Privacy Policy
We run a newsletter and a contact form. That is the entire extent of the personal data we ask you for, and this page explains exactly what happens to it.
Last updated
Who is responsible for your data
The controller of the personal data described here is ASKING GALAXY SRL, a company registered in Romania (CIF 45643049, Registrul Comerțului J3/382/2022), with its registered office at Str. Dobrești, Nr. 306, Sat Dobrești, Comuna Dobrești, Județul Argeș, 117365, Romania.
For anything related to your data, write to office@askinggalaxy.com. We have not appointed a Data Protection Officer, because the scale and nature of our processing does not require one under Article 37 GDPR.
What we collect, why, and on what legal basis
Newsletter
When you subscribe we store your email address, the date and time you gave consent, the IP address the signup came from, and the exact wording of the consent checkbox you ticked. The legal basis is your consent (Art. 6(1)(a) GDPR). The IP address and the stored wording exist only so that we can demonstrate that consent was actually given, as Art. 7(1) requires.
The list is double opt-in: after signing up you receive one email with a confirmation link, and nothing further is ever sent unless you open it. Unconfirmed signups are useless to us and are deleted (see retention below).
Every newsletter contains a personal unsubscribe link, and you can withdraw consent at any time without giving a reason. Withdrawing is as easy as giving consent was.
Contact form
We store the name, email address, subject and message you submit, plus the IP address of the submission. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR) in answering enquiries and in protecting the form from abuse. If your message concerns a contract or a legal request, we also rely on Art. 6(1)(b) and (c).
Server logs
Our hosting provider records technical request data — IP address, timestamp, requested URL, user agent, response status — for operating and securing the service. That is our legitimate interest under Art. 6(1)(f). We do not use these logs to build profiles of visitors.
Administration
The editorial back office is password-protected and uses a single strictly necessary session cookie (acb_session). It is only ever set for logged-in staff and never for visitors.
Cookies and similar technologies
The public site is deliberately light. We do not use analytics, tracking pixels, social plugins or third-party fonts — our typefaces are served from our own domain, so no font provider ever sees your IP address.
Cookies and local storage in use:
| Name | Type | Purpose | Lifetime |
|---|---|---|---|
acb_session | Strictly necessary cookie | Keeps an editor signed in to the admin area. Never set for public visitors. | 7 days |
acb_consent | Strictly necessary local storage | Remembers your advertising-cookie choice, so we do not ask again. Only created once advertising is enabled and you answer the banner. | 6 months |
Because none of the above requires consent, you will normally see no cookie banner. If and when we introduce advertising (Google AdSense), a consent banner appears before any advertising script is loaded, non-essential cookies stay blocked until you accept, and rejecting is a single click that is given the same prominence as accepting. Until you consent, Google Consent Mode is set to deny advertising and analytics storage.
Who else processes your data
We keep the number of processors to a minimum. Each one acts on our instructions under a data processing agreement:
| Processor | Role | Where |
|---|---|---|
| Vercel Inc. | Hosting and content delivery; server logs | Requests are served from the EU (Frankfurt); the company is US-based |
| Neon Inc. | Managed PostgreSQL database holding subscribers and contact messages | United States (us-east-2) |
| Resend (Plus Five Five, Inc.) | Sending the confirmation email and contact notifications | United States |
| Google Ireland Ltd. | Advertising (AdSense) — only if advertising is enabled and only after you consent | EU and United States |
Transfers outside the EEA
Our database and our email provider are operated by companies in the United States, so your email address and any message you send us are transferred there. These transfers rely on the EU–US Data Privacy Framework where the provider is certified, and otherwise on the European Commission's Standard Contractual Clauses together with the providers' technical safeguards (encryption in transit and at rest). You can ask us for details of the safeguards that apply to a specific provider.
How long we keep it
- Confirmed subscribers: until you unsubscribe or ask for erasure.
- Unconfirmed signups: the confirmation link expires after 7 days and the record is deleted afterwards.
- Unsubscribed addresses: we keep the address together with the opt-out timestamp so it cannot be accidentally re-added. Ask us and we will erase it completely.
- Contact messages: up to 24 months after the matter is closed.
- Server logs: short-term, according to our hosting provider's retention.
Your rights
Under the GDPR you may ask us to:
- give you access to the data we hold about you, and a copy of it;
- correct anything inaccurate;
- erase your data ("right to be forgotten");
- restrict or object to processing based on legitimate interest;
- receive your data in a portable machine-readable format;
- withdraw consent at any time, which does not affect processing already done.
Write to office@askinggalaxy.com and we will respond within one month. There is no charge, and we will not ask you for more identifying information than we need to locate your record.
If you believe we are handling your data unlawfully you can complain to the Romanian supervisory authority, the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP): https://www.dataprotection.ro, anspdcp@dataprotection.ro. You may also complain to the authority in your own country of residence.
Automated decision-making
We do not carry out automated decision-making or profiling that has legal or similarly significant effects on you.
Children
The site is aimed at security and technology professionals and is not directed at children. We do not knowingly collect data from anyone under 16.
Security
The site is served exclusively over HTTPS. Administrator passwords are stored as salted scrypt hashes, and session tokens are stored only as SHA-256 hashes, so a database leak would not expose usable credentials. Access to the back office is limited to named accounts.
Changes
If we change how we process personal data we will update this page and its "last updated" date. Where a change requires your consent we will ask for it again rather than assume it.