Noveam Architecture & Governance Request a walkthrough

Privacy Policy

Last updated: 5 August 2026 · Version 1.0

1. In short

  • We run a website that describes a product. There is no account, no login and no shop.
  • We do not use analytics, tracking pixels, advertising cookies, session recording, heatmaps, A/B testing tools, social-media plugins or a third-party form service.
  • We collect personal data in exactly one place: the contact form. Plus the technical logs that any website produces.
  • We use what you send us to answer you. Nothing else.
  • We never sell your data and we never share it for marketing.
  • You can ask us what we hold about you, and ask us to delete it, at [email protected].

The rest of this page is the detail. It is written to be read, not to be skipped.

2. Who is responsible for your data

The controller is:

IELLO TECH S.R.L.
Str. Argentina nr. 25, Bucharest, Sector 1, 011753, Romania
Trade register J40/12189/2021 · Fiscal code (CUI) 44593082
Email: [email protected]

"Controller" means we decide why and how your data is processed.

We have not appointed a Data Protection Officer. We are not a public authority, we do not monitor people on a large scale, and we do not process special categories of data on a large scale, so Article 37 GDPR does not require one. For any data-protection question, write to [email protected]. That address reaches a person, not a queue.

We are established in Romania, so no EU representative under Article 27 GDPR is needed.

3. What we collect, why, and on what legal basis

We process personal data for four purposes. Each has its own basis. We do not use a blanket "you consented" for everything, because that would not be true.

What we collect — the fields of the contact form: your name, your work email address, your organisation, your role (optional), your country, which deployment interests you, which regime you are working to (optional), and your message. Plus the date and time you sent it.

Why — to read your enquiry and reply to it, and to prepare for a walkthrough if you ask for one.

Legal basis — Article 6(1)(f) GDPR, our legitimate interest in responding to a business enquiry that you chose to send us.

We explain the balancing behind that basis, because you are entitled to see the reasoning:

  • Our interest: we cannot run a business if we cannot answer people who write to us.
  • Necessity: there is no way to reply to you without using your name and address.
  • Your expectations: you filled in a contact form and asked for an answer. Being answered is exactly what you expected.
  • Impact on you: minimal. Business contact details, given voluntarily, used once, for the thing you asked for, then deleted on a fixed schedule.
  • Your control: you can object at any time under Article 21 GDPR and we stop.

Where the person is themselves the prospective customer — for example a sole trader or an independent consultant asking about a licence — the basis is Article 6(1)(b) GDPR instead: steps taken at your request before entering a contract.

A note about the tick box — the contact form asks you to confirm that you have read how we handle your enquiry. That confirmation is an acknowledgement that you have read this policy. It is not the legal basis for the processing, and un-ticking it later does not change anything, because the basis is legitimate interest. What does work is objecting or asking us to delete: see section 7.

What we collect — technical data that is generated automatically when your browser requests a page: your IP address, the time of the request, the page requested, the response code, the user-agent string your browser sends, and rough location derived from the IP (country level). Our hosting provider produces these records.

We also apply a rate limit to the contact form, so one sender cannot flood it.

Why — to deliver the pages, to keep the site up, to detect and block attacks, and to stop automated spam through the form.

Legal basis — Article 6(1)(f) GDPR, our legitimate interest in the security and availability of our own website. Keeping a site online and free of abuse is a legitimate interest that Recital 49 GDPR names explicitly.

We do not use these logs to build a profile of you, and we do not connect them to your enquiry.

What we keep — your enquiry and our reply.

Why — so that we can find the thread again if you come back to us, and so we have a record if a dispute ever arises about what was promised.

Legal basis — Article 6(1)(f) GDPR, our legitimate interest in keeping a short record of our own business correspondence and in being able to establish, exercise or defend a legal claim.

What — if a law requires us to keep or produce something, we do.

Legal basis — Article 6(1)(c) GDPR, compliance with a legal obligation.

Today this affects the website almost not at all, because the site sells nothing. If you become a customer, invoicing and accounting records fall under Romanian accounting law, and we will give you a separate privacy notice at that point.

4. What we do not do

These statements are specific on purpose. Vague promises are worthless.

