Privacy Policy
Last updated: September 16, 2026
Who we are
Mediasphere is a content marketing agency based in Bucharest, Romania. “Mediasphere” is the trading name of MUREȘAN O. ANDREI PERSOANĂ FIZICĂ AUTORIZATĂ, a Romanian sole trader registered with the Romanian Trade Registry under No. F40/1944/2022, European Unique Identifier (EUID) ROONRC.F40/1944/2022, sole registration code (CUI) 46088338, with its professional seat at B-dul Mărășești No. 2B, Block D, Staircase 1, Floor 3, Apartment 6, Sector 4, Bucharest, Romania. Our website is https://mediasphere.digital.
For the personal data described in this policy, we are the data controller. That means we decide why and how the data is used, and we're responsible for protecting it.
You can reach us about anything in this policy at hello@mediasphere.digital. We haven't appointed a Data Protection Officer because the scale and nature of our processing don't require one under Article 37 of the GDPR. Every request sent to that address is handled directly by our team.
What this policy covers
This policy applies to visitors to mediasphere.digital, people who contact us or book a call, clients and the people who work with us on their behalf, newsletter subscribers, professionals we research and contact as potential clients, visitors to our LinkedIn page, and our suppliers.
It does not cover personal data we handle on behalf of our clients, such as a client's email subscribers, customer lists, or audience data inside their marketing platforms. For that data, the client is the controller and we act as their processor. The section “Data we process for clients” explains how that works.
The laws that apply
We process personal data under the General Data Protection Regulation (EU) 2016/679 (“GDPR”), Romanian Law No. 190/2018 on measures implementing the GDPR, and Romanian Law No. 506/2004 on the processing of personal data and the protection of privacy in electronic communications, which governs cookies and electronic marketing.
What we collect and why
When you contact us or book a call
If you write to us through the website or by email, or book a discovery call, we collect what you give us. That's usually your name, work email, company, job title, phone number, and message. Calls are booked through Cal.com, which also records the time you choose and your answers to any booking questions.
We use this to reply, hold the call, and decide together whether working with us makes sense. The legal basis is our legitimate interest in responding to business inquiries (Article 6(1)(f) GDPR). Where you contact us on your own behalf about a possible contract, the basis is taking steps at your request before entering into it (Article 6(1)(b) GDPR).
When your company becomes a client
Our contracts are usually with companies, so most client data we hold is about the people we work with there: names, job titles, work contact details, and our correspondence. We also hold contracts, invoices, and billing details, the brand materials and briefs you share, access to the marketing platforms you grant us, and performance data for the work we deliver.
We process the details of the people we work with at your company on the basis of our legitimate interest in running the engagement well (Article 6(1)(f) GDPR). Where the contract is with you personally, for example as a sole trader, the basis is performance of that contract (Article 6(1)(b) GDPR). We keep contracts, invoices, and accounting records because Romanian accounting and tax law requires it (Article 6(1)(c) GDPR).
Where a platform allows it, we ask for access through our own user account rather than a shared password.
Data we process for clients
Some of our work involves personal data that belongs to a client's own audience, such as email subscribers, CRM contacts, social media followers, or campaign audiences. For this data, the client is the controller. We act as a processor under Article 28 GDPR, or as a service provider under US state privacy laws where they apply, and we use the data only on the client's documented instructions.
If your data reached us this way and you want to exercise your rights, please contact the company you have a relationship with. We'll help them respond.
We don't accept health information about a client's patients or customers, including protected health information under US law, unless a separate written agreement covering it is in place.
When you visit our website
When you browse mediasphere.digital, our servers and service providers receive technical data: your IP address, browser and version, device and operating system, the page that referred you, the pages you visit, and how long you spend on them. We use this data in two ways.
First, to deliver the site and keep it secure. This relies on strictly necessary technology and our legitimate interest in running a safe, working website (Article 6(1)(f) GDPR).
