VivaCoding’s Privacy Policy is a transparency notice under Regulation (EU) 2016/679 (GDPR): what personal data the website vivacoding.com collects, why, on which legal bases, who receives it, how long it is kept, and what rights you have. It covers processing via inquiry forms, email, and technical means on the site.

Key takeaways
- Controller: VivaCoding, Gladstonos 28, Paphos 8046, Cyprus; requests — hello@vivacoding.com.
- We process form and email data to reply to inquiries and to enter into / perform contracts (Art. 6 GDPR).
- Your rights: access, rectification, erasure, restriction, objection, portability, withdraw consent, complain to the Cyprus supervisory authority.
- We do not collect special-category data via the site and do not use solely automated decisions with legal or similarly significant effects.
1. Who is the controller
The data controller is the VivaCoding studio (“we” / the “Controller”), processing personal data on vivacoding.com and related forms.
- Address: Gladstonos 28, Paphos 8046, Cyprus.
- Email for data-subject requests: hello@vivacoding.com.
- Website: https://vivacoding.com/.
No separate Data Protection Officer (DPO) is appointed: processing is typical for a B2B services website and does not fall under the mandatory DPO cases in Art. 37 GDPR. Full legal-entity details are provided on request and appear in client contracts.
2. What data we process
Data subjects: website visitors; people who submit an inquiry or email us; client contact persons under a contract.
Categories of data (depending on forms / correspondence and site operation):
- identity and contact data: name / salutation, phone, email;
- inquiry content: message text, task description, project correspondence;
- technical data: IP address, cookies and similar identifiers, browser/device info, referrer, date and time — as needed for site operation, security, and (if enabled) analytics;
- contract-related client data — as needed to perform the contract (outside website forms).
We do not collect special categories of personal data (Art. 9 GDPR) or biometric data via the site. We do not knowingly solicit children’s data; services target a business audience.
3. Purposes and legal bases (Art. 6 GDPR)
Each purpose is tied to a legal basis. Without the contact details needed for a reply, we cannot respond to an inquiry or enter into a contract at your request.
- Handling inquiries — Art. 6(1)(b) GDPR (steps prior to entering a contract at your request) and/or Art. 6(1)(a) (consent via the form checkbox).
- Entering into and performing contracts for development, support, and related services — Art. 6(1)(b).
- Business correspondence and documentation — Art. 6(1)(b) and, where appropriate, Art. 6(1)(f) (legitimate interest in managing obligations).
- Website security (logs, anti-spam, abuse prevention) — Art. 6(1)(f); data-subject interests do not override the need to protect the service.
- Web analytics (if enabled) — typically Art. 6(1)(a) (cookie/analytics consent) or another basis stated in the tool’s settings; aggregated/anonymized statistics may rely on Art. 6(1)(f) where permitted.
- Legal obligations (accounting, regulator requests) — Art. 6(1)(c) where applicable.
Where processing is based on consent, you may withdraw it at any time (Art. 7(3) GDPR); withdrawal does not affect lawfulness before withdrawal.
4. Where data comes from
- Directly from you — via website forms, email, messengers, or calls.
- Automatically when you visit the site — technical logs and cookies/similar technologies.
- From your representative or counterparty — if you are named as a contract contact (Art. 14 GDPR: information is in this policy and on request at hello@vivacoding.com).
5. Who receives the data
We engage processors only for the purposes above and under a contract / standard processing terms. Typical recipient categories:
- website hosting and infrastructure;
- outbound email (SMTP) for form deliveries;
- CRM and project tools — when handling a deal/project;
- web analytics (if enabled), e.g. Yandex Metrica;
- contractors under a client agreement — only as needed to perform obligations.
We do not sell personal data or share it with third parties for their own marketing without separate consent.
6. Transfers outside the EEA
The Controller is established in Cyprus (EEA). Some processors or infrastructure may be outside the EEA (for example certain cloud or analytics services). In those cases we use a Chapter V GDPR mechanism: an EU adequacy decision, Standard Contractual Clauses (SCCs) and/or other permitted safeguards, plus technical and organisational measures.
Ask hello@vivacoding.com for the current list of key processors and countries.
7. Retention
- pre-contract inquiries and correspondence — until the purpose is achieved or consent is withdrawn, if no other basis applies; usually no longer than 24 months without activity on the inquiry, unless agreed otherwise;
- contract data — for the contract term plus mandatory document retention (tax/accounting) under applicable law;
- technical logs and anti-spam signals — typically up to 12 months, longer only for incident investigation;
- analytics and cookies — per cookie lifetime / service settings.
8. Cookies and similar technologies
The site may use cookies and similar technologies for session, interface language, security, and statistics. Non-essential cookies (e.g. analytics) are enabled with consent where required by EU/Cyprus e-privacy rules. You can restrict cookies in your browser; some site features may then work in a limited way.
9. Your rights (Arts. 12–22 GDPR)
You may (subject to GDPR conditions and exceptions):
- access your data (Art. 15);
- rectify inaccurate data (Art. 16);
- request erasure (“right to be forgotten”, Art. 17) where grounds apply;
- request restriction of processing (Art. 18);
- receive data in a structured format / portability (Art. 20) where applicable;
- object to processing based on legitimate interests (Art. 21);
- withdraw consent where processing relies on it (Art. 7(3));
- not be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects (Art. 22) — we do not take such decisions via the site.
How to exercise your rights:
- Email hello@vivacoding.com with the subject “Personal data / GDPR”.
- State which right you wish to exercise and enough detail to identify the request.
- We will respond without undue delay, normally within one month (Art. 12(3) GDPR; the period may be extended in complex cases with notice).
You may also lodge a complaint with a supervisory authority. For a Cyprus-based controller that is the Office of the Commissioner for Personal Data Protection (Cyprus). If you live or work elsewhere in the EEA, you may also contact your local authority.
10. Security measures
- HTTPS and form protections (including honeypot / anti-spam);
- role-based and need-to-know access;
- processor contractual obligations;
- infrastructure backups;
- incident response and notifications under Arts. 33–34 GDPR where applicable.
11. Changes to this policy
We may update this policy. The current version is always on this page; the update date is below. Material changes affecting data already collected may be accompanied by an additional notice (e.g. on the site or by email) where appropriate.
Related pages
FAQ
Is the form consent checkbox required?
Yes. Submitting a website inquiry requires accepting this policy so we can lawfully process the request; without it the form is not accepted.
Can I delete inquiry data?
Yes — email hello@vivacoding.com. If a contract is already in place or law requires retention, some records may be kept on other bases (Art. 6(1)(b)/(c) GDPR).
Do you share data with ad networks?
Not for their own marketing. Inquiry data is used to reply and deliver the project; analytics only if a service is enabled and under its rules / your cookie consent.
Where else is the policy published?
In the site footer and in consent text on inquiry forms. Canonical URL: https://vivacoding.com/pd/ (EN: /en/pd-en/ when published).