Legal
Privacy policy
Last updated:
1. Who is responsible for your data
The controller of personal data processed through marketextent.com isStefan Stoica, an individual based in Bucharest, Romania. MarketExtent is the name used for the website and related professional work.
This policy applies to site visitors and to people who contact MarketExtent personally or on behalf of a seller, e-commerce business, marketplace, software provider, or other organisation.
To ask a privacy question or exercise your rights, use thecontact form. Any reply will be sent to the address you provide in that request.
2. Data we process
Depending on how you use the site, we may process:
- Contact details and message: your name, email address, company or store if supplied, selected topic, and the context you submit.
- Attribution data: the page or campaign source and UTM parameters when they are present in the link you use.
- Submission records: submission time, confirmation that the privacy notice was read, the request identifier, and the status of any internal notification.
- Technical security data: the application stores a hash of the IP address, not the plain IP address, together with the Cloudflare Ray identifier. Cloudflare may process the IP address and other technical signals required to deliver the site and perform anti-abuse checks.
- Later correspondence: information you provide if the conversation continues after the initial request.
Do not submit passwords, API keys, credentials, contact lists, special-category personal data, or personal information about sellers or other people. The site and services are intended primarily for professionals and are not directed at children. We do not knowingly request data from anyone under 16.
3. Why we process it
- To respond to and assess a request. This may be necessary to take steps at your request before a contract, under Article 6(1)(b) GDPR, or based on our legitimate interest in managing professional correspondence you initiate, under Article 6(1)(f).
- To secure the site and prevent abuse. The IP hash, Cloudflare Ray, and Turnstile help rate-limit submissions, diagnose failures, and protect the form. This is based on our legitimate interest in protecting the site and its records, under Article 6(1)(f) GDPR.
- To keep a minimum record and protect legal rights. We retain evidence of what was received and how it was handled based on legitimate interests and, where applicable, legal obligations under Article 6(1)(c) GDPR.
- To make an introduction you request or accept. Data is not forwarded automatically. We first identify the recipient and purpose, then share only what is necessary for that step.
The checkbox confirms that you have read this notice. It is not consent to advertising, a newsletter, or an outbound campaign. Contact requests are not automatically added to Smartlead or another marketing list. The current site does not operate a newsletter.
4. How the contact form works
After validation and anti-spam verification, the request is stored in a Cloudflare D1 database. The site reports success only after that record has been saved.
If transactional email is configured, the saved request may trigger an internal notification. That notification is secondary. Its failure does not remove the stored request, and the site does not promise an automatic confirmation email to the sender.
5. Who may receive data
We do not sell or rent personal data. It may be accessed or processed by:
- the MarketExtent operator, to review and manage the request;
- Cloudflare, Inc., for site delivery, Workers, D1 storage, security, and Turnstile;
- Google, because the site currently loads Google Fonts from Google's domains, which creates a technical browser request;
- an email provider, only when an internal notification or email reply is generated;
- a marketplace, software provider, or operational provider, only after you request or accept an introduction and only to the extent needed for it;
- authorities or professional advisers when disclosure is legally required or needed to establish, exercise, or defend a legal claim.
A third party receiving data to offer its own service may act as a separate controller. Its own privacy information will then also apply.
6. International transfers
Cloudflare operates a global network. Depending on the service and configuration, technical and hosted data may be processed outside the European Economic Area. Where required, Cloudflare describes safeguards including standard contractual clauses and other recognised transfer mechanisms.
See Cloudflare'sprivacy policy,data processing documentation, andTurnstile privacy addendum. Google publishes itsprivacy policy separately.
7. How long we keep data
We retain a request only as long as reasonably necessary to review and answer it, manage follow-up, document the relationship, and protect legal rights. The period depends on the request, the last interaction, and whether a project, contract, or legal obligation follows.
If no collaboration follows, the data will be deleted or minimised when it is no longer needed for those purposes. If a contractual relationship begins, some records may be retained for tax, accounting, or legal limitation periods. The IP hash and Cloudflare Ray identifier follow the retention of the associated request. Provider-held technical logs follow the provider's configuration and policies.
8. Your rights
Subject to the conditions in Regulation (EU) 2016/679, you may request access, rectification, erasure, restriction, portability, or object to processing based on legitimate interests. Where processing is actually based on consent, you may withdraw that consent without affecting earlier lawful processing.
Use the contact form and state that your request concerns personal data. We may ask for reasonable information to verify your identity. GDPR response periods and permitted extensions apply.
9. Cookies, security, and automated checks
The site currently has no behavioural advertising, marketing tracking, or active analytics script. Cloudflare may use cookies or similar technologies strictly necessary for network delivery and security. Turnstile may use technical signals, cookies, or local storage needed to distinguish legitimate form submissions from abuse.
The current configuration does not require a marketing-cookie banner. If non-essential technologies are added, this notice and the choice mechanism will be updated before they are activated.
Turnstile and anti-abuse rules may automatically block a suspicious submission. This is used for form security, not marketing profiling. MarketExtent does not make solely automated decisions that produce legal or similarly significant effects about site visitors.
10. Complaints
You may lodge a complaint with Romania's National Supervisory Authority for Personal Data Processing, ANSPDCP. The authority publishes current contact and complaint information atdataprotection.ro. You do not need to contact MarketExtent first, although we would welcome the opportunity to address your concern.
11. Changes and contact
We may update this policy when the site, suppliers, categories of data, or applicable law changes. The current version and update date are shown on this page.
For privacy questions or data-rights requests, use thecontact form.