Who we are
One in Sixty is a boutique technology consultancy operating across Central & Eastern Europe. The data controller for this website isDRCATCHERS SRL, registered at Principala Street 520, Gheorghieni, Cluj, Romania(referred to below as “we”, “us”, or “the controller”).
For any privacy question or to exercise a right under the GDPR, emailhello@oneinsixty.eu. We reply within thirty days.
Scope
This policy covers oneinsixty.eu, our brief-intake wizard at /brief, our contact form at/contact, and any email or paid consultation booked through the site.
What we collect, why, and how long we keep it
Contact form (/contact)
- What. Your name, email address, optional company name, and the message you send. Plus, if your visit was tagged, the campaign attribution parameters (UTM source, medium, campaign, content, term) and the URL / referrer of the page you first landed on — so we know which of our posts or links you came from.
- Why. To reply to the enquiry and follow up.
- Legal basis. Contract / pre-contract steps at your request (Art. 6(1)(b) GDPR) for the enquiry itself; our legitimate interest in measuring which of our own posts / campaigns work (Art. 6(1)(f)) for the attribution parameters.
- Retention. Twenty-four months from our last exchange, then deleted from our CRM.
Brief wizard — free path (/brief)
- What. Your answers to four scoping questions (stage, need, urgency, and route), plus name, email, optional company, and message. Plus, if your visit was tagged, the campaign attribution parameters and landing / referrer URL described in the Contact section above.
- Why. To prepare the complimentary email reply you asked for.
- Legal basis. Contract / pre-contract (Art. 6(1)(b) GDPR); attribution parameters under legitimate interest (Art. 6(1)(f)).
- Retention. Twenty-four months from our last exchange.
Brief wizard — paid €90 consultation
- What. Everything from the free path (including the attribution parameters described above), plus payment metadata Stripe returns to us (Checkout session ID, amount, currency, tax breakdown, invoice reference). We never see or store your card details — Stripe hosts the payment page and holds all card data.
- Why. To fulfil the consultation contract and issue an invoice.
- Legal basis. Contract (Art. 6(1)(b)) and a legal obligation to keep accounting records (Art. 6(1)(c), together with Romanian tax and accounting law).
- Retention. Consultation notes: twenty-four months. Invoice and accounting records: ten years, as required by Romanian law.
Booking a slot — self-hosted scheduling (Cal.com)
After a paid consultation is initiated, the /brief/successpage embeds our self-hosted Cal.com scheduling system, which runs on our EU-region VPS. It collects your name, email, and time zone to schedule the meeting, and that booking data stays on our own infrastructure — there is no third-party scheduling service. Two sub-processors are involved only in the mechanics of a booking: the confirmation email is delivered by Resend, and the agreed slot is written to our Google calendar.
Analytics — Umami (self-hosted)
- What. Page path, referrer, browser and OS family, device type, screen size, and country derived from IP (the IP itself is discarded). Cookieless. No cross-site tracking. No personal identifiers.
- Why. To understand which content is useful and where the site can improve.
- Legal basis. Our legitimate interest in running the site (Art. 6(1)(f) GDPR). Because Umami is cookieless and does not process personal data in a form we can tie to you, most EU supervisory authorities do not require consent for analytics of this kind.
- Retention. Individual event records for twelve months; aggregate statistics indefinitely.
- Where. Self-hosted by us on our EU-region VPS — no third-party analytics provider is involved.
Session replay — OpenReplay (self-hosted)
- What. Mouse movement, clicks, scrolling, and the page’s visual structure — enough to reproduce how a visitor navigated the site. All input fields, email addresses in text, and date values are automatically masked in the visitor’s browser before anything is transmitted.
- Why. To diagnose usability problems (e.g. a broken mobile form).
- Legal basis. Our legitimate interest (Art. 6(1)(f)), balanced against your rights by the input masking above; you can opt out by declining to use the site or by contacting us.
- Retention. Thirty days, then automatically deleted.
- Where. Self-hosted by us on our EU-region VPS.
