</> Coding Nadezda Balujeva Nadezda EI · Montpellier Contact

Privacy policy

This policy explains what personal data is collected, why, on what legal basis, how long it is kept, who else sees it, and what you can require. It is written to meet Regulation (EU) 2016/679 (GDPR) and the French loi Informatique et Libertés.

1. Who is responsible

The controller is Balujeva Nadezda — Entrepreneur Individuel (EI), SIREN 999 961 071, registered address 25 Rue Gustave Eiffel, 34070 Montpellier, France. Data protection matters are handled directly by Nadezda Balujeva. Contact: info@codingbynadezda.online or +48 732 145 104.

No Data Protection Officer is required or appointed: this is a one-person business, its core activity is not large-scale monitoring, and no special category data is processed on a large scale.

2. What is collected, why, and for how long

Category Purpose Legal basis Retention
Name, email address, telephone number and the content of your message, from the contact form or sent directly To answer your enquiry and, where it leads to work, to prepare a proposal Art. 6(1)(b) — steps prior to entering a contract; otherwise Art. 6(1)(f) legitimate interest in responding to enquiries 3 years from our last contact, then deleted
Billing name, address, email address, order contents and order number To perform the contract and to issue and keep invoices Art. 6(1)(b) and Art. 6(1)(c) — accounting obligations 10 years, the retention period for accounting records under art. L123-22 of the Code de commerce
Payment method type, transaction reference, outcome and the last four digits of the card To confirm payment, reconcile accounts, process refunds and handle disputes Art. 6(1)(b) and Art. 6(1)(c) 10 years with the accounting records; card fragments deleted after 13 months
The express request to begin work immediately and the acknowledgement about the withdrawal period, recorded at checkout with a timestamp To evidence that the request was made, as consumer law requires Art. 6(1)(c) — legal obligation 5 years, the limitation period for contractual claims
The brief you complete, and credentials or access you grant to a product, design file or website To perform the service purchased Art. 6(1)(b) Access revoked on delivery; briefs kept 24 months so follow-up work has context
Server and security logs: IP address, user agent, pages requested, timestamps To keep the site available, detect abuse and investigate incidents Art. 6(1)(f) — legitimate interest in the security of the service 12 months
Analytics and audience-measurement data set through cookies or similar technologies To understand how the site is used Art. 6(1)(a) — your consent, given in the cookie banner As stated in the cookie policy; consent withdrawable at any time

No special category data is collected, and you are asked not to send any. If it arrives unsolicited within a brief or a message, it is deleted.

3. Where the data comes from

Almost all of it comes from you directly. Server logs are generated automatically when you visit. Where a service requires it, data is read from platforms you have given access to; that data remains yours, and section 7 explains the role played in relation to it.

4. Providing your data is not compulsory

You are under no obligation to provide personal data. Without billing details and an email address, however, no contract can be concluded, no invoice issued and no service delivered; and without the access a service requires, that service cannot be performed.

5. Who it is shared with

Personal data is never sold, never shared for anyone else’s marketing, and disclosed only as set out here. A small number of processors are used, each engaged under a written contract limiting them to documented instructions and imposing confidentiality and security obligations:

  • the website hosting provider, which stores the site and its database;
  • the payment provider, which processes payments on its own hosted pages — full card numbers are never received here;
  • the email and file-sharing providers through which deliverables and correspondence pass;
  • the accountant, for statutory bookkeeping and tax filings.

Disclosure also occurs where legally required, or to establish, exercise or defend legal claims. Ask and you will be told which provider handles a given category of data.

6. Transfers outside the European Union

Where a provider processes data outside the European Economic Area, the transfer is made under an adequacy decision or under the European Commission’s standard contractual clauses, with a transfer risk assessment and supplementary technical measures where appropriate. A copy of the relevant safeguard is available on request from info@codingbynadezda.online.

7. When your business data is processed on your behalf

Delivering a service sometimes means handling personal data belonging to your business — user records, audience lists, CRM exports, analytics data. For that data you are the controller and the provider is the processor. The following terms apply and constitute a data processing agreement under article 28 GDPR:

  • Subject matter and duration: the service purchased, for its duration.
  • Nature and purpose: analysis, correction, measurement and design production as described on the service page.
  • Categories of data and data subjects: as determined by you and limited to what the service requires.
  • Instructions: processing occurs only on your documented instructions, including as to transfers, unless required otherwise by law, in which case you are told first unless the law forbids it.
  • Confidentiality: everyone with access is bound by a duty of confidence.
  • Security: access at the lowest useful level, held in a password manager with multi-factor authentication, encrypted in transit, revoked on delivery.
  • Sub-processors: only those listed in section 5. You are notified before any addition that would touch your data, and may object.
  • Assistance: help is given with data subject requests and, so far as the processing makes it necessary, with impact assessments and prior consultation.
  • Breach: notification without undue delay and in any event within 48 hours of becoming aware.
  • Deletion or return: on completion or on request, data is deleted or returned and confirmed in writing, retaining only what the law requires.
  • Audit: the information needed to demonstrate compliance is made available, and audits are accommodated on reasonable notice.

8. Your rights

Under articles 15 to 22 GDPR you have the right of access, rectification, erasure, restriction of processing, data portability, and objection to processing based on legitimate interest. Where processing rests on consent, you may withdraw it at any time without affecting the lawfulness of what was done before. You may also give directives on the fate of your data after your death, under article 85 of the loi Informatique et Libertés.

Write to info@codingbynadezda.online or call +48 732 145 104. A response follows within one month, extendable by two further months for complex requests, in which case you are told why within the first month. No fee is charged unless a request is manifestly unfounded or excessive. Proof of identity may be requested where there is genuine doubt about who is asking.

9. Complaints to the supervisory authority

Please raise the matter here first — most issues are quicker to resolve directly. You also have the right to lodge a complaint with the Commission Nationale de l’Informatique et des Libertés (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, www.cnil.fr, or with the supervisory authority of the Member State where you live or work.

10. Automated decisions

No decisions producing legal or similarly significant effects are taken by automated means, and no profiling is carried out.

11. Children

Services are sold to businesses and to adults. Data is not knowingly collected from children, and this site is not directed at them.

12. Security

Measures appropriate to the risk are applied: encryption in transit, multi-factor authentication on every account holding client data, access limited to what is necessary, managed devices, and prompt patching. No transmission over the internet is completely secure and absolute security cannot be guaranteed.

13. Changes

This policy is updated as the processing changes. Where a change materially affects you, you are told by email before it takes effect. The version published here is always the one that applies.

Business and contact details

These details apply to everything on this page, and are the details to use for any formal notice.

Trading name Coding Nadezda
Legal name Balujeva Nadezda
Legal form Entrepreneur Individuel (EI)
Represented by Nadezda Balujeva, in her own name
SIREN 999 961 071
SIRET (main establishment) 999 961 071 00019
APE / NAF code 6202A — Conseil en systèmes et logiciels informatiques
Registered with Registre National des Entreprises (RNE), France
Date of registration 19 January 2026
Registered address 25 Rue Gustave Eiffel, 34070 Montpellier, France
Email info@codingbynadezda.online
Telephone +48 732 145 104
VAT TVA non applicable, art. 293 B du CGI — VAT is neither charged nor recoverable
Website codingbynadezda.online
Response time Within one working day, Monday to Friday
Working languages English and French

The registered address is a correspondence address. All services are performed and delivered remotely; there is no walk-in office and no facility for visitors.