Privacy Policy
Last updated: 2025-10-27
1) Who I am (Controller)
Controller: Natural person (individual), operating WaveFibs as a personal, non-commercial project.
Contact: [email protected]
Location: Varna, Bulgaria (no registered company).
Scope: wavefibs.com and the public pages listed below.
I provide transparency as required by GDPR Articles 12–14. I am a natural person “controller” for any processing I perform via this site. :contentReference[oaicite:0]{index=0}
2) What this policy covers
This notice explains how personal data may be collected and used when you visit wavefibs.com, read content, or contact me. It also explains cookies/consent (ePrivacy). :contentReference[oaicite:1]{index=1}
3) What I collect (at launch)
- Security/server logs (IP, timestamp, URL, user-agent) to keep the site safe and diagnose issues.
- Cookie consent records from the banner (choice, timestamp, anonymous token).
- Analytics (optional, only if you consent): GA4 pseudonymous usage data (pages, events, device).
- Pixels/embeds (optional, only if you consent): Meta Pixel; TradingView/YouTube may set cookies when loaded.
- Emails you send to me ([email protected]).
- No user accounts, no paid subscriptions, no premium access.
- Donations (optional): handled by third-party processors; I don’t see your card details.
4) Why I process data (lawful bases)
- Site security & reliability (server/CDN/WAF logs): legitimate interests (GDPR Art. 6(1)(f)).
- Analytics, pixels, embeds (non-essential): consent (GDPR Art. 6(1)(a)); they load only after you agree. You can withdraw anytime. :contentReference[oaicite:2]{index=2}
- Communications (replying to your emails): legitimate interests (Art. 6(1)(f)). :contentReference[oaicite:3]{index=3}
- Donations: donation is voluntary and not consideration for a service. Any minimal records I keep (e.g., to acknowledge a donation or for tax where applicable) are based on legitimate interests and/or legal obligation (if applicable). Payment data is processed by the donation provider as a separate controller.
5) Details by purpose
- A. Security & operations — server/CDN/WAF logs kept up to 30 days to defend against abuse and ensure availability.
- B. Consent records — stored up to 2 years to evidence cookie choices. :contentReference[oaicite:4]{index=4}
- C. Analytics (consent-based) — GA4 standard events with IP anonymization and a 14-month retention setting.
- D. Pixels/embeds (consent-based) — Meta Pixel; TradingView/YouTube embeds load only after consent via the CMP.
- E. Communications — emails kept up to 24 months for audit trail and follow-ups.
6) Cookies & consent
I use a Consent Management Platform (CMP). Non-essential cookies/pixels (analytics, ads, embeds) are set only after consent. You can change your choice anytime from the footer’s Cookie settings. :contentReference[oaicite:5]{index=5}
7) Third-party tools & recipients
- Hosting: Hostinger (UK data centre).
- CDN/WAF: Cloudflare (proxied).
- Analytics: Google Analytics 4 (loads only with consent).
- Advertising pixel: Meta Pixel (loads only with consent).
- Embeds: TradingView charts; YouTube videos (both gated by consent).
- Donation processors (if enabled): e.g., PayPal/Stripe/crypto gateways act as their own controllers for payment data.
8) International transfers
- UK hosting is permitted under the EU’s adequacy decision for the UK.
- Global providers may process outside the EEA; where they do, they rely on Standard Contractual Clauses and related safeguards.
9) Community & moderation
WaveFibs content is free and educational. I strive to follow transparent “notice-and-action” and give brief reasons for significant moderation decisions (aligned with the DSA spirit). :contentReference[oaicite:6]{index=6}
10) AI/automation
I do not send personal data to AI models and do not store personal data in automation logs. If this changes, I will request consent where required and update this notice before activation.
11) Retention
- Server/CDN/WAF logs: up to 30 days
- Analytics (GA4): 14 months
- Consent records: up to 2 years
- Support emails: up to 24 months
- Donation acknowledgements (minimal): as short as possible, or longer only if a legal obligation applies
12) Your rights
You may request access, rectification, erasure, restriction, portability, and object to processing, and you may withdraw consent at any time. Email [email protected]. I reply within 30 days and may verify identity to protect your data. :contentReference[oaicite:7]{index=7}
13) Age limit
This site is intended for users 18+. I do not knowingly collect data from minors.
14) Security
HTTPS/TLS, Cloudflare WAF, access controls, and regular patching of WordPress/server components.
15) Complaints
You may complain to the Bulgarian Commission for Personal Data Protection (CPDP) or your local EU authority. Please contact me first so I can help.
16) Changes & versioning
I may update this policy as the site evolves (e.g., if donation methods are enabled). I will post updates here and change the date above.
Pages covered
- Homepage, Blog, Crypto Technical Analysis, Real-Time Alerts (BTC/ETH/SOL/ADA/XRP/DOGE), News & Insights, Telegram links.
Cross-links
GDPR = Regulation (EU) 2016/679; key articles used: Art. 6 (legal bases), Arts. 12–14 (transparency), Arts. 15–22 (data subject rights).
ePrivacy Directive (cookies) as implemented via consent before non-essential cookies.
UK is covered by an EU adequacy decision; other extra-EEA flows rely on SCCs.