  • No analytics. There is no Google Analytics, no Plausible, no Matomo, no Fathom, no Cloudflare Web Analytics, and no self-built page-view counter on this site.
  • No advertising. No advertising cookies, no remarketing tags, no conversion pixels, no Meta pixel, no LinkedIn Insight Tag, no Google Ads tag.
  • No behavioural tracking. No session recording, no heatmaps, no scroll tracking, no mouse tracking, no A/B testing tool.
  • No third-party form service. The contact form posts to our own endpoint. It is not Typeform, HubSpot, Formspree or anything similar.
  • No social plugins. No embedded Like buttons, no embedded feeds, no share widgets that phone home.
  • No external fonts. Fonts are served from our own domain. No request goes to Google Fonts or any font CDN.
  • No marketing list. Writing to us does not sign you up for anything. There is no newsletter on this site.
  • No selling, renting or sharing your data with anyone for their own purposes.
  • No automated decision-making and no profiling in the sense of Article 22 GDPR.
  • No special categories of data. We do not ask for and do not want data about health, politics, religion, trade-union membership, sex life, biometrics or ethnicity. Please do not put any in the message field.

If we ever add measurement, it will be cookieless and first-party: aggregate counts only, no identifier stored on your device, no third-party recipient. We will update this page and the cookie page before it goes live, and we will say so plainly.

5. Who else touches your data

We use a small number of service providers. They process data on our instructions only, under a written data-processing agreement that meets Article 28 GDPR. They are not allowed to use your data for their own purposes.

The full list, with purpose, location and transfer mechanism, is in Annex A: Processors at the end of this page.

In summary:

  • Cloudflare hosts the site, serves the pages, runs the form endpoint, and stores the enquiry.
  • Resend sends us the notification that an enquiry has arrived.
  • Google holds the mailbox [email protected], through Google Workspace.

Beyond those, we disclose personal data only:

  • to a court, a regulator or a public authority, when the law obliges us;
  • to our lawyers or accountants, bound by professional secrecy, if we need advice;
  • to a buyer, if the business is ever sold — and we would tell you before that happened.

6. Sending data outside the European Economic Area

We keep data inside the EEA where we can, and we tell you honestly where we cannot.

The enquiry itself is stored in a Cloudflare D1 database created in Cloudflare’s eu jurisdiction. That setting makes the database run and store data inside the European Union, and it cannot be changed after the database is created.

Cloudflare is a US company and its group operates worldwide. For transfers to the United States, Cloudflare is certified under the EU–US Data Privacy Framework, the Swiss–US framework and the UK extension. Its Data Processing Addendum also incorporates the European Commission’s Standard Contractual Clauses, which apply if the certification ever lapses. So there are two mechanisms in place, one behind the other.

Resend is a US company. Even when email is sent from its European sending region, Resend states that account data, email metadata and logs are stored in the United States. That is a transfer outside the EEA. It is covered by Resend’s Data Processing Addendum, which includes the Standard Contractual Clauses, and Resend is certified under the EU–US Data Privacy Framework and the UK extension.

We limit what crosses that border. The notification we receive is designed to tell us that an enquiry arrived, not to carry the enquiry: it contains no name, no address and no message text. We read the enquiry itself in the database, which is in the EU.

You can ask us for a copy of the transfer safeguards. Write to [email protected].

7. Your rights

Under the GDPR you have the following rights. They are free to use.

  • Access — ask what personal data we hold about you and get a copy.
  • Rectification — have wrong data corrected, or incomplete data completed.
  • Erasure — have your data deleted, where one of the grounds in Article 17 applies. For a contact-form enquiry, asking us to delete it is normally enough.
  • Restriction — ask us to stop using data while a dispute about it is resolved.
  • Objection — object at any time to processing based on legitimate interest, which covers almost everything on this site. If you object, we stop unless we can show compelling grounds that override your interests. For an enquiry, we will simply stop and delete.
  • Withdraw consent — where we ever rely on consent, you may withdraw it at any time. Withdrawing does not undo what was lawful before.
  • Complain — to a supervisory authority. See section 8.

About portability. The right to data portability (Article 20 GDPR) applies only where processing is based on consent or on a contract and is automated. Our processing is based on legitimate interest, so portability does not normally apply here. We say this rather than listing a right you cannot actually use.

