Privacy policy

Last updated: September 15, 2026

This policy explains what happens to personal data when you visit atanasiu.me. It is written under Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree 196/2003 as amended (Codice Privacy).

1. Who is responsible

The data controller is Doinel Atanasiu, VAT number IT 03947550541.

For anything concerning this policy or your data, the channel I prefer is the certified address (PEC) atanasiu@pec.it. For general contact you can also write to doinel@atanasiu.me. These details also constitute the information that Italian Legislative Decree 70/2003 requires providers of online services to publish.

No Data Protection Officer has been appointed: the processing described below is limited in scope and does not meet the conditions of Article 37 GDPR.

2. What this site does not do

  • No user accounts, no login, no comment section.
  • No advertising, no ad networks, no retargeting pixels.
  • No profiling cookies, no cross-site or cross-device tracking.
  • No sale or disclosure of personal data to data brokers.
  • No automated decision-making producing legal or similarly significant effects (Article 22 GDPR).
  • No third-party fonts or embedded widgets: fonts are served from this domain, so no request is made to Google Fonts or similar services while you read a page.

3. Data processed

3.1 Technical logs

The site is hosted on Vercel. Like any web server, the infrastructure records the data needed to serve a request: IP address, browser user agent, requested URL, referrer and timestamp.

  • Purpose: delivering the site, keeping it secure, diagnosing errors and abuse.
  • Legal basis: legitimate interest in the security and correct operation of my own site (Article 6(1)(f) GDPR).
  • Retention: runtime logs are kept for one hour and then discarded, and requests served straight from the CDN cache are not recorded at all. I have configured no log drain, so no copy that I control or can consult exists beyond that window, and I do not use these logs to identify individual visitors.

3.2 Audience measurement

I use Vercel Web Analytics to know which pages are read and where readers come from. It is a cookieless tool: it neither stores nor reads anything on your device, and it does not build a persistent identifier for you. Each visit is derived from a temporary hash of the incoming request, computed from your IP address, user agent and a daily rotating salt; the IP address itself is not retained, and Vercel discards the hash after 24 hours. Every data point carries the page visited, the referrer, an approximate origin down to city level, and the device, operating system and browser. The reports I see are aggregate figures only, there is no way for me to trace a session back to a person, and no data is shared across sites.

  • Purpose: understanding which content is useful, in aggregate.
  • Legal basis: legitimate interest in measuring the audience of my own site (Article 6(1)(f) GDPR). Since no information is stored on or read from your device, the prior consent required by Article 122 of the Codice Privacy does not apply.
  • Retention: the reporting window is one month; past it, the figures are no longer available to me.

3.3 Performance measurement

I also use Vercel Speed Insights, which measures how quickly pages actually render for the people reading them (the Core Web Vitals). It is cookieless in the same way: nothing is written to or read from your device, and the recording is anonymous, so it can neither reconstruct a browsing session across pages nor identify anyone. Each measurement carries the route and URL, the connection speed, the browser, device type and operating system, the country, the metric itself and the page element it refers to.

  • Purpose: spotting and fixing the pages that render slowly.
  • Legal basis: legitimate interest in the correct operation and quality of my own site (Article 6(1)(f) GDPR). As with audience measurement, nothing is stored on or read from your device, so the prior consent required by Article 122 of the Codice Privacy does not apply.
  • Retention: the last 10,000 measurements are retained over a 30-day window, which I can consult over ranges of 24 hours and 7 days.

3.4 Session recording (Microsoft Clarity)

I also use Microsoft Clarity to see how individual pages are used: clicks, scrolling, mouse movement, page views, and the referrer, including whether a visit originates from a link generated by an AI assistant such as ChatGPT, Perplexity or Copilot. The project is configured without cookies: Clarity neither writes to nor reads from your device. This site has no forms, accounts or login, so there is no free-text input for Clarity to capture in the first place.

  • Purpose: understanding how the site's content and layout are actually used, in more detail than the aggregate figures in 3.2, and measuring how much traffic comes from AI assistants.
  • Legal basis: legitimate interest in improving my own site (Article 6(1)(f) GDPR). As with audience and performance measurement, nothing is stored on or read from your device, so the prior consent required by Article 122 of the Codice Privacy does not apply.
  • Retention: individual session recordings are kept for 30 days; the aggregate heatmaps built from them are kept for 9 months. Both are deleted automatically once their window elapses.

3.5 Contacting me

If you write to me by email, through the address published on this site, or by message on LinkedIn, I process what you send: your name, your email address and the content of your message.

  • Purpose: replying to you and, where relevant, discussing a possible collaboration.
  • Legal basis: for exchanges concerning a possible assignment, the performance of pre-contractual measures taken at your request (Article 6(1)(b) GDPR). For any other correspondence, legitimate interest in replying to those who write to me (Article 6(1)(f) GDPR).
  • Retention: as long as the exchange is professionally relevant. Correspondence tied to an assignment is kept for the duration of the assignment and for the periods required by Italian tax and civil law.
  • Providing this data is optional, but without at least an email address I have no way to reply to you.