Second, to understand how visitors use the site. We do this only if you accept analytics cookies (Article 6(1)(a) GDPR and Article 4(5) of Law No. 506/2004). You can change your choice at any time through the cookie settings link in the footer. Our Cookie Policy lists every cookie we use and how long each one lasts.
When you subscribe to our newsletter
If you subscribe, we collect your email address and any preferences you choose. We send the newsletter through Resend, which records whether each email was delivered and whether it was opened or clicked. The legal basis is your consent (Article 6(1)(a) GDPR). You can withdraw it at any time through the unsubscribe link in every email or by writing to us.
When we research and contact potential clients
We look for companies that might benefit from our services and contact people there whose roles involve marketing or growth decisions. For this, we collect professional information: name, job title, company, work email address, business phone number, LinkedIn profile URL, and public professional activity such as LinkedIn posts. We also collect company information such as size, industry, funding stage, and the technology the company uses.
This information comes from company websites, public professional profiles, public business registries, and commercial business data providers, currently Vibe Prospecting, operated by Explorium. Those providers are independent controllers of the data they supply, and their own privacy policies apply to it.
The legal basis is our legitimate interest in finding and contacting businesses that fit our services (Article 6(1)(f) GDPR). We've weighed that interest against your rights. We limit research to professional information, contact only people whose role makes our message relevant, and keep outreach brief and infrequent.
Every outreach message identifies us, links to this policy, and lets you opt out with a single reply. Because we don't collect this data from you directly, we give you the information in this policy within one month of collecting it, or in our first message if that comes sooner (Article 14 GDPR). If you object, we stop contacting you and keep only your email address and company name on a suppression list so we don't contact you again.
When you interact with our LinkedIn page
LinkedIn gives us aggregated statistics about visitors to and followers of our company page. For these statistics, we and LinkedIn Ireland Unlimited Company are joint controllers under Article 26 GDPR. LinkedIn handles most obligations for this data, including requests to exercise your rights, as set out in LinkedIn's Privacy Policy and its Page Insights Joint Controller Addendum. The statistics we see are aggregated.
When you work with us as a supplier
If you provide services to us as a freelancer, contractor, or advisor, we collect your name, business contact details, and the details needed for contracts and invoices. The legal basis is performance of our contract with you (Article 6(1)(b) GDPR), or our legitimate interest where you represent a company (Article 6(1)(f) GDPR), along with our legal obligation to keep accounting records (Article 6(1)(c) GDPR).
What we don't do
We don't sell, rent, or trade personal data. We don't make decisions about you based solely on automated processing that have legal or similarly significant effects (Article 22 GDPR). We don't ask for sensitive data, such as health information, and we ask you not to send it to us.
You don't have to give us any personal data. Without contact details, though, we can't reply to you, and without billing details we can't enter into a contract with your company.
Who we share data with
We share personal data only with the categories of recipients below, and only as far as each one needs it.
| Recipient | Why | Who |
|---|---|---|
| Website hosting and delivery | Running and securing the site | Emergent Labs |
| Scheduling | Booking discovery calls | Cal.com |
| Sending our newsletter | Resend | |
| Analytics | Measuring site use, with your consent | Google Analytics 4 |
| Business data providers | Researching potential clients | Vibe Prospecting (Explorium) |
| Productivity, file storage, and AI tools | Research, drafting, collaboration, and project delivery | Google Workspace, Microsoft SharePoint, Anthropic (Claude) |
| Professional advisors | Accounting, tax, and legal advice | Our accountant and lawyers |
| Public authorities | Where the law requires it | For example ANAF, courts, or ANSPDCP |
Every provider that processes data on our behalf is bound by a data processing agreement under Article 28 GDPR. We share client data with third party platforms only when the client authorizes it.
