LEGAL

The Syntonia Signal Method™: Privacy Policy

Protection of personal data · Compliant with the GDPR and Law no. 190/2018

Last updated: 23 August 2026

Please read this policy carefully before providing us with personal data.

1. Introduction and purpose of this policy

The confidentiality and protection of your personal data are of the utmost importance to us. By the very nature of the work involved, a process of self-discovery that entails sharing deeply personal information, the relationship between practitioner and client is fundamentally based on trust. This policy transparently describes how we collect, use, store and protect your personal data.

This policy is drafted in accordance with:

  • Regulation (EU) 2016/679: the General Data Protection Regulation ("GDPR")
  • Law no. 190/2018: on measures implementing the GDPR in Romania
  • Law no. 506/2004: on the processing of personal data and the protection of privacy in the electronic communications sector
  • Government Ordinance no. 13/2024: on information society services
BEFORE YOU CONTINUE. By using the site and/or our services, you confirm that you have read, understood and accepted this policy. If you do not agree with any of its provisions, please do not use the site or the services.

2. Who we are: Identity of the data controller

For the purposes of the GDPR, the controller of personal data is:

  • IONESCU R. ANDREEA PERSOANĂ FIZICĂ AUTORIZATĂ
  • Bulevardul Bucureștii Noi, nr. 136, parter, ap. 5, Sector 1, București
  • 54849790
  • F2026029768002
  • +40 749 071 582
  • contact@andreeaionescu.ro

For any questions, complaints or to exercise your rights under the GDPR, you may contact us through any of the channels above. We will respond to requests within 30 calendar days, in accordance with the GDPR.

3. Legal grounds for processing data

We process your personal data solely on valid legal grounds:

3.1. Consent (Art. 6(1)(a) GDPR)

When you subscribed to the newsletter, completed the contact form, completed the inner clarity test on the site, or provided us with information for a counselling session, your consent is the basis for processing. Consent may be withdrawn at any time.

3.2. Performance of a contract (Art. 6(1)(b) GDPR)

For clients who have contracted our services (the 1:1 Session or the 8-Session Program), data processing is necessary for the performance of the service contract.

3.3. Legal obligations (Art. 6(1)(c) GDPR)

Certain data (e.g. invoices, accounting documents) are processed in order to meet our legal obligations regarding accounting, tax and archiving records.

3.4. Legitimate interest (Art. 6(1)(f) GDPR)

In certain cases (e.g. site security, anonymous traffic analysis, direct marketing to existing clients), processing is based on our legitimate interest, assessed against your rights.

3.5. Special categories of data (Art. 9 GDPR)

Please note: Our Method involves discussions about deeply emotional and personal matters. Such data may constitute "special categories of data" under the GDPR and are processed solely on the basis of your explicit consent, documented in writing, and with additional security measures.

4. What data we collect

We collect only the data strictly necessary to provide the services you request ("the data minimisation principle"). Depending on how you interact with us, we may collect:

4.1. Identification and contact data

  • First and last name
  • E-mail address
  • Telephone number
  • Postal address (only where necessary for invoicing)
  • Location / city (to adapt the time zone of sessions)

4.2. Professional and contextual data

  • Profession, industry, current role
  • Professional and personal objectives
  • Information about your personal context, relevant to coaching

4.3. Data generated during sessions

  • Session notes (answers to exercises, reflections, signals identified)
  • Assessment results (signal scores, the Talent Constellation, the Identity Emission)
  • Written materials you submit as part of the pre-session preparation
  • Interviews with the "accidental experts" (5 people from your life)
  • Personal reflections on sensitive topics (childhood, criticism received, values, emotions)

4.4. Technical and browsing data

  • IP address (stored in encrypted / hashed form, solely for the forms' anti-spam filter)
  • Browser type and version
  • Operating system
  • Pages visited and time spent
  • The source from which you reached the site
  • Cookies and similar technologies (see section 10)

4.5. Payment data

We do NOT directly store bank card data. Card payments are processed through Stripe, an external provider compliant with the PCI-DSS standard; we also accept payment by bank transfer. We store only the payment confirmation, the amount and the transaction date.

4.6. Special categories of data (GDPR, Art. 9)

During sessions, we may come to discuss matters falling within the special categories provided for by the GDPR:

  • Data concerning mental and emotional health
  • Philosophical or spiritual beliefs
  • Data about sexual life or sexual orientation (if relevant to the discussion)
  • Racial or ethnic origin
  • Political beliefs

Such data are processed solely on the basis of your explicit consent and are protected with additional technical and organisational measures.

