Skip to main content

Privacy Policy

Last updated: February 2026

This Privacy Policy explains how SystemTrails collects, uses, stores, and protects your personal data. It applies to all interactions with our website and services, regardless of where you are located.

Because SystemTrails is operated by a company established in the European Union (Romania), the EU General Data Protection Regulation (GDPR — Regulation 2016/679) applies to all personal data we process, including data of users outside the EU (per GDPR Article 3(1)). This means all users worldwide benefit from GDPR-level data protection when interacting with us.


1. Data Controller

The data controller for all personal data processed through SystemTrails is:

Dan Podina (trading as GQLTeam)


2. What Data We Collect

2.1 When you visit the website

  • Server logs: IP address, browser type, operating system, pages visited, referring URL, and timestamps. These are collected automatically by our web server for security and performance purposes.
  • Analytics (with consent): If you accept cookies via the consent banner, we use Google Analytics 4 to understand site usage (pages viewed, session duration, referral source). If you decline cookies, no analytics data is collected. Google Analytics uses cookies and may transfer data to servers in the United States. IP anonymization is enabled.

Legal basis: Legitimate interest (server logs for security — GDPR Art. 6(1)(f)); Consent (analytics cookies — GDPR Art. 6(1)(a)).

2.2 When you contact us

  • Name and email address (from the contact form or direct email)
  • Role/type (if selected from the contact form dropdown)
  • Any information you voluntarily include in your message about your project

Legal basis: Contract performance / pre-contractual steps (GDPR Art. 6(1)(b)); Legitimate interest in responding to inquiries (GDPR Art. 6(1)(f)).

2.3 When you purchase a service

  • Payment information (processed by Stripe — we never see, receive, or store your full card number, CVV, or banking details)
  • Name, email, and business details provided at checkout
  • Information about your project or system shared as part of the engagement

Legal basis: Contract performance (GDPR Art. 6(1)(b)); Legal obligation for tax/accounting records (GDPR Art. 6(1)(c)).

2.4 When you share code or system access

  • Repository access (read-only) for the duration of the teardown or engagement
  • Deployment, infrastructure, and system configuration details you choose to share
  • Technical findings and notes produced during the review

Legal basis: Contract performance (GDPR Art. 6(1)(b)).


3. How We Use Your Data

We use your personal data exclusively to:

  • Provide the services you purchased or requested
  • Communicate with you about your engagement or inquiry
  • Produce and deliver the agreed deliverables
  • Process payments and issue invoices
  • Comply with applicable legal and tax obligations
  • Improve our website and services (via anonymized, aggregated analytics)

We do not use your data for marketing (unless you explicitly opt in), sell it to third parties, or share it with anyone outside the scope of the engagement.


4. Code and System Access

Your code and system information receive the highest level of protection:

  • We access your code only for the specific purpose described in the engagement
  • Access is revoked or discontinued promptly after the engagement ends
  • We do not copy, retain, fork, or redistribute your source code after the engagement
  • Code access is subject to confidentiality obligations and, if requested, a mutual NDA
  • Any technical findings are treated as confidential and are not shared without your explicit written consent

5. Data Retention

Data typeRetention period
Project data (code notes, findings, working documents)90 days after engagement completion, then permanently deleted
Contact information (name, email)Retained until you request deletion, or 2 years after last interaction
Payment and invoicing recordsRetained as required by Romanian tax and accounting law (currently 10 years under the Romanian Fiscal Code)
Server logs90 days, then automatically purged
Analytics dataGoverned by Google Analytics retention settings (currently set to 14 months)

You may request earlier deletion of any data (except where legal retention obligations apply) at any time.


6. Third-Party Services (Sub-processors)

We use the following third-party services to deliver our website and services:

ServicePurposePrivacy policy
Google Analytics 4Website usage analytics (consent-based)Google Privacy Policy
StripePayment processingStripe Privacy Policy
Cal.comAppointment schedulingCal.com Privacy Policy
FormspreeContact form processingFormspree Privacy Policy
DigitalOceanWebsite hostingDigitalOcean Privacy Policy

Some of these services may process data outside the European Economic Area (EEA). Where this occurs, appropriate safeguards are in place (e.g., Standard Contractual Clauses, EU-US Data Privacy Framework adequacy decisions).


