Privacy Policy & Cookie Disclosure
Effective Date: September 2026
Last Updated: September 2026
Data Controller: Ștefan Prohnițchi d/b/a anicetix.pro (“Architect,” “anicetix.pro,” “we,” “us,” “our”)
Website: https://anicetix.pro
Privacy Inquiries & Data Rights Requests: info@anicetix.pro
1. OVERVIEW & SCOPE
This Privacy Policy describes how anicetix.pro collects, uses, stores, shares, and protects personal information obtained through our website (https://anicetix.pro), our commercial diagnostic forms (including the Asymmetric Pipeline Teardown intake), and our advisory communications.
We operate under a strict data minimization principle. Our services are exclusively intended for commercial enterprises, professional practices, and business operators (B2B). We comply with:
- The General Data Protection Regulation (EU) 2016/679 (“GDPR”) and the UK GDPR;
- The e-Privacy Directive (Directive 2002/58/EC) and applicable national implementing laws;
- The California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (“CCPA / CPRA”);
- Other applicable state and national data privacy statutes.
2. STRICT EXCLUSION OF PATIENT & HEALTH DATA (HIPAA & GDPR ART. 9)
CRITICAL NOTICE FOR HEALTHCARE & DENTAL PRACTICES:
anicetix.pro is an architectural and systems consultancy. WE DO NOT COLLECT, SOLICIT, INGEST, OR STORE PROTECTED HEALTH INFORMATION (PHI) UNDER HIPAA OR SPECIAL CATEGORY HEALTH DATA UNDER ARTICLE 9 OF THE GDPR.
When submitting intake diagnostics, CRM architecture reviews, or practice teardown questionnaires, DO NOT INCLUDE PATIENT NAMES, MEDICAL HISTORIES, TREATMENT RECORDS, OR IDENTIFIABLE CLINICAL CHARTS. Any patient data received inadvertently will be purged immediately without retention.
3. CATEGORIES OF PERSONAL DATA COLLECTED
We collect only the minimum personal information necessary to deliver commercial architecture services, evaluate teardown and partnership applications, and maintain website security.
3.1. Information You Provide Directly
- Commercial Contact Data: Name, professional business email address, phone number (or WhatsApp handle), practice/firm name, professional website URL, and primary geographic location.
- Practice Diagnostic & Intake Data: Business model details, practice specialty (e.g., Orthodontics, High-Ticket Dentistry, Commercial Law), target Average Engagement Value (AEV), current software stack (CMS/CRM), pipeline bottlenecks, and general practice revenue ranges submitted through our intake questionnaires.
- Transaction & Billing Data: Company legal name, billing address, tax identification number (VAT/CUI/EIN), and payment confirmation. Note: We do not process or store raw credit card numbers. All payments are processed directly by PCI-DSS compliant third-party payment processors or Merchants of Record (e.g., Stripe, Paddle, Lemon Squeezy).
- Direct Communications: Records of email correspondence, consultation notes, and intake interview transcripts.
3.2. Information Collected Automatically (Log Data & Analytics)
When you browse anicetix.pro, our servers automatically record technical telemetry, including:
- IP address (truncated or anonymized where applicable);
- Browser type and version;
- Device architecture, screen resolution, and operating system;
- Referring URL, pages visited, timestamps, and dwell time per page;
- Language preferences (e.g., browser locale for hreflang routing).
3.3. Cookies & Tracking Technologies
We utilize cookies and similar technologies:
- Strictly Necessary Cookies: Essential for page routing, session stability, security, and recording your cookie consent preferences. These cannot be disabled.
- Performance & Analytical Cookies (Optional): Used to understand visitor navigation flows (e.g., Google Tag Manager / Google Analytics with IP anonymization enabled). Under the EU e-Privacy Directive, these cookies are blocked by default and execute only after your affirmative opt-in consent via our Cookie Banner.
