Legal

Privacy Policy

Last updated: July 28, 2026

This site presents our work. It has no user accounts, processes no payments, and uses no analytics or tracking tools. The only personal data we receive is what you send us through the contact form, plus the unavoidable technical logs that hosting produces. The policy below describes exactly those uses and nothing more.

1. Who we are (the data controller)

This site (“the site”, “we”) is operated by:

We are the data controller within the meaning of the General Data Protection Regulation (GDPR — Regulation (EU) 2016/679).

Macsimotivus LTD
Registration No.: HE 456757
Registered office: Stasikratous 35, Christou Morfaki, Office 301, 1065 Nicosia, Cyprus
VAT No.: CY60050384W
Phone: +357 22583000
Romanian branch: Macsimotivus LTD Nicosia Sucursala Apahida, CUI 51236562, J2025007897004, Str. Ghiocelului 11, Apahida, jud. Cluj, România, Tel. +40 727 180 934

2. What data we collect

We collect only the following categories of data:

  • Contact-form data: the name, email address, subject and message you fill in, together with your confirmation that you accepted this policy. There are no other fields and we ask for no additional information.
  • Technical access logs on our own server: the date and time of the request, the address of the page requested and the browser identifier (user-agent). These logs are deliberately configured not to record IP addresses.
  • Anti-bot check: when you submit the form, Cloudflare Turnstile issues a single-use token which we send to Cloudflare to be verified. It confirms that a person submitted the form and carries none of the text you wrote.
  • Network error reports (Network Error Logging): the network in front of this site sends automatic reports when a connection fails, and those reports include the IP address. Reports are generated on errors, not on every visit.
  • We collect nothing else. There are no accounts, no payments, no analytics and no cross-site tracking.

3. Legal basis for processing

We process the data described above on the following grounds:

PurposeLegal basis (GDPR Art. 6)
Receiving and delivering your contact-form messageConsent, given by ticking the consent box before you submit (Art. 6(1)(a))
Replying to your enquiryLegitimate interest — answering someone who wrote to us (Art. 6(1)(f))
Checking that the form was submitted by a person, not a botLegitimate interest — keeping the form usable and free of abuse (Art. 6(1)(f))
Technical access, security and availability logsLegitimate interest — running and protecting the site (Art. 6(1)(f))

4. Who we share data with (sub-processors)

We do not sell your data and we do not use it for marketing. We share it with only three providers, strictly so that the site and the form work:

  • Hetzner Online GmbH — the server that runs this site, located in Nuremberg, Germany. Your form message passes through that machine on its way to our mailbox and is not stored on it.
  • Cloudflare, Inc. — content delivery, site protection and the Turnstile anti-bot check. Processes connection data, including your IP address and browser identifier, verifies the Turnstile token, and generates the network error reports mentioned above.
  • Google (Google Ireland Limited) — our email provider, through Google Workspace. Your message is delivered to our [email protected] mailbox and is stored there like any other email we receive. Google was already our email provider before this form existed; the form adds no new recipient.

5. International transfers

The server that runs this site is in Nuremberg, Germany, inside the European Union. Your form message is received there and sent on to our mailbox from there.

Cloudflare operates a global network, so connection data and the anti-bot check may be processed in data centres outside the European Economic Area, on the basis of the applicable legal mechanisms (standard contractual clauses or, where applicable, the relevant adequacy decision).

Google Workspace holds our mailbox, and Google may process its contents outside the EEA on the same basis. This applies to any email you send us, not only to the form.

6. How long we keep data

Retention periods are as follows:

  • Form messages in our mailbox: kept as long as needed to reply and to document business correspondence, then deleted. The mailbox is the only place a message is stored.
  • The component that sends the message keeps nothing at all: no database and no queue. It holds your message in memory only for as long as sending takes, and its own log records the time and the outcome — never your name, your address or your text.
  • Technical access logs: short periods. They contain no IP addresses.
  • Network error reports: retention is set by Cloudflare, on the order of days.

7. Cookies and local storage

This site sets no cookies and uses no browser storage (localStorage or sessionStorage). There are no analytics, advertising or preference cookies, and the language is determined solely from the page address.

For that reason the site does not show, and does not need, a cookie consent banner.

8. Your rights

Under Articles 15-22 of the GDPR, you have the following rights regarding your data:

  • The right of access — to find out what data we hold about you (Art. 15).
  • The right to rectification — to have inaccurate data corrected (Art. 16).
  • The right to erasure — to have your data deleted (Art. 17).
  • The right to restriction of processing (Art. 18).
  • The right to data portability (Art. 20).
  • The right to object to processing based on legitimate interest (Art. 21).
  • The right to withdraw consent at any time, without affecting the lawfulness of processing carried out beforehand.
  • The right not to be subject to a decision based solely on automated processing (Art. 22). We make no such decisions.

9. Security

The site is served exclusively over an encrypted connection (HTTPS), and the form is transmitted encrypted to the provider that receives it. The site is static: there is no database of our own and no user account that could be compromised.

Access to the mailbox where messages arrive is limited to the people who need to reply to you.

10. Minors

The site is not directed at people under 16 and we do not knowingly collect data from them. If you become aware that a minor has sent us personal data through the form, write to us and we will delete it without delay.

11. Changes to this policy

We may update this policy when the way the site works changes. The current version is permanently available at this address, with the last-updated date shown at the top of the page.

12. Contact

For any question about your personal data, or to exercise the rights above, you can write to us at:

You also have the right to lodge a complaint with a supervisory authority — in Cyprus, the Commissioner for Personal Data Protection, or the authority in your country of residence (in Romania, ANSPDCP).

[email protected]