Scope and controller
This policy applies to the public portfolio at https://ionut-necula.com and its localized pages. Ionuț-Alexandru Necula is the data controller for the processing described here.
You can browse the public site without creating an account. The site does not sell personal data, run advertising, or use personal data for automated decisions that produce legal or similarly significant effects.
For privacy questions or requests, use the controller email shown in this policy. Please do not send passwords, financial records, health information, identity documents, or other sensitive information through the contact form.
At a glance
- Public analytics and performance telemetry stay off until you accept.
- Declining analytics does not reduce the site's functionality.
- Contact-form contents are stored in Convex and are visible only through administrator-protected tools.
- Analytics events exclude contact fields, message text, authentication data, database IDs, and unsanitized URLs.
- You can reopen analytics preferences from the footer at any time.
What information is processed
The table separates always-on site operation from optional measurement and information you choose to submit.
| Activity | Information | Purpose | Legal basis | Recipients / retention |
|---|---|---|---|---|
| Site delivery and security | IP address and request metadata, requested path, timestamp, browser/device and network information, referrer where supplied, diagnostics, and security signals. | Deliver the site, maintain availability, diagnose failures, and prevent abuse. | Legitimate interests (GDPR Art. 6(1)(f)): operating a secure, reliable public site. | Vercel and infrastructure subprocessors. Kept according to operational, security, and legal needs and provider log cycles. |
| Language and privacy preferences | Selected language and whether analytics was accepted or declined. | Return the requested language and remember the privacy choice. | Legitimate interests (Art. 6(1)(f)); device storage is limited to functionality requested by the visitor. | First-party browser storage; language and consent preferences expire after one year unless renewed or removed earlier. |
| Optional analytics | Page path and title, broad referrer/domain, approximate region, language, browser, device and operating system, navigation and section events, outbound-link category, and Core Web Vitals. | Understand aggregate site use, content usefulness, compatibility, and performance. | Consent (Art. 6(1)(a)). No optional telemetry provider is loaded while consent is unknown or declined. | Google Analytics, Vercel Web Analytics, and Vercel Speed Insights. Provider/account retention settings and the necessity criteria below apply. |
| Professional correspondence | Name, email address, message, submission time, response/workflow state, limited internal notes, and email, domain, and hashed (non-reversible) IP rate-limit keys used only to prevent abuse. Direct emails also include ordinary email headers and content. | Review, respond to, secure, and keep an appropriate record of professional correspondence. | Legitimate interests (Art. 6(1)(f)); steps requested before a possible agreement may also rely on Art. 6(1)(b). | Convex, the restricted site administrator, and the email provider when a reply is sent. Kept only while needed for correspondence, security, or legal claims. |
Cookies and browser storage
The site uses two first-party preferences. Google Analytics cookies appear only after acceptance; Vercel Web Analytics and Speed Insights do not require analytics cookies.
| Name | Type | Purpose | Duration | Optional |
|---|---|---|---|---|
| portfolio_locale | First-party, HttpOnly cookie | Remember the requested language | 1 year | No |
| portfolio.analytics-consent | First-party cookie + local storage | Remember accept or decline | 1 year | No |
| _ga | Google Analytics first-party cookie | Distinguish visitors for measurement | Up to 2 years | Yes |
| _ga_<container-id> | Google Analytics first-party cookie | Persist session state | Up to 2 years | Yes |
You can remove cookies or local storage in browser settings. Removing the preference may cause the site to ask again. Withdrawing analytics consent stops future optional telemetry and removes Google Analytics cookies accessible to this site; it does not affect the lawfulness of processing performed before withdrawal.
Service providers
These providers process information only for the roles described. Their public privacy and processing terms contain further operational detail.
| Provider | Role | Information involved |
|---|---|---|
| Vercel | Hosting, delivery, security, optional Web Analytics and Speed Insights | Request, device, route, broad location, usage and performance data |
| Google Analytics | Optional aggregate audience and interaction measurement | Analytics identifiers, device/browser, approximate location, page and event data |
| Convex | Application backend and restricted contact-message storage | Contact fields, message workflow data, rate-limit data, and service metadata |
| Google / Gmail | Email correspondence when you email the controller or receive a reply | Email address, headers, message content, and attachments you choose to send |
Transfers outside the EEA
Some providers or their subprocessors may process information in the United States or other countries outside the European Economic Area. Those countries may have different data-protection rules.
Where Chapter V of the GDPR applies, transfers must use an available legal mechanism, such as an adequacy decision (including the EU-U.S. Data Privacy Framework for certified recipients) or the European Commission's Standard Contractual Clauses, together with relevant contractual and security measures.
Provider transfer terms are available in the Vercel and Convex data-processing agreements and Google's data-transfer framework. You may request information about safeguards by emailing the controller.
How retention is decided
- Contact correspondence is kept until the matter is resolved and for only as long afterward as reasonably needed for follow-up, abuse prevention, accountability, or the establishment, exercise, or defence of legal claims. Messages can be permanently deleted from the restricted administration system.
- Analytics event and user-level data follow the configured provider/account retention controls and are kept only while needed to compare aggregate use and performance over reasonable periods. Aggregated reports may remain after source-level retention ends.
- Hosting and security logs follow provider operational and security cycles. Residual copies may persist temporarily in protected backups until the relevant provider's rotation completes.
- The exact preference and cookie periods are listed above. A valid legal hold or binding legal obligation may require longer retention in a particular case.
Your choices
- Accept or decline optional analytics without losing site functionality.
- Change the analytics choice at any time using the control below or the footer.
- Use email instead of the contact form if you prefer, understanding that the chosen email provider will process the message.
- Block or remove browser storage through browser settings; the language or consent preference may then need to be selected again.
Your GDPR rights
Depending on the processing and the circumstances, you may ask to:
- access personal data and receive a copy;
- correct inaccurate or incomplete data;
- erase data when the legal conditions are met;
- restrict processing in the cases provided by law;
- object to processing based on legitimate interests;
- receive or transfer data where the portability right applies; and
- withdraw consent at any time for future optional analytics.
Requests are normally answered without undue delay and within one month. The period may be extended by up to two further months for a complex or numerous request; if so, you will be told within the first month. Reasonable identity verification may be requested before data is disclosed or changed.
You also have the right to lodge a complaint with the Romanian supervisory authority or another competent EEA supervisory authority.
National Supervisory AuthorityComplaint form / Formular de plângere
Security
The site uses HTTPS, a restrictive Content Security Policy and security headers, input length and format validation, layered rate limits, administrator authentication, and role checks on private reads and writes.
No internet service can guarantee absolute security. If a personal-data incident creates a risk requiring notification, the applicable GDPR notification duties will be followed.
Other important points
- The site is not directed to children and does not intentionally solicit children's personal data.
- No personal data is sold. There is no direct marketing, advertising profile, or solely automated decision-making with legal or similarly significant effects.
- GitHub and LinkedIn are outbound links, not embedded trackers. Their own terms apply after you choose to visit them.
- Providing contact-form fields is not a statutory requirement. It is necessary only if you want to use that form; without them, the form cannot deliver a message for review.
Contact and policy changes
Controller: Ionuț-Alexandru Necula, Galați, Romania.
Privacy requests and questions: ionutn0301@gmail.com.
Use a clear subject such as “Privacy request”. Do not send additional identity documents unless they are specifically and reasonably requested.
Email a privacy requestChanges to this notice
This page will be updated when the site's processing changes or the notice needs clarification. Material changes will be reflected in the date at the top. A new purpose or legal basis will not be applied retroactively without the notice or consent required by law.