Privacy policy

This notice explains, in plain language, what information this portfolio processes, why it is processed, who helps process it, and the choices you have.

Controller
Ionuț-Alexandru Necula · Galați, Romania
Last updated
19 August 2026
The site's three data flows
  1. Browser requestVercelSite delivery and security
  2. Your consentGoogle Analytics + VercelOptional usage and performance measurement
  3. Contact formConvexRestricted correspondence storage

Scope and controller

This policy applies to the public portfolio at https://ionut-necula.com and its localized pages. Ionuț-Alexandru Necula is the data controller for the processing described here.

You can browse the public site without creating an account. The site does not sell personal data, run advertising, or use personal data for automated decisions that produce legal or similarly significant effects.

For privacy questions or requests, use the controller email shown in this policy. Please do not send passwords, financial records, health information, identity documents, or other sensitive information through the contact form.

At a glance

  • Public analytics and performance telemetry stay off until you accept.
  • Declining analytics does not reduce the site's functionality.
  • Contact-form contents are stored in Convex and are visible only through administrator-protected tools.
  • Analytics events exclude contact fields, message text, authentication data, database IDs, and unsanitized URLs.
  • You can reopen analytics preferences from the footer at any time.

What information is processed

The table separates always-on site operation from optional measurement and information you choose to submit.

What information is processed
ActivityInformationPurposeLegal basisRecipients / retention
Site delivery and securityIP address and request metadata, requested path, timestamp, browser/device and network information, referrer where supplied, diagnostics, and security signals.Deliver the site, maintain availability, diagnose failures, and prevent abuse.Legitimate interests (GDPR Art. 6(1)(f)): operating a secure, reliable public site.Vercel and infrastructure subprocessors. Kept according to operational, security, and legal needs and provider log cycles.
Language and privacy preferencesSelected language and whether analytics was accepted or declined.Return the requested language and remember the privacy choice.Legitimate interests (Art. 6(1)(f)); device storage is limited to functionality requested by the visitor.First-party browser storage; language and consent preferences expire after one year unless renewed or removed earlier.
Optional analyticsPage path and title, broad referrer/domain, approximate region, language, browser, device and operating system, navigation and section events, outbound-link category, and Core Web Vitals.Understand aggregate site use, content usefulness, compatibility, and performance.Consent (Art. 6(1)(a)). No optional telemetry provider is loaded while consent is unknown or declined.Google Analytics, Vercel Web Analytics, and Vercel Speed Insights. Provider/account retention settings and the necessity criteria below apply.
Professional correspondenceName, email address, message, submission time, response/workflow state, limited internal notes, and email, domain, and hashed (non-reversible) IP rate-limit keys used only to prevent abuse. Direct emails also include ordinary email headers and content.Review, respond to, secure, and keep an appropriate record of professional correspondence.Legitimate interests (Art. 6(1)(f)); steps requested before a possible agreement may also rely on Art. 6(1)(b).Convex, the restricted site administrator, and the email provider when a reply is sent. Kept only while needed for correspondence, security, or legal claims.

Cookies and browser storage

The site uses two first-party preferences. Google Analytics cookies appear only after acceptance; Vercel Web Analytics and Speed Insights do not require analytics cookies.

Cookies and browser storage
NameTypePurposeDurationOptional
portfolio_localeFirst-party, HttpOnly cookieRemember the requested language1 yearNo
portfolio.analytics-consentFirst-party cookie + local storageRemember accept or decline1 yearNo
_gaGoogle Analytics first-party cookieDistinguish visitors for measurementUp to 2 yearsYes
_ga_<container-id>Google Analytics first-party cookiePersist session stateUp to 2 yearsYes

You can remove cookies or local storage in browser settings. Removing the preference may cause the site to ask again. Withdrawing analytics consent stops future optional telemetry and removes Google Analytics cookies accessible to this site; it does not affect the lawfulness of processing performed before withdrawal.

Service providers

These providers process information only for the roles described. Their public privacy and processing terms contain further operational detail.

