Privacy Policy

How We Handle Your Data

1. Introduction & Controller Identity

This Privacy Policy explains how Ciprian Titire ("we", "us", "our") collects, uses, and protects your personal data when you use our website at titi.re and purchase our services.

We are the data controller responsible for your personal data. Contact: ciprian@titi.re

We comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).

2. Data We Collect

Information you provide directly

Information collected automatically

We do not currently use analytics cookies, advertising trackers, or third-party analytics tools.

3. Lawful Bases (GDPR Art. 6)

Processing ActivityLawful Basis
Order fulfillment (name, email, project details)Contract (b)
Payment processing (via Stripe)Contract (b) + Legal Obligation (c) — tax
Account creation / loginContract (b)
Maintenance service deliveryContract (b)
Email confirmations / receiptsContract (b) + Legitimate Interest (f)
Marketing emails (opt-in only)Consent (a)
Fraud prevention (Stripe Radar)Legitimate Interest (f)
Legal compliance (accounting, disputes)Legal Obligation (c)

4. Purposes of Processing

We use your data to:

5. Recipients & Subprocessors

We share data with the following subprocessors, all bound by Data Processing Agreements incorporating UK/EU Standard Contractual Clauses:

SubprocessorPurposeLocationSafeguards
Stripe, Inc.Payments, checkout, subscriptionsUSASCCs, PCI DSS Level 1
Vercel, Inc.Hosting, CDN, edge functionsUSASCCs, SOC 2 Type II
Supabase Inc.Database, auth, edge functionsUSA/EUSCCs, SOC 2, ISO 27001
Resend Inc.Transactional & marketing emailUSASCCs, SOC 2
Notion Labs, Inc.Project managementUSASCCs, SOC 2 Type II
Slack Technologies, LLCInternal notificationsUSASCCs, SOC 2 Type II
Cal.com, Inc.Discovery call schedulingUSASCCs

No data is sold to third parties.

6. International Transfers

Some subprocessors operate outside the UK. Where data is transferred internationally, we rely on UK International Data Transfer Agreements (IDTAs) or EU Standard Contractual Clauses (SCCs) as appropriate safeguards.

7. Retention Periods

Data CategoryRetentionBasis
Order / contract data6 years from end of tax yearHMRC / Companies Act
Payment records (Stripe)6 years + currentPCI DSS / Tax
Account / profile dataUntil deletion request + 30 daysGDPR Art. 17
Email correspondence3 years from last contactLegitimate interest
Marketing consent logs6 yearsPECR / GDPR
Server access logs12 monthsSecurity
Notion project dataUntil project closed + 2 yearsContract fulfillment

8. Your Rights (GDPR Art. 15–22)

You have the right to:

To exercise any right, email ciprian@titi.re. We respond within 1 month.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO): ico.org.uk/make-a-complaint

9. Cookies & Tracking

We use only essential cookies for payment processing and authentication. For full details, see our Cookie Policy.

We do not use analytics, advertising, or social media cookies.

10. Security Measures

11. Changes to This Policy

We may update this policy from time to time. Changes will be posted on this page with an updated "Last updated" date. Significant changes will be communicated via email.

12. Contact & Supervisory Authority

For any privacy-related queries, contact: ciprian@titi.re

Supervisory authority: Information Commissioner's Office (ICO)
Website: ico.org.uk
Complaints: ico.org.uk/make-a-complaint