Privacy Policy
Last updated: June 2026
MariNoa ("we", "us") is committed to protecting personal data in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR"). This policy explains how we process personal data when you visit this website or contact us.
1. Data controller
MariNoa, established in the European Union, is the controller for personal data processed via this website. You can reach us at contact.marinoa@gmail.com.
2. What data we process and why
Contact and enquiry data
When you submit our contact form or email us, we process the data you provide (name, work email, company, message content) to respond to your enquiry and prepare proposals. Legal basis: Article 6(1)(b) GDPR (pre-contractual steps) and Article 6(1)(a) (consent), where given.
Technical data
Our hosting infrastructure processes IP addresses and request metadata in server logs as technically necessary to deliver the site securely. Legal basis: Article 6(1)(f) GDPR (legitimate interest in operating a secure website). This website does not use tracking cookies or third-party analytics.
Client project data
When we annotate data on behalf of clients, we act as a processor under Article 28 GDPR and process such data solely on the client's documented instructions, under a Data Processing Agreement. The client remains the controller.
3. Data residency
All personal data we process is stored and processed on infrastructure located within the European Economic Area. We do not transfer personal data to third countries.
4. Retention
Enquiry data is retained for as long as needed to handle your request and for up to 24 months thereafter, unless a business relationship is established. Server logs are retained for a maximum of 30 days. Client project data is deleted at project end as agreed in the applicable DPA.
5. Recipients
We do not sell or share personal data with third parties for marketing. Data may be processed by EEA-based hosting providers acting as our processors under Article 28 agreements.
6. Your rights
Under the GDPR you have the right to access, rectify and erase your personal data, restrict or object to its processing, receive your data in a portable format, and withdraw consent at any time with effect for the future (Articles 15–21 GDPR). To exercise these rights, contact contact.marinoa@gmail.com. You also have the right to lodge a complaint with your competent supervisory authority (Article 77 GDPR).
7. Security
We apply appropriate technical and organizational measures (Article 32 GDPR), including encryption in transit and at rest, role-based access control, and access logging.
8. Changes
We may update this policy as our services or legal requirements evolve. The current version is always available on this page.