Your information
Privacy Policy
This policy explains how VidaHa handles personal data, why it is needed, and the choices available to you.
Effective 25 August 20261. Who is responsible
Vida Sorin Bogdan, established in Romania, operates VidaHa and is the controller for the personal data described in this policy.
Privacy requests can be sent to isvidabogdan@gmail.com. Please do not include passwords, authentication codes, or other secrets in an email.
2. Information we process
- Account data: email address, display name, avatar, user ID, authentication providers, and email-confirmation status.
- Security and session data: authentication events, session identifiers, timestamps, IP address, browser and device information, and abuse-prevention signals.
- Profile and service content: profile settings and information you choose to enter when a VidaHa feature supports it.
- Support communications: the content of messages you send and the contact details needed to respond.
- Local preferences: theme, visual-performance, menu, and interface preferences stored on your device.
3. Where the information comes from
Most information comes directly from you. When you use Google or Facebook sign-in, that provider supplies the basic identity information you approve, such as your email address, name, and profile image. Hosting, authentication, and security providers also generate limited technical logs while delivering the service.
4. Purposes and legal bases
VidaHa currently does not use advertising trackers or optional analytics cookies.
| Purpose | GDPR legal basis |
|---|---|
| Create and operate your account, authenticate you, and provide requested features | Performance of a contract or steps requested before entering one (Article 6(1)(b)) |
| Protect accounts, prevent abuse, diagnose failures, and maintain service reliability | Legitimate interests in security and reliable operation (Article 6(1)(f)) |
| Respond to requests and keep necessary business or compliance records | Contract, legitimate interests, or legal obligation, depending on the request (Articles 6(1)(b), (f), or (c)) |
| Use optional analytics, advertising, or other non-essential storage if introduced later | Consent collected before use (Article 6(1)(a)) |
5. Service providers and recipients
- Supabase provides authentication, database, session, and security infrastructure.
- Vercel hosts and delivers the web application and may process request and operational logs.
- Google processes data when you choose Google sign-in, according to the permissions shown on its consent screen.
- Meta processes data when you choose Facebook sign-in, according to the permissions shown on its consent screen.
- Cloudflare Turnstile may process technical and abuse-prevention signals when a security challenge is enabled.
- Authorities or professional advisers may receive information when required by law or reasonably necessary to protect legal rights.
6. International transfers
Some providers may process data outside Romania or the European Economic Area. Where required, transfers rely on an adequacy decision, approved contractual safeguards such as Standard Contractual Clauses, or another lawful transfer mechanism. Provider policies contain further details about their locations and safeguards.
7. How long information is kept
- Account and profile information is generally kept while the account remains active.
- Authentication and security logs are kept only for operational, security, dispute, and legal needs, subject to provider retention schedules.
- Support correspondence is kept as long as needed to resolve the request and maintain necessary records.
- Device preferences remain until you clear browser storage or reset the application.
- Deletion requests are completed unless information must be retained for security, legal claims, or a legal obligation.
8. Your data-protection rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent at any time where consent is the legal basis.
Delete your VidaHa account from Settings → Account. A recent sign-in and an exact confirmation phrase are required. For help, email isvidabogdan@gmail.com from the address connected to your account. Associated application data is deleted unless limited retention is required for security, legal claims, or a legal obligation.
- Send requests to isvidabogdan@gmail.com. Identity verification may be required before fulfilling a request.
- You may complain to the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) or another competent supervisory authority.
9. Security
VidaHa uses access controls, encrypted transport, managed authentication, row-level database policies, session protections, and restricted administrative credentials. No internet service can guarantee absolute security, so use a strong unique password and protect access to your email and connected identity providers.
10. Children
VidaHa is not directed to children under 16. If you believe a child provided personal data without appropriate authorization, contact isvidabogdan@gmail.com.
11. Automated decisions
VidaHa does not currently make decisions producing legal or similarly significant effects through solely automated processing.
12. Changes to this policy
This policy may be updated when the service, providers, or legal requirements change. Material changes will be communicated through the service or another appropriate channel, and the effective date will be updated.