4.7. Data from the Inner Clarity Test

When you begin the Inner Clarity Test on the site, your answers are saved as you progress, under an automatically generated identifier that contains neither your name nor your email address. We save the language in which you took the test, the options you chose, the question you reached, whether you completed the test, the resulting profile, and the page you arrived from.

The purpose is to understand at which question the test becomes difficult to complete, so that we can improve it. The legal basis is our legitimate interest in improving the service, under Article 6(1)(f) GDPR.

If at the end you choose to receive your result and provide your first name and email address, these are processed separately, through Brevo, on the basis of your consent. The record of your answers only receives a marker that the test was completed: it contains none of your contact details and is not linked to them.

5. The purposes for which we use the data

Your data are used solely for the purposes for which you provided them and on a valid legal ground:

5.1. Providing the services

  • Delivering coaching sessions (the 1:1 Session or the 8-Session Program)
  • Adapting the method to your personal context
  • Generating the deliverables (the Identity Emission, the Talent Constellation, post-session reports)
  • Communication regarding scheduling, rescheduling, and the 30- and 90-day follow-ups

5.2. Contractual communication

  • Sending pre-session and post-session materials
  • Notifications regarding the program and any changes
  • Invoicing and accounting records

5.3. Marketing communication (optional, with consent)

  • Newsletter with free content about the method
  • Announcements about new workshops or programs
  • Testimonials (only with the client's explicit consent, see section 8)

5.4. Improving the services

  • Anonymised analysis of feedback
  • Developing the methodology (without identifying individual persons)

5.5. Legal obligations

  • Archiving invoices in accordance with the Fiscal Code (10 years)
  • Responding to requests from competent authorities

6. To whom we disclose data: Transfers to third parties

Your personal data are NOT sold, rented or disclosed to third parties for marketing purposes. They may be transmitted solely to the following categories of recipients, strictly as necessary to provide the services:

6.1. Service providers (processors under the GDPR)

  • Video-conferencing platforms: Zoom, Google Meet or a similar platform, for conducting online sessions. The scheduling of sessions is carried out through the Cal.eu platform (cal.eu), which processes the name, e-mail address and booking details. Sessions must NOT be recorded without explicit bilateral agreement.
  • E-mail provider: Zoho Mail: the e-mail service used for the contact mailbox (contact@andreeaionescu.ro) and for communication with clients.
  • Payment processors: Stripe: a card payment processor, compliant with the PCI-DSS standard. We also accept payment by bank transfer.
  • Storage: Session notes and sensitive materials are kept on the practitioner's personal laptop and in Notion (or other similar secure applications). Data submitted through the site's forms (contact and newsletter), as well as the answers and progress from the Inner Clarity Test, are stored in the Supabase database.
  • E-mail services: Brevo: for managing the newsletter, sending automated transactional e-mails and the e-mail with the result of the clarity test completed on the site.
  • Video hosting: Vimeo, Inc., based in the United States of America, for hosting and playing back audio-video materials, namely the meditations available on the site. Vimeo processes your IP address and technical information about your device when you play a piece of content.
  • Newsletter and publishing platform: Substack, Inc. (United States of America): the platform hosting and distributing our newsletter. Substack processes your email address, your name (where provided) and subscription-related usage data: opens, unsubscribes, and free or paid subscriber status. Substack acts as a data processor under its Publisher Agreement and the data processing terms included therein. You may unsubscribe at any time using the link included in every email you receive.
  • Accountant / chartered accountant: for meeting tax obligations.
  • Web hosting providers: for the operation of the site.

With all of these providers we have, or will conclude, data processing agreements (DPA, Data Processing Agreement) in accordance with Art. 28 GDPR.

6.2. Public authorities

We may disclose data to public authorities only when legally required to do so (e.g. investigative bodies, courts, ANSPDCP).

6.3. International data transfers

Some of our providers may process data outside the European Economic Area: depending on the project region selected, Supabase, as well as Substack, Inc. and Vimeo, Inc., based in the United States of America. These transfers are protected through:

  • Standard contractual clauses approved by the European Commission
  • Adequacy decisions (for countries with protection similar to the GDPR)
  • International certifications (ISO 27001, SOC 2)

In the case of Substack and Vimeo, the transfer is covered by the Standard Contractual Clauses approved by the European Commission and included in the corresponding data processing agreements, under which we act as the controller and the provider as the processor.

