Privacy Policy — Side Effects
Last updated:
1. Controller
This policy describes personal-data processing associated with sideeffects.studio. The website presents the Side Effects project and allows visitors to contact its owner; it does not provide online ordering or accept payments.
The website operator and data controller is Mykola Yanovych, owner of the Side Effects project in Bulgaria. Contact for privacy enquiries and rights requests: contact@sideeffects.studio.
Location: Burgas, Bulgaria.
2. Information and purposes
Website requests
Hosting and security providers process technical request information, including IP address, browser/device information, request time, requested address and connection information, to deliver and protect the website. Where a version of this website is delivered through Cloudflare, Cloudflare processes these requests. Our purpose is reliable operation and preventing abuse. The basis is our legitimate interest in website security and operation, Article 6(1)(f) GDPR.
Contact form
The contact form displays fields for your name, email address, LinkedIn link, other contact details, enquiry topic, proposal title and description, website or application link, target countries, team and one attachment. Submission is temporarily unavailable. Entering information or selecting a file does not send it to us; the website does not upload the file or store these fields. You may instead email contact@sideeffects.studio.
The description field is limited to 1000 characters. One attachment may be selected, up to 10 MiB (10,485,760 bytes). Required fields are marked in the form; these local checks do not enable delivery. Enquiry data is not used for marketing emails without a separate lawful basis. Sending a work proposal does not constitute agreement to indefinite retention in a recruitment database.
Email correspondence
When you email us, we receive your sender address, name, message, attachments and information you provide. We use it to respond and consider your enquiry.
Article 6(1)(b) may apply to steps requested by an individual before a contract with that individual. For company representatives and other business communications, our basis is Article 6(1)(f), our legitimate interest in handling enquiries and business communication. Compliance with applicable legal obligations and rights requests relies on Article 6(1)(c).
Please do not send unnecessary identity documents, health information, sensitive data or information about other people.
Form protection and statistics
This website does not currently load Cloudflare Turnstile or optional browser-based Cloudflare Web Analytics. There is no analytics consent or withdrawal control because optional browser analytics is not connected.
3. Cookies and browser storage
We do not use advertising pixels or create advertising profiles of visitors.
Where the bookmark feature is available, it stores selected page paths in your browser’s localStorage after your action. These records are not sent to us and remain until removed or browser site data is cleared. An existing theme preference may also be read from localStorage where applicable. You can clear local preferences using browser settings.
Cloudflare security cookies depend on enabled protection features. Their functions and lifetimes are described in the Cloudflare cookie documentation.
The current website does not set analytics cookies or store an analytics-consent choice. Necessary delivery and security operations are separate from optional audience measurement.
4. Recipients and international processing
Where Cloudflare, Inc., United States, provides hosting, content delivery or security, it acts as a processor when processing on the controller’s instructions and may act as an independent controller for certain provider purposes. The website currently does not submit form entries or attachments to a delivery service.
Email correspondence is processed by the email services used by the sender and recipient. Access to enquiries is limited to what is needed to handle them. Information may be disclosed to competent authorities where legally justified. We do not sell personal data or disclose it for third-party advertising.
Providers may process data outside the EEA, including in the United States. Such transfers must meet applicable GDPR requirements, which may involve an applicable adequacy decision or EU standard contractual clauses and necessary additional safeguards. Cloudflare describes its terms in its Data Processing Addendum. Contact us for information about safeguards applicable to your data. We do not promise exclusively EU processing.
5. Retention and security
Correspondence and attachments are retained for as long as necessary to consider the enquiry, respond and continue the discussion. Retention depends on whether the discussion has concluded, an ongoing project or relationship exists, applicable obligations, and the need to protect rights in a specific dispute. Information no longer required for these purposes is subject to deletion. Contractual and accounting records have separate applicable retention requirements.
Deleting correspondence does not necessarily immediately remove every provider technical copy; processing and deletion of such copies depend on the relevant service terms.
Provider technical-data retention depends on the services, settings and terms used. We do not claim a universal log-retention period.
We use proportionate safeguards such as restricted access and protected connections. Absolute security or instantaneous removal of every backup cannot be guaranteed.
6. Your rights
Where GDPR conditions apply, you may request access, rectification, erasure, restriction or portability, and object to legitimate-interest processing. Where consent is the basis, you may withdraw it without affecting the lawfulness of previous processing. Rights are subject to legal conditions and exceptions.
Contact contact@sideeffects.studio. We respond without undue delay, normally within one month. Where necessary, an extension of up to two further months is possible, with notice and reasons during the first month. We may request proportionate information to confirm identity.
You may complain to the authority in your habitual residence, workplace or place of alleged infringement. Bulgaria’s authority is the Commission for Personal Data Protection (CPDP), 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592. See its complaint procedure; some electronic methods require a qualified electronic signature.
7. External services and decisions
External links, including Share actions where available, open third-party services governed by their own policies. We do not make solely automated decisions about visitors producing legal or similarly significant effects, or use marketing profiling. Security systems may automatically restrict suspicious requests.
8. Changes
We update this policy when services or processing change. The current version and date appear here. We provide additional notice or request consent where required.