International transfers
Several of our providers are based in the United States or process data there. When personal data leaves the European Economic Area, we rely on a European Commission adequacy decision, including the EU-U.S. Data Privacy Framework for providers certified under it, or on the European Commission's Standard Contractual Clauses. You can ask for a copy of the relevant safeguards at hello@mediasphere.digital.
How long we keep data
We keep personal data only as long as we need it for the purpose we collected it for, or as long as the law requires.
| Data | How long we keep it |
|---|---|
| Inquiries and call bookings that don't lead to a contract | 12 months after our last exchange |
| Client contact details and project materials | For the length of the contract, then 3 years, the general limitation period for claims under the Romanian Civil Code |
| Access to client marketing platforms | Removed within 30 days after the contract ends |
| Contracts, invoices, and accounting records | 5 years from July 1 of the year after the financial year in which they were created (Article 25 of Law No. 82/1991) |
| Potential client research | 12 months after collection, unless you reply and a conversation begins |
| Outreach suppression list (email address and company only) | For as long as we carry out outreach, so your objection keeps being honored |
| Newsletter subscriptions | Until you unsubscribe. We delete your data within 30 days and keep only your email address on a suppression list |
| Website analytics | 14 months, as set in Google Analytics 4 |
| Server and security logs | 30 days |
| Supplier records | For the length of the contract, then 3 years. Accounting records follow the 5 year rule above |
If a legal claim or a request from an authority requires us to keep data longer, we keep it only as long as that requires.
Your rights
Under the GDPR, you have the following rights over your personal data.
| Right | What it means |
|---|---|
| Access (Article 15) | Get a copy of your data and details of how we use it |
| Rectification (Article 16) | Have inaccurate or incomplete data corrected |
| Erasure (Article 17) | Have your data deleted when we no longer have a valid reason to keep it |
| Restriction (Article 18) | Have us pause the use of your data while a concern is resolved |
| Portability (Article 20) | Receive data you gave us in a common, machine readable format, where we process it by consent or contract |
| Objection (Article 21) | Object to processing based on our legitimate interests. For direct marketing, including our outreach, your objection always wins |
| Withdrawing consent (Article 7(3)) | Withdraw consent at any time, without affecting processing that happened before |
To use any of these rights, write to hello@mediasphere.digital. It's free. We may ask you to confirm your identity before we act. We reply within one month. For complex or numerous requests, we can extend that by two more months, and we'll tell you why within the first month.
You can also complain to the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336 Bucharest, Romania, www.dataprotection.ro, or to the data protection authority in the EU country where you live or work. We'd appreciate the chance to resolve your concern first.
If you're in the United States
We work mainly with US companies. Whether or not a particular US state privacy law applies to us, we handle requests from US residents to access, correct, or delete their personal information in the same way as the requests above. We don't sell personal information, and we don't share it for targeted advertising based on your activity across other websites.
How we protect your data
We use encrypted connections (TLS) for our website and services, limit access to personal data to the people who need it, require multifactor authentication on our business accounts, and work only with providers bound by data processing agreements. We review these measures regularly.
If a personal data breach occurs, we notify ANSPDCP within 72 hours where the law requires it. If the breach is likely to put your rights at high risk, we also tell you without undue delay.
Children
Our services are for businesses and professionals. We don't knowingly collect personal data from anyone under 16. If you believe we have, contact us and we'll delete it.
Changes to this policy
When we update this policy, we change the “Last updated” date at the top. For material changes, we email our clients and newsletter subscribers before the changes take effect. That includes any move of the Mediasphere business to a different legal entity, since the data controller would change with it. Earlier versions are available on request.
Contact us
For any question about this policy or your personal data, write to hello@mediasphere.digital.
Our postal address is MUREȘAN O. ANDREI PERSOANĂ FIZICĂ AUTORIZATĂ, trading as Mediasphere, B-dul Mărășești No. 2B, Block D, Staircase 1, Floor 3, Apartment 6, Sector 4, Bucharest, Romania (CUI 46088338, Trade Registry No. F40/1944/2022).