7. How long we keep the data

We keep your data only for as long as strictly necessary for the purposes of processing:

Type of dataRetention period
Contact data for users who have not contracted servicesMaximum 12 months from the last interaction
Data on active clientsDuration of the contractual relationship + 3 years (for follow-up and re-use of services)
Session notes and generated materials3 years from the end of the program, then deletion or anonymisation
Invoices and accounting documents10 years (legal obligation, the Fiscal Code)
Newsletter dataUntil consent is withdrawn
Answers and progress from the Inner Clarity Test24 months from completion, then deletion or anonymisation
Technical data and cookiesMaximum 24 months (except those strictly necessary)
Testimonials published with consentUntil consent is withdrawn

After the periods above expire, the data are either permanently deleted or anonymised (processed so that the person can no longer be identified).

8. Your rights under the GDPR

As a data subject, you have the following rights in relation to personal data:

8.1. The right to be informed (Art. 13-14 GDPR)

You have the right to receive clear and accessible information about how your data are processed these details are provided in this very policy.

8.2. The right of access (Art. 15 GDPR)

You have the right to obtain confirmation that we process data about you and to receive a copy of that data.

8.3. The right to rectification (Art. 16 GDPR)

You may request the correction of inaccurate data or the completion of incomplete data.

8.4. The right to erasure / "the right to be forgotten" (Art. 17 GDPR)

You may request the deletion of data when:

  • The data are no longer necessary for the purposes of processing
  • You have withdrawn your consent and there is no other legal ground
  • You object to the processing and there are no overriding legitimate grounds
  • The data have been processed unlawfully

Note: Certain data (e.g. invoices) cannot be deleted before the legal archiving period expires.

8.5. The right to restriction of processing (Art. 18 GDPR)

You may ask us to temporarily restrict processing under certain conditions (e.g. when you contest the accuracy of the data).

8.6. The right to data portability (Art. 20 GDPR)

You have the right to receive the data you provided in a structured, commonly used and machine-readable format (e.g. JSON, CSV) and to transfer it to another controller.

8.7. The right to object (Art. 21 GDPR)

You may object to the processing of data for direct marketing purposes or where processing is based on legitimate interest.

8.8. The right to withdraw consent

Where processing is based on consent, you may withdraw it at any time, without affecting the lawfulness of prior processing.

8.9. The right not to be subject to automated decisions (Art. 22 GDPR)

We do not make significant automated decisions about you based solely on automated processing.

8.10. The right to lodge a complaint

You may lodge a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP):

ANSPDCP
B-dul G-ral. Gheorghe Magheru no. 28-30, Sector 1, Bucharest
Telephone: +40.318.059.211 / +40.318.059.212
E-mail: anspdcp@dataprotection.ro
Website: www.dataprotection.ro

8.11. How to exercise these rights

Any request to exercise your rights may be sent to our e-mail address specified in section 2. We will respond within 30 calendar days (with the possibility of an extension by a further 60 days in complex cases, with notice). Exercising these rights is free of charge. In exceptional cases (manifestly unfounded or excessive requests), we reserve the right to charge a reasonable fee or to refuse the request, in accordance with the GDPR.

9. Confidentiality of information from sessions

Our commitment to confidentiality goes beyond legal requirements. Nothing you share in sessions will be disclosed without your explicit consent, save for the exceptions strictly limited by law.

9.1. Basic principles

  • Total confidentiality: All information shared during sessions is strictly confidential.
  • No disclosure: We do not discuss clients with third parties and we do not use in public communication any example that would allow a person to be identified.
  • Secure storage: Session notes are kept on the practitioner's personal laptop and in Notion, encrypted and accessible only to the practitioner.
  • Anonymisation: We sometimes use elements from practice in articles, in educational materials and in public communication about the method. Each time, they are anonymised: no names, no exact occupation and no details that would allow a person to be identified.

9.2. Mandatory exceptions to confidentiality

Confidentiality may be excepted ONLY in situations strictly provided for by law:

  • Imminent and serious danger to your life or the life of others
  • Well-founded suspicion of abuse of a minor
  • An official request from a judicial authority
  • A valid court order

In such cases, we will inform you (where legally possible) before any disclosure.

9.3. Testimonials and case studies

Any testimonial, case study or example that could allow you to be identified requires your written and explicit consent. You may withdraw this consent at any time. Even with consent, we may choose to anonymise the details. Fully anonymised examples, from which no person can be recognised, do not fall into this category.

