Privacy
Last updated: 2026-10-01
The short version
- This website collects nothing about you by itself. No forms, no accounts, no analytics, no ads, no cookies.
- If you email me, I get your email address and what you write. I use it to reply and to keep a record.
- If I emailed you first, it was a one-to-one message, not a mailing list. Reply “no thanks” or “unsubscribe” and I stop.
- I do not sell your data and I do not use it for advertising.
Who I am
Bindery 77 is the trading name of a one-person web studio. I am an individual working in Moldova as an independent entrepreneur (antreprenor independent). Bindery 77 is not a company. I decide how the personal data described here is used, so I am the “controller” under data protection laws.
The only contact is [email protected]. I do not publish a postal address or phone number on this site.
What this site collects
Nothing on purpose. The site is a static page. It has no contact form, no login, no analytics, no advertising or tracking scripts, and no embedded content from other companies. It sets no cookies of its own. Its one font is stored on the site itself, so your browser does not ask any font company for anything.
Hosting logs
The site is hosted on Cloudflare Pages, and the domain’s DNS also runs on Cloudflare. To deliver pages and block abuse, Cloudflare processes technical request data such as your IP address, browser type and the time of the request. Cloudflare is a US company with servers around the world. That processing is under Cloudflare’s own privacy policy. I have not turned on Cloudflare Web Analytics, and I do not use this data to identify or profile visitors.
If you email me
Email to [email protected] is handled by Zoho Mail, on Zoho’s data centres in the EU. I receive your email address, your name if it appears, and whatever you write or attach. I use it to reply and to keep a record of the conversation. I do not sell it and I do not share it for advertising.
My source code is kept in a private GitHub repository. It contains no visitor or email data.
If I emailed you first
I send a small number of individual, hand-written, one-to-one business emails. I am not running a bulk list or an automated sequence.
- Where I got your address. From your business’s own public listing or website, where a business contact address was published.
- Why. To tell you who I am and to ask if a conversation would be useful to you.
- How to stop. Reply “no thanks” or “unsubscribe”. I will not contact you again, and I aim to act on it the same day. US law allows up to 10 business days; I will not use that time.
- Postal address. US anti-spam law (CAN-SPAM) requires a valid physical postal address in commercial email. I put it in the email itself, not on this website.
- What I keep. The business name, your contact details, the date, and where I found them. If you opt out, I keep only your email address on a suppression note so I do not email you again.
You can also ask me what I hold about you, to correct it, or to erase it (see Your rights).
Cookies, Do Not Track and Global Privacy Control
This site sets no cookies and runs no trackers, so there is nothing to track you across other websites and no data to sell or share for advertising. I do not change what the site does when your browser sends a Do Not Track or Global Privacy Control signal, because it already does the most privacy-protective thing for everyone. I treat a Global Privacy Control signal as a valid opt-out request wherever a law gives that effect. Cloudflare may set strictly necessary security cookies of its own to protect the service.
Why I use data, and my legal basis
- Serving the site and keeping it secure. Legitimate interests (running a safe website). Cloudflare does this.
- Replying to your email and keeping a record. Legitimate interests; if you are asking about work with me, taking steps before an agreement.
- One-to-one outreach to business contacts. Legitimate interests (offering my services to businesses), balanced against your reasonable expectations. You can object at any time.
- Legal duties, such as honouring an opt-out or tax records. Legal obligation.
I do not make automated decisions about you or profile you.
Who receives data, and transfers abroad
- Cloudflare (hosting, DNS, delivery). Processes request data. US company with global infrastructure.
- Zoho (email). Processes email on EU data centres.
- GitHub holds code only, no personal data.
I do not sell data. I share it with no one else, except where a law or court requires it. Because I work from Moldova and Cloudflare operates globally, your data can cross borders. Where this involves a transfer that needs a safeguard, I rely on the safeguards the provider describes in its own terms and privacy documentation (for example standard contractual clauses or an adequacy mechanism). Ask me if you want the details.
How long I keep data
- Hosting logs. Held by Cloudflare under its own retention rules. I do not keep my own copy.
- Email with no resulting work. Deleted 12 months after the last message.
- Prospects who did not reply. Deleted 6 months after my last email.
- Opt-outs. Your email address alone is kept as a suppression note, for at least five years, so I do not contact you again.
- If we do work together. That is covered by the written agreement. Records that tax or accounting law requires me to keep are kept for the period that law requires.
Security
Mail and hosting run with established providers, and I keep access to those accounts limited to me. No system is perfectly secure. If a breach affects you in a way the law requires me to report, I will tell you and the relevant authority.
Your rights
Write to [email protected]. I aim to reply within a few business days and to complete a request within one month. I may ask you to confirm who you are. There is no fee.
EU and UK (GDPR and UK GDPR). You can ask for access to your data, correction, erasure, restriction, a portable copy, and you can object to processing based on legitimate interests (including outreach), and withdraw consent where I rely on it. I have not appointed an EU or UK representative, because I do not target people there and any processing is occasional and low risk. If you think I am wrong about that, tell me.
Moldova. Moldova’s Law No. 195/2024 on personal data protection, which applies since 23 August 2026, gives similar rights (information, access, correction, erasure, restriction, portability, objection). The same email address works.
California and other US states. California’s CCPA/CPRA and about twenty other state privacy laws give residents rights such as to know, correct, delete, and to opt out of sale, sharing and targeted advertising. These laws apply only to businesses above certain size or data-volume thresholds. Bindery 77 is almost certainly below them. I honour these requests anyway. I do not sell or share personal information, I do not use it for targeted advertising, and I will not treat you worse for asking. If you wish, an authorised agent may write for you.
Complaints
Please tell me first and I will try to fix it. You can also complain to:
- Moldova: the National Centre for Personal Data Protection (datepersonale.md).
- EU or UK: your local data protection authority, for example the UK Information Commissioner’s Office (ico.org.uk). A list of EU authorities is at edpb.europa.eu.
- US: the Federal Trade Commission (reportfraud.ftc.gov) or your state attorney general.
Children
This site is not for children and is not directed to anyone under 13 (or under 16 in the EU). I do not knowingly collect their data. If a child has written to me, tell me and I will delete it.
Links to other sites
The site does not currently embed other sites. If a link takes you elsewhere, that site’s privacy policy applies, not this one.
Changes
If I change this page, I will change the date at the top. For a material change I will say so on the page.