Legal
Privacy policy
Last updated 14 August 2026
1. Who is responsible for your data
The controller of your personal data is SEE WITH YOUR HEART SRL, registered office Str. Becas nr. 30, ap. 16, Cluj Napoca, jud. Cluj, fiscal code 36812661. For anything in this policy, write to andrea@andreavaradigoia.com.
This policy explains what we collect, why, and what you can ask us to do about it.
2. What we collect and why
When you use the contact form
- Data: your name, email address, subject and message.
- Why: to read and answer you.
- Lawful basis: our legitimate interest in replying to people who write to us (art. 6(1)(f) GDPR).
When you book a workshop
- Data: attendee name(s) and email address(es), phone number, and the billing address required to process a card payment (street, city, county, postal code, country).
- Why: to take payment, confirm your place, and send you the practical details of the event.
- Lawful basis: performance of the contract between us (art. 6(1)(b) GDPR), and compliance with our accounting obligations (art. 6(1)(c) GDPR).
We also send a limited technical profile of your browser (user agent, language, time zone, screen size and IP address) to the payment processor. This is required by the 3-D Secure card authentication rules to assess the risk of fraud on the transaction.
We never receive your card number, expiry date or CVV. Those are entered on NETOPIA's own secure page and never reach this website.
3. Who else processes it
We keep the number of third parties deliberately small. Each acts as our processor or as an independent controller:
- NETOPIA Payments (NETOPIA FINANCIAL SERVICES, Romania) — card payment processing.
- Resend (US, transfers covered by the EU standard contractual clauses) — delivers the emails sent by this site.
- Vercel (US, standard contractual clauses) — hosts the site and keeps short-lived server logs.
- Our accountant and, where the law requires it, the tax authorities.
We do not sell your data, and we do not use it for advertising or profiling.
4. How long we keep it
- Contact form messages — as long as the conversation is useful, and no more than 2 years.
- Booking and payment records — 10 years, as required by Romanian accounting law.
- Server logs — a short retention period set by our hosting provider, typically 30 days.
5. Your rights
Under the GDPR you may ask us to:
- confirm what data we hold about you and give you a copy (access);
- correct anything inaccurate (rectification);
- delete it (erasure), where we are not obliged to keep it;
- restrict how we use it, or object to our use of it based on legitimate interest;
- receive it in a portable, machine-readable format;
- withdraw consent at any time, where we relied on consent.
Write to andrea@andreavaradigoia.com and we will answer within one month. If you are not satisfied, you may complain to the Romanian supervisory authority, ANSPDCP — dataprotection.ro.
6. Security
The site is served over HTTPS. Payment data is handled entirely by NETOPIA under the PCI DSS standard. Access to booking records is limited to the organiser and the accountant. No system is perfectly secure, but we keep the amount of data we hold to the minimum needed.
7. Children
The workshops are for adults. We do not knowingly collect data from anyone under 16.
8. Cookies
Covered separately in the cookie policy.
9. Changes
If we change this policy we will update the date at the top of the page. Material changes affecting existing bookings will be sent to you by email.