7. Cookies

Our website uses cookies only for analytics purposes, and only with your explicit consent.

  • No cookies are set if you decline the consent banner.
  • If you accept, Google Analytics sets first-party cookies to distinguish unique visitors and sessions.
  • You can withdraw consent at any time by clearing your browser cookies and revisiting the site, which will display the consent banner again.

We do not use advertising cookies, tracking pixels, or social media trackers.


8. Your Rights Under GDPR

Because our company is established in the EU, these GDPR rights apply to all users worldwide, regardless of where you are located. Under the GDPR, you have the following rights regarding your personal data:

  • Right of access (Art. 15) — Request a copy of the personal data we hold about you.
  • Right to rectification (Art. 16) — Request correction of inaccurate or incomplete data.
  • Right to erasure (Art. 17) — Request deletion of your data (“right to be forgotten”), subject to legal retention obligations.
  • Right to restrict processing (Art. 18) — Request that we temporarily stop processing your data in certain circumstances.
  • Right to data portability (Art. 20) — Request your data in a structured, commonly used, machine-readable format.
  • Right to object (Art. 21) — Object to processing based on legitimate interest.
  • Right to withdraw consent (Art. 7(3)) — Withdraw consent at any time (e.g., for analytics cookies). Withdrawal does not affect the lawfulness of processing performed before withdrawal.

To exercise any of these rights, email [email protected]. We will respond within 30 days as required by the GDPR.


9. Right to Lodge a Complaint

If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority.

EU/EEA users: You may contact the Romanian supervisory authority (as the controller’s authority) or the authority in your own member state:

ANSPDCP — Autoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal

UK users: You may also contact the UK’s supervisory authority:

ICO — Information Commissioner’s Office

  • Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom
  • Phone: +44 303 123 1113
  • Website: ico.org.uk

Users outside the EU/EEA and UK: You may contact us directly at [email protected], or lodge a complaint with ANSPDCP (listed above), which is the supervisory authority for our company.


10. International Data Transfers

Our website is hosted within DigitalOcean’s infrastructure. Some third-party services (Google Analytics, Stripe) may transfer data to servers located outside the EEA, including the United States and the United Kingdom. Where such transfers occur, they are protected by:

  • The EU-US Data Privacy Framework (where applicable)
  • The EU adequacy decision for the United Kingdom (renewed December 2025), allowing free data flow between the EU and UK
  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Other appropriate safeguards under GDPR Chapter V

11. Data Security

We implement appropriate technical and organizational measures to protect your personal data, including:

  • All data transmitted to and from our website is encrypted via HTTPS/TLS
  • Access to shared repositories and project data is limited to the engagement team and secured with strong authentication
  • Confidentiality is enforced through contractual obligations and, where applicable, NDAs
  • Server access is restricted and monitored

No method of transmission or storage is 100% secure. If you become aware of a security vulnerability, please contact us immediately.


12. Region-Specific Disclosures

United Kingdom

If you are located in the United Kingdom, the UK GDPR (as retained under the Data Protection Act 2018) applies to the processing of your personal data. Your rights under UK GDPR are substantively the same as those listed in Section 8. You may contact the ICO (Section 9) to exercise your rights or lodge a complaint.

California, United States

The California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) apply to businesses that meet specific revenue and data-processing thresholds. As a small consulting practice, SystemTrails does not currently meet these thresholds. However, we want California residents to know:

  • We do not sell your personal information.
  • We do not share your personal information for cross-context behavioral advertising.
  • We do not use or disclose sensitive personal information for purposes beyond what is necessary to provide the Services.
  • We respect browser “Do Not Track” signals — if you decline analytics cookies, no tracking occurs.

If you are a California resident and wish to exercise any privacy right, contact us at [email protected].

Other Jurisdictions

Regardless of where you are located, we apply GDPR-level protections to all personal data we process. If your local law provides additional rights, we will honor them to the extent they apply.


13. Children’s Data

Our Services are not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected such data, contact us and we will delete it promptly.


14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, services, or applicable law. The “Last updated” date at the top reflects the most recent revision. If changes are material, we will make reasonable efforts to notify affected individuals.


15. Contact

Questions about this Privacy Policy or your personal data? Email us at [email protected].