How to exercise a right. Write to [email protected]. Say what you want. You do not need a form and you do not need to give a reason, except when objecting on grounds specific to your situation.

What happens next.

  • We reply within one month of receiving your request.
  • If the request is complex, we may extend by two further months, and we will tell you within the first month, with the reason.
  • If we cannot identify you from what you sent, we may ask for more information — only enough to be sure we are not sending your data to somebody else.
  • If we refuse, we tell you why, and we tell you how to complain.
  • Requests are free. If a request is manifestly unfounded or excessive, particularly if it is repetitive, we may charge a reasonable fee or refuse, and we will explain which.

8. Complaining to the supervisory authority

If you think we have handled your data wrongly, tell us first — we would rather fix it. But you may go straight to the supervisory authority at any time.

Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
B-dul G-ral. Gheorghe Magheru nr. 28–30, Sector 1, 010336 Bucharest, Romania
Telephone: +40 31 805 9211
Email: [email protected]
Website: https://www.dataprotection.ro

Complaints can be sent by post or email, or handed in at the authority’s headquarters. The authority publishes complaint forms on its website.

You may also complain to the supervisory authority in the EU country where you live or work, or where you think the problem happened. You can also go to court.

9. How long we keep things

The periods are in Annex B: Retention at the end of this page. They are numbers, not "as long as necessary".

Two rules sit behind the table:

  1. When a period ends, the record is deleted, not archived.
  2. If you ask us to delete sooner, we do, unless a law says we must keep it.

10. Cookies and what we store on your device

Short version: the site sets no analytics cookies and no advertising cookies. The full inventory and the rules are on the Cookie and Storage Policy page.

11. Children

This site is for people doing their job at an organisation. It is not directed at children and we do not knowingly collect data from them.

Under Romanian Law no. 190/2018, the age at which a child can consent for themselves to an information society service is 16. If you are under 16, please do not use the contact form. If you believe a child has sent us data, write to [email protected] and we will delete it.

12. How we protect your data

  • The site is served only over HTTPS.
  • The form endpoint is rate-limited and validated on the server, not just in the browser.
  • Access to the enquiry database is limited to the people who need it.
  • We keep the number of people with access small, and we review it.
  • We do not copy enquiry data onto laptops, personal devices or spreadsheets.

No system is perfectly secure. If a breach happens and it is likely to put your rights at risk, we notify ANSPDCP within 72 hours of becoming aware, and we tell you directly when the risk to you is high, as Articles 33 and 34 GDPR require.

13. Do you have to give us your data

No. Nothing on this site requires you to identify yourself.

The contact form is voluntary. If you fill it in, the required fields really are required — without a name, an address to reply to, an organisation, a country, a deployment interest and a message, we cannot give you a useful answer. The optional fields are optional, and leaving them blank costs you nothing.

You can always write to [email protected] instead and share less.

14. Changes to this policy

We may update this policy. When we do:

  • we change the "Last updated" date and the version number at the top;
  • if the change is significant — a new purpose, a new processor, a new transfer, a longer retention period — we publish a notice on the site for 30 days;
  • if the change affects an enquiry you already sent, and we still hold your address, we email you before it takes effect.

15. Contact

Email: [email protected]
Post: IELLO TECH S.R.L., Str. Argentina nr. 25, Bucharest, Sector 1, 011753, Romania

Annex A (processors) and Annex B (retention) are published as part of this page. They are below.

