How We Handle Your Data
1. Introduction & Controller Identity
This Privacy Policy explains how Ciprian Titire ("we", "us", "our") collects, uses, and protects your personal data when you use our website at titi.re and purchase our services.
We are the data controller responsible for your personal data. Contact: ciprian@titi.re
We comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).
2. Data We Collect
Information you provide directly
- Account data: name, email address, password (when you create an account)
- Order data: name, email, billing address, project details submitted via forms
- Payment data: processed by Stripe — we do not store card numbers
- Communications: emails, messages, and form submissions you send us
Information collected automatically
- Server logs: IP address, browser type, pages visited, time of access
- Stripe fraud detection: device fingerprints, location data (via Stripe Radar)
We do not currently use analytics cookies, advertising trackers, or third-party analytics tools.
3. Lawful Bases (GDPR Art. 6)
| Processing Activity | Lawful Basis |
|---|---|
| Order fulfillment (name, email, project details) | Contract (b) |
| Payment processing (via Stripe) | Contract (b) + Legal Obligation (c) — tax |
| Account creation / login | Contract (b) |
| Maintenance service delivery | Contract (b) |
| Email confirmations / receipts | Contract (b) + Legitimate Interest (f) |
| Marketing emails (opt-in only) | Consent (a) |
| Fraud prevention (Stripe Radar) | Legitimate Interest (f) |
| Legal compliance (accounting, disputes) | Legal Obligation (c) |
4. Purposes of Processing
We use your data to:
- Process and fulfill your orders
- Deliver services and communicate about your projects
- Process payments securely through Stripe
- Send transactional emails (order confirmations, receipts, project updates)
- Comply with legal and tax obligations
- Prevent fraud and protect our services
5. Recipients & Subprocessors
We share data with the following subprocessors, all bound by Data Processing Agreements incorporating UK/EU Standard Contractual Clauses:
| Subprocessor | Purpose | Location | Safeguards |
|---|---|---|---|
| Stripe, Inc. | Payments, checkout, subscriptions | USA | SCCs, PCI DSS Level 1 |
| Vercel, Inc. | Hosting, CDN, edge functions | USA | SCCs, SOC 2 Type II |
| Supabase Inc. | Database, auth, edge functions | USA/EU | SCCs, SOC 2, ISO 27001 |
| Resend Inc. | Transactional & marketing email | USA | SCCs, SOC 2 |
| Notion Labs, Inc. | Project management | USA | SCCs, SOC 2 Type II |
| Slack Technologies, LLC | Internal notifications | USA | SCCs, SOC 2 Type II |
| Cal.com, Inc. | Discovery call scheduling | USA | SCCs |
No data is sold to third parties.
6. International Transfers
Some subprocessors operate outside the UK. Where data is transferred internationally, we rely on UK International Data Transfer Agreements (IDTAs) or EU Standard Contractual Clauses (SCCs) as appropriate safeguards.
7. Retention Periods
| Data Category | Retention | Basis |
|---|---|---|
| Order / contract data | 6 years from end of tax year | HMRC / Companies Act |
| Payment records (Stripe) | 6 years + current | PCI DSS / Tax |
| Account / profile data | Until deletion request + 30 days | GDPR Art. 17 |
| Email correspondence | 3 years from last contact | Legitimate interest |
| Marketing consent logs | 6 years | PECR / GDPR |
| Server access logs | 12 months | Security |
| Notion project data | Until project closed + 2 years | Contract fulfillment |
8. Your Rights (GDPR Art. 15–22)
You have the right to:
- Access your personal data (Art. 15)
- Rectify inaccurate data (Art. 16)
- Erase your data ("right to be forgotten") (Art. 17)
- Restrict processing (Art. 18)
- Data portability — receive your data in a structured format (Art. 20)
- Object to processing based on legitimate interest (Art. 21)
To exercise any right, email ciprian@titi.re. We respond within 1 month.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO): ico.org.uk/make-a-complaint
9. Cookies & Tracking
We use only essential cookies for payment processing and authentication. For full details, see our Cookie Policy.
We do not use analytics, advertising, or social media cookies.
10. Security Measures
- All data transmitted over encrypted HTTPS connections
- Payment data handled exclusively by Stripe (PCI DSS Level 1 certified)
- Authentication managed by Supabase with secure session tokens
- Regular security patches and dependency updates
- Access logs monitored for suspicious activity
11. Changes to This Policy
We may update this policy from time to time. Changes will be posted on this page with an updated "Last updated" date. Significant changes will be communicated via email.
12. Contact & Supervisory Authority
For any privacy-related queries, contact: ciprian@titi.re
Supervisory authority: Information Commissioner's Office (ICO)
Website: ico.org.uk
Complaints: ico.org.uk/make-a-complaint