about children
The site is not addressed to children, and I do not intentionally collect personal data from children under the age of 16. If a parent or guardian notices that a child has provided personal data through the site, they can write to me at contact@georgianamanolache.ro and I will delete the data immediately. The age threshold of 16 is set by Art. 8 of Regulation (EU) 2016/679 (GDPR) for a minor’s valid consent in information society services. Romania has not lowered this threshold through national law, so it remains 16 directly from the Regulation.
Data security
I take reasonable technical and organisational measures to protect your data against unauthorised access, loss, or disclosure. These include:
- encrypted HTTPS connection across the whole site
- regular updates of the WordPress system and plugins
- strong passwords and two-factor authentication where available
- regular site backups through the hosting provider
- access to administrative data restricted to me only
No system, however, can be guaranteed as absolutely secure. If a security incident occurs that affects personal data, I will notify the ANSPDCP within a maximum of 72 hours of detection, in accordance with Art. 33 GDPR. If the incident creates a high risk to your rights and freedoms, I will also inform you directly, without undue delay, in accordance with Art. 34 GDPR.
Links to other sites
The site may contain links to other external sites (for example, LinkedIn, articles cited on the blog). This privacy policy does not apply to those sites. I recommend that you read the privacy policy of each external site you visit.
Changes to this policy
This policy may be updated from time to time, to reflect legal changes, changes in how the site operates, or in the services used. Any major change is announced at least 14 days before it takes effect, through a visible notice on the site. The current version bears the date at the beginning of this document. Previous versions are available on request, at contact@georgianamanolache.ro.
Questions
For any question regarding this policy, your data, or your rights, contact me at contact@georgianamanolache.ro. I reply personally.
Data Protection Officer (DPO)
For questions regarding the processing of your personal data or the exercise of your GDPR rights, contact the data controller directly:
Controller: Manolache G. Georgiana PFA
Tax ID (CUI): 54589208
Email for GDPR requests: contact@georgianamanolache.ro
Response time: maximum 30 days from receipt of the request (Art. 12(3) GDPR)
Note: Under Art. 37 GDPR, appointing a formal DPO (Data Protection Officer) is NOT mandatory for micro-enterprises / sole traders that do not process special-category data on a large scale. All GDPR requests are handled directly by the legal representative.
International transfers and Schrems II
The site uses services that involve data transfers to non-EU countries, in particular the United States:
- Google Analytics 4 (via Google Site Kit), anonymised statistical data processed by Google LLC, USA
- Google Fonts: fonts self-hosted locally on the site (does NOT send IP addresses to the Google CDN, in line with the ruling of the Munich Regional Court of 20 January 2022)
- Google Workspace email: email communication with Google Ireland Ltd. (EU servers) + USA fallback
In accordance with the CJEU ruling in Case C-311/18 (Schrems II) and the EU-US adequacy decision for the EU-US Data Privacy Framework (Decision 2023/1795 of 10 July 2023), these transfers are carried out on the basis of:
- EU-US Data Privacy Framework (DPF): Google LLC is certified under the DPF programme, ensuring an equivalent level of protection
- Standard Contractual Clauses (SCC): European Commission Decision 2021/914, as a supplementary measure
- IP anonymisation: Google Analytics 4 automatically anonymises the last IP octet before storage
- Prior explicit consent: Google Analytics loads ONLY after cookies are accepted through the GDPR banner (Complianz)
You can withdraw your consent for analytics at any time through the cookie panel accessible in the site footer.
Resolving disputes and complaints
If you consider that your personal data has been processed unlawfully, or if we disagree about a GDPR request, you have the right:
- To lodge a complaint with the ANSPDCP, the National Supervisory Authority for Personal Data Processing
Email: anspdcp@dataprotection.ro
Website: www.dataprotection.ro
Phone: +40.318.059.211 - To use Alternative Dispute Resolution (SAL) through the ANPC: reclamatiisal.anpc.ro
- To bring the matter before the competent court under Art. 79 GDPR
This section was updated on 22 May 2026 to reflect the updated European legal framework: Schrems II + EU-US Data Privacy Framework (2023/1795), Standard Contractual Clauses (Decision 2021/914), Government Ordinance 38/2015 (ADR).
