Privacy
Privacy policy.
What personal data we use when you visit the site or write to us, why we use it, who may receive it, and what rights you have.
- Behavioural advertising
- No
- Sale of personal data
- No
- Response to requests
- 30days
- Last updated
- 2026-08-03
01 · The controller
Who is responsible for your data.
The website tangled-design.ro is operated by the company below, which acts as the controller for the processing described in this policy. In this text, “Tangled Design”, “we”, “us” and “our” refer to that company.
TANGLED DESIGN SRL
Registered office: 30 Aurel Vlaicu Street, Room 2, Târgu Jiu, Gorj County, Romania
Tax identification number (CUI): 38476258
Trade Register number: J18/1169/2017
For any question about personal data, or to exercise a right, email us at [email protected]. We are not required to appoint a data protection officer; requests are handled directly by the company's management.
02 · What we use
Purpose, legal basis, retention.
We use the information you send us and a limited amount of technical data generated automatically when you visit the site. Each category is set out below, with its purpose, legal basis and retention.
Contact form
Messages and project enquiries.
When you submit the contact form we receive your name, email address, the project type you select, a budget range if you choose to give one, and your message. The name, email address, project type and message are required for us to assess and answer the enquiry — without them we cannot reply; the budget range is optional and only helps us understand the project. The IP address the message was sent from is recorded alongside it, together with the date and time — we use those two details to limit automated and abusive submissions. The message arrives in our inbox, and an automatic acknowledgement is sent to the address you entered. We use the information to review your enquiry, reply to you, decide whether we can take the project on and, where relevant, prepare a conversation or a proposal. We do not use it for marketing messages and we do not add it to a mailing list.
- Legal basis
- Steps taken at your request before entering into a contract, and our legitimate interest in responding to professional enquiries and protecting the form against abuse.
- Retention
- Correspondence is kept for the duration of the conversation and a reasonable period afterwards, so we can pick up the context if you come back. Where an enquiry does not lead to a working relationship, we delete the message on request or once it no longer serves a purpose.
Working together
Contracts, invoices, records.
If a conversation turns into a project, we use the information needed to prepare and perform the contract, to communicate about the work, to issue and manage financial and accounting records, and to establish, exercise or defend a legal claim.
- Legal basis
- Performance of a contract, compliance with our legal obligations — accounting and tax obligations in particular — and, where relevant, our legitimate interest in defending legal claims.
- Retention
- Contractual and accounting records are kept for the duration of the relationship and afterwards for as long as the statutory periods applicable to each category of record require.
Free audit
The website address you submit.
The site offers a free accessibility audit. When you submit an address through that form we ask for no name and no email address: we take only the website address and assign it a randomly generated identifier. The address is sent to GitHub, where an automated job runs the check and publishes the resulting report. One thing matters here: both the address you submit and the report are public — anyone with the link can read them, and they remain in the history of a public repository. Please do not submit addresses you would rather keep private. The IP address the request comes from is used only to cap the number of requests per hour and never appears in the report.
- Legal basis
- Our legitimate interest in offering a public testing tool and in protecting it against abuse.
- Retention
- Reports stay public in the audits repository until we remove them. You can ask us to delete a report at any time using the email address below.
Technical data
Logs, security, language choice.
The servers and services that run and protect the site automatically record information such as the IP address, the date and time of access, the page requested, the browser and device type, and any errors raised. We use these records to secure the site, prevent abuse, diagnose faults and keep the service available. Separately, on a first visit we use the IP address to estimate which country you are in and to choose between the Romanian and English versions of the site. That check happens at the moment of the request, we do not store its result, and you can override it at any time with the language switcher.
- Legal basis
- Our legitimate interest in keeping the site working and secure, and in showing you the appropriate language version straight away.
- Retention
- Access and security logs are generated and deleted automatically by our hosting and delivery providers under their own retention policies. We do not build separate archives from them.
Website analytics
Umami Cloud, no analytics cookies.
We use Umami Cloud for statistics; it sets no analytics cookies. In our configuration it may process the page viewed, the date and time, the referring source, the approximate country or region, the browser, operating system and device type, the screen size and the browser language. We also record two events of our own: a successful contact-form submission, and the fact that a visitor has the reduced-motion preference enabled in their operating system — the second tells us how often that setting is in use and whether it is worth maintaining. To distinguish sessions, Umami generates a technical identifier from the IP address, the browser information and the website identifier; according to the service's documentation, the raw IP address is not stored. We do not use analytics for advertising, to identify visitors by name, or to follow them across other websites.
