GDPR Policy

Last updated: September 4, 2026

This page explains, specifically, how pearos.xyz complies with the EU General Data Protection Regulation (Regulation (EU) 2016/679) and Romanian Law No. 190/2018. For a plain-language description of what we collect, see our Privacy Policy.

1. Data controller

The data controller for pearos.xyz is Pear Software and Services S.R.L. (CUI 50888207, Nr. Reg. Com. J2024041454000), an independently run open-source project, registered office at 133 Dacia Blvd, Floor D, Sector 2, Bucharest 020056, Romania, reachable at alex@pear-software.com.

2. Legal bases for processing

Processing activityData involvedLegal basis (GDPR Art. 6)
Analytics (Google Analytics, Clarity)IP address, device/browser, pages visitedConsent — Art. 6(1)(a)
Advertising (Google AdSense)IP address, cookie identifiersConsent — Art. 6(1)(a)
Processing a donationAmount, payment method metadata (via Stripe/PayPal/Ko-fi/Patreon)Contract — Art. 6(1)(b)
Download throttling / signed unlock linksIP address, request timestampLegitimate interest — Art. 6(1)(f)
Replying to your emailEmail address, message contentLegitimate interest / pre-contractual steps — Art. 6(1)(f)/(b)

3. No automated decision-making

We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects on you, as defined in Article 22 GDPR.

4. Data Protection Officer

Given the small scale and nature of our data processing, we are not required to appoint a Data Protection Officer under Article 37 GDPR. For any data protection question or request, contact alex@pear-software.com directly.

5. Your rights (Articles 15–22 GDPR)

  • Right of access — obtain confirmation of, and a copy of, the personal data we hold about you.
  • Right to rectification — correct inaccurate or incomplete data.
  • Right to erasure ("right to be forgotten") — request deletion of your data where applicable.
  • Right to restrict processing — limit how we use your data in certain circumstances.
  • Right to data portability — receive data you provided us in a structured, machine-readable format.
  • Right to object — object to processing based on legitimate interest, including for direct marketing.
  • Right to withdraw consent at any time, without affecting the lawfulness of processing before withdrawal (simplest way: clear this site's local storage, or email us).

6. How to exercise your rights

Email alex@pear-software.com describing your request. We will respond within one month as required by Article 12(3) GDPR (extendable by two further months for complex requests, with notice). We may ask you to verify your identity before acting on a request.

7. Right to lodge a complaint

If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Romanian supervisory authority:

Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, Bucharest, Romania
www.dataprotection.ro

If you are based elsewhere in the EU, you may instead complain to your own country's supervisory authority.

8. International transfers

Where personal data is transferred outside the European Economic Area (for example to US-based processors such as Google, Microsoft, Stripe, or Cloudflare), this relies on the EU-U.S. Data Privacy Framework and/or Standard Contractual Clauses approved by the European Commission as an appropriate safeguard.

9. Security measures

  • The entire site is served over HTTPS.
  • Card payment data is handled exclusively by PCI-DSS-certified processors (Stripe, PayPal) — it never reaches our own servers.
  • Paid download links are HMAC-signed and time-limited rather than being permanently open.
  • We collect the minimum data necessary for each processing activity described above.

10. Data retention

We retain personal data only as long as necessary for the purpose it was collected for, or as required by law (e.g. financial/tax retention periods that apply to our payment processors). Analytics data follows each provider's default retention window (see our Privacy Policy).

11. Changes to this policy

We may update this policy to reflect changes in our data practices or in applicable law. The date at the top of this page reflects the most recent revision.