Privacy Policy
This policy explains what personal data Silicon Spirit Studio collects through siliconspirit.studio and in the course of doing business, why, who handles it and what you can ask of us. Silicon Spirit Studio is a brand of ETTICO LABS SRL, which is the data controller.
1. Who we are
The data controller is ETTICO LABS SRL, a Romanian limited liability company trading as Silicon Spirit Studio.
Registered in Romania under J2021005582403, with its legal address at Strada Pitar Moș nr. 27, et. 5, ap. 17, Sector 1, 010452 Bucharest. Contact: hello@siliconspirit.studio.
We have not appointed a data protection officer because the law does not require one at our size and for the data we handle, but please contact us at the address above, or via the contact form, for any question or requests about your data and someone from our team, probably Alex, will answer within a week.
2. What we collect and why
We collect only what each situation needs. For each one, this is the data involved, why we use it and the legal basis under the GDPR.
You book a call or send a message through the site
Data: name, email, company, country, what you are working on, the stage of the project, and the date and time you choose. Purpose: to prepare for the call, hold it and follow up with a written view. Legal basis: steps taken at your request before entering a contract (Art. 6(1)(b)).
You email us or we work together
Data: contact details, the content of our correspondence, project documents and invoicing details. Purpose: to deliver the work, manage the relationship and meet our accounting and tax obligations. Legal basis: performance of a contract (Art. 6(1)(b)) and our legal obligation to keep accounting records (Art. 6(1)(c)).
We contact you about our services
Data: business name, job title, work email, company, public professional profile and interaction history. Purpose: to introduce our services to companies that may need them. Legal basis: our legitimate interest in developing our business (Art. 6(1)(f)). You can object at any time and we stop.
Business contact data comes from public professional profiles, company websites and licensed B2B data providers, not from the person directly. The first message we send includes a link to this policy and a way to opt out. We do not use this data to contact private individuals.
You apply for a role with us
Data: name, contact details, CV, cover letter, portfolio links, work samples, answers to our questions, interview notes and references you give us. Purpose: to assess your application and run the hiring process. Legal basis: steps taken at your request before entering a contract (Art. 6(1)(b)) and our legitimate interest in hiring well (Art. 6(1)(f)).
Applying is not an employment relationship. We use application data only to decide whether to make an offer. If we hire you, a separate employee privacy notice applies from your first day. Send us only the information the role asks for; we do not need, and ask you not to include, data about your health, beliefs, trade union membership or other special categories. If a job board or recruiter forwards your application, their policy covers the data until it reaches us.
You visit the site
Data: IP address, device and browser type, pages viewed, approximate location and referring site. Purpose: to keep the site secure and, with your consent, to measure how it is used. Legal basis: our legitimate interest in security (Art. 6(1)(f)) and your consent for analytics cookies (Art. 6(1)(a)).
We do not make decisions about you by automated means alone, and we do not sell personal data.
3. Who processes it on our behalf
These providers handle data under our instructions and under a data processing agreement. None of them may use your data for their own purposes.
- Webflow hosts the site and stores form submissions. United States.
- Google Workspace provides our email, calendar and document storage. United States, with EU data centres available.
- Google Analytics measures how the site is used, only after you consent. United States.
- Calendly lets you pick a time for a call. United States.
- n8n routes form submissions to the tools below. Germany.
- Attio holds our customer relationship records. United Kingdom.
- Slack notifies the team when a form arrives. United States.
- Apollo provides B2B contact data and outreach sequences. United States.
Beyond processors, we disclose data only to our accountants and legal advisers where needed, to a buyer in the event the business is sold, and to public authorities where the law requires it. We do not share application data with anyone outside the hiring panel for that role.
4. International transfers
Some of the providers above store data outside the European Economic Area, mainly in the United States. Each transfer rests on one of the safeguards the GDPR recognises:
- an adequacy decision of the European Commission, which covers the United Kingdom and, for certified companies, the United States under the EU-US Data Privacy Framework
- the European Commission's Standard Contractual Clauses, built into the provider's data processing agreement, where the provider is not certified
You can ask us at the privacy contact for a copy of the safeguard that applies to a given provider. If you are in the United Kingdom, the same safeguards apply through the UK Extension to the Data Privacy Framework and the UK International Data Transfer Addendum.
5. How long we keep it
- Booking form submissions and call notes where no engagement follows: 24 months from last contact, enough to pick the conversation up if you come back.
- Client records, contracts and project files: the duration of the engagement plus 5 years, the limitation period for contract claims.
- Invoices and accounting records: 10 years from the end of the financial year, as Romanian accounting law requires.
- Prospecting records: 24 months from last interaction, or at once when you object.
- Job applications where we do not hire: 6 months after the role closes, or 24 months with your consent to stay in our talent pool.
- Analytics data: 14 months, the Google Analytics retention setting.
- Server and security logs: 90 days, enough to investigate an incident.
When a period ends we delete the data or anonymise it so it no longer identifies you.
6. Your rights
You can ask us, at any time and free of charge, to:
- tell you what data we hold about you and give you a copy
- correct data that is wrong or incomplete
- delete your data, where we no longer have a reason to keep it
- restrict what we do with it while a question is settled
- give you your data in a machine-readable format
- stop using your data for prospecting, which we do without asking why
- stop any other processing based on legitimate interest, where your situation outweighs ours
- withdraw a consent you gave, with no effect on what was done before
Write to hello@siliconspirit.studio. We may ask you to confirm your identity. We answer within one month, or tell you within that month if a complex request needs up to two more.
If you are not satisfied with our answer you can complain to the Romanian supervisory authority, the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, Bucharest, dataprotection.ro, or to the authority in the EU country where you live or work.
7. Regional terms
We work with clients in the European Union, the United Kingdom, the United States, Canada and Australia. The sections above apply to everyone. Where a local law gives you more, this section adds it.
United Kingdom
The UK GDPR and the Data Protection Act 2018 give you the rights listed in section 6. The supervisory authority is the Information Commissioner's Office, ico.org.uk. We have no UK establishment; the privacy contact above handles UK requests.
California and other US states
We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of. Where the California Consumer Privacy Act or a similar state law applies to you, you have the right to know what we collect, to delete it, to correct it, and not to be treated differently for using those rights. Use the privacy contact; an authorised agent may act for you with written permission.
Canada
Where the Personal Information Protection and Electronic Documents Act applies, we rely on your consent, which you give by booking a call, writing to us or applying for a role, and on the exceptions the Act allows for business contact information. You can withdraw consent and ask for access or correction through the privacy contact, and you may complain to the Office of the Privacy Commissioner of Canada.
Australia
Where the Privacy Act 1988 and the Australian Privacy Principles apply, this policy serves as our collection notice. Your data may be stored outside Australia with the providers in section 3. You may complain to us first and then to the Office of the Australian Information Commissioner.
8. Security
Our information security management is built to ISO 27001. Access to personal data is limited to the people who need it for their work, protected by single sign-on and hardware-backed two-factor authentication, and reviewed when roles change. Data in transit and at rest is encrypted by the providers in section 3. If a breach puts your rights at risk we will tell you and the supervisory authority within 72 hours of becoming aware of it.
9. Children
The site and our services are for businesses. We do not knowingly collect data from anyone under 16. If you believe a child has sent us data, write to the privacy contact and we will delete it.
10. Cookies
The cookies the site uses, what they do and how to change your choice are described in the Cookie policy.
11. Changes to this policy
We update this policy when our practices or the law change. The date at the top shows the current version. A change that affects how we use data you have already given us will be announced on the site before it takes effect, or by email where we hold your address. First version published on 7 October 2026.