Privacy Policy
This policy explains what personal data we collect on iuliaistrati.com, why we collect it, who helps us process it, and the rights you have under the EU General Data Protection Regulation (GDPR).
1. Who We Are (Data Controller)
This website, iuliaistrati.com (the “Site”), is operated by Iulia Istrati, a sole trader registered in Romania as a persoană fizică autorizată (PFA) under the name Istrati Iulia Persoană Fizică Autorizată (“we”, “us”). Our registered office is at B-dul Bucureștii Noi 136, et. parter, ap. 5, Sector 1, București, Romania. We are registered in the Trade Register under number F2024012860005, CUI 50747836. We are the data controller for the personal data described in this policy. For anything related to your data, contact us at contact@iuliaistrati.com.
2. What Data We Collect and Why
We only collect personal data that you actively provide, plus the minimal technical data needed to run the Site securely.
- Contact and enquiry forms — first and last name, email address, phone number, country (where asked), occupation, company (where relevant), the service you are interested in, and your message. We use this to respond to your enquiry. Legal basis: our legitimate interest in responding to enquiries (Art. 6(1)(f) GDPR). Where your enquiry is a step towards a service you have asked us to prepare, that step is based on the performance of a contract or pre-contractual measures taken at your request (Art. 6(1)(b) GDPR).
- Training registration and payment — the same details as above plus your selected training slot. Your card details are entered directly on Stripe’s secure, PCI-compliant checkout page and never reach or get stored on our servers. Legal basis: performance of a contract (Art. 6(1)(b) GDPR), and our legal obligation to keep payment records for tax and accounting purposes (Art. 6(1)(c) GDPR).
- Technical data — our hosting infrastructure processes standard server logs (such as IP address, browser type, and requested pages) to deliver the Site and protect it against abuse. Our forms also include an invisible anti-spam field. Legal basis: legitimate interest in operating a secure website (Art. 6(1)(f) GDPR).
3. Who Processes Your Data For Us
We do not sell or rent your personal data. We share it only with the service providers (processors) needed to operate the Site:
- Stripe (Stripe, Inc. / Stripe Payments Europe) — processes training payments and sends you your payment receipt. See the Stripe Privacy Policy.
- Resend — delivers the internal email notification we receive when you submit a form or complete a booking. See the Resend Privacy Policy.
- Google (Google Ireland Ltd.) — form submissions and bookings are stored as records in a private Google spreadsheet that only we can access. See the Google Privacy Policy.
- Our hosting provider — serves the Site and processes technical server logs on our behalf.
4. E-book Purchases (Payhip and Amazon)
The Mind Alchemy e-book is sold through Payhip and Amazon. When you buy the e-book, your purchase, payment, and download are handled entirely by the platform you choose, acting as an independent controller under its own privacy policy. We do not receive your payment details from these platforms.
5. Analytics and Cookies
We use Simple Analytics, a privacy-first, EU-based analytics service. It sets no cookies, does not collect personal data or IP addresses, does not use fingerprinting, and cannot track you across websites. We only see aggregated statistics such as page views.
We do not use any advertising, profiling, or cross-site tracking technologies. The only thing the Site stores on your device is one small functional value in your browser’s local storage, which remembers that you dismissed the announcement bar. It contains no personal data, never leaves your device, and is strictly necessary for that feature to work as you asked it to. Because we place no cookies or other non-essential storage on your device, the Site does not show a cookie consent banner.
6. International Data Transfers
Some of our providers (Stripe, Google, Resend) are based in, or have parent companies in, the United States. Where your data is transferred outside the European Economic Area, we rely on the safeguards required by GDPR: the European Commission’s Standard Contractual Clauses, and, for providers certified under it, the EU–U.S. Data Privacy Framework. If either mechanism ceases to apply, we will put an alternative safeguard in place before continuing the transfer.
7. How Long We Keep Your Data
We keep enquiry data only as long as needed to handle your request and any follow-up, and in any case no longer than 24 months after our last contact, unless you become a client. Booking and payment records are kept for as long as required by applicable Romanian tax and accounting legislation. Data we no longer need is deleted.
8. Your Rights Under the GDPR
You have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data deleted (“right to be forgotten”);
- restrict or object to our processing;
- receive your data in a portable format;
- withdraw consent at any time, where processing is based on consent.
To exercise any of these rights, email contact@iuliaistrati.com. We will respond within one month. You also have the right to lodge a complaint with a supervisory authority, in particular the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP, www.dataprotection.ro) or the data protection authority in your country of residence.
9. No Profiling, No Automated Decisions
We do not use your personal data for automated decision-making or profiling, and we do not use advertising or tracking technologies on the Site.
10. Children
The Site and our services are directed at adults and are not intended for children under 16. We do not knowingly collect personal data from children.
11. Changes to This Policy
If we change how we process personal data, we will update this page and revise the “Last updated” date above. Significant changes will be highlighted on the Site.

