What data reaches us, why it is used and how to exercise your rights. Analytics is optional; a project enquiry is not a marketing subscription.
1. Controller and contact
EDU BOOST SRL provides the services presented under the name Alexandru Jungean. Tax identification number (CUI): 50079362; Trade Register: J2024001347052; EUID: ROONRC.J2024001347052. Location: Cluj-Napoca, Romania.
Direct contact: alex.jungean@gmail.com · +40 757 673 677.
EDU BOOST SRL determines the purposes and means of processing data received through alexjungean.com and in its own business relationships. This notice is provided under Articles 12–14 of Regulation (EU) 2016/679 (GDPR). When processing on a client’s behalf, roles and instructions are governed by that project’s data-processing agreement.
2. Data received and its sources
- Contact: your name, email, selected service and message, followed by correspondence and information needed to respond.
- Project enquiry: contact and organisation details, role, phone if supplied, objectives, requirements, budget, timing, working preferences, links and files you choose to upload.
- Contract and billing: identity, representative, billing and payment details, communications, approvals and documents needed for the engagement.
- Operation and security: IP address, browser/device information, request times and technical data, errors and abuse-prevention signals to the extent generated by the services used.
- Analytics, only after consent: pseudonymous identifiers, pages visited, interactions and general device and usage information. Pseudonymous data is not described as anonymous.
Data mainly comes from you and your website use. Project data may also come from the organisation you represent or a partner introducing us; we provide the applicable information under Article 14 GDPR. Do not send passwords, identity documents or sensitive data through the general form.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Responding to your request, preparing your proposal and performing a contract with you | Article 6(1)(b) GDPR: steps requested before a contract and contract performance. |
| Communicating with business representatives and managing B2B relationships | Article 6(1)(f): legitimate interests in responding to the organisation and managing the engagement, respecting the individual’s rights. |
| Billing, accounting records and mandatory authority requests | Article 6(1)(c): applicable legal obligations. |
| Security, spam prevention and legal claims | Article 6(1)(f): proportionately protecting the website, correspondence and legal interests. |
| Optional analytics | Article 6(1)(a): consent, alongside storage/access rules in Romanian Law 506/2004. |
Article 6 GDPR distinguishes these bases. Responding to an enquiry is not conditional on analytics consent. Sending a message does not automatically subscribe you to marketing. Required fields are needed to handle the request; without them the form cannot be processed, but you may contact us directly.
4. Drafts and file uploads
The /start project form stores answers locally in your browser under intake_form_draft so you can resume. Clear the draft after using a shared device. Draft answers and uploaded files follow different data flows.
A file selected for upload may be sent to Cloudflare R2 immediately, before final submission of the enquiry. Removing it from the form or clearing the local draft does not confirm deletion of the already-uploaded copy. To request deletion of a transmitted file, contact us with its name and approximate upload time; do not resend the file just to request deletion.
The contact form sends the message through a Netlify-hosted processing function and the email service. Google reCAPTCHA performs anti-spam checks and may process technical data before the message is accepted.
5. Recipients and service providers
- Netlify: website delivery, form-processing functions and infrastructure operation.
- Google / Gmail: sending and receiving correspondence.
- Google reCAPTCHA: assessing spam risk for the contact form, potentially receiving IP and browser/interaction information.
- Google Analytics: usage measurement only after analytics is enabled; message and file contents are not intentionally sent as analytics events.
- Cloudflare R2: storage of files uploaded through the project form.
- Authorised people and advisers: project collaborators, accounting and legal advisers, and authorities, only where access is necessary and lawful.
Provider information: Netlify, Google and Cloudflare. Their notices do not replace EDU BOOST SRL’s duties. We do not sell personal data received through the forms.
6. Transfers outside the EEA
International providers may involve processing or access outside the European Economic Area, including in the United States. We do not guarantee that all data stays in Romania or the EU simply because you visit from Europe.
Transfers must comply with Articles 44–49 GDPR. The relevant mechanism depends on the entity and service: an applicable adequacy decision or safeguards such as standard contractual clauses, with the necessary assessments and measures. A US provider’s existence alone does not establish certification coverage. You can request information about transfers affecting your data and a copy of relevant safeguards, with third-party confidential information protected.
7. Retention
Retention follows purpose, the contractual relationship and legal obligations; all categories are not automatically kept for the same period. The following criteria reflect storage limitation under Articles 5(1)(e) and 13(2)(a) GDPR.
- Enquiries and proposals without a contract: as needed to assess and actively discuss your request; after closure, only for a justified continuing purpose such as an agreed follow-up or a legal claim.
- Project records: during the contract and afterwards as needed for applicable obligations and limitation periods, considering suspension, interruption or disputes. Unnecessary operational copies are removed separately from evidential records.
- Accounting books and supporting records: the general rule is five years from 1 July of the year following the financial year in which they were created, under Article 25 of Romanian Accounting Law 82/1991; other categories may have different rules.
- Uploads: while needed for assessment or the project; a legal obligation or dispute may justify limited further retention. Clearing the browser draft does not automatically delete external storage.
- Technical and analytics data: according to the security or measurement purpose and service settings; browser cookie duration is separate from provider event retention.
- Analytics preference: 180 days in the browser. The enquiry draft remains locally until cleared, reset or removed through the browser’s site-data settings.
You may request the period or criterion applicable to a specific category. A retention obligation may prevent immediate deletion of a record without allowing new uses of it.
8. Your rights and how to use them
Subject to GDPR conditions, you have rights to information and access (Article 15), rectification (16), erasure (17), restriction (18), portability for automated processing based on consent or contract (20) and objection to legitimate-interest processing (21). You may withdraw consent at any time without affecting earlier lawful processing (Article 7(3)). Rights have legal conditions and exceptions; they do not require deletion of every accounting record.
Send requests to alex.jungean@gmail.com. We request only additional information needed to verify identity. We respond without undue delay and normally within one month; complex or numerous requests may require up to two additional months, with reasons and notice in the first month under Article 12(3). Requests are normally free, subject to Article 12(5).
For analytics, use . Withdrawal stops future collection; it is not automatically an erasure request for information already received by the provider.
You can complain to Romania’s ANSPDCP or the supervisory authority where you live, work or where an alleged infringement occurred, under Article 77 GDPR, without losing access to judicial remedies.
9. Security and automated decisions
We use technical and organisational safeguards appropriate to risk, including HTTPS transport and form checks. Project information should be accessible only to those who need it. Security and incident duties follow Articles 32–34 GDPR.
Form data is not used for solely automated decisions producing legal or similarly significant effects within Article 22 GDPR. Automated spam filtering may reject a message; if that happens, contact us by email or phone.
10. Notice updates
The version date appears at the start. If purposes or processing change in a way that requires new information or consent, those requirements are met before the relevant change. Publishing a new policy does not retroactively create a legal basis for data already collected.