Service providers
ProviderRoleInformation involved
VercelHosting, delivery, security, optional Web Analytics and Speed InsightsRequest, device, route, broad location, usage and performance data
Google AnalyticsOptional aggregate audience and interaction measurementAnalytics identifiers, device/browser, approximate location, page and event data
ConvexApplication backend and restricted contact-message storageContact fields, message workflow data, rate-limit data, and service metadata
Google / GmailEmail correspondence when you email the controller or receive a replyEmail address, headers, message content, and attachments you choose to send

Transfers outside the EEA

Some providers or their subprocessors may process information in the United States or other countries outside the European Economic Area. Those countries may have different data-protection rules.

Where Chapter V of the GDPR applies, transfers must use an available legal mechanism, such as an adequacy decision (including the EU-U.S. Data Privacy Framework for certified recipients) or the European Commission's Standard Contractual Clauses, together with relevant contractual and security measures.

Provider transfer terms are available in the Vercel and Convex data-processing agreements and Google's data-transfer framework. You may request information about safeguards by emailing the controller.

How retention is decided

  • Contact correspondence is kept until the matter is resolved and for only as long afterward as reasonably needed for follow-up, abuse prevention, accountability, or the establishment, exercise, or defence of legal claims. Messages can be permanently deleted from the restricted administration system.
  • Analytics event and user-level data follow the configured provider/account retention controls and are kept only while needed to compare aggregate use and performance over reasonable periods. Aggregated reports may remain after source-level retention ends.
  • Hosting and security logs follow provider operational and security cycles. Residual copies may persist temporarily in protected backups until the relevant provider's rotation completes.
  • The exact preference and cookie periods are listed above. A valid legal hold or binding legal obligation may require longer retention in a particular case.

Your choices

  • Accept or decline optional analytics without losing site functionality.
  • Change the analytics choice at any time using the control below or the footer.
  • Use email instead of the contact form if you prefer, understanding that the chosen email provider will process the message.
  • Block or remove browser storage through browser settings; the language or consent preference may then need to be selected again.

Your GDPR rights

Depending on the processing and the circumstances, you may ask to:

  • access personal data and receive a copy;
  • correct inaccurate or incomplete data;
  • erase data when the legal conditions are met;
  • restrict processing in the cases provided by law;
  • object to processing based on legitimate interests;
  • receive or transfer data where the portability right applies; and
  • withdraw consent at any time for future optional analytics.

Requests are normally answered without undue delay and within one month. The period may be extended by up to two further months for a complex or numerous request; if so, you will be told within the first month. Reasonable identity verification may be requested before data is disclosed or changed.

You also have the right to lodge a complaint with the Romanian supervisory authority or another competent EEA supervisory authority.

Security

The site uses HTTPS, a restrictive Content Security Policy and security headers, input length and format validation, layered rate limits, administrator authentication, and role checks on private reads and writes.

No internet service can guarantee absolute security. If a personal-data incident creates a risk requiring notification, the applicable GDPR notification duties will be followed.

Other important points

  • The site is not directed to children and does not intentionally solicit children's personal data.
  • No personal data is sold. There is no direct marketing, advertising profile, or solely automated decision-making with legal or similarly significant effects.
  • GitHub and LinkedIn are outbound links, not embedded trackers. Their own terms apply after you choose to visit them.
  • Providing contact-form fields is not a statutory requirement. It is necessary only if you want to use that form; without them, the form cannot deliver a message for review.

Contact and policy changes

Controller: Ionuț-Alexandru Necula, Galați, Romania.

Privacy requests and questions: ionutn0301@gmail.com.

Use a clear subject such as “Privacy request”. Do not send additional identity documents unless they are specifically and reasonably requested.

Email a privacy request

Changes to this notice

This page will be updated when the site's processing changes or the notice needs clarification. Material changes will be reflected in the date at the top. A new purpose or legal basis will not be applied retroactively without the notice or consent required by law.