This website does not track you. We use no external traffic analytics, no advertising pixels and no profiling cookies, and we set no cookies of our own when you open a page. This document explains, openly, the only technologies that remain in operation — those serving security and those brought in by two external services we rely on to display the page — and how you can control them.
Last updated: 20 August 2026.
This Cookie Policy supplements our Privacy Policy, which describes in full how we process personal data.
1. What cookies and similar technologies are
A cookie is a small text file that a website stores in your browser and can read back on later visits. By “similar technologies” we mean any other means of storing information on your terminal equipment or gaining access to information already stored there: the browser’s local storage and session storage, pixel tags, device fingerprinting.
Legally, the technical label matters less than the effect: under Article 4(5) of Romanian Law no. 506/2004 (which transposes the ePrivacy Directive), storing information on a user’s equipment or gaining access to information stored there is permitted only with that user’s prior consent, unless the operation is strictly necessary to provide the service the user has expressly requested.
2. In short: what this website does
- When you browse the public pages, the site sets no cookies of its own.
- We use no Google Analytics and no other external audience-measurement service. We work out visit numbers from our own server logs, in aggregate form — with no cookies and no code in the page (section 3.6).
- We use no advertising pixels, no remarketing, no ad networks and no social buttons that load external code. The LinkedIn and Facebook links in the footer are plain hyperlinks: they transmit nothing until you click them.
- We build no visitor profiles and we sell no data to third parties.
The situations set out below remain, in which either strictly necessary cookies are set or your browser communicates with an external provider. Each is described in turn — including those where neither of the two happens.
3. What is actually in use
3.1. Security cookies set by Cloudflare
The site is delivered through the Cloudflare network, which filters automated attacks and secures the delivery and availability of the pages. An ordinary visit does not normally trigger any cookie. When the protection systems consider a check necessary — for instance in case of suspicious automated traffic — Cloudflare may set one of the following technical cookies:
__cf_bm— distinguishes human traffic from traffic generated by automated programs; expires after 30 minutes of inactivity;cf_clearance— records that a security check has been passed, so that it is not requested again;_cfuvid,__cfruid,__cfseq— allow rate-limiting rules to be applied correctly, including where several users share one IP address.
The provider states that these cookies are strictly necessary to provide the service, do not correspond to any user identifier and are not used for advertising or tracking purposes. The full, current list is published in the Cloudflare cookie documentation.
Consent: not required. These cookies fall within the exception in the second sentence of Article 4(5) of Law no. 506/2004, being strictly necessary for the secure provision of the service you requested.
3.2. The anti-spam check on the “Speak” page
The contact form is protected by Cloudflare Turnstile, a check that establishes whether a message is sent by a person or by an automated program. The verification code is loaded from challenges.cloudflare.com when you open the “Speak” page.
For this purpose, Cloudflare processes your IP address and a set of technical browser signals — device characteristics and the pattern of your interaction with the page. According to the provider’s documentation, Turnstile does not access or transmit the content of the fields you fill in, does not use cookies to collect or store visitor information and does not build profiles; in certain configurations, which we have not enabled, a technical pre-clearance cookie may be used. See the Turnstile privacy policy.
Legal basis: our legitimate interest in preventing automated messages and abuse of the form — Article 6(1)(f) GDPR. The check forms part of the service you request when you use the form.
3.3. The typefaces used to display the text
The site’s text is displayed in the Cormorant Garamond, Spectral and Hanken Grotesk typefaces. The font files are hosted on our own server and delivered from the stoian.biz domain.
Your browser therefore does not contact the Google Fonts servers (fonts.googleapis.com, fonts.gstatic.com), and no IP address is transmitted to an external provider in order to display the text. Until 20 August 2026 these typefaces were loaded directly from Google’s servers; we moved them to our own server precisely in order to remove that communication.
The typefaces are published under the SIL Open Font License 1.1, which permits self-hosting. No cookies are set and nothing is stored on your equipment in connection with them.
3.4. The map on the “Speak” page (Google Maps)
A map provided by Google Maps is embedded on the contact page. We draw your attention to this expressly: the map loads automatically, together with the page, without any action on your part. At that moment your browser contacts Google’s servers directly (google.com, maps.googleapis.com, maps.gstatic.com).
The data that reaches Google in this way:
- your IP address — unavoidable, as it is the address to which Google sends the map imagery back;
- the date and time at which the map was loaded;
- the address of the page from which the request was made — that is, our contact page, transmitted as the referrer;
- the type and version of your browser, your operating system and your configured language;
- technical characteristics of your device and window — the size of the displayed area and the screen density, used to render the map at the appropriate resolution;
- if you are signed in to a Google account in the same browser, Google may associate this data with your account.
Through the content thus loaded, Google may also store information on your terminal equipment or access information already stored there.
