Privacy policy
On this page
This policy explains what M A Naeli Abdelkarim, who runs Sperfy, does with personal data collected through sperfy.com and during advisory work. It is written to be read, so the language is plain. Where a term comes from the General Data Protection Regulation, we use it and explain it.
1. Who we are
M A Naeli Abdelkarim is the data controller, registered in Romania as a PFA (persoană fizică autorizată) at Registrul Comerțului under F40/1187/2019, fiscal code 41276358, at 84 Strada Ropotului, Andronache, Bucharest 022521, Romania.
For anything in this policy, write to privacy@sperfy.com or call +40 746 162 748. No data protection officer has been appointed, because this processing does not meet the thresholds in Article 37 GDPR. Every request comes to me directly.
2. What this policy covers
It covers visitors to sperfy.com, people who contact the desk by form, email or phone, staff at the client and supplier companies I deal with, and anyone who writes to ask about working together. It does not cover personal data that a client processes inside their own systems while I advise them. In that situation the client is the controller and I act on their instructions under a separate written agreement.
3. What we collect
3.1 When you use the website
Pages are served through Cloudflare. Their edge servers log the request: IP address, time, page requested, the referring page, and your browser and device strings. These logs exist so the site stays available and abuse can be traced. No visitor profiles are built and no analytics tag is installed on this site today.
3.2 When you write to the desk
The enquiry form asks for your name, email address and a description of your situation. Company name, phone number, preferred call time and subject are optional. The form also carries a hidden field that is invisible to people and usually filled in by automated scripts, which lets me discard obvious spam.
3.3 During client work
I hold business contact details for the people I work with, notes and documents produced during an engagement, and the records my accountant needs for invoicing. Where a document contains personal data belonging to your organisation, I keep it only as long as the engagement and the retention rules below require.
3.4 People who ask about working together
If you write to offer your services as a subcontractor or a specialist, I keep your message and any CV or profile you send with it. No automated decision making is used at any stage.
4. Why we use it, and on what legal basis
- To answer you. Legal basis: your consent when you tick the box on the form, or my legitimate interest in replying to a business enquiry sent to me directly (Article 6(1)(a) and 6(1)(f)).
- To carry out an engagement. Legal basis: performance of a contract, or steps taken at your request before entering one (Article 6(1)(b)).
- To meet accounting and tax obligations. Legal basis: legal obligation under Romanian law (Article 6(1)(c)).
- To keep the site available and free of abuse. Legal basis: my legitimate interest in a working, secure website (Article 6(1)(f)).
- To consider working with you. Legal basis: steps taken before a contract, and your consent if I ask to keep your details on file afterwards.
Where consent is the basis you can withdraw it at any time, and doing so does not affect anything done before you withdrew it.
5. Cookies
The site sets one cookie, which records your cookie choice. Nothing in the measurement or marketing categories runs unless you switch it on. The cookie policy lists the exact name, purpose and lifetime, and you can at any time.
6. Who else sees it
The circle stays small. The organisations that process data for the practice are:
- Cloudflare, Inc., for hosting and delivery of this website.
- Our email and document provider, used for the mailbox and the files produced during engagements.
- An accountant in Bucharest, for invoices and statutory bookkeeping.
- Google LLC and jsDelivr, which serve the fonts and two libraries this site loads. They receive the IP address of the request as part of delivering those files and set no cookies here.
Each of them acts under a written agreement that limits what they may do with the data. Personal data is never passed to anyone for money, and never to advertisers.
7. Transfers outside the EEA
Some of those providers are established in the United States. Where data reaches them, the transfer relies on the European Commission's standard contractual clauses, on the EU-US Data Privacy Framework where the provider is certified, or on both. Ask and I will tell you which mechanism applies to a particular provider.
8. How long we keep it
| Record | Kept for | Reason |
|---|---|---|
| Enquiries that do not become work | 24 months | Context if you come back to us |
| Engagement files and correspondence | 6 years after the last invoice | Defence of legal claims |
| Invoices and accounting records | 10 years | Romanian accounting law |
| Offers of collaboration not taken up | 12 months | Kept as a record, then deleted |
| Cloudflare request logs | Per Cloudflare's own retention schedule | Availability and abuse handling |
9. How we protect it
Access to the mailbox and document store is mine alone, protected by a second factor. Laptops are encrypted. Client material lives in a separate folder per engagement, and any temporary access given to a subcontractor is removed when the work closes. If a breach happens that puts your rights at risk, I notify the Romanian supervisory authority within 72 hours and tell you directly where the regulation requires it.
10. Your rights
Under the GDPR you can ask for a copy of your data, ask me to correct it, delete it, restrict what is done with it, or send it to another controller in a machine readable form. You can object to processing based on legitimate interest, and withdraw consent where consent is the basis.
Write to privacy@sperfy.com. I answer within one month. If a request is unusually complex I may take up to two months more, and I will tell you why inside the first month. I may ask you to confirm who you are first, which protects you rather than me.
11. Complaints
If you think your data has been handled badly, tell me first and I will try to fix it. You can also complain to the Romanian supervisory authority, the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal, at Bulevardul General Gheorghe Magheru 28-30, Sector 1, Bucharest, or through dataprotection.ro. If you live in another EU country you may complain to your own authority instead.
12. Changes to this policy
When something changes the version number and the revision date at the top of this page change with it. Material changes are announced on the home page for a month. Older versions are available on request from privacy@sperfy.com.