Privacy policy
Effective date: 6 September 2026
1. Who we are
Mystic Monk is a software studio. We build business software, connect systems and review existing projects to help clients improve their technology.
The controller responsible for the processing described here is Mystic Monk SRL, operating under the Mystic Monk brand, Republic of Moldova. Company registration identifier and registered office address are available on request at salut@mysticmonk.io.
For privacy questions or requests, write to salut@mysticmonk.io.
This policy covers mysticmonk.io and our communications with prospective clients, clients’ representatives and business partners. We process personal data under the Republic of Moldova’s Law No. 195/2024 on personal data protection.
2. What information we handle
When you email us, we receive your email address, the name you provide, your message and any attachments. You may also share your job title, company, telephone number or project requirements. Please send only what is needed for the discussion. Do not send passwords, identity documents or live customer databases in an initial enquiry.
For a business engagement, we may handle contact details, correspondence, contract information and invoicing or payment records that identify an individual. A colleague or business partner may provide your professional contact details to involve you in a project. If we receive your data indirectly, we provide the required information about the source and processing within the applicable legal timeframe.
When you visit the website, the technical data processed includes your IP address, browser type and version, operating system, referring page, pages requested, timestamps and HTTP status codes in server and security logs. Fonts and brand images are served from our domain; we do not load third-party fonts or advertising pixels at page load.
3. Why we use it
| Purpose | Data concerned | Legal basis |
|---|---|---|
| Answer an enquiry and prepare a proposal | Contact details, message and project information | Steps you request before a contract, where you would be a party; otherwise our legitimate interest in answering business enquiries. |
| Manage a client relationship and deliver agreed work | Professional contacts, project communications and contract records | Performance of a contract with you; for a client’s staff, our legitimate interest in coordinating the engagement. |
| Keep required accounting records and respond to binding legal requests | Relevant transaction and identification records | Compliance with applicable legal obligations. |
| Operate and protect the website, investigate faults or abuse | Relevant technical and security data | Our legitimate interest in maintaining a secure, reliable service. |
| Establish or defend legal claims | Relevant correspondence and records | Our legitimate interest in protecting our rights. |
We assess legitimate interests against your rights and use only the data needed for the purpose. A reference to legitimate interests is not permission to use your information for unrelated activities.
Providing information for an enquiry is voluntary. Without a reply address or enough project detail, we may be unable to respond or prepare a useful proposal. We explain any information required for a contract or by law when it is requested.
4. Website storage and marketing
- mm-locale (first-party cookie, Mystic Monk): remembers your language preference for up to one year; SameSite=Lax; path=/; essential for localized navigation.
- Vercel Web Analytics (Vercel Inc.): cookieless, first-party page-view measurement on the production site; no advertising profiles.
We do not use optional advertising or remarketing cookies. This site has no contact form.
Our policy is to activate optional analytics or advertising technologies only after you choose to allow them. Where such tools are offered, you can reject them or change your choice through the website’s privacy settings. Essential functions are described separately. Merely visiting the site does not mean you consent to optional processing.
An enquiry does not subscribe you to a newsletter. If we introduce an email marketing subscription, we will explain its purpose and seek a separate opt-in. You can withdraw consent or object to direct marketing at any time by emailing us. We stop using your data for direct marketing after an objection. Withdrawal does not undo processing that was lawful before it.
5. Who receives information
Access is limited to people who need it for their work. Depending on the engagement, recipients may include authorised team members, contracted specialists, hosting and email providers, collaboration providers, accountants or legal advisers. We disclose information to authorities when legally required.
Providers, relevant recipient categories and processing countries include authorised Mystic Monk team members and contracted specialists; Vercel Inc. (website hosting, CDN and Web Analytics, United States and other regions where Vercel operates); our email service provider for salut@mysticmonk.io; and accountants or legal advisers where needed.
Providers processing data on our behalf are subject to appropriate contractual instructions and confidentiality requirements. Some recipients, such as authorities or professional advisers, may act as separate controllers for their own legal responsibilities.
We do not sell personal data.
6. Processing outside Moldova
Some personal data is processed outside the Republic of Moldova, primarily on Vercel infrastructure in the United States and other regions where Vercel operates. Email and collaboration tools used for business correspondence may also involve processing outside Moldova.
Where data is transferred abroad, we use a transfer mechanism permitted under Moldovan law, including appropriate contractual safeguards where required. A provider’s general claim of “GDPR compliance” is not, by itself, our transfer safeguard. You can request information or a copy of the relevant safeguards at salut@mysticmonk.io, with necessary redactions to protect other people or confidential information.
7. How long we keep it
| Records | Retention |
|---|---|
| Enquiries that do not become projects | Up to 24 months after our last meaningful contact, unless a longer period is required for a dispute or legal obligation |
| Website and security logs | Typically up to 30 days for routine access logs; security-related logs may be kept longer where justified |
| Contracts, project correspondence and accounting records | For the duration of the engagement and thereafter as required by applicable accounting, tax and commercial law |
| Backup copies | Encrypted backups rotated on a documented schedule, generally not longer than 90 days |
We delete or anonymise records when they are no longer needed. Records relevant to a dispute or a legal preservation duty may be retained longer for that specific purpose. Backup copies are removed through the documented backup cycle, with access restricted in the meantime.
8. Data entrusted to us by clients
During development, integrations or audits, a client may give us access to personal data in its systems. Where we act as its processor, we work under the client’s documented instructions and a separate data-processing agreement. That client’s privacy notice explains its purposes and legal basis. This policy does not authorise new uses of its customer data.
If your request concerns a client’s system, contact that client first. If you contact us, we will assist with directing the request to the responsible controller, as appropriate.
9. Security and automated decisions
We use safeguards proportionate to the information and risks, including controlled access, confidentiality obligations and secure transfer methods. No system is risk-free. If a personal data breach occurs, we assess it and notify the authority and affected people where the law requires.
We do not use your website visit or enquiry to make solely automated decisions that produce legal or similarly significant effects on you.
Our website and business services are not directed at children. If a child has sent personal information, contact us so we can assess and address it.
10. Your choices and rights
Subject to the applicable conditions, you may request access, correction, deletion or restriction of your personal data. You may object to processing based on legitimate interests because of your particular situation. You may also request portability of data you supplied where automated processing relies on consent or a contract.
Send requests to salut@mysticmonk.io. We normally respond within one month. If complexity or volume requires up to two additional months, we explain this within the first month. Requests are normally free. We may seek proportionate identity verification where justified.
You may complain directly to the National Center for Personal Data Protection of the Republic of Moldova (CNPDCP) through datepersonale.md, including at centru@datepersonale.md. You do not have to contact us first. You may also seek judicial remedies.
11. Changes
We publish updates on this page with a revised date and provide further notice where required. If a new purpose needs your consent, a policy update does not replace that consent.