Website policy

Privacy draft

This draft explains the intended data practices for the Duminov Design website. It must be checked against the final host, contact details and any services actually installed before publication.

Draft for private design review · not approved for launch

1. Scope

This notice covers the Duminov Design studio website. Nudge Me has a separate app privacy draft because an app and a website can process different data.

2. Who is responsible

The data controller is the legal operator of Duminov Design in Moldova. The operator's registered legal name, legal form, registration number, address and public privacy email are still pending. They must replace this statement before launch.

3. Website data

The current private preview does not install analytics, advertising, AdSense or other ad technology.

  • Technical delivery data: the hosting provider may receive IP address, browser details, requested URL, timestamps and security logs to deliver and protect the site.
  • Privacy preference: the site saves dd_consent_v1 in local storage for 180 days so the banner does not ask on every visit.
  • Direct contact: if you email an address published on the site, the operator will receive the information you include in the message.

4. Why data may be used

Technical data may be processed to provide the requested website, maintain security and comply with legal duties. Where consent is legally required for a future optional service, that service must remain off until a valid choice is recorded.

5. Recipients, transfers and retention

The final policy must name or clearly describe the hosting and email providers, their locations, any international-transfer safeguards, and realistic retention periods. Duminov Design should disclose only services actually used and keep data no longer than necessary.

6. Your rights

Depending on the law that applies, individuals may have rights to information, access, correction, deletion, restriction, objection, portability and withdrawal of consent. Moldova's Law No. 195/2024 on personal data protection is the core local framework. GDPR requirements may additionally apply where the relevant territorial conditions are met. Requests need a verified public contact route before launch.

7. Complaints and changes

The final notice should explain how to contact the operator first and identify the competent supervisory authority. The official Moldovan data-protection authority is the National Centre for Personal Data Protection. Material policy changes should be dated and communicated where required.

Before publication

Items the operator must confirm

  • Insert the legal operator identity, registration details, address and privacy email.
  • Confirm the production host, email provider, logs, subprocessors, transfers and retention.
  • Reconcile this notice with the production cookie inventory and consent interface.
  • Obtain Moldova-focused professional review and assess whether GDPR also applies.