Privacy
Who is responsible for your data, what we collect and why, who else handles it, how long it is kept, and your rights under the GDPR.
This policy has not yet been reviewed by a lawyer. It describes what the code behind this site actually does, and the two are kept in step. Last changed on 28 September 2026.
Who is responsible
- Data controller: Intell Dynamic
- Data-protection requests: contact@intelldynamic.ro
The controller decides why and how your personal data is processed and answers for it under the General Data Protection Regulation (EU) 2016/679. No data protection officer has been appointed; everything about your data goes to the address above, and you will get an answer within one month.
What we collect
- Your email address, because sign-in is by Google or magic link and there is no password. Firebase, which handles sign-in, keeps its own record of that address and when you last signed in.
- What you post and answer, because that is the marketplace: your nuntios, their photos, your answers and quotes, your business profile if you create one, and the reviews you write.
- The contact details you choose to give — a phone number or an address on a nuntio, an answer or a profile — and the display name you choose.
- A locality, so we can show you what is near you. Never a precise location.
- Who asked to see a contact, and when. If you post a nuntio or run a provider profile, we show you how many distinct people and AI assistants asked for your details in the last 30 days — a count, never their names or their email addresses.
- If you pay to promote a nuntio: what you bought, when, how much it cost and whether it went through. Your card details are not on that list and never will be — they are typed on Stripe's own checkout pages and never touch our servers.
- Photos you add to a nuntio. A photo from a phone normally carries hidden data including the exact place it was taken; we remove all of it when the photo is uploaded, and the copy we publish and keep does not have it.
- Reports you file about content, and the decisions taken about content you posted.
- The notices in your account — what the bell at the top counts — and what you chose to be told, by email or here. If you ticked the box for news and offers, the moment you did.
- If you report a problem with the site: what you wrote, the page you sent it from, the account you were signed in with if you were, and a reply address if you gave one. Only the people who run the site read it.
- If you create an API key: its label and when it was used. The key itself is stored only as a one-way fingerprint.
- A short diagnostic trail of pages requested and errors, described below.
- When you open a page, your network address and browser description are used for the moment it takes to count the visit and to avoid counting you twice today. Neither is stored. What is stored is a daily total for that page and a scrambled, single-day fingerprint that cannot be linked to any other day.
- When you arrive at the site's bare address without having chosen a language, your network address is looked up in a table that ships with the site, to see whether you are in Romania: if you are, you are shown Romanian, and otherwise English. The lookup happens on our own server, nothing is sent to anybody, and neither the address nor the country is stored or remembered. Once you choose a language with the switch, your choice is used instead, wherever you are. The table is IP to Country Lite by DB-IP (db-ip.com), used under CC BY 4.0.
- When you ask for a sign-in link, post, answer, report or ask for a contact, a counter of how many times, so the site cannot be flooded. It is keyed on your account, on the email address a link is sent to, or on your network address — always passed through a secret key first, so the counter cannot be turned back into any of them — and it is deleted once the window it counts has closed.
Why, and on what legal basis
| What for | Which data | Legal basis |
|---|---|---|
| Your account and signing in | Email address, the sign-in record | Contract — Art. 6(1)(b) GDPR |
| Posting, answering, a business profile, reviews | What you write, the place you choose, photos | Contract — Art. 6(1)(b) |
| Passing your contact details on when you release them or accept an answer | The contact details you gave | Contract — Art. 6(1)(b) |
| Emails and notices in your account about your own activity: an answer arrived, a listing is about to close, somebody asked for your contact | Email address; the notices themselves | Contract — Art. 6(1)(b). You choose which, and where, under Notifications on your dashboard. |
| News and offers from Nuntrix | Email address, and the moment you said yes | Consent — Art. 6(1)(a): only if you ticked the box, and unticking it withdraws it at once |
| Keeping contact details off public pages, limiting how often things can be done, stopping spam and abuse | What you post; counters keyed, under a secret key, on your account, your email address or your network address | Legitimate interests — Art. 6(1)(f): a marketplace people can use safely |
| Handling reports, taking content down, telling people why | The report, the decision, the statement of reasons | Legal obligation — Art. 6(1)(c), under the Digital Services Act (EU) 2022/2065 |
| Payments for promotion, invoices and accounting | What was bought, amount, date, the payment reference | Contract — Art. 6(1)(b), and legal obligation — Art. 6(1)(c) under accounting law |
| Finding out why something broke | Pages requested, errors, a shortened network address, three words about your browser | Legitimate interests — Art. 6(1)(f): keeping the site working |
| Counting how much each page is read | Daily totals only | Legitimate interests — Art. 6(1)(f); nothing that identifies you is stored |
| Reading and answering a problem you reported | What you wrote, the page, your account or the reply address you gave | Legitimate interests — Art. 6(1)(f): a site that works, and an answer when you asked for one |
| Remembering the place and language you chose | Two cookies | Your request; you can switch them off on the cookies page |
Where we rely on legitimate interests, you can object, and we will stop unless we have compelling grounds that override yours. None of this is used for advertising, and no decision with legal or similarly significant effects on you is taken by a machine. Contact details typed into public text are removed automatically, and when that happens to your words you are told what was removed and why.
