This Privacy Policy explains how Milannial Software SRL(“Milannial Software”, “we”, “us”, “our”) collects, uses, stores and protects your personal data when you visit https://milannialsoftware.com or interact with us through our website, contact form, AI chat, booking link or email. We act as the data controller for the data processed via this site.
1. Who we are
Milannial Software SRL, a Romanian limited liability company registered in Bucharest, Romania. Contact email: contact@milannialsoftware.com.
2. What data we collect
We collect only what we need to operate the site and respond to you:
- Contact form & email submissions — name, email, optional company name, message body, optional project details (budget range, timeline).
- AI chat (“Ask Milan”) — the messages you send to the chat assistant. We use these to generate a reply and to improve the quality of the assistant. Do not enter sensitive personal data into the chat.
- Booking — when you book a discovery call via the Cal.com link, your booking details are processed by Cal.com under their own privacy policy. We receive the booking confirmation (name, email, time slot).
- Brochure download — generated PDFs are produced on-demand; we may log the request (timestamp + anonymized fingerprint) for abuse-prevention purposes.
- Technical & analytics data — IP-based country (not stored), browser type, OS, referrer, page paths, basic timing metrics. Where used, analytics is configured to avoid storing identifiable IP addresses.
- Cookies — see the Cookies section below.
We do not knowingly collect personal data from children under 16. If you believe a child has submitted data, contact us and we will delete it.
3. Why we process your data (lawful bases)
- Pre-contractual measures & legitimate interest (Art. 6(1)(b) and 6(1)(f) GDPR) — to respond to enquiries, prepare proposals, and discuss potential engagements.
- Consent (Art. 6(1)(a) GDPR) — for non-essential cookies and any marketing communications you opt into.
- Legal obligation (Art. 6(1)(c) GDPR) — for fiscal, accounting and regulatory record-keeping where applicable.
- Legitimate interest (Art. 6(1)(f) GDPR) — for site security, abuse-prevention and basic, privacy-respecting analytics.
4. Who we share data with
We do not sell your personal data. We share only with the limited set of processors needed to operate the site:
- Hosting — our infrastructure provider (Render), processing data within the EU/EEA.
- Transactional email — provider used to deliver your contact-form submission to us (e.g. Resend), processing within the EU/EEA where supported.
- AI chat backend— your chat messages are sent to our LLM provider (e.g. OpenAI / Anthropic) to produce the assistant’s reply. These providers act as processors on our behalf and are bound by data processing agreements.
- Booking — Cal.com, when you choose to book a call.
- Authorities — where required by law or to protect our legal rights.
Where personal data is transferred outside the EU/EEA, we rely on European Commission adequacy decisions or Standard Contractual Clauses (SCCs) and apply supplementary technical measures where appropriate.
5. How long we keep your data
- Contact submissions — up to 24 months after the last interaction, then deleted or anonymized, unless we have entered a contractual relationship.
- AI chat logs — up to 12 months for quality and abuse-prevention, aggregated thereafter.
- Server logs — up to 90 days.
- Fiscal records (if applicable) — for the period required by Romanian law (currently 10 years for accounting documents).
6. Your rights under GDPR
You have the right to: access your data, rectify it, request erasure, restrict or object to processing, request data portability, and withdraw consent at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, email contact@milannialsoftware.com. We respond within 30 days.
You also have the right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) at dataprotection.ro.
7. Security
We apply industry-standard technical and organizational measures: TLS encryption in transit, encrypted storage at rest where applicable, principle of least privilege, regular security reviews, and dependency monitoring. No system is perfectly secure, but we treat security as a first-class engineering concern.
8. Cookies
We use a minimal set of cookies and similar technologies. Strictly necessary cookies (e.g. for theme preference and language) are set without consent. Any non-essential analytics or marketing cookies are loaded only after you opt in via the cookie banner, where applicable.
9. Changes to this policy
We may update this policy from time to time. The “Last updated” date at the top reflects the most recent revision. Material changes will be highlighted on this page.
10. Contact
For any privacy question, email contact@milannialsoftware.com. We aim to respond within five working days.