We neither receive, see, nor can read this data. It is processed by Google as its own controller, not as our processor, under the Google Privacy Policy. For users in the European Union, responsibility lies with Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, and the processing may involve transfers to Google LLC in the United States (section 7).
Legal basis: our legitimate interest in showing you easily where our professional seat is located, on the premise that someone opening the contact page is looking for precisely that — Article 6(1)(f) GDPR.
How to avoid this transmission. The map is a convenience, not a component necessary for the site to work: our address is displayed in full, in text, both on the contact page and in the footer of every page. You can block the map from loading in your browser settings or with a third-party content blocker (section 6), without affecting the rest of the site. You may also object to this processing under Article 21 GDPR, by a request sent to [email protected].
3.5. Cookies used to administer the site
The platform on which the site is built (WordPress) uses authentication and preference cookies — of the type wordpress_logged_in_…, wordpress_sec_…, wp-settings-… — for people who log in to the administration area. These concern exclusively the lawyers and staff of the firm who update the content, not the site’s visitors. They are strictly necessary to maintain an authenticated session.
3.6. Our own visit statistics
We keep our own record of how many visits the site receives. It is the only form of audience measurement we use, and we mention it here because, although it involves no cookie and no code running in your browser, we think you ought to know about it.
It works entirely on the server: once an hour, a program of ours reads the web server logs (section 3.1 of our Privacy Policy describes what they contain) and works out how many pages were displayed and how many distinct addresses appeared that day. The addresses are counted, then the list is discarded — only the totals are kept.
No connection to any external service is made, nothing is stored on your equipment, and these figures cannot be used to reconstruct who visited the site or what they read. The full description is in our Privacy Policy, section 3.7.
4. Why you do not see a consent banner
A consent banner is required where a site sets cookies that are not strictly necessary — typically analytics or advertising cookies. This site sets none. The only cookies that may appear are the security cookies described in section 3.1 and the administration cookies in section 3.5, both exempt by law from the prior-consent requirement.
The only element delivered by a third party is the map in section 3.4. We have chosen to display it on the basis of legitimate interest, rather than behind an acceptance window, because we wanted a visitor looking for our office to see it straight away. We consider that we owe you accurate information in return: section 3.4 therefore lists item by item what data reaches Google, and section 6 explains how to block the map from loading if you prefer. You may object at any time under Article 21 GDPR, by writing to [email protected].
On every other page of the site — the home page, Story, Services, Specialists, Spotlights and the articles in that section — your browser loads no resource whatsoever from an external provider. The map, LinkedIn and Facebook links in the footer are plain hyperlinks: they transmit nothing until you click them.
5. What we do not use
- external traffic analytics or audience-measurement services;
- advertising cookies, remarketing, online advertising auctions;
- social-network tracking pixels;
- device fingerprinting for marketing purposes;
- sharing of browsing data with third parties for commercial purposes;
- typefaces or other presentation assets loaded from third parties — the site’s fonts are hosted by us.
6. How to control cookies and third-party connections
You can at any time view, block or delete cookies from your browser settings, and block the loading of content hosted by third parties:
Please note that blocking strictly necessary cookies may prevent the security check from being passed and, consequently, prevent a message from being sent through the contact form. Should that happen, you can always write to us directly by e-mail or call us.
7. Transfers outside the European Economic Area
Cloudflare, Inc. and Google LLC are companies established in the United States of America, and the operations described above may involve the transfer of technical data outside the European Economic Area. Those transfers rely on the European Commission’s adequacy decision on the EU–U.S. Data Privacy Framework, to which both providers are certified, and, in the alternative, on the standard contractual clauses adopted by the European Commission. For Google services, in relation to users in the Union, responsibility lies with Google Ireland Limited, established in Ireland.
8. How long the information is kept
- Cloudflare security cookies: from a few seconds up to 24 hours, depending on the cookie;
__cf_bmexpires after 30 minutes of inactivity. - WordPress administration cookies: the duration of the session, or up to 14 days where the logged-in person selects “remember me”.
- Technical data processed by Cloudflare and Google: according to those providers’ own retention policies.
- Our own web-server logs: 7 days, by automatic rotation.
9. Changes to this policy
We update this document whenever the technologies used on the site or the applicable legal requirements change. The version in force is always the one published on this page, and the date of the last update is shown at the beginning. We recommend re-reading it periodically.
10. Contact
For any question concerning cookies or the processing of your data, you may write to us at [email protected] or [email protected], or call +40 264 402 597. The firm’s full identification details are published on the Legal & Professional Information page.
11. Applicable legal framework
- Law no. 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector, as amended — in particular Article 4(5);
- Regulation (EU) 2016/679 (GDPR), in particular Articles 6, 13 and 44–49;
- Law no. 190/2018 implementing Regulation (EU) 2016/679;
- Directive 2002/58/EC (the ePrivacy Directive), as amended by Directive 2009/136/EC.