Annex A — Processors

Processors, what they do, where they process and the transfer mechanism
ProcessorWhat it does for usPersonal data it touchesWhere it processesTransfer mechanism outside the EEA
Cloudflare, Inc. (US) and its EU affiliatesHosts the site on Cloudflare Pages, serves every page, terminates TLS, filters abusive traffic, runs the contact-form endpoint as a Pages FunctionIP address, request metadata, user-agent; the full contact-form submissionGlobal edge network. The enquiry database (Cloudflare D1) is created in the eu jurisdiction, so it runs and stores data inside the EUCloudflare’s Data Processing Addendum incorporating the EU Standard Contractual Clauses; Cloudflare is additionally certified under the EU–US Data Privacy Framework, the Swiss–US framework and the UK extension, with the SCCs as the fallback
Resend (Plus Five Five, Inc.) (US)Sends the notification email that tells us an enquiry has arrivedThe recipient address (ours) and the notification content. The notification carries no enquirer data — it says only that an enquiry arrived, as described in section 6Sending region may be set to eu-west-1 (Ireland), but Resend stores account data, email metadata and logs in the United StatesResend’s Data Processing Addendum incorporating the Standard Contractual Clauses; Resend is certified under the EU–US Data Privacy Framework and the UK extension
Google Ireland Limited (Google Workspace)Holds the mailbox [email protected], where enquiries and our replies liveName, email address, organisation, role, country, message content, and the reply threadGoogle’s global infrastructure. Mail is not confined to the EEA: we do not use the Workspace data-region setting, so a message may be processed outside itThe Google Workspace Cloud Data Processing Addendum, which incorporates the EU Standard Contractual Clauses; Google LLC is additionally certified under the EU–US Data Privacy Framework

Not processors, listed so the picture is complete: the registrar and DNS provider for noveam.net is Cloudflare, already named above as the processor that hosts the site, so it is not a separate recipient; our accountant and our lawyers, who act as separate controllers or under professional secrecy, and only if a specific matter requires it.

Article 28 obligations. Each processor is engaged under a written data-processing agreement that binds it to process only on our documented instructions, to keep the data confidential, to apply appropriate security, to help us answer data-subject requests, to tell us about breaches, to seek our authorisation for sub-processors, and to delete or return data at the end.

Annex B — Retention

What we keep, for how long, and why that period
DataPurposeHow long we keep itBasis for the period
Contact-form enquiry (name, work email, organisation, role, country, deployment interest, regime, message, timestamp) — no commercial relationship followsAnswering you; keeping a short record of the exchange12 months from our last message in the thread, then deleted from the database and the mailboxLong enough for you to come back and be recognised; short enough that a cold enquiry does not sit with us for years
Contact-form enquiry — a commercial relationship followsManaging the relationshipMoves into the customer record and is governed by the agreement and its own privacy notice; it stops being website dataA separate notice is given at that point. This website policy does not attempt to cover it
Reply thread in the mailbox [email protected]Continuity of the conversation12 months from the last message, then deletedSame reasoning as above
Web server and security logs (IP address, timestamp, URL, status code, user-agent)Delivering pages, security, abuse detectionHeld by Cloudflare on its own schedule. We keep no copy of these logs and we do not set the period. The exact number of days is not written here yet — see the note under this tableSecurity and availability; kept no longer than needed to investigate an incident
Rate-limit counters for the contact formStopping automated abuse of the formMinutes to hours; they expire automatically and are never read for any other purposeOnly useful while the limit window is open
Notification email held by ResendTelling us an enquiry arrivedHeld by Resend on its own schedule. The notification carries no enquiry content, so what Resend holds is that a message was sent, not what was in it. The exact number of days is not written here yet — see the note under this tableKept no longer than the provider’s minimum
Records of data-subject requests (what was asked, what we did, when)Showing we complied with Articles 12–22 GDPR3 years from closing the requestWe must be able to demonstrate compliance; three years covers the usual limitation period for such a challenge
A record that a breach happened, and what we didArticle 33(5) GDPR obliges us to document every breach5 years from the incidentArticle 33(5); five years is a defensible fixed period
Consent record in your browser, if a consent gate is ever builtShowing what you chose12 months, then we ask againSection 3 of the consent specification

Deletion means deletion. At the end of a period the record is removed from the live database and from the mailbox. Backups are overwritten on their own cycle, and a record that survives briefly in a backup is not restored into use. We run no backup of the enquiry database ourselves; Cloudflare operates its own recovery window for the database.

Three periods on this page are not yet numbers. How long Cloudflare keeps the logs it produces for us, how long Resend keeps its record of a sent notification, and how long a deleted enquiry can survive inside Cloudflare’s own recovery window for the database. All three are set by the provider, not by us. We would rather show you the gap than publish a number we have not checked. If you need the current answer, write to [email protected] and we will get it from the provider and give it to you in writing.