Anti-spam — Cloudflare Turnstile
The contact form uses Cloudflare Turnstile to distinguish humans from bots. To compute the challenge, Cloudflare processes limited technical data (IP address, user-agent, browser fingerprint signals). Legal basis: our legitimate interest in blocking spam (Art. 6(1)(f)). SeeCloudflare’s privacy policy.
Hosting & delivery — Cloudflare Pages
The site is served through Cloudflare’s content delivery network, which logs standard request metadata (IP, timestamp, path, response status) for security and reliability. Legal basis: legitimate interest (Art. 6(1)(f)). Cloudflare’s privacy policy applies to that processing.
Cookies and similar technologies
We do not set third-party advertising or tracking cookies. The cookies we do set are:
o60_gate— strictly-necessary technical cookie, set only while the site is running behind a temporary access PIN (for example during a private preview). The site is currently public and does not set it. Contains no personal information.o60_attr— first-party marketing-attribution cookie, expires in 90 days. Stores the campaign parameters (UTM source, medium, campaign, content, term) plus landing path and referrer of the page you first arrived on. Used only so that, if you later submit our contact form or brief wizard, we can associate that enquiry with the post or link that brought you to us. Never shared with third parties. We also mirror the same data in your browser’slocalStorageunder the same name for resilience. Skipped entirely if your browser sends the Do-Not-Track (DNT) header or a Global Privacy Control signal.
Who we share your data with
We do not sell your personal data and we do not share it for advertising purposes. We share it only with processors we have engaged, under a Data Processing Agreement, for the purposes above:
- Cloudflare, Inc. — content delivery, DNS, Cloudflare Tunnel, Turnstile.
- Stripe Payments Europe, Ltd. — payment processing for the €90 consultation.
- Resend (Plus Five Five, Inc.) — delivery of the booking-confirmation email for paid consultations (only if you initiate one).
- Google Ireland Ltd. — the agreed consultation slot is written to our calendar via our self-hosted scheduling system.
- Hostinger International Ltd. — VPS hosting for our self-hosted internal tools (CRM, analytics, session replay, scheduling).
Our CRM (EspoCRM), analytics (Umami), session-replay (OpenReplay), and scheduling (Cal.com) systems are self-hosted by us. No third-party scheduling service is involved in a booking.
International transfers
Cloudflare, Stripe, Resend, and Google may transfer limited data outside the European Economic Area, primarily to the United States. Where they do, transfers are covered by the European Commission’s Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.
Your rights under the GDPR
- Access — a copy of the personal data we hold about you.
- Rectification — correction of inaccurate data.
- Erasure (“right to be forgotten”) — subject to accounting-record obligations for invoices.
- Restriction or objection to processing based on legitimate interest.
- Data portability — receive your data in a common machine-readable format.
- Withdraw consent at any time, where consent is the legal basis.
- Complain to a supervisory authority — in Romania, the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (dataprotection.ro), or to the supervisory authority of your EU/EEA country of residence.
To exercise any of these, emailhello@oneinsixty.eu. We do not charge for reasonable requests, and we do not require you to prove your identity beyond what is necessary to protect the data.
Security
Data in transit is protected by TLS end-to-end (Cloudflare origin + Cloudflare Tunnel to our internal tools). Our servers use SSH key-only access, are fronted by a firewall, and secrets live in environment files that are never committed to version control. Session-replay recordings are masked in your browser before leaving your device.
Automated decision-making and profiling
We do not carry out any solely automated decision-making, including profiling, that produces legal or similarly significant effects on you.
Children
The site and its services are intended for professionals acting in a business capacity. We do not knowingly collect data from children under the age of 16.
Changes to this policy
We may update this policy occasionally to reflect changes in the site, our tooling, or the law. The current version’s date is shown at the top of the page. Substantive changes will be highlighted here.
Contact
Data controller: DRCATCHERS SRL, registered atPrincipala Street 520, Gheorghieni, Cluj, Romania.
Email for privacy requests:hello@oneinsixty.eu.