BOOSTEDMODE
BM—12 / PRIVACY / EN Legal document

What data I take from you, where it sits and how you delete it.

Controller Vivid Eye S.R.L.-D.
CUI 36390001
Last updated 18.09.2026
Legal framework GDPR · Romanian Law 190/2018

This is an English translation, provided so you can read it. The binding version of this policy is the Romanian original; where the two differ, the Romanian text prevails.

The shortest summary I can give you: this site measures visits with Google Analytics, but only if you press “Accept” in the banner. If you decline or don't answer, no request goes to Google and no cookie is set. Separately, a counter of my own counts visits in total, without a cookie and without identifying you. There is no Facebook pixel and no remarketing.

The only data I have about you is what you write into a form yourself. I use it to reply to you. I don't sell it to anyone and I don't sign you up to any list.

01 — What I collect BM—12.1 / THE DATA

Only what you write into a form. Nothing in the background.

The site has two forms: the contact one and the one you use to request a PDF guide. Those are the only places where anything about you reaches me, apart from the visit measurements you accept yourself (section 03).

When you fill in the contact form, the following fields reach me. Only the email address is required — the rest you fill in if you want, and they help me answer to the point.

  • ControllerVivid Eye S.R.L.-D., tax ID 36390001, registry no. J08/1612/2016, registered at Str. Prunului nr. 10, bl. E3, sc. B, et. 10, ap. 41, Brașov, Brașov county, 500318, Romania. Boosted Mode is the brand I work under — the full details.
  • EmailSo I can reply to you. It's the only field without which the form doesn't send.
  • NameSo I know what to call you.
  • BusinessWhat you do, so I understand whether what I sell fits what you need.
  • The blockageWhat's stopping you right now. It's the field that shows whether a conversation makes sense.
  • The sourceWhere you heard about me.
  • The packageIt fills itself in if you came from a button on the pricing page.

When you request a PDF guide, only the email address and the name of the requested guide are saved. The article on the page is read freely, without leaving anything — the gate is on the PDF only.

When you book the 20-minute consultation, booking runs through Cal.com or Calendly, an external service. The scheduling widget loads only after you press “Pick a time”; until then no request goes out to them. In the calendar you fill in your name, email address or phone number, and the answer to the question in the booking form. The purpose is just one: to fix the time and let me know what you want to talk about. The calendar provider acts as a third-party provider processing this data on my behalf; its own rules apply in addition (section 09).

In my forms I don't ask for and don't store a phone number, national ID number, card details or other sensitive data. Nowhere on the site, outside the booking calendar above, is there a field where you could type them.

There is a hidden field called website, which doesn't appear on screen and which a human never sees. It's a trap for spam bots: if it arrives filled in, the request is thrown away. It collects nothing about you.

02 — What I do with it BM—12.2 / THE PURPOSE

I reply to you. That's it.

The form data has one real purpose: so I can continue the conversation you started. In practice that means an email from me, or a WhatsApp message if you left your number in the body of the message.

If you requested a guide, you get the guide. One single email, on request — I don't sign you up to any list and no sales sequence follows it.

The legal basis is simple to state: for contact messages it's legitimate interest in replying to someone who wrote to me; for guides it's your consent , given the moment you pressed the button; for client invoices it's the legal obligation to keep them.

What I don't do: I don't sell, rent or pass your data on to marketing agencies, data brokers or advertising networks. I don't build automated profiles about you and I take no automated decision concerning you.

03 — Cookies BM—12.3 / CONSENT ONLY

Cookies only if you agree.

On your first visit you see a banner with “Accept” and “Decline”. Until you choose, the site sets no cookie and sends nothing to Google.

If you press “Accept”, Google Analytics 4 loads, a service of Google Ireland Limited, and measures how the site is used: which pages are opened, where you come from (the country, not your address) and what kind of device you use. It sets two cookies, _ga and _ga_Y4P8WFJB4P, valid for up to two years. I don't turn on Google signals and I don't use the data for advertising or remarketing.

The measurement data is kept for fourteen months, then deleted. It can also reach Google outside the European Economic Area, under the EU–US Data Privacy Framework.

If you press “Decline”, or press nothing, nothing loads from Google and no cookie is set. You can change your choice at any time from the “Cookie settings” link in the footer of every page. If you withdraw consent, the Google cookies are deleted immediately.

Your choice is remembered in localStorage, that is, in your browser, not in a cookie. A second thing is written locally and isn't a cookie: when you come to the site from a post of mine, the link may contain a short code, for example ?p=k7m2xq4r. I remember it so that, if you reach the form after three clicks, I know which post you came from.

The code is saved in sessionStorage, that is, in the browser tab's memory, and deletes itself when you close the window. It goes nowhere until the moment you send the form, it doesn't follow you across other sites and it can't identify you: it's a code for the post, not for you. It needs no consent banner, because it doesn't track anyone.

Separately from Google, the site has a counter of its own that counts visits in total. When you open a page, your browser sends the server only the address of the page and the category of where you came from (for example “Google”, “Instagram” or “direct”), and the server adds one to a number in a table kept per day. It sets no cookie and keeps no IP address, no browser details, no full referring address and no identifier, and it cannot tell how many different visitors there are, only how many pages were opened. The IP address is used only in memory, for at most a minute, to stop abuse, and is never written anywhere. Because it identifies no one, the counter also runs if you declined cookies.