Who else handles it
We use a small number of service providers, each bound by a data processing agreement to act only on our instructions. We do not sell personal data to anybody.
| Service | What it does for us | When |
|---|---|---|
| Google Cloud (Google Ireland Ltd) | Runs the site, stores the database and the photos, in the European Union | Always |
| Firebase Authentication (Google) | Signs you in and sends the sign-in link | Always |
| Stripe (Stripe Payments Europe Ltd) | Takes card payments on its own pages. Stripe is also a controller in its own right for fraud prevention and financial regulation. | Only if you promote a nuntio |
| The email service this site is configured with (Resend, or the operator's own mail server) | Delivers notices about your activity | Only if email notices are switched on |
Some of these companies, or their own sub-processors, may process data outside the European Economic Area, mainly in the United States. Where they do, the transfer relies on the EU–US Data Privacy Framework for recipients certified under it, or on the European Commission's Standard Contractual Clauses.
How long it is kept
| What | How long |
|---|---|
| Your account, and what you posted | Until you delete it. A published nuntio is open for 45 days and then closes, but its page stays until you or we remove it. |
| A nuntio you started and never finished | 30 days |
| Being signed in on a device | 30 days; a sign-in link works for 15 minutes |
| The diagnostic trail | 14 days |
| Notices in your account | 90 days, then deleted |
| A problem you reported | 180 days, then deleted, whether or not it was answered |
| The daily code that counts unique visitors | Two days, then deleted |
| The counters that limit how often something can be done | Until the window they count closes — at most a day — then deleted |
| Payment records | As long as accounting law requires — in Romania, ten years |
| Reports and moderation decisions | Kept as the record of the decision, so it can be appealed and reviewed |
| The record that somebody asked for a contact | Kept, and after the account involved is deleted it names nobody |
| Firebase's sign-in record | Deleted when you delete your account |
What is public
Your nuntios, your display name, your verification tier and your provider profile if you have one. Contact details are never public: we strip phone numbers, email addresses, links and messaging handles out of public text before it is published, because this site is deliberately readable by AI crawlers and anything published there is public permanently. Your email address and phone number are never on a public page: they are released only when someone takes an authenticated action, and we tell you when that happens.
Between users
We answer for the data we process to run Nuntrix, as this page describes. We do not answer for what users choose to publish, or for what they do with information they get from each other.
- What you publish is on you. Do not put anybody else's personal data — a name, a face in a photo, an address — into a nuntio, an answer, a profile or a review unless you are entitled to. If you do, you answer for it.
- When somebody's contact details are released to you — because you asked for them, or because you accepted their answer — what you do with them from then on is your responsibility. Use them to talk about the job and for nothing else: not for advertising, not to sell, not to pass on. If you run a business, you hold them as a controller in your own right under the GDPR, with the duties that come with it.
- Whatever you say, send or agree once you are talking directly — by phone, by email, by message or in person — happens outside Nuntrix. We do not see it, and this page does not cover it.
If somebody misuses your data — contacts you for something other than the job, passes your number on, or publishes something about you — report what they posted, or write to contact@intelldynamic.ro. We can take down what is on Nuntrix and suspend the account. What happened away from Nuntrix is a matter for the data protection authority, under Complaints below, or for the police.
