How We Handle Your Data
1. Introduction & Controller Identity
This Privacy Policy explains how Ciprian Titire ("we", "us", "our") collects, uses, and protects your personal data when you use our website at titi.re and purchase our services.
We are the data controller responsible for your personal data. Contact: cip@titi.re
We comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).
2. Data We Collect
Information you provide directly
- Account data: name, email address, password (when you create an account)
- Order data: name, email, billing address, project details submitted via forms
- Payment data: processed by Stripe — we do not store card numbers
- Communications: emails, messages, and form submissions you send us
- FAQ questions: the question you type into the Services FAQ, and the answer you were shown. No name or email is attached, and your IP address is not stored: the limits that stop one visitor flooding it use a salted, one-way digest of it. The last few questions and answers are also kept in your own browser, in this tab only, so the thread is still there if you reload the page; closing the tab clears them and they are never sent anywhere
- Speech, if you use the microphone: pressing the microphone in the Services FAQ hands the audio to your own browser's speech recognition, not to me. Where your browser can do that on your own device it is asked to, and the audio then never leaves your machine; where it cannot, Chrome and Edge send it to Google to turn it into text. The words arrive in the box for you to read and edit, and nothing is sent until you press Ask. No audio is recorded or kept by this site
Information collected automatically
- Server logs: IP address, browser type, pages visited, time of access
- Stripe fraud detection: device fingerprints, location data (via Stripe Radar)
We do not currently use analytics cookies, advertising trackers, or third-party analytics tools.
3. Lawful Bases (GDPR Art. 6)
| Processing Activity | Lawful Basis |
|---|---|
| Order fulfillment (name, email, project details) | Contract (b) |
| Payment processing (via Stripe) | Contract (b) + Legal Obligation (c) — tax |
| Account creation / login | Contract (b) |
| Maintenance service delivery | Contract (b) |
| Email confirmations / receipts | Contract (b) + Legitimate Interest (f) |
| Marketing emails (opt-in only) | Consent (a) |
| Fraud prevention (Stripe Radar) | Legitimate Interest (f) |
| Legal compliance (accounting, disputes) | Legal Obligation (c) |
4. Purposes of Processing
We use your data to:
- Process and fulfill your orders
- Deliver services and communicate about your projects
- Process payments securely through Stripe
- Send transactional emails (order confirmations, receipts, project updates)
- Comply with legal and tax obligations
- Prevent fraud and protect our services
5. Recipients & Subprocessors
We share data with the following subprocessors, all bound by Data Processing Agreements incorporating UK/EU Standard Contractual Clauses:
| Subprocessor | Purpose | Location | Safeguards |
|---|---|---|---|
| Stripe, Inc. | Payments, checkout, subscriptions | USA | SCCs, PCI DSS Level 1 |
| Vercel, Inc. | Hosting, CDN, edge functions | USA | SCCs, SOC 2 Type II |
| Supabase Inc. | Database, auth, edge functions | USA/EU | SCCs, SOC 2, ISO 27001 |
| Resend Inc. | Transactional & marketing email | USA | SCCs, SOC 2 |
| Notion Labs, Inc. | Project management | USA | SCCs, SOC 2 Type II |
| Slack Technologies, LLC | Internal notifications | USA | SCCs, SOC 2 Type II |
| Cal.com, Inc. | Discovery call scheduling | USA | SCCs |
| OpenRouter, Inc. | Answering questions typed into the Services FAQ | USA | Question text only; no account, order or payment data |
| NVIDIA Corporation | Fallback model for the same FAQ answers | USA | Question text only; no account, order or payment data |
No data is sold to third parties.
A question typed into the Services FAQ is sent to whichever model provider is configured at that moment, currently OpenRouter with NVIDIA as the fallback, together with the public facts from this site that the answer must be drawn from. Nothing else about you is sent with it. Please do not type personal details into that box; the contact form is the place for those, and it is the route the FAQ points you to whenever it cannot answer.
6. International Transfers
Some subprocessors operate outside the UK. Where data is transferred internationally, we rely on UK International Data Transfer Agreements (IDTAs) or EU Standard Contractual Clauses (SCCs) as appropriate safeguards.
7. Retention Periods
| Data Category | Retention | Basis |
|---|---|---|
| Order / contract data | 6 years from end of tax year | HMRC / Companies Act |
| Payment records (Stripe) | 6 years + current | PCI DSS / Tax |
| Account / profile data | Until deletion request + 30 days | GDPR Art. 17 |
| Email correspondence | 3 years from last contact | Legitimate interest |
| Marketing consent logs | 6 years | PECR / GDPR |
| Server access logs | 12 months | Security |
| FAQ questions & answers | 180 days | Legitimate interest: answering better |
| Notion project data | Until project closed + 2 years | Contract fulfillment |
8. Your Rights (GDPR Art. 15–22)
You have the right to:
- Access your personal data (Art. 15)
- Rectify inaccurate data (Art. 16)
- Erase your data ("right to be forgotten") (Art. 17)
- Restrict processing (Art. 18)
- Data portability — receive your data in a structured format (Art. 20)
- Object to processing based on legitimate interest (Art. 21)
To exercise any right, email cip@titi.re. We respond within 1 month.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO): ico.org.uk/make-a-complaint
9. Cookies & Tracking
We use only essential cookies for payment processing and authentication. For full details, see our Cookie Policy.
We do not use analytics, advertising, or social media cookies.
10. Security Measures
- All data transmitted over encrypted HTTPS connections
- Payment data handled exclusively by Stripe (PCI DSS Level 1 certified)
- Authentication managed by Supabase with secure session tokens
- Regular security patches and dependency updates
- Access logs monitored for suspicious activity
11. Changes to This Policy
We may update this policy from time to time. Changes will be posted on this page with an updated "Last updated" date. Significant changes will be communicated via email.
12. Contact & Supervisory Authority
For any privacy-related queries, contact: cip@titi.re
Supervisory authority: Information Commissioner's Office (ICO)
Website: ico.org.uk
Complaints: ico.org.uk/make-a-complaint