3.6 Downloading my CV

The CV published at /cv is a static PDF. Downloading it involves no form and no additional collection beyond the technical logs described in 3.1.

4. Cookies and local storage

This site sets no cookies at all: no profiling, no marketing, no technical cookie either. That is why you see no cookie banner: there is nothing to consent to. Microsoft Clarity (3.4) is configured the same way: for visitors in the EU, UK and Switzerland it operates without cookies by default in the absence of a consent signal, and I have additionally turned cookies off for the project regardless of where a visit comes from, so it never writes anything to your device either.

The page's language follows the URL you open - English is the site's default - or the choice you make with the switcher in the top right. That choice holds for the current visit only: it isn't remembered from one visit to the next, since no cookie or other data is written to your device to do that.

This site stores nothing on your device: no cookies, no local storage, no session storage, no IndexedDB, no fingerprinting of your browser. The hosting platform may set strictly technical cookies of its own where its security measures require it - bot mitigation, or protection of a deployment - which serve no analytical or advertising purpose.

If I ever adopt a tool that does require consent, a banner will be added and that tool will not load before you accept it.

5. Who else sees the data

  • Vercel Inc. - hosting, CDN, audience and performance measurement, acting as data processor under a data processing agreement.
  • Microsoft Ireland Operations Limited - session recording and heatmaps (Microsoft Clarity), acting as data processor under a data processing agreement.
  • Google Ireland Limited - Google Workspace, which hosts the mailbox that receives your messages, acting as data processor.
  • Aruba PEC S.p.A. - the certified email provider that operates the pec.it mailbox, if you write to me at the certified address, acting as data processor.
  • LinkedIn - only if you choose to contact me there. LinkedIn (Microsoft Ireland Unlimited Company) acts as an independent data controller for that exchange, under its own privacy policy.

Data may also be disclosed where required by law or by a legitimate request from a public authority.

6. Transfers outside the EEA

Three of the processors named above are, or rely on, companies established in the United States.

  • Vercel Inc. is certified under the EU-US Data Privacy Framework, and its Data Processing Addendum additionally incorporates the European Commission's Standard Contractual Clauses.
  • Microsoft Clarity is supplied to me by Microsoft Ireland Operations Limited. Where data reaches Microsoft Corporation in the United States, the transfer rests on Microsoft's Data Protection Addendum, which incorporates the Standard Contractual Clauses, and on Microsoft Corporation's own certification under the EU-US Data Privacy Framework.
  • Google Workspace is supplied to me by Google Ireland Limited. Where data reaches Google LLC in the United States, the transfer rests on Google's Cloud Data Processing Addendum, which incorporates the Standard Contractual Clauses, and on Google LLC's own certification under the EU-US Data Privacy Framework.

All three are accompanied by supplementary technical measures, encryption in transit and at rest among them. The addenda linked above reproduce the Standard Contractual Clauses in full, and you may request a copy by writing to the certified address (PEC) atanasiu@pec.it. All three certifications can be checked on the Data Privacy Framework list.

7. Security

Traffic is served exclusively over HTTPS with HSTS. The site sends a Content Security Policy that restricts the origins a page may load code, styles, fonts and images from and, through the connect-src directive, the origins it may send data to. It is accompanied by the usual protective headers (X-Content-Type-Options, Referrer-Policy, X-Frame-Options, Permissions-Policy), which limit what a page may do and how it may be embedded.

8. Your rights

Under Articles 15 to 21 GDPR you have the right to obtain access to your data, its rectification or erasure, and the restriction of its processing. Portability (Article 20 GDPR) covers only the exchanges described in 3.5 that rest on pre-contractual measures, the sole processing founded on a contract; ordinary correspondence and every other processing described in this policy rest on legitimate interest and are not portable.

Right to object

Where the processing rests on legitimate interest - technical logs (3.1), audience measurement (3.2), performance measurement (3.3), session recording (3.4) and ordinary correspondence (3.5) - you have the right to object to it at any time, on grounds relating to your particular situation, under Article 21 GDPR. A message is enough, and if I cannot demonstrate compelling legitimate grounds that override your interests, the processing stops.

To exercise these rights, write to the certified address (PEC) atanasiu@pec.it. I will reply within one month, as required by Article 12(3) GDPR. Note that for technical logs and analytics I hold no identifier that lets me link the data to you, so I may be unable to act on a request without additional information that identifies the records concerned (Article 11 GDPR).

If you believe your data is processed unlawfully, you may lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali, or with the supervisory authority of your country of residence, and you retain the right to a judicial remedy.

Pages on this site link to third-party services - LinkedIn, GitHub, and the sources cited in articles and projects. Once you follow one of those links, that site's own privacy policy applies. I have no control over, and no responsibility for, how those services process your data.

10. Minors

This site addresses a professional audience and is not directed at minors. I do not knowingly collect data relating to anyone under the age of 14.

11. Changes to this policy

This policy may be updated as the site changes. The date shown at the top always reflects the version in force, and any substantial change will be visible there.