MVP version · updated 5 September 2026
Privacy Notice
In brief: we collect only what is needed for the map, reviews, moderation and security. We do not sell personal data or publish contributors’ email addresses.
1. Who we are
Transylvania GeoPulse LTD operates Merdenele.net and Patiserii.net and determines why and how personal data is used. Contact us at privacy@transylvaniageopulse.com.
2. Who this notice applies to
This notice applies to visitors, people who nominate locations or submit reviews, field contributors, bakery representatives and anyone who contacts us.
3. Data we collect
- Account details and authentication-provider identifiers.
- Nominations, reviews, written contributions, photographs and information about visited locations.
- Messages, support requests and information used to verify a profile claim.
- Technical security data such as IP address, access time, browser, device and logs.
- Receipts and information needed for approved reimbursements; these are not public.
4. Why we use data
- To provide accounts and requested features.
- To verify, moderate and publish profiles and contributions.
- To prevent abuse, maintain security and handle disputes.
- For reimbursements, accounting and legal obligations.
- For non-essential analytics or marketing only where an appropriate legal basis exists and consent is obtained when required.
5. What may become public
If you submit a contribution for publication, your chosen public name or pseudonym, rating, text, photographs, approximate date and reviewed location may appear publicly. We do not publish your email address, authentication identifier, IP address, receipts or payment information.
6. Suppliers and international transfers
During the MVP we use suppliers for hosting, authentication, forms, storage, email, domains and security, including OpenAI Sites, Cloudflare, Google, Spaceship/Spacemail and GoDaddy. We share only the data required for each service. Where personal data is transferred internationally, we use applicable legal safeguards such as adequacy decisions and standard contractual clauses. Details of an EEA representative will be added if appointment is required.
7. Retention
- Account data: while the account is active and normally no longer than 24 months after closure.
- Rejected materials and routine technical logs: normally 90 days.
- Published contributions: while relevant, or until deletion or anonymisation where applicable.
- Financial and contractual records: for the legally required period, normally up to 6 years.
- Backups: cycles of up to 90 days, except where law or incident handling requires longer retention.
8. Cookies
We use only items strictly necessary for operation, security and authentication. Non-essential analytics, advertising or personalisation cookies will not be activated before the user’s choice where consent is legally required.
9. Your rights
Depending on the circumstances, you may request access, correction, deletion, restriction or portability and object to certain uses. You may withdraw consent at any time. Email privacy@transylvaniageopulse.com; we may request reasonable information to verify your identity.
10. Complaints, children and security
You may complain to the Romanian ANSPDCP or the UK Information Commissioner’s Office. Please contact us first so we can try to resolve the issue. The platform is not deliberately directed at children under 16, and participation as a field contributor is limited to adults aged 18 or over. We use access controls, administrator two-factor authentication, logging and restricted data access.
Changes
We will update this page when the platform, suppliers or legal requirements change. Important changes will be announced clearly.