Along with the form, two inferences from what your browser sends anyway also go out: the app you opened the link from (Instagram, Facebook, an ordinary browser) and the name of the site you came from — the name only, without the full page address, because that can contain things which are none of my business.

04 — Where it sits BM—12.4 / THE PLACE AND THE ACCESS

In a database on my server, plus an email notification.

When you send the form, two things happen. The data is written into a PostgreSQL database running on the system's own server, and a notification email goes out to me so I know someone wrote. The conversation after that is carried on from my ordinary inbox.

Both are accessed by one single person: me. There is no team, no partner agency and no external CRM your data syncs into.

The providers I rely on that touch your data are the two above, server hosting and the email provider, plus Google, but only if you accepted measurement, and Cal.com or Calendly, but only if you book the 20-minute consultation (section 01). Google Ireland Limited receives measurement data only if you accepted (section 03), and it may also reach outside the European Economic Area, under the EU–US Data Privacy Framework. Otherwise, I don't transfer data outside the European Economic Area for any purpose other than running the two services above.

Your IP address isn't saved. It's read the moment you send the form, solely so nobody can send a thousand requests in a minute — a maximum of twelve per minute from the same address. It stays in the application's working memory for sixty seconds and never reaches the database.

05 — Your rights BM—12.5 / GDPR

Six rights, one single email to use them.

Write to me at [email protected] with the subject Personal data. You don't have to explain why and you don't have to fill in any form.

Access You can ask for a copy of everything I have about you. I send exactly what's in the database, not a summary.
Rectification If something is wrong — a misspelled name, an old address — you tell me and I correct it.
Erasure The right to be forgotten. I delete everything, permanently, and confirm when it's done.
Restriction I can keep the data but use it for nothing, if that's what you prefer.
Portability I send you the data in a format any other system can read, JSON or CSV.
Objection You can refuse a particular use of the data. In practice, here that means I stop writing to you.

I answer within 30 calendar days, as the GDPR requires. In reality it takes a day or two — I don't have the volume that would turn this into a procedure.

06 — How long I keep it BM—12.6 / THE PERIODS

Two years for a conversation. Five for an invoice.

  • Contact messagesUp to two years from the last interaction, then they're deleted. If you ask me sooner, they're deleted sooner.
  • Guide requestsThe same period. The address stays attached to the event that produced it, not to a separate list.
  • The provenance signalsThe post code and the app you came from are part of the same event, so they have the same period.
  • Google Analytics measurementFourteen months, only if you accepted. The cookies expire after two years at most, but the data from them is not kept longer than fourteen months.
  • Accounting documentsIf you become a client, invoices and contracts are kept for a minimum of five years, as Romanian accounting law requires. That period cannot be shortened on request.

There is no period for analytics data, because there is no analytics data. Nobody measures what you clicked on this site.

07 — Security BM—12.7 / THE MEASURES

What I concretely do so it doesn't end up where it shouldn't.

  • HTTPS everywhereThe whole site, forms included. Nothing travels unencrypted between your browser and the server.
  • The database isn't exposedThe application listens only on the server's local address, behind an nginx. It can't be reached directly from the internet.
  • Key-based accessThe server is entered with an SSH key, not a password. The email accounts have two-step authentication.
  • Encrypted backupsThe database backups are encrypted, and the decryption key doesn't sit on the same server as they do.
  • No local copiesI don't keep exports of your data on laptops or unencrypted sticks.

No measure is guaranteed a hundred per cent, and I won't claim otherwise. If a breach occurs that puts your data at risk, I notify you within 72 hours at most and I notify the authority as well, exactly as the GDPR requires.

08 — Complaints BM—12.8 / ANSPDCP

If something seems wrong to you, there's somewhere to complain.

The competent authority in Romania is the National Supervisory Authority for Personal Data Processing (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal).

  • Websitedataprotection.ro
  • AddressB-dul G-ral. Gheorghe Magheru nr. 28-30, Sector 1, Bucharest, Romania

Before that, write to me. Not to discourage you — but because at the scale I work at, any problem of this kind is solved in a day or two, whereas a formal complaint takes months.

09 — External links BM—12.9 / OTHER SITES

When you leave here, their rules apply.

The site contains links to other places — Instagram, YouTube, LinkedIn, WhatsApp. I'm not responsible for what they do with your data, because I have no control over them.

One thing is worth saying explicitly: links are just links. I haven't embedded on any page like widgets, buttons or players that would load code from another site and see you while you're here. The only third-party code is the Google Analytics tag, which loads only if you pressed “Accept”, and the Cal.com or Calendly widget for booking the consultation, which loads only after you press “Pick a time”.

10 — Changes BM—12.10 / THE VERSION

The date at the head of the page says which version is current.

If something important changes — a new provider touching the data, a new purpose, a longer period — I announce it on the site's front page and, if you had left me your address, by email as well.

Small corrections, of wording or phrasing, come without an announcement. They show anyway from the date at the start of the document.

11 — Contact BM—12.11 / WHO ANSWERS

I answer. It isn't a support address.

  • Email[email protected]
  • SubjectWrite Personal data or GDPR, so it doesn't get lost among the other messages.
  • DeadlineA maximum of 30 calendar days, as the GDPR requires. In practice, a day or two.

That was the whole document.

If you read this far because you wanted to see how seriously I treat this before writing to me — the answer is the document above. Let's talk.