Privacy policy
This page describes what this website collects, why, how long it is kept, and what you can ask me to do about it. It covers this website only, and it is written against what the code actually does rather than against what a template assumes a website might do.
Who is responsible
Enrico Gărăiman, Bucharest, Romania, is the controller of the personal data described here. I run this site myself: there is no company behind it and no marketing team. You can reach me at contact@enricogaraiman.com about anything on this page, including a request to see or delete what I hold about you.
What is collected
When you send me a message
The contact form stores your name, your email address, the subject if you filled one in, and the message itself. Alongside it I store the time, a shortened copy of your browser's user agent string, and a one-way hash of your IP address rather than the address itself.
Legal basis: your consent, given by ticking the box before you send, under Article 6(1)(a) GDPR. You give it deliberately, and you can withdraw it by asking me to delete the message.
When you rate the site
The rating widget stores the number of stars, the page you were on, the time, a shortened user agent string, and the same one-way hash of your IP address. No name, no email, nothing that identifies you directly.
Legal basis: my legitimate interest in knowing whether the site is any good, and in stopping one person from voting a hundred times, under Article 6(1)(f) GDPR. The hash is what makes the second part possible without keeping your address.
Why a hash instead of your address
Your IP address is never written to the database. What is stored is the SHA-256 hash of your address combined with a secret held on the server. It lets me recognise that two votes came from the same place without being able to work backwards to where that place is, and without holding an identifier I could hand to anyone.
Server logs
The web server keeps an access log with the requesting IP address, the page, the time and the user agent, as web servers do. It is used to investigate errors and abuse. It is not part of the application database and is not linked to the data above.
Legal basis: legitimate interest in operating and securing the site, under Article 6(1)(f) GDPR.
Cookies and analytics
The site sets no cookies of its own for an ordinary visit. Your choice about analytics is kept in your browser's local storage, together with the moment you made it, so that the notice does not follow you around. That entry never leaves your browser.
If you agree to analytics, and only then, the site loads Google Analytics and Google sets its own cookies. IP anonymisation is switched on. If you decline, or if you ignore the notice entirely, the analytics script is never loaded at all, not merely hidden. You can change your mind at any time through the cookie preferences link in the footer, and refusing is exactly as easy as accepting.
The contact form can be protected by Google reCAPTCHA, which scores how likely it is that a message was typed by a person. When it is on, the form says so under the send button, with links to Google's own terms, and the check is fetched from Google only once you start filling the form in, never while you are reading the page. If that line is not there, reCAPTCHA is off and Google is not contacted at all.
Who else sees this data
- The hosting provider that runs the server this site sits on, as an inevitable consequence of the site being hosted somewhere.
- The email provider that delivers the notification of your message to me and the confirmation back to you.
- Google, but only if you agreed to analytics, and only for analytics data. That involves a transfer to the United States, which Google covers through the EU-US Data Privacy Framework and standard contractual clauses.
Nothing is sold, and nothing is shared for advertising. No third party receives your contact message other than the mail provider that carries it.
How long it is kept
There is no automatic deletion schedule, so rather than quote a number I will not keep to, here is what actually determines how long each thing lives.
- Contact messages: kept while they are still useful. A message that led to work or a collaboration stays as long as that relationship does, and the rest I clear out when I go through the inbox. Ask me and yours goes immediately.
- Ratings: kept while the site shows an average, since an average without its history is not an average. They carry no direct identifier.
- Server logs: kept on the server for as long as they are useful for tracing an error or a burst of abuse, and cleared out by hand rather than on a timer. Ask me and I will tell you what is currently held.
- Your analytics choice: in your browser until you change it or clear it.
Your rights
Under the GDPR you can ask me to:
- tell you what I hold about you and give you a copy, under Article 15
- correct anything that is wrong, under Article 16
- delete it, under Article 17
- restrict what I do with it while something is being sorted out, under Article 18
- hand it to you in a portable format, under Article 20
- object to processing I base on legitimate interest, under Article 21
- withdraw a consent you gave, without affecting what was lawful before you withdrew it, under Article 7(3)
Write to contact@enricogaraiman.com and I will answer within one month. Because the data is small and I handle it personally, deletion usually happens the same week.
If you think I have handled your data badly, you can complain to the Romanian supervisory authority, the National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul General Gheorghe Magheru 28-30, Sector 1, Bucharest, at dataprotection.ro. If you live in another EU country you may complain to your own authority instead.
Whether you have to give me anything
No. Nothing here requires you to identify yourself. The contact form asks for a name, an email address and a message because otherwise I cannot read your message or reply to it. If you would rather not fill it in, email me directly instead.
Children
This site is aimed at people looking for professional or academic work and is not directed at children. I do not knowingly collect anything from anyone under 16.
How it is protected
The site is served over HTTPS. The data sits in a database that is not reachable from the internet, on a server I administer. Access to the administration panel is limited to a single account, protected by a password and by throttling after repeated failures. No system is perfect, and I will not pretend otherwise.
Changes to this page
If what the site does changes, this page changes with it, and so does the date below. That date is the whole record: there is no notification list, so checking it is how you tell whether anything has moved since you last read this.
Last updated: 27 July 2026.