4. PURPOSES AND LEGAL BASES FOR PROCESSING (GDPR ART. 6)
Under European and international data protection law, we must establish an explicit legal basis for every processing activity:
| Processing Purpose | Category of Data | Legal Basis (GDPR Art. 6) |
|---|---|---|
| Evaluating Intake Applications & Delivering Teardowns | Commercial contact data, practice diagnostic data. | Performance of a Contract (Art. 6(1)(b)) or steps taken prior to entering a contract. |
| Executing Commercial Invoicing & Payment Processing | Billing details, tax IDs, transaction records. | Performance of a Contract (Art. 6(1)(b)) and Compliance with Legal Obligations (Art. 6(1)(c)) (tax/accounting rules). |
| Website Security, Fraud Prevention & System Integrity | Server log data, IP addresses, technical user agents. | Legitimate Interests (Art. 6(1)(f)) (safeguarding digital infrastructure against attack). |
| Anonymized Macro-Economic & Case Autopsy Analysis | Fully aggregated, de-identified diagnostic metrics. | Legitimate Interests (Art. 6(1)(f)) (refining proprietary commercial architecture models). |
| Direct B2B Inquiries & Consultation Scheduling | Business email, contact history. | Legitimate Interests (Art. 6(1)(f)) or Consent (Art. 6(1)(a)). |
| Website Analytics & Dwell Time Measurement | Analytical cookies, user navigation telemetry. | Consent (Art. 6(1)(a)) obtained via our Cookie Banner. |
5. SUB-PROCESSORS & DATA SHARING
We do not sell, rent, monetize, or trade your personal information to any third party.
We share personal data only with trusted service providers (sub-processors) bound by strict contractual data protection agreements (DPAs):
- Web Hosting & Infrastructure: High-performance, secure cloud servers and CDN infrastructure (e.g., Cloudflare, certified hosting facilities in the EU/US).
- Payment Gateways & Merchants of Record: PCI-DSS Level 1 compliant processors (Stripe, Paddle, or Lemon Squeezy) to process diagnostic fees and international VAT/sales tax.
- Communications & Form Processing: Professional workspace infrastructure (e.g., Google Workspace) and secure form routing plugins.
- Web Analytics: Google Tag Manager / Google Analytics configured with IP anonymization and disabled ad-personalization features.
- Legal & Regulatory Compliance: We may disclose data if legally compelled by valid subpoena, court order, or official regulatory investigation.
6. INTERNATIONAL DATA TRANSFERS
anicetix.pro operates globally, serving practices across the United States, the European Union (specifically Romania), the United Kingdom, and candidate states (Moldova).
When personal data originates in the European Economic Area (EEA) or the UK and is transferred to service providers or servers in third countries (such as the United States), we ensure an adequate level of protection through:
- Standard Contractual Clauses (SCCs): Incorporating the European Commission’s approved standard contractual clauses into our agreements with sub-processors;
- UK International Data Transfer Addendum: Ensuring equivalent protections under UK data protection law;
- Data Privacy Framework (DPF): Selecting US sub-processors certified under the EU-US Data Privacy Framework where available.
7. DATA RETENTION SCHEDULE
We retain personal information only for as long as necessary to fulfill the operational purposes outlined in this Policy:
- Diagnostic & Intake Submissions: Retained for the duration of the active consultation or engagement. Unaccepted applications or abandoned inquiries are deleted or irreversibly anonymized after twelve (12) months.
- Client Engagement & Deliverable Records: Retained for the duration of the engagement plus twenty-four (24) months for longitudinal architectural reference, unless earlier erasure is requested.
- Tax, Invoice & Accounting Records: Retained for statutory periods mandated by commercial and tax codes (typically five (5) to ten (10) years).
- Server Access Logs: Retained for thirty (30) to ninety (90) days for cybersecurity and debugging, after which they are automatically purged.
8. YOUR STATUTORY DATA RIGHTS (GDPR & UK GDPR)
If you reside in the EEA, the United Kingdom, or jurisdictions with equivalent privacy frameworks, you have the following rights under Articles 15–22 of the GDPR:
- Right of Access (Art. 15): Request a copy of the personal information we hold about you.
- Right to Rectification (Art. 16): Request correction of inaccurate, outdated, or incomplete data.
- Right to Erasure (“Right to Be Forgotten”) (Art. 17): Request deletion of your personal data where retention is no longer justified by contract, legitimate interest, or statutory obligation.
