Skip to content
Draft

Last updated: 2026-07-25

Privacy Policy

Working draft for lawyer review — not legal advice and not final. Replace the registered-office placeholder and remove this Draft badge only after counsel approval. Questions: contact@milannialsoftware.com.

Important: This document is a working draft prepared for review by qualified legal counsel. It is not legal advice. Do not treat it as final until the Draft badge is removed after lawyer approval and the registered office placeholder is replaced.

This Privacy Policy explains how Milannial Software SRL(“Milannial Software”, “we”, “us”, “our”) collects, uses, stores, discloses and protects personal data when you visit https://milannialsoftware.com(including www and locale paths) or interact with us through our website contact form, AI chat (“Ask Milan”), brochure or proposal generation, booking link, or email. We act as the data controller for personal data processed via this website under Regulation (EU) 2016/679 (GDPR) and applicable Romanian data-protection law.

1. Who we are (controller)

Milannial Software SRL
CUI: 44998817
Nr. Reg. Com.: J52/1036/2021
EUID: ROONRC.J52/1036/2021
Date of incorporation: 2021-10-04
Registered office (sediu social): {{SEDIU_SOCIAL_COMPLET}}
Email (privacy / GDPR requests): contact@milannialsoftware.com

We do not currently appoint a separate Data Protection Officer (DPO). Privacy requests should be sent to the email above. If we appoint a DPO later, we will update this policy.

2. Scope

This policy covers personal data processed in connection with:

  • browsing and using the public website;
  • submitting the contact form or sending email to contact@milannialsoftware.com;
  • using Ask Milan (AI chat) and optional in-chat email lead capture;
  • generating brochure or proposal PDFs on the site;
  • booking a discovery call via the Cal.com link we publish.

It does not govern personal data processed under a separate signed client services agreement (those engagements use their own contractual and privacy terms).

3. What personal data we collect

We apply data minimisation. We do not ask for special categories of data (Art. 9 GDPR). Do not submit health, biometric, political, religious, trade-union, sexual, genetic data, or other Art. 9 data via our forms or chat.

3.1 Contact form and email

  • Name, email address, optional company name, optional budget range;
  • Message content and any project details you choose to include;
  • Optional estimator session note if you forward an estimate into the form;
  • Timestamp of submission and anti-abuse signals (see §3.5);
  • Explicit consent that you have read this Privacy Policy (checkbox required to submit).

3.2 Ask Milan (AI chat)

  • The text of messages you send and the replies generated;
  • Optional lead fields (name and email) if you use “prefer email” lead capture, plus confirmation of privacy consent;
  • Technical request metadata needed to operate the chat (see §3.5).

Do not enter passwords, API keys, national ID numbers, payment card data, confidential business secrets you are not authorised to share, or special-category data into the chat.

3.3 Booking (Cal.com)

If you book via our Cal.com link, Cal.com processes booking data under Cal.com’s privacy policy. We typically receive confirmation details such as your name, email and chosen time slot. Cal.com may act as an independent controller or processor depending on the configuration; review their terms before booking.

3.4 Brochure / proposal PDFs

PDFs are generated on demand. We may process a display name you provide for personalisation and may retain short-lived technical logs for abuse prevention (see §3.5). We do not use PDF generation as a marketing list.

3.5 Technical, security and anti-abuse data

  • IP address and related request metadata used for rate limiting and abuse prevention (stored in short-lived in-memory structures on the application server; not used for advertising profiles);
  • User-Agent, path, approximate timing, and error diagnostics in server logs;
  • Referrer URL where sent by your browser (used e.g. for chat page context).

3.6 What we do not collect via this site (current state)

  • No third-party marketing or behavioural advertising cookies.
  • No third-party analytics product (e.g. Google Analytics, Plausible) is installed at the time of this draft. Decorative UI elements such as a synthetic visitor counter are not measuring real traffic and are not personal-data analytics.
  • No cookie consent banner is shown because we do not load non-essential tracking cookies. If we introduce non-essential cookies or analytics later, we will update this policy and implement a consent mechanism before activation.

3.7 Children

The site is directed at business users. We do not knowingly collect personal data from children under 16. If you believe a child has submitted data, contact us and we will delete it without undue delay.