What we do not do
We do not sell personal data. We do not run third-party advertising trackers. We do not join your browsing to an advertising profile.
What we keep in your browser
Four cookies, none of them a tracker: one keeps you signed in, one records the answer you gave about the other two whether you dismissed the note about them, and whether you confirmed your age to open the Matrimonials section, and the last two remember the place and the language you chose. The last two are optional and there is a switch for them on the cookies page. There is no analytics cookie, no advertising cookie and no third-party tracker, so there is nothing here that follows you off the site.
Measuring the site
We measure how much each page is read, on our own servers, with no analytics cookie and no third-party analytics service. Only daily totals per page are kept, so those counters hold no history of anybody's visits and nothing in them identifies you. The same totals count reads by programs through our open API, our MCP server and our machine-readable indexes, by which of those roads they came. Whoever posted a listing can see its totals — how many people, how many assistants, which ones — and never who any person was, because nothing kept could say. When you open one of our pages from somewhere else, that day's total also counts where you came from, by name only — a search engine, an assistant, a social network or another website's domain — taken from what your browser sends with the request; never the page you were on there, what you searched for, or anything that could tell one visit from another.
Finding out why something broke
Separately from those counters we keep a short diagnostic trail, so that when something fails we can see what led to it rather than guessing. It records the pages our server was asked for and any error — the message, where it happened, and the technical stack trace — grouped into one visit so it can be read in order. Your browser reports only when something goes wrong: a page that works sends us nothing from your browser, and one that fails sends the error with the screen it happened on. Your browser also tells us on its own when our security policy blocks something on a page; we keep which page and what was blocked, and drop the rest of the address. Only an administrator can see it. Four things bound it. It is kept for 14 days and then destroyed. Your IP address is never stored: the last part is removed before anything is written, leaving a network rather than a household. Your browser is recorded as three coarse words, like “phone · ios · safari”, never as the full identifying string. And it introduces no new way to identify you: a visit is labelled with the same daily code the page counters already use, which is derived fresh each day and cannot be linked to yesterday — or, if you are signed in, with your account. Because a signed-in trail is yours, it is in the file you can download and it is destroyed when you delete your account, like everything else you own.
Your rights
- Access and portability: download everything we hold about you as one file, from your settings page. It includes the records we keep after a deletion — payments, decisions about your content, the contacts you asked for and the reports you filed.
- Rectification: change your name, your contact details and your listings yourself; for anything you cannot change, write to us.
- Erasure: delete your account from your settings page. That destroys your nuntios, your answers, your photos, your reviews, your business profile, your API keys, the notices in your account, the problems you reported, your diagnostic trail and Firebase's sign-in record.
- Restriction and objection: ask us to stop or pause processing based on our legitimate interests, by writing to the address above.
- Withdrawing a choice: switch off the optional cookies on the cookies page, and each kind of notice, by email or in your account, and your yes to news and offers, under Notifications on your dashboard, at any time.
Three things survive a deletion, each for its own reason — payments, because a receipt is an accounting record we must keep; moderation decisions, so they stay appealable; and the record that somebody asked for your contact, because it is about what they did. Before they are kept, what identified you is taken out of them: the address you gave when you reported something, the words you sent a business, the title a payment or a report quoted. What is left is the fact itself, with no account behind it.
For anything else, write to contact@intelldynamic.ro. We answer within one month, and tell you if we need longer and why. Exercising your rights is free.
Complaints
You can complain to the data protection authority in the EU country where you live, where you work, or where you think the breach happened. In Romania that is the National Supervisory Authority for Personal Data Processing (ANSPDCP), www.dataprotection.ro. We would rather hear from you first, but you do not have to write to us before going to them.
Age
Nuntrix is not meant for children. You must be at least 18 to create an account or post. The Matrimonials section asks everybody, signed in or not, to confirm they are 18 or older and of legal age where they live before it shows anything; the answer is kept in your browser and, if you are signed in, on your account with the moment you gave it, and it is in your export. If we learn that an account belongs to somebody younger, we delete it.
Changes
When this policy changes, the date at the top changes with it, and this page always shows the version in force.