Privacy Policy

Last updated: 2025-10-27

1) Who I am (Controller)

Controller: Natural person (individual), operating WaveFibs as a personal, non-commercial project.
Contact: [email protected]
Location: Varna, Bulgaria (no registered company).
Scope: wavefibs.com and the public pages listed below.

I provide transparency as required by GDPR Articles 12–14. I am a natural person “controller” for any processing I perform via this site. :contentReference[oaicite:0]{index=0}

2) What this policy covers

This notice explains how personal data may be collected and used when you visit wavefibs.com, read content, or contact me. It also explains cookies/consent (ePrivacy). :contentReference[oaicite:1]{index=1}

3) What I collect (at launch)

  • Security/server logs (IP, timestamp, URL, user-agent) to keep the site safe and diagnose issues.
  • Cookie consent records from the banner (choice, timestamp, anonymous token).
  • Analytics (optional, only if you consent): GA4 pseudonymous usage data (pages, events, device).
  • Pixels/embeds (optional, only if you consent): Meta Pixel; TradingView/YouTube may set cookies when loaded.
  • Emails you send to me ([email protected]).
  • No user accounts, no paid subscriptions, no premium access.
  • Donations (optional): handled by third-party processors; I don’t see your card details.

4) Why I process data (lawful bases)

  • Site security & reliability (server/CDN/WAF logs): legitimate interests (GDPR Art. 6(1)(f)).
  • Analytics, pixels, embeds (non-essential): consent (GDPR Art. 6(1)(a)); they load only after you agree. You can withdraw anytime. :contentReference[oaicite:2]{index=2}
  • Communications (replying to your emails): legitimate interests (Art. 6(1)(f)). :contentReference[oaicite:3]{index=3}
  • Donations: donation is voluntary and not consideration for a service. Any minimal records I keep (e.g., to acknowledge a donation or for tax where applicable) are based on legitimate interests and/or legal obligation (if applicable). Payment data is processed by the donation provider as a separate controller.

5) Details by purpose

  • A. Security & operations — server/CDN/WAF logs kept up to 30 days to defend against abuse and ensure availability.
  • B. Consent records — stored up to 2 years to evidence cookie choices. :contentReference[oaicite:4]{index=4}
  • C. Analytics (consent-based) — GA4 standard events with IP anonymization and a 14-month retention setting.
  • D. Pixels/embeds (consent-based) — Meta Pixel; TradingView/YouTube embeds load only after consent via the CMP.
  • E. Communications — emails kept up to 24 months for audit trail and follow-ups.

6) Cookies & consent

I use a Consent Management Platform (CMP). Non-essential cookies/pixels (analytics, ads, embeds) are set only after consent. You can change your choice anytime from the footer’s Cookie settings. :contentReference[oaicite:5]{index=5}

7) Third-party tools & recipients

  • Hosting: Hostinger (UK data centre).
  • CDN/WAF: Cloudflare (proxied).
  • Analytics: Google Analytics 4 (loads only with consent).
  • Advertising pixel: Meta Pixel (loads only with consent).
  • Embeds: TradingView charts; YouTube videos (both gated by consent).
  • Donation processors (if enabled): e.g., PayPal/Stripe/crypto gateways act as their own controllers for payment data.

8) International transfers

  • UK hosting is permitted under the EU’s adequacy decision for the UK.
  • Global providers may process outside the EEA; where they do, they rely on Standard Contractual Clauses and related safeguards.

9) Community & moderation

WaveFibs content is free and educational. I strive to follow transparent “notice-and-action” and give brief reasons for significant moderation decisions (aligned with the DSA spirit). :contentReference[oaicite:6]{index=6}

10) AI/automation

I do not send personal data to AI models and do not store personal data in automation logs. If this changes, I will request consent where required and update this notice before activation.

11) Retention

  • Server/CDN/WAF logs: up to 30 days
  • Analytics (GA4): 14 months
  • Consent records: up to 2 years
  • Support emails: up to 24 months
  • Donation acknowledgements (minimal): as short as possible, or longer only if a legal obligation applies

12) Your rights

You may request access, rectification, erasure, restriction, portability, and object to processing, and you may withdraw consent at any time. Email [email protected]. I reply within 30 days and may verify identity to protect your data. :contentReference[oaicite:7]{index=7}

13) Age limit

This site is intended for users 18+. I do not knowingly collect data from minors.

14) Security

HTTPS/TLS, Cloudflare WAF, access controls, and regular patching of WordPress/server components.

15) Complaints

You may complain to the Bulgarian Commission for Personal Data Protection (CPDP) or your local EU authority. Please contact me first so I can help.

16) Changes & versioning

I may update this policy as the site evolves (e.g., if donation methods are enabled). I will post updates here and change the date above.

Pages covered

  • Homepage, Blog, Crypto Technical Analysis, Real-Time Alerts (BTC/ETH/SOL/ADA/XRP/DOGE), News & Insights, Telegram links.

Cross-links

Footnotes
GDPR = Regulation (EU) 2016/679; key articles used: Art. 6 (legal bases), Arts. 12–14 (transparency), Arts. 15–22 (data subject rights).
ePrivacy Directive (cookies) as implemented via consent before non-essential cookies.
UK is covered by an EU adequacy decision; other extra-EEA flows rely on SCCs.