4. Purposes and lawful bases (Art. 6 GDPR)

  • Art. 6(1)(b) — steps at your request prior to entering a contract (responding to enquiries, preparing discussions or proposals).
  • Art. 6(1)(a) — consent where required (e.g. acknowledgement of this Privacy Policy before contact/lead submit; any future non-essential cookies or marketing only with prior opt-in).
  • Art. 6(1)(f) — legitimate interests in securing the site, preventing abuse/spam, and operating a professional business website, balanced against your rights.
  • Art. 6(1)(c) — legal obligations (e.g. accounting / tax retention) if and when a commercial relationship creates such records.

Where we rely on legitimate interests, you may object under Art. 21 GDPR (see §8). Where we rely on consent, you may withdraw it at any time without affecting prior lawful processing.

5. Recipients and processors

We do not sell personal data. We do not share it for third-party advertising. We disclose data only to:

  • Hosting / infrastructure — Render — hosts the website and application runtime (service configured for the Frankfurt / EU region where available).
  • Transactional email — Resend — delivers contact and lead notifications to our inbox. Domain sending is configured for milannialsoftware.com.
  • AI inference — OpenAI— processes Ask Milan chat content to generate replies. OpenAI acts as a processor for this purpose under its API / DPA terms. Messages are transmitted to OpenAI’s systems (which may involve processing outside the EU/EEA).
  • Scheduling — Cal.com — if you choose to book a call (see §3.3).
  • Professional advisers and authorities — only where necessary (e.g. lawyers, accountants) or required by law, or to establish, exercise or defend legal claims.

6. International transfers

Some processors (notably OpenAI) may process data in the United States or other countries outside the EU/EEA. Where we transfer personal data outside the EU/EEA, we rely on appropriate safeguards under Chapter V GDPR, typically the European Commission’s Standard Contractual Clauses (SCCs) and the processor’s data processing agreement, plus supplementary measures where appropriate. You may request information about the safeguards in place by emailing us.

7. Retention

  • Contact / lead submissions — up to 24 months after the last relevant interaction, then deleted or anonymised, unless a contract or legal claim requires longer retention.
  • Chat content — processed to generate a reply; we do not operate a long-term public chat archive. Operational or abuse-related logs: up to 12 months unless a security investigation requires limited longer retention.
  • Server / security logs — typically up to 90 days.
  • In-memory rate-limit data — ephemeral; cleared on process restart and not used as a marketing database.
  • Accounting / fiscal records — for the periods required by Romanian law when applicable (commonly up to 10 years for certain accounting documents).

8. Your rights

Under the GDPR you may have the right to:

  • access your personal data (Art. 15);
  • rectify inaccurate data (Art. 16);
  • erase data (Art. 17), subject to legal exceptions;
  • restrict processing (Art. 18);
  • data portability (Art. 20), where applicable;
  • object to processing based on legitimate interests (Art. 21);
  • withdraw consent at any time (Art. 7(3)), where processing is consent-based;
  • not be subject to solely automated decisions producing legal or similarly significant effects (Art. 22) — we do not make such decisions via this website.

To exercise rights, email contact@milannialsoftware.com with sufficient detail to identify your request. We will respond within one month (extendable as permitted by Art. 12(3) GDPR).

You may lodge a complaint with the Romanian supervisory authority: Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), www.dataprotection.ro. You may also contact your local EU supervisory authority.

9. Security

We apply technical and organisational measures appropriate to the risk, including TLS in transit, least-privilege access, dependency hygiene, security headers, and input validation / rate limiting on public APIs. No method of transmission or storage is perfectly secure. You use the public internet at your own residual risk; report suspected incidents to contact@milannialsoftware.com promptly.

10. Cookies and similar technologies

We use only strictly necessary cookies or local storage equivalents where required for basic site function (for example language or theme preference). These do not require consent under the ePrivacy rules as implemented for essential storage.

We do not currently set non-essential analytics, advertising, or social tracking cookies. There is therefore no cookie banner for optional categories. If that changes, we will obtain prior consent before setting non-essential cookies and update this section.

11. Automated decision-making and profiling

Ask Milan generates automated text replies for information only. It does not produce legal effects or similarly significant decisions about you. We do not build advertising profiles from site use.

12. Changes

We may update this policy. The “Last updated” date at the top reflects the latest revision. Material changes will be indicated on this page. Continued use of the site after an update constitutes acknowledgement of the revised policy for subsequent interactions; where consent is required, we will re-collect it as needed.

13. Contact

Privacy and GDPR requests: contact@milannialsoftware.com. We aim to acknowledge within five working days.