- Right to Restriction of Processing (Art. 18): Request that we suspend processing while a dispute regarding data accuracy or legal basis is resolved.
- Right to Data Portability (Art. 20): Request your data in a structured, commonly used, machine-readable format.
- Right to Object (Art. 21): Object at any time to processing based on legitimate interests or direct commercial communications.
- Right to Withdraw Consent (Art. 7(3)): Withdraw your consent for analytical cookies or communications at any time without affecting the lawfulness of processing prior to withdrawal.
- Right to Lodge a Complaint: You have the right to lodge a complaint with your local data protection supervisory authority. In Romania, this is the National Supervisory Authority for Personal Data Processing (ANSPDCP –
anspdcp@dataprotection.ro). In the UK, this is the Information Commissioner’s Office (ICO –ico.org.uk).
To exercise any of these rights, contact our Data Controller at info@anicetix.pro. We respond within thirty (30) days without fee.
9. CALIFORNIA PRIVACY RIGHTS (CCPA / CPRA NOTICE)
This Section applies solely to California residents pursuant to the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020:
9.1. Categories of Personal Information Collected & Disclosed
In the preceding twelve (12) months, anicetix.pro has collected and disclosed for business purposes the following categories of Personal Information:
- Identifiers: Name, business email, IP address, practice name.
- Commercial Information: Diagnostic intake responses, engagement transaction records, services purchased.
- Internet / Network Activity: Log files, page navigation, device telemetry.
9.2. No Sale or Sharing of Personal Information
anicetix.pro does not “sell” your personal information, nor do we “share” personal information for cross-context behavioral advertising (as those terms are defined under the CCPA/CPRA). We have not engaged in such sales or sharing in the preceding twelve (12) months.
9.3. Your Rights Under CCPA / CPRA
- Right to Know / Access: Request details regarding the categories and specific pieces of personal information collected about you.
- Right to Delete: Request the deletion of personal information collected, subject to standard statutory exceptions (e.g., completing commercial transactions, legal compliance).
- Right to Correct: Request correction of inaccurate personal data.
- Right to Non-Discrimination: We will never deny services, charge different rates, or degrade service quality because you exercised your privacy rights.
To submit a CCPA/CPRA request, email: info@anicetix.pro with the subject line “California Privacy Rights Request”.
10. COOKIE MANAGEMENT & USER CONTROLS
When you first visit anicetix.pro, our Cookie Banner gives you explicit control over optional tracking scripts:
- Browser Controls: You can set your browser to reject cookies or notify you when a cookie is placed. Note that disabling essential cookies may impact site navigation.
- Consent Withdrawal: You can modify your analytical tracking preferences at any time by clicking the “Cookie Preferences” link in our website footer.
11. DATA SECURITY ARCHITECTURE
We deploy robust technical and organizational safeguards appropriate to the risk level:
- Encryption in Transit: All traffic to and from
anicetix.prois encrypted via SSL/TLS 256-bit protocols (HTTPS). - Access Control: Diagnostic intake data is accessible strictly on a need-to-know basis by the Principal Architect using multi-factor authentication (MFA).
- Vendor Governance: All third-party software tools (CRM, hosting, payment) are audited for SOC2, ISO 27001, or GDPR adequacy compliance.
12. CHILDREN’S PRIVACY
anicetix.pro is strictly a professional B2B platform. We do not knowingly solicit or collect data from individuals under the age of 18. If we discover that personal data of a minor has been collected, it will be deleted immediately.
13. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy periodically to reflect changes in our operational architecture, technology stacks, or regulatory requirements. Any modifications will be posted to https://anicetix.pro/en/privacy-policy/ with an updated “Last Updated” timestamp. We encourage you to review this page periodically.
14. CONTACT INFORMATION & DATA CONTROLLER
For any questions, concerns, or data rights requests, please contact:
Ștefan Prohnițchi
Data Controller d/b/a anicetix.pro
Email: info@anicetix.pro / contact@anicetix.pro
Website: https://anicetix.pro/en/privacy-policy/
