Privacy Policy
Last updated: 4/14/2026
Who we are
This site (kiril.dev / kirilurbonas.com) is operated by Kiril Urbonas, a freelance software developer based in Europe ("we," "us," "our"). We are the data controller for the personal data collected through this website. For any privacy-related questions, contact us at kiril.u@gmail.com.
Information we collect
We collect personal data in the following ways:
- Visitor analytics (with consent only): If you accept analytics cookies, we record page views, approximate visit time, referrer URL, IP address, and country. This data is stored in our database and used to understand how the site is used. Visitor tracking only activates after you consent via the cookie banner.
- Chat widget: If you use the live chat, we store your email address (which you provide voluntarily) and your messages so we can reply. A session cookie links you to the same conversation.
- Contact form: When you submit the contact form, we store your name, email, message, project type, and any UTM campaign parameters from the URL. You must check the privacy consent box before submitting.
- Technical data: Our hosting provider (Vercel) may log your IP address, browser type, and device information for security and performance purposes. We do not use this to personally identify you.
- Newsletter: If you subscribe to our newsletter, we store your email address. You must check the privacy consent box before subscribing. We send periodic emails about web development and business insights. You can unsubscribe at any time by contacting us.
Legal basis for processing
We process your data based on: (a) your explicit consent, given via cookie banner checkboxes and form privacy consent checkboxes; (b) our legitimate interest in responding to your enquiries and managing our business; (c) contractual necessity when we enter into a project agreement with you. You may withdraw consent at any time without affecting the lawfulness of processing based on consent before withdrawal.
Automated decision-making
When you submit the contact form, we use an AI service (Anthropic Claude) to automatically assess the quality and relevance of your enquiry on a scale of 1–10. This helps us prioritise responses. The score is used internally only and does not affect your ability to contact us or receive a reply. You have the right to request human review of any automated assessment by contacting us.
Cookies we use
We use a cookie consent banner that appears on your first visit. You can choose "Accept all" (necessary + analytics) or "Necessary only." Your choice is stored for one year. You can change it at any time via the "Manage cookie preferences" link in the footer.
Necessary cookies (always active): cookie_consent (stores your cookie preference, 1 year), chat session cookie (links you to your conversation, session only). Analytics cookies (only with consent): visitor_id and v_anon (anonymous visitor tracking, 1 year), Google Analytics _ga and _gid cookies (traffic analysis, up to 2 years). We do not use advertising or marketing cookies.
Third-party service providers
We share personal data with the following service providers, who process it on our behalf under appropriate data processing agreements:
- Vercel Inc. (USA) — Website hosting, edge delivery, and Vercel Analytics. Processes: page views, IP addresses, technical data.
- Resend Inc. (USA) — Transactional email delivery. Processes: recipient email addresses, email content.
- Anthropic PBC (USA) — AI-powered lead quality assessment. Processes: name, email, message content from contact form submissions.
- Google LLC (USA) — Google Analytics 4 for website traffic analysis (only with consent). Processes: anonymised page views, session data.
- EmailJS (EU) — Contact form email notifications. Processes: name, email, message.
- Stripe Inc. (USA) — Payment processing for invoices. Processes: payment details, email address.
International data transfers
Some of our service providers are based in the United States. We rely on Standard Contractual Clauses (SCCs) approved by the European Commission, or the provider's own GDPR-compliant data processing addendum, to ensure your data receives an adequate level of protection when transferred outside the EU/EEA. Israel is recognised by the European Commission as providing an adequate level of data protection.
How long we keep data
We retain data only as long as necessary for the purposes described above. Specifically: visitor analytics data is automatically deleted after 90 days. Chat messages and conversations are deleted after 180 days. Contact form submissions are retained for 1 year. Newsletter subscriber data is retained until you unsubscribe. Project and invoice data is retained for 7 years for legal and accounting purposes. You can request earlier deletion at any time (see Your Rights below).
Your rights
Under the GDPR and applicable privacy laws, you have the right to: access a copy of your personal data; rectify inaccurate data; erase your data ("right to be forgotten"); restrict or object to processing; data portability (receive your data in a structured format); withdraw consent at any time; lodge a complaint with your local data protection authority. To exercise any of these rights, email us at kiril.u@gmail.com. We will respond within 30 days.
Contact
For privacy-related requests or questions, email us at kiril.u@gmail.com.