Privacy policy
Effective date: 21.08.2026
Last updated: 21.08.2026
This Privacy Policy describes how MAXIM IOANA PERSOANĂ FIZICĂ AUTORIZATĂ (hereinafter referred to as the “Controller”), with its registered office at 136 Bucureștii Noi Blvd., Ground Floor, Apt. 5, Sector 1, Bucharest, registered with the Trade Register under no. F2025006891003, Tax Identification Number (CUI) 51387212, e-mail: hello@ioanamaxim.eu, collects, uses, stores, and protects your personal data when you use the website https://ioanamaxim.eu, its subdomains, services, programs, products, or features associated with the digital ecosystem.
Your personal data is processed in accordance with Regulation (EU) 2016/679 on the protection of personal data (“GDPR”), as well as applicable national legislation.
This Policy may be updated periodically to reflect changes to the services, technologies used, service providers involved, or legal requirements. The updated version will be published on this page, and the date of the latest update will be indicated at the beginning of the document.
1. What Personal Data May Be Collected
În funcție de modul în care interacționezi cu ecosistemul Ioana Maxim, pot fi colectate următoarele categorii de date:
- first and last name;
- e-mail address;
- phone number, when necessary for the requested service;
- information you choose to provide through forms, email, or other means of communication;
- data required for scheduling and providing the contracted services;
- data required to process a purchase or provide a product or service;
- billing details and other information required to comply with financial, accounting, and tax obligations;
- delivery address, when you purchase a physical product;
- technical information such as your IP address, device type, browser, operating system, and information about your use of the website, insofar as such data is collected through necessary technologies or technologies for which you have given your consent;
2. How Your Data Is Collected
Data may be collected when:
- you complete a form available on the website;
- you send an email or contact the Controller through other communication channels;
- you request information about a service, program, or collaboration;
- you register for a program, session, workshop, event, or other service;
- you purchase a product or resource;
- you voluntarily subscribe to the newsletter or other communications;
- you use features provided through external platforms such as Beacons;
- you browse the website and consent to the use of certain analytics technologies or cookies.
3. Purposes and Legal Bases for Processing
Your data may be used for the following purposes:
- To respond to your requests – when you contact me for information, collaborations, career counseling, HR, speaking engagements, workshops, acting, or other matters. The legal basis may be the Controller’s legitimate interest in communicating with interested individuals or taking steps at your request prior to entering into a contract.
- For the provision of contracted services or programs – including career counseling, Career Reframing, HR consulting, Fractional HR, speaking engagements, training, workshops, and other services. The legal basis is the performance of a contract or taking the necessary steps prior to entering into a contract.
- For the processing and provision of purchased products or resources – including digital products, programs, materials, or physical products. The legal basis is the performance of a contract.
- For managing payments and billing – including the issuance of financial and accounting documents and compliance with tax obligations. The legal basis is compliance with the legal obligations applicable to the Controller.
- For sending newsletters and marketing communications – when you expressly choose to subscribe to such communications. The legal basis is your consent.
- For collecting and publishing testimonials – when you consent to their use. The legal basis is your consent or the specific agreement established between the parties.
- For analyzing the performance and use of the website – through analytics tools and similar technologies, insofar as these require and have received your consent.
- For the security and operation of the website – including preventing unauthorized access, identifying technical issues, and protecting the infrastructure. The legal basis is the Controller’s legitimate interest in maintaining the security and operation of digital services.
- For the establishment, exercise, or defense of legal claims – when necessary in connection with a contractual relationship, a request, or a dispute. The legal basis is the Controller’s legitimate interest or compliance with legal obligations.
4. Newsletter and Email Communications
If you choose to subscribe to the newsletter or other periodic communications, data such as your name and email address may be processed to send you information about career counseling, portfolio careers, People & Culture, programs, resources, workshops, events, projects, products, services, and other topics related to Ioana Maxim’s activities.
For managing these communications, external email marketing platforms such as Beacons, Brevo and/or MailerLite.
You can unsubscribe at any time using the unsubscribe link available in the communications you receive or by sending a request to hello@ioanamaxim.eu.
The withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.
5. Online Purchases
Certain products, programs, resources, registrations, automations, and other features of the Ioana Maxim ecosystem may be managed through external platforms and services, such as Beacons.
When you use a feature provided through such a platform, certain data may be transferred to and processed through that platform in order to provide the requested service, process a purchase, access a resource, or carry out other related operations.
Payments for certain products or services may be processed through external payment service providers, such as Beacons and/or Stripe, depending on the payment method available at the time. Payment-related data is processed in accordance with the policies and terms of the providers involved.
The platforms and payment processors used, including Beacons and Stripe, may process data as processors, independent controllers, or in another capacity determined by applicable law and the specific service provided.
