Privacy Policy

Last updated: 21 August 2026

This policy explains what personal data diflowrin.com collects, why it is collected, who it is shared with, and what you can do about it. It is written to meet Regulation (EU) 2016/679 (GDPR), which applies because the site is operated from Romania.

Who is responsible for your data

The data controller is Dragan Florin, an independent software developer trading as Diflowrin, based in Arad, Romania.

Diflowrin is a trading name, not a separate company — the services offered on this site are provided by Dragan Florin as a self-employed individual. Fiscal identification details appear on invoices and are available on request.

There is no Data Protection Officer. The site is run by one person, and that person answers privacy questions directly at the address above.

What we collect and why

Contact form

The form on the contact page asks for your first name, last name, email address and message. Submissions are stored in the site database and are also sent to us by email, so that we can reply. Nothing you send through the form is used for marketing, and it is never sold or passed to advertisers.

Legal basis: taking steps at your request before entering into a contract, and our legitimate interest in answering enquiries about our services (GDPR Art. 6(1)(b) and 6(1)(f)). We do not rely on consent here, so declining cookies does not stop us replying to a message you chose to send.

App suggestions

The form on the suggest an app page asks for the name of an application, an optional link to it, and an optional note about why it is worth covering. None of that is personal data about you, and it is stored in the site database so the suggestion can be read and acted on.

The email field on that form is optional and is stored only if you also tick the box asking to be told when the suggestion becomes an article. It is used for that single message and deleted immediately afterwards. It is not added to any list, and there is no list to add it to. If you leave the field empty, nothing is kept that could identify you.

To stop the same person submitting hundreds of suggestions at once, the site keeps a one-way cryptographic hash of your IP address alongside the suggestion. The address itself is never stored, and the hash cannot be turned back into it.

Legal basis: your consent for the email address, given by ticking the box (GDPR Art. 6(1)(a)), and our legitimate interest in receiving suggestions and keeping the form free of abuse (GDPR Art. 6(1)(f)).

Comments on articles

If you leave a comment, we store what you type into the comment form — name, email address and the comment itself, plus an optional website address. WordPress also records your IP address and browser user-agent string, which helps identify spam. Your name and comment become publicly visible once approved; your email address does not.

WordPress may send a hashed version of your email address to the Gravatar service to look up a profile picture. Gravatar is operated by Automattic Inc.; its privacy policy is at automattic.com/privacy.

Legal basis: your consent (GDPR Art. 6(1)(a)).

Server logs

Like every web server, ours records each request: your IP address, the page requested, the time, the response code, the referring page and your browser user-agent. These logs exist to keep the site running and to investigate abuse or attacks. They are not used to build a profile of you.

Legal basis: our legitimate interest in the security and availability of the site (GDPR Art. 6(1)(f)).

Cookies and analytics

Nothing but the cookies the site needs to work is set before you answer the cookie banner. The two analytics tools below are held back until you accept analytics cookies: until then their tags sit in the page inert, and no request leaves your browser for Google or Microsoft.

Set in every case, because the site cannot work otherwise:

  • Consent cookies — record your choice in the cookie banner and the current session, so you are not asked again on every page.
  • Comment cookies — if you leave a comment, you may opt in to have your name, email and website remembered so you do not have to retype them. These last up to one year.
  • Login and session cookies — only set for people who log in to administer the site, not for ordinary visitors.

Set only if you accept analytics cookies:

  • Google Analytics 4 — counts visits and shows which pages get read. It sets two cookies, _ga and _ga_5RH7FZNJDD, and sends Google your IP address, the pages you open and basic details about your browser and device.
  • Microsoft Clarity — records how the pages are actually used, which includes a replay of mouse movement, scrolling and clicks, and turns that into heatmaps. It may set identifiers of its own.

You can change your mind at any time. The Cookie Preferences control reopens the banner, and declining leaves both tags inert and sets none of those cookies. Nothing you type into a form is sent to either service.

Legal basis: your consent for the analytics cookies (GDPR Art. 6(1)(a)), and our legitimate interest in the strictly necessary ones (GDPR Art. 6(1)(f)).

What we do not do

We do not sell or rent personal data. We do not run advertising, and nothing the analytics tools collect is used to build a profile of you, sold, or passed to advertisers. We do not use your data for automated decision-making that produces legal effects for you. Visitors cannot register accounts on this site.

Who your data is shared with

We use a small number of service providers who process data on our behalf. They may only use it to provide their service to us.

ProviderWhat they handleWhere
Hetzner Online GmbHWebsite hosting and server logsHelsinki, Finland (EU)
Namecheap, Inc.Email hosting — messages sent from and received through the contact formUnited States
GoogleGoogle Analytics 4 — only after you accept analytics cookiesUnited States
Microsoft CorporationMicrosoft Clarity session recordings and heatmaps — only after you accept analytics cookiesUnited States
Automattic Inc. (Gravatar)Comment avatars, looked up from a hash of your email addressUnited States

The website itself and its database are hosted inside the European Union. Transfers to the providers based in the United States rely on the EU–US Data Privacy Framework and, where applicable, the European Commission’s Standard Contractual Clauses.

How long we keep it

DataRetention
Contact form submissions and the resulting email correspondence24 months after our last exchange, then deleted
App suggestions (name, link, note)Kept while the suggestion is open, and as a record once it becomes an article
Email address given for a publication noticeDeleted as soon as that one message is sent, or within 12 months if no article follows
Comments and their metadataFor as long as the comment remains published
Google Analytics event data2 months, the shortest retention the product offers
Microsoft Clarity recordings and heatmapsKept by Microsoft under Clarity’s own retention policy
Server access logs14 days, then rotated out automatically
Cookie consent recordUntil it expires or you clear your browser storage

Where a contact leads to actual work, invoicing records are kept for as long as Romanian accounting and tax law requires, regardless of the periods above.

Your rights

Under the GDPR you can ask us to:

  • Access the personal data we hold about you, and receive a copy (Art. 15)
  • Correct anything inaccurate or incomplete (Art. 16)
  • Delete your data, where we have no overriding reason to keep it (Art. 17)
  • Restrict how we use it while a dispute is resolved (Art. 18)
  • Receive it in a portable format you can take elsewhere (Art. 20)
  • Object to processing based on legitimate interest (Art. 21)
  • Withdraw consent at any time, which does not affect processing already carried out (Art. 7(3))

Write to admin@diflowrin.com and we will respond within one month. Exercising these rights is free of charge.

If you want to complain

If you believe we have mishandled your data, please contact us first — most problems are quicker to fix directly. You also have the right to lodge a complaint with the Romanian supervisory authority:

Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336 București, Romania
www.dataprotection.ro — anspdcp@dataprotection.ro

If you live in another EU country, you may complain to your own national authority instead.

Children

This site offers professional development services and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has sent us personal data, tell us and we will delete it.

Security

The site is served over HTTPS, so traffic between your browser and the server is encrypted. Email is sent over an authenticated, encrypted SMTP connection. No system is perfectly secure, but access to the server and the database is restricted to the site owner.

Changes to this policy

If what we collect or who we share it with changes, this page is updated and the date at the top changes with it. Substantial changes will be flagged on the site itself.

Contact

Questions about this policy, or about anything we hold on you:

Dragan Florin — Diflowrin
Arad, Romania
admin@diflowrin.com
+40 757 465 012