Legal document
Privacy Policy
Last updated: September 15, 2026
BuiltForLocal respects your privacy and is committed to protecting your personal data. This Privacy Policy explains what information we collect, how we use and safeguard it, and what rights and choices you have when visiting our website or communicating with us.
Data Controller & Operator Identity
BuiltForLocal is operated by Maxim Francesco PFA, an authorized sole proprietorship registered in Romania (European Union), who acts as the data controller for personal data processed through this website and related commercial communications.
- Legal entity
- Maxim Francesco PFA
- Legal structure
- Persoană Fizică Autorizată (PFA / Sole Proprietorship registered in Romania, EU)
- Registered address
- Strada Dimitrie Leonida nr. 87, Bloc M3, Ap. 29Piatra-Neamț, Neamț County, 610168Romania (European Union)
- Tax ID (CUI)
- 52564061
- Trade Register No.
- F2025036030001
- Registration date
- September 24, 2025
- Phone
- +40 758 990 675
- Website
- https://builtforlocal.us
For any questions or requests concerning your data and privacy, you can contact us at maaximfrancesco@gmail.com or by phone at +40 758 990 675.
Scope of This Policy
This policy applies to personal data collected through builtforlocal.us, direct email inquiries, and WhatsApp communications initiated with us regarding our website design and management services.
Information We Collect
A. Information Collected Automatically
When you browse our website, our hosting and content delivery infrastructure automatically processes standard technical request logs necessary to deliver the site securely and reliably. This may include:
- Internet Protocol (IP) address
- Browser type, version, and operating system
- Date, time, and duration of requests
- Referring URLs and requested pages/resources
This data is used solely for network transmission, system security, and server diagnostics. We do not use server access logs to build behavioral profiles about individual visitors.
B. Analytics Data (Google Analytics 4 — Consent-Gated)
Google Analytics 4 is loaded only after you provide affirmative consent via our cookie consent banner. If you decline or have not yet made a choice, Google Analytics scripts are not downloaded, and no analytics events or cookies are created.
When analytics is enabled with your consent, data collected may include:
- Pages and sections viewed (e.g., viewing pricing or FAQ sections)
- Aggregate engagement events (e.g., clicking a package button, expanding an FAQ row)
- Device category, screen resolution, and approximate geographic location (country/city level)
- Pseudonymous analytics identifiers and cookies (_ga)
We never send to Google Analytics:
- Your name, email address, or phone number
- Contents of WhatsApp chats or emails
- Any custom text, business briefs, or materials you provide
C. Information You Provide Directly (Inquiries & Project Data)
Our website does not use tracking web forms. When you contact us voluntarily via email or WhatsApp, you provide information such as:
- Your name and business name
- Your email address and phone number
- Details about your services, location, pricing, and project requirements
- Photographs, logos, testimonials, and existing website or social links you wish to include in your build
- Invoicing and billing details upon project approval
D. Cookie Consent Preferences
We store your analytics preference (granted or denied) in your browser's localStorage so we do not display the banner repeatedly. This preference record contains no personal data.
How We Use Your Information
We process your information for the following specific purposes:
- Project Delivery: To communicate with you, draft website proposals, build preview websites, and launch approved projects.
- Customer Support: To respond to questions, provide post-launch support, and handle ongoing maintenance for Managed care clients.
- Invoicing & Accounting: To issue invoices, process payments, and comply with mandatory tax and statutory recordkeeping.
- Website Improvement: To understand aggregated site usage patterns and optimize performance (only with analytics consent).
- Security & Integrity: To detect, prevent, and mitigate security threats, abuse, or unauthorized activity.
Legal Bases for Processing (GDPR)
Where the European General Data Protection Regulation (GDPR) applies to our processing activities, we rely on the following lawful bases:
- Consent (Art. 6(1)(a) GDPR): For the deployment of non-essential analytics cookies and scripts (Google Analytics 4). You may withdraw consent at any time.
- Performance of a Contract / Pre-Contractual Steps (Art. 6(1)(b) GDPR): For processing your inquiries, providing quotes, developing your website preview, and delivering contracted services.
- Legitimate Interests (Art. 6(1)(f) GDPR): For securing our web infrastructure, preventing fraud, and conducting standard direct business communications.
- Legal Obligation (Art. 6(1)(c) GDPR): For maintaining accounting records, invoices, and fulfilling statutory tax obligations.
Third-Party Service Providers
We do not sell, rent, or trade your personal information. We share data only with trusted service providers necessary for operating our business and delivering our services:
- Hosting & CDN Providers: Infrastructure providers that deliver our website assets securely.
- Google Analytics (Google LLC): Web analytics service (active only upon affirmative consent, configured with IP anonymization).
- WhatsApp / Meta Platforms: Messaging platform used when you choose to initiate direct communication via WhatsApp.
- Email Service Providers: Infrastructure used to receive and send business emails.
- Accounting & Tax Authorities: When legally required to comply with statutory fiscal and accounting obligations in Romania.
International Data Transfers
Because our service providers (such as Google or Meta) maintain global server networks, your technical data or communications may be processed outside the European Economic Area (EEA) or your country of residence, including in the United States.
Where transfers from the EEA occur, our service providers utilize recognized transfer mechanisms under applicable data protection laws, such as the EU-U.S. Data Privacy Framework or European Commission Standard Contractual Clauses (SCCs).
Data Retention & Security
We retain personal data only for as long as necessary to fulfill the purposes outlined in this policy:
- Inquiry communications are retained during project discussions and for a reasonable period thereafter to facilitate follow-up.
- Client project files and invoices are retained for the duration required by applicable statutory tax and accounting laws.
- Analytics preferences in localStorage remain until you change them or clear your browser storage.
We employ appropriate technical and organizational measures to safeguard your personal data against unauthorized access, loss, alteration, or disclosure.
Your Privacy Rights (EU / EEA / UK)
Under the GDPR and equivalent European data protection laws, you have the following rights regarding your personal data:
- Right of Access: You may request confirmation and a copy of personal data we hold about you.
- Right to Rectification: You may request correction of inaccurate or incomplete data.
- Right to Erasure ('Right to be Forgotten'): You may request deletion of your data where no overriding legal retention obligation exists.
- Right to Restriction & Objection: You may object to or request restriction of certain processing activities.
- Right to Data Portability: You may request transfer of your data in a structured, commonly used format.
- Right to Withdraw Consent: Where processing is based on consent (such as analytics), you may withdraw it at any time via the Cookie preferences link in the footer.
- Right to Lodge a Complaint: You have the right to lodge a complaint with the National Supervisory Authority for Personal Data Processing in Romania (ANSPDCP at dataprotection.ro) or your local European supervisory authority.
Notice to U.S. Residents & State Privacy Rights
Residents of certain U.S. states (including California, Virginia, Colorado, Connecticut, Utah, Texas, and others) may have specific privacy rights under state privacy laws where applicable to us.
Depending on your state of residence and applicable legal thresholds, these rights may include:
- The right to know and access personal information collected about you.
- The right to request deletion of your personal information.
- The right to correct inaccurate personal information.
- The right to obtain a portable copy of your data.
- The right to be free from discrimination for exercising your privacy rights.
No Sale or Sharing: BuiltForLocal does not sell your personal information and does not share your personal information for cross-context behavioral advertising.
To exercise any applicable privacy rights, please contact us at maaximfrancesco@gmail.com.
California Online Privacy Disclosures
Under the California Online Privacy Protection Act (CalOPPA) and applicable California privacy standards:
- Categories Collected: Identifiers (IP address, contact details if provided directly), commercial transaction records, and internet usage data (if analytics is consented to).
- Do Not Track & Browser Signals: Our website does not deploy third-party advertising trackers. Non-essential analytics tracking is turned off by default unless affirmative consent is granted in the Cookie preferences banner.
- Third-Party Tracking: We do not allow third parties to conduct cross-site behavioral tracking on our website for advertising purposes.
Children's Privacy
BuiltForLocal provides business-to-business website services intended for commercial business owners. Our website is not directed to children, and we do not knowingly collect personal information from individuals under 13 years of age (or under 16 where applicable). If you believe a child has provided personal data to us, please contact us so we can promptly delete it.
Third-Party Links & Services
Our website contains links to external services, including WhatsApp and email clients. When you navigate to external platforms, their respective privacy practices and terms govern your interactions. We encourage you to review the privacy policies of third-party platforms you use.
Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices, technical implementations, or applicable laws. When updates occur, we will update the "Last updated" date at the top of this document.
Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy or our handling of your data, please contact us:
- Email: maaximfrancesco@gmail.com
- Phone: +40 758 990 675
- Data Controller: Maxim Francesco PFA
- Address: Strada Dimitrie Leonida nr. 87, Bloc M3, Ap. 29, Piatra-Neamț, Neamț County, 610168, Romania (European Union)