Privacy Policy
Built by Maksim | Effective 7 August 2026
This policy explains how Maksim Erofeev, operating under the name “Built by Maksim”, collects, uses, stores and shares personal data through builtbymaksim.com, project enquiries, email communications and business outreach.
1. Who we are
The data controller is Maksim Erofeev, a natural person operating under the name “Built by Maksim” from Georgia (“Built by Maksim”, “I”, “me” or “my”). Built by Maksim is not currently a separately incorporated legal entity or a registered trade mark.
Contact details:
- Email: info@builtbymaksim.com
- Postal address: Tbilisi 0186, Georgia
- Website: https://builtbymaksim.com/
2. Scope of this policy
This policy applies when you visit the website, submit an enquiry, communicate with me, request or receive information about services, subscribe to marketing emails, interact with an email I send, or receive relevant business-to-business outreach from me. It does not govern the independent privacy practices of clients, third-party websites or services linked from the website.
3. Personal data I collect
| Category | Examples |
|---|
| Enquiry and contact data | Your name; email address, telephone number or another contact method you choose; and your comment or brief project description. |
| Correspondence and project data | Messages, attachments, meeting notes, requirements, proposals, decisions and other information you provide during discussions or a working relationship. |
| Business contact data | A person’s name, role, company, work contact details and the public source from which those details were obtained. |
| Email and engagement data | Subscription status, consent record, delivery and bounce events, unsubscribe or suppression status, and—where enabled—email opens and link clicks. |
| Technical data | IP address, date and time, requested page, browser or device information, referrer and security/error log information generated by the server. |
Please do not send sensitive personal data or confidential information through the initial enquiry form unless it is genuinely necessary and we have agreed an appropriate way to provide it.
4. How I obtain personal data
- Directly from you, including through the contact form, email, calls, meetings and project communications.
- Automatically from the website server and email-delivery systems when you visit the website or interact with an email.
- From publicly available business sources such as a company website, professional directory or public professional profile, and occasionally from a business contact who reasonably believes an introduction may be relevant.
- From service providers that deliver, secure or report on communications sent on my behalf.
5. Why I use personal data and the legal basis
| Purpose | Typical legal basis |
|---|
| Respond to an enquiry, assess a proposed project, arrange discussions and prepare a proposal. | Steps taken at your request before entering into a contract; legitimate interests in responding to business enquiries. |
| Enter into, administer and deliver a project or service. | Performance of a contract; compliance with legal obligations; legitimate interests in managing the working relationship. |
| Maintain correspondence, records, security, service reliability and evidence of agreed terms. | Legitimate interests in operating and protecting the business and establishing, exercising or defending legal claims; legal obligations where applicable. |
| Send a newsletter or other optional marketing requested through the website. | Your consent. You may withdraw it at any time. |
| Send limited, relevant B2B outreach to publicly listed professional contacts. | Legitimate interests in promoting services to organisations that may reasonably find them relevant, where permitted by the law applicable to the recipient. Consent is used where the applicable law requires it. |
| Measure delivery and engagement with emails, including opens and link clicks where enabled. | Consent for voluntary subscribers where required; otherwise legitimate interests only where the applicable law permits and the impact on recipients is proportionate. |
Where processing is based on legitimate interests, I consider the business purpose, necessity and likely effect on the individual. You may object to direct marketing at any time. A privacy notice does not override country-specific electronic marketing or tracking rules; outreach and tracking are used only where the applicable rules allow them.
6. Contact form and newsletter choice
Submitting the contact form is voluntary. The form asks for your name, a contact method and a brief description of the task. This information is stored in a PostgreSQL database controlled by Built by Maksim and is also sent through Mailgun and delivered to my Zoho Mail inbox.
If the form offers a newsletter option, that option is separate, optional and off by default. You can submit an enquiry without subscribing. You can unsubscribe using the link in a marketing email or by contacting me.
7. Email marketing, outreach and tracking
I may send occasional emails to people who have subscribed and may also send carefully targeted B2B messages to work addresses found in public business sources, where permitted. Marketing messages identify the sender and provide a practical way to opt out. If you opt out, I retain the minimum information necessary on a suppression list so that I do not contact you again by mistake.
Mailgun may record delivery, bounce, complaint, unsubscribe, open and click events. Open tracking generally uses a small tracking pixel, while click tracking may route a link through a tracking service before reaching its destination. These signals can be affected by privacy tools, image proxies, automated scanners and security software, so they may not reliably show that a particular person read or clicked an email. Engagement tracking may be disabled or limited where required by applicable law.
8. Cookies, local storage and website analytics
The website uses self-hosted Umami Analytics, available through analytics.builtbymaksim.com, to help me understand how visitors use the website and improve its content, navigation, performance and conversion paths.
When analytics is enabled, it may collect information such as the pages you visit, the time and sequence of visits, time spent on pages, referring website, date and time of access, approximate country or location, browser, operating system, device type, screen resolution and browser language. It may also record interactions with the website, such as navigation clicks, link clicks, document openings, form submissions and other configured events. The contents of contact-form fields are not intentionally included in analytics events.
Umami may process your IP address and User-Agent information to generate a pseudonymous session identifier. The analytics is operated on infrastructure controlled by Built by Maksim and is not used for advertising, cross-site tracking or the creation of advertising profiles.
Analytics is non-essential and is activated only after you give permission through the website’s privacy controls. You may reject analytics without losing access to any website functionality. You can change or withdraw your choice at any time by selecting “Privacy Settings” in the website footer. Withdrawing consent does not affect processing that occurred before withdrawal.
The website stores a strictly necessary privacy preference on your device so that it can remember whether you accepted or rejected analytics. This preference is not used for tracking and is retained for up to six months, after which the website may ask for your choice again.
The website also uses session storage solely to preserve the navigation menu position while you browse. This information remains on your device, is not used for tracking and is deleted when the browser tab is closed.
Detailed analytics events and session information are generally retained for up to 12 months. Aggregated statistics that can no longer reasonably be associated with a particular visitor or session may be retained for longer.
The hosting environment may also create ordinary server logs for security, troubleshooting and reliable delivery of the website. These logs may contain technical information such as an IP address, request time, requested page, browser information and error details.
9. Service providers and recipients
I share personal data only when reasonably necessary for the purposes described above. Relevant recipients may include:
- isHosting, which provides the rented VPS used for the website and related systems;
- Mailgun, which transmits emails and provides delivery and engagement events;
- Zoho Mail, which receives and stores my business email;
- technical contractors or professional advisers who require limited access and are subject to appropriate confidentiality duties;
- public authorities, courts or other parties where disclosure is required by law or reasonably necessary to protect legal rights, safety or the integrity of the services.
These providers may act as processors or independent controllers depending on the service and context. Their own terms and privacy notices may also apply to their independent processