TONLART / UPDATED 04 OCTOBER 2026

PRIVACY
& COOKIES.

This notice explains what information is processed when you visit tonlart.com or contact TonlART, why it is processed, and the choices you have. It describes how the website works today.

At a glance

Who is responsible

This website is operated by TonlART, an independent visual studio (“TonlART”, “we”, “us”). TonlART is responsible for the personal data described in this notice. For any privacy question or request, write to contact@tonlart.com.

Information you choose to send us

If you contact us by email, we receive your email address, your name if you include it, and anything you write or attach, such as project details. We use this information to reply, to discuss and prepare a possible project, and to deliver work you commission.

We rely on taking steps at your request before entering into a contract, or on performing a contract with you (Article 6(1)(b) GDPR), and on our legitimate interest in responding to enquiries (Article 6(1)(f) GDPR). Please do not send sensitive information that is not needed for your enquiry.

Our email service is provided by Zoho through its EU service (Zoho Mail, zoho.eu), which processes our correspondence on our behalf.

Technical data when you visit

To load any web page, your browser automatically sends technical information: your IP address, the page or file requested, the date and time, and browser and device details (user agent). This is needed to deliver the website and keep it secure.

The website is hosted and delivered by Cloudflare, which also protects it against abuse and attacks. Cloudflare processes this request data to deliver and secure the site, as described in the Cloudflare Privacy Policy.

We do not run our own server logs or visitor analytics. Cloudflare’s dashboard may show us aggregated traffic statistics and security event information, which can include the IP address of a request that was blocked or challenged. We use this only to operate and protect the website, based on our legitimate interest in providing a secure, working website (Article 6(1)(f) GDPR).

Cookies and browser storage

The TonlART website does not set cookies and does not use local storage, session storage, IndexedDB or fingerprinting. Because no analytics, advertising or other non-essential cookies are used, there is no cookie banner to accept or reject.

In some situations, such as an automated security check, Cloudflare may set a strictly necessary security cookie to tell legitimate visitors apart from automated traffic. These cookies are not used for analytics or advertising. See Cloudflare’s cookie documentation. You can view and delete cookies in your browser settings at any time.

If we ever introduce analytics or other non-essential cookies, they will stay off until you consent, and this page will be updated first.

Films, fonts and external links

Films and images are served from tonlart.com. No YouTube, Vimeo or other third-party player is embedded, and the site uses fonts already installed on your device rather than loading web fonts.

Links to Instagram and to email open only when you select them. Once you leave this website, the privacy terms of that service apply. Our pages are configured not to pass on the address of the page you were viewing (the referrer) when you follow a link.

Sharing your information

We do not sell or rent personal data and do not share it for advertising. We share it only with the service providers named above (Cloudflare for hosting, delivery and security; Zoho for email), with people or companies you ask us to involve in a project, or where the law requires it.

International transfers

Cloudflare operates a global network, so request data may be processed outside the European Economic Area, including in the United States. Cloudflare states that it relies on recognised safeguards for these transfers, including the EU–U.S. Data Privacy Framework and the European Commission’s Standard Contractual Clauses. Our email account uses Zoho’s EU service. Each provider’s privacy policy has further details.

How long we keep information

We keep emails for as long as needed to answer your enquiry and to handle any resulting project. After that, we keep them only where the law requires it, for example for accounting and tax records, or where they are needed to establish or defend legal claims. Technical request data is retained by Cloudflare under its own policies; we do not keep a separate copy.

Your rights

Under the GDPR and other applicable data protection law, you can ask us to:

To make a request, email contact@tonlart.com. We may need to confirm your identity first. We will reply within one month, as the GDPR requires, or tell you within that time if we need longer. You can also complain to a data protection supervisory authority, either where you live or work or, in Romania, the National Supervisory Authority for Personal Data Processing (ANSPDCP).

Security

The website uses encrypted HTTPS connections and security headers, including a content security policy that blocks third-party scripts. No method of transmitting or storing information is completely secure, but we take reasonable steps to protect the information we handle.

Changes to this notice

We will update this page when the website or our practices change. The date at the top shows the latest update.

Contact

TonlART — contact@tonlart.com