Legal

Privacy Policy

Last updated: May 2026

1. Who we are

This website (theprincipalrecruiter.com) is operated by Andreea Lungulescu, trading as The Principal Recruiter, Neue Grünstraße 39, 10179 Berlin, Germany. We are the controller of personal data processed through this site under the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).

Contact for any privacy question: andreea@theprincipalrecruiter.com.

2. What we collect

We deliberately keep data collection to a minimum. We process:

  • Server log data automatically generated when you visit the site (IP address, browser, referrer, timestamp). This is processed by our hosting provider for security and to deliver the site.
  • Information you send us when you email us, book a call, or otherwise reach out — typically your name, email address, company, and the content of your message.

We do not run user accounts, we do not take payments through this site, and we do not collect special category data.

3. Why we process it (legal bases)

  • To deliver the website securely and reliably — Art. 6(1)(f) GDPR (legitimate interest in operating a functional, secure site).
  • To respond to your enquiry when you contact us — Art. 6(1)(b) GDPR (steps prior to entering a contract) or Art. 6(1)(f) (legitimate interest in answering business enquiries).
  • To meet legal obligations, e.g. tax record-keeping — Art. 6(1)(c) GDPR.

4. Cookies and tracking

This site uses only essential, first-party storage required for the page to render and to remember basic UI state. We do not currently use analytics cookies, marketing pixels, or third-party trackers, and we do not build advertising profiles.

If we add analytics or marketing tools in the future, you will see a consent banner and nothing non-essential will load until you opt in.

5. Third-party services

We use a small number of processors to run the site and the business:

  • Lovable / Cloudflare — website hosting and content delivery (servers in the EU and globally).
  • Cal.com — when you book an introductory call via the "Book a call" link, your name, email, and scheduling details are processed by Cal.com under their own privacy policy.
  • Email provider — when you email us, your message is stored in our standard business inbox.

Where personal data leaves the EEA, we rely on the European Commission's Standard Contractual Clauses or an adequacy decision.

6. How long we keep it

Server logs are retained for a short rolling window for security purposes. Email correspondence is retained for as long as needed to manage the relationship and to meet legal retention obligations (commercial correspondence: typically 6 years; tax-relevant documents: 10 years under § 147 AO).

7. Your rights

Under the GDPR you have the right to access, rectify, erase, restrict, or object to the processing of your personal data, the right to data portability, and the right to withdraw any consent at any time without affecting the lawfulness of prior processing. To exercise any of these rights, email andreea@theprincipalrecruiter.com.

You also have the right to lodge a complaint with a supervisory authority. The competent authority for us is the Berliner Beauftragte für Datenschutz und Informationsfreiheit.

8. Changes to this policy

We may update this policy as the site and our services evolve. The "Last updated" date at the top reflects the latest revision.