- Legal basis
- Our legitimate interest in understanding how the site is used and improving it.
- Retention
- Statistical data is held by Umami Cloud under the settings on our account and is used only in aggregate.
03 · Cookies
Functional and security only.
The site uses no advertising cookies and no analytics cookies. Because the only technologies in use are strictly necessary for the service to work and stay secure, we do not ask for consent through a banner. If we ever introduce non-essential technologies, we will update this page and ask for consent where the law requires it.
locale
Duration · one year
Remembers which language version to serve, so you are not redirected on every visit. It is set on the first request, with the automatically determined language, and updated when you switch language.
Provider · Tangled Design
__cf_bm
Duration · around 30 minutes
Helps identify and limit automated or abusive traffic. It may only be set in certain circumstances.
Provider · Cloudflare, through DigitalOcean App Platform infrastructure
04 · Who receives it
Providers and recipients.
We do not sell personal data and we do not disclose it to other organisations for their own marketing. We do rely on providers that process data on our behalf so that the site and our email can work at all.
Hetzner
Mailboxes and email delivery
Germany · European Economic Area
DigitalOcean
Application hosting and technical infrastructure
Application hosted in the Frankfurt region
Cloudflare
Traffic delivery and protection, through the edge network built into DigitalOcean App Platform
Global network
Umami Cloud
Website analytics, without analytics cookies
Provider-hosted service
GitHub
Running the free accessibility audit and hosting the resulting reports publicly
Global network · reports are public
These providers may use the data only in line with the contracts and instructions that apply to the service they supply. Some of them also process certain information in their own right, for security, billing or service administration; the exact role depends on the product and contract in use. We may also disclose data to public authorities or professional advisers where the law requires it or where it is necessary to defend a legal claim.
05 · Transfers
What leaves the European Economic Area.
The application is hosted in the Frankfurt region and the mailboxes sit in Germany. Traffic delivery and protection, however, run over a global network, and both the analytics and the audit tool are operated by providers that may use infrastructure or subprocessors outside the European Economic Area. Where such a transfer takes place, it relies on the mechanisms provided for by the GDPR — an applicable adequacy decision, or the Standard Contractual Clauses approved by the European Commission, in the form set out in each provider's data processing agreement. You can ask us for further detail at the email address at the foot of this page.
06 · Your rights
What you can ask for.
Depending on the circumstances and on the legal basis the processing rests on, you have the following rights. A single email is enough to exercise any of them.
01
Access
Ask whether we use your data and receive a copy of it.
02
Rectification
Ask us to correct inaccurate data or complete data that is incomplete.
03
Erasure
Ask us to delete your data, where the legal conditions are met.
04
Restriction
Ask us to limit the use of your data temporarily, in the situations the law provides for.
05
Objection
Object to processing based on our legitimate interests, on the terms set out in the GDPR.
06
Portability
Receive certain data in a structured format and pass it to another controller, where the right applies.
07
Withdrawal of consent
Where processing rests on consent, withdraw it at any time, without affecting processing carried out beforehand.
08
Complaint
Lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), or with the authority in the country where you live or work.
We do not take decisions based solely on automated processing that produce legal effects, or similarly significant effects, for you. The automated checks we do run — the form's spam filter and the cap on submissions per hour — do not have that effect.
To exercise any of these rights, email us at [email protected]. We may ask for further information where it is needed to verify your identity and protect the data. We respond without undue delay and normally within one month. If a request is complex, or several arrive at once, that period may be extended in accordance with the GDPR — in which case we will tell you about the extension and the reasons for it.
07 · Security
How we protect the data.
We use technical and organisational measures proportionate to the risk: encrypted traffic, restricted access to mailboxes and provider dashboards, keys and passwords held only in environment variables, and protection against automated form submissions. No method of transmission or storage can guarantee absolute security. If an incident affecting personal data occurs, we handle it and report it as the law requires.
08 · External links
Leaving our site.
This site links to the websites of our clients, to their projects, and to other external services. When you follow such a link you leave our site, and the processing of your data is governed by that operator's policy. We do not determine or control how those websites use personal data.
09 · Changes
If this policy changes.
We update this page whenever our services, providers or data practices change, and we revise the last-updated date shown below. If a change materially affects how we use data we already hold, we will give additional notice appropriate to the circumstances.
Last updated · 2026-08-03
10 · Contact
Questions?
Anything about this policy — what data we use, who receives it, how to exercise a right — comes to the same inbox.
[email protected]