What we know about you,
and what we do with it.
This site sets no cookies and loads no trackers — the only personal data we receive is what you choose to type into the brief form. Everything below is detail.
Two data flows exist on this site — the brief form you fill in on purpose, and the server logs every website has. No cookies, no analytics scripts, no advertising, no profiling. Booking a call and the free GDPR audit run on separate systems, outside this website.
Who we are
microanalytics is an independent marketing & digital analytics practice — Bucharest and Brașov, working since 2014. For this website the data controller is Microanalytics Services S.R.L., a Romanian company registered under CUI 15981285 (Trade Register J2015001108406), with its registered office at Str. Burniței 24, office B20, floor 1, sector 3, Bucharest.
For anything in this notice, write to us through the brief form — contact.html; a person replies, usually within one business day. We work to GDPR, ANSPDCP guidance and Law 506/2004 every day, for clients; this page is the same standard applied to ourselves.
What we collect — the whole inventory
Two data flows. This is all of them.
- How we get ityou type it in and press send. That act is the collection — nothing is taken automatically, nothing is read out of your browser, and no field is filled in for you. Close the page without sending and we have none of it.
- Whatname, email, company (optional), and whatever you write in the brief. Your email address reaches us only because you put it there.
- Whyto answer you. No newsletter, no drip sequence, no "keeping you posted."
- Basisart. 6(1)(b) GDPR — steps taken at your request before any contract.
- Routethe form travels as one email — through our own relay (Google Cloud, region europe-west1, EU) and Resend (email delivery, dispatched from Ireland) — into our Google Workspace mailbox. Nothing is stored on this website; there is no database behind it.
- How longlike any business correspondence — for as long as the conversation it belongs to. Tell us to delete yours and we delete the thread, not just the formality.
- Whatevery web server sees the technical envelope of a request — IP address, user agent, requested path, referrer. Ours is no different.
- Whyserving pages, keeping the site up and abuse out, and giving us aggregate numbers — views, visitors, countries, which crawlers came by. We see totals, not people: no profile of you exists, here or anywhere we can reach.
- Basisart. 6(1)(f) GDPR — the legitimate interest in running a website and knowing whether anyone reads it.
- Wherethe logs live with our host, here.now, and we read them only as aggregates.
What we don't do
- ×No cookies. No analytics script. No pixels, no fingerprinting, no session recording.
- ×No advertising, no remarketing audiences.
- ×No profiling, no automated decisions.
- ×No selling, renting or "sharing with carefully selected partners" — there are no partners.
The cookie policy is one sentence long; it still gets its own page — cookies.html.
Who else touches the data
Each processes data only for the job named above, under a data-processing agreement. Where a provider is outside the EEA, transfers rest on the European Commission's approved safeguards — adequacy, the EU–US Data Privacy Framework, or standard contractual clauses.
Two things happen outside this website and are not covered above — booking a call, which runs on Calendly under Calendly’s own notice, and the free GDPR audit at audit.microanalytics.ro, a separate deployment of ours. Ask us through the brief form what either one collects and for how long — contact.html. The LinkedIn link in the footer is just a link; nothing loads from LinkedIn here.
Your rights
GDPR gives you the full set — access, rectification, erasure, restriction, portability, objection (arts. 15–21). Exercising them here is one message through the brief form — contact.html. No portal, no identity theatre beyond what the law asks.
We're small enough that no DPO is required — the founders answer personally. If we ever can't resolve something, the supervisory authority is ANSPDCP — dataprotection.ro. We'd prefer the message first, but that's your right, not ours to manage.
Changes
This notice changes when the site does — a new tool, a new flow, a new page. Material changes get a new date below; we don't do silent edits.