6. Who Your Data May Be Shared With
Your data may be shared, strictly to the extent necessary for the purposes described in this Policy, with categories of service providers such as:
- the provider of hosting and technical infrastructure services;
- Beacons, for products, resources, payments, automations, and features managed through this platform;
- payment processors used through Beacons or other associated services;
- Brevo and/or MailerLite, for managing the newsletter and email communications;
- providers of scheduling and calendar services, if used;
- providers of statistical analytics and traffic measurement services, insofar as their use is permitted by your cookie preferences;
- providers of accounting services and other professional services necessary for conducting business activities;
- courier or transportation services, when the delivery of a physical product is required;
- public authorities, courts, or other competent bodies, when disclosure is required by law.
Only the data necessary for the provision of the respective service is shared with service providers, in accordance with their respective roles and applicable legal obligations.
7. International Data Transfers
Some of the service providers used to operate the digital ecosystem may operate or store data outside the European Economic Area.
In such cases, data transfers will be carried out in accordance with applicable law, using mechanisms recognized under the GDPR, such as adequacy decisions, Standard Contractual Clauses, or other appropriate legal safeguards.
8. How Long I Keep Your Data
Personal data is retained only for as long as necessary to fulfill the purpose for which it was collected or to comply with applicable legal obligations.
Depending on the circumstances:
- data related to requests and communications is retained for as long as necessary to handle the request and, where justified, for a reasonable period thereafter;
- data related to clients and contracted services may be retained for the duration of the contractual relationship and thereafter for as long as necessary to comply with legal obligations or defend legal claims;
- financial and accounting documents are retained for the periods required by applicable tax and accounting legislation;
- data used for newsletters and marketing communications is retained until consent is withdrawn or the user unsubscribes, except for information that must be retained to demonstrate compliance with legal obligations;
- data collected through cookies and similar technologies is retained for the periods specific to each tool, in accordance with the Cookie Policy.
Once the applicable retention periods expire, the data will be deleted, anonymized, or retained only to the extent that there is a legal basis for its continued storage.
9. Your Rights
Under the conditions set out in the GDPR, you have the following rights:
- the right of access – you may request information about the personal data being processed and a copy of that data;
- the right to rectification – you may request the correction of inaccurate data or the completion of incomplete data;
- the right to erasure – you may request the deletion of your data in the cases provided by law;
- the right to restriction of processing – you may request the restriction of processing in certain circumstances;
- the right to object – you may object to certain processing activities based on legitimate interests;
- the right to data portability – where provided for by law, you may request to receive your data in a structured format and have it transmitted to another controller;
- the right to withdraw consent – where processing is based on consent, you may withdraw it at any time;
- the right not to be subject to a decision based solely on automated processing, including profiling, where the conditions set out in the GDPR are met;
- the right to lodge a complaint with the National Supervisory Authority for Personal Data Processing.
To exercise your rights, you may send a request to hello@ioanamaxim.eu. Your request will be handled in accordance with the conditions and time limits set out in applicable law.
10. Cookies and Similar Technologies
The Website may use cookies and other similar technologies necessary for its operation or used for analytics, measurement, the integration of external services, or other features.
Where the use of a cookie or similar technology requires your consent, it will only be activated in accordance with the choices you make through the consent management mechanism available on the Website.
For more information about cookies, their purposes, and your options, please refer to Cookie policy.
11. Data Security
The Controller implements reasonable and appropriate technical and organizational measures to protect personal data against unauthorized access, accidental or unlawful loss, alteration, disclosure, or destruction.
These measures may include the use of secure connections, access controls for the platforms and accounts used, keeping the technical infrastructure up to date, and limiting access to data to individuals and service providers who need it to perform their duties.
However, no method of electronic transmission or storage can guarantee absolute data security.
12. Datele furnizate de terți
If you provide personal data belonging to another person, it is your responsibility to ensure that you have the right to disclose such information and that the person concerned is properly informed about this processing.
13. External Links and Services
The ioanamaxim.eu ecosystem may contain links to websites, platforms, and services operated by third parties, including Beacons, social media services, scheduling platforms, video services, or other external resources.
This Privacy Policy applies to the processing carried out by the Controller and does not replace the privacy policies of external service providers.
I recommend reviewing the policies applicable to each external service before providing your data through it.
14. Data Concerning Minors
The website’s services and content are not specifically intended to collect personal data from minors. However, where a parent or legal guardian expressly consents to the provision of services to a minor under their care, such data will only be processed in accordance with this Policy.
If the Controller determines that data has been collected from a minor without the applicable legal requirements being met, the necessary measures will be taken to delete or appropriately manage such data.
15. Data Protection Contact
If you have any questions about this Policy, how your data is processed, or if you wish to exercise any of your rights under the GDPR, you can contact me at:
MAXIM IOANA PERSOANĂ FIZICĂ AUTORIZATĂ
B-dul Bucureștii Noi, 136, et. Parter, ap. 5, SECTOR 1, BUCUREȘTI
E-mail: hello@ioanamaxim.eu
You also have the right to lodge a complaint with: National Supervisory Authority for Personal Data Processing (ANSPDCP), if you believe that the processing of your data violates applicable data protection legislation.