10. Cookies and similar technologies

Our site uses cookies and similar technologies to ensure proper functioning and to improve the browsing experience.

10.1. Types of cookies

  • Strictly necessary: For the operation of the site (cannot be disabled).
  • Functional: To remember your preferences (language, time zone).
  • Analytics: To understand how the site is used. We use Umami: a web analytics tool that does not use cookies and does not collect identifiable personal data. Under GDPR, this analysis does not require explicit consent, because it uses no cookies and processes no identifying data. It is on by default, and if you prefer not to be included in the statistics, you can opt out at any time from the cookie settings.
  • Marketing: The site does NOT use marketing or advertising cookies.

10.2. Detailed list of technologies used

In accordance with Art. 13 GDPR and the ePrivacy Directive requirements, below is the complete list of cookies and local storage keys used by our site:

NameTypePurposeDurationCategory
cookie-consent-v2localStorageStores your cookie consent choice (accepted/refused per category).12 monthsStrictly necessary
localelocalStorageStores your preferred language (RO/EN) so you don't have to reselect it each visit.Persistent (until manually cleared)Functional
clarity_quest_seenlocalStorageRemembers that you have already seen the intro prompt on the home page, so it isn't shown again.Persistent (until manually cleared)Functional
player.vimeo.comThird partyCookies set by the Vimeo video player when you play a meditation, for playback preferences and viewing statistics.According to Vimeo's policyThird party
cal.euThird partyCookies set by Cal.com when the booking calendar is opened, for the scheduling and payment flow to work.According to Cal.com's policyThird party
prima_acordare_unlockedLocal storage, first partyRemembers that you have unlocked the Prima acordare™ meditation, so your details are not requested again.Until manually cleared from the browserFunctional
ict_session_idsessionStorageLinks the answers given in the test to the current session, so that progress is not lost if you reload the page. Contains no identifying data.Until the browser tab is closedStrictly necessary
UmamiNo cookies / no localStorageAggregated traffic statistics (pages visited, referrer), with no personal identifiers. On by default, with the option to opt out.Nothing stored in the browserAnalytics

The site does NOT use cookies or technologies for marketing, advertising, retargeting, social media tracking (Facebook Pixel, Google Ads, TikTok Pixel etc.), heatmaps (Hotjar, Microsoft Clarity) or live chat with tracking (Intercom, Drift).

10.3. Managing cookies

On your first visit, you will receive a banner through which you can grant or refuse consent for non-essential cookies. You may change your preferences at any time by accessing your browser settings or the "Cookie settings" link in the site footer.

11. Data security

We implement appropriate technical and organisational measures to protect your data against loss, misuse, unauthorised access, disclosure, alteration or destruction:

11.1. Technical measures

  • SSL/TLS encryption for all data transfers on the site
  • Encryption at rest for sensitive files
  • Two-factor authentication for access to work platforms
  • Strong, periodically rotated passwords
  • Regular software updates
  • Encrypted backups, stored separately
  • Active antivirus and firewall

11.2. Organisational measures

  • Access to data exclusively by the practitioner-controller
  • Continuous training in the field of data protection
  • Security incident response procedures
  • Periodic review of security measures

11.3. Notification of security breaches

In the event of a security breach that may affect your data, we will:

  • Notify ANSPDCP within 72 hours of discovery (in accordance with Art. 33 GDPR)
  • Inform you directly if there is a significant risk to your rights
  • Document the incident and take measures to limit the damage

12. Data of minors

Our services are intended solely for persons aged at least 18. We do not knowingly collect data from minors. If we discover that we have collected data from a minor without the consent of a parent/guardian, we will delete it immediately.

If you are a parent and believe your child has provided us with data, please contact us at the e-mail address in section 2.

13. Changes to this policy

We reserve the right to amend this policy to reflect changes in our practices or in applicable legislation. Any change will be published on this page with a new update date at the top.

In the event of significant changes, we will notify you by e-mail (if we have that information) or through a visible notice on the site, at least 30 days before it takes effect.

14. Contact

For any questions, concerns or requests regarding the protection of personal data, you may contact us at:

  • contact@andreeaionescu.ro
  • Bulevardul Bucureștii Noi, nr. 136, parter, ap. 5, Sector 1, București
  • +40 749 071 582

Thank you for the trust you have placed in us.

THE SYNTONIA SIGNAL METHOD™ / METODA SINTONIEI™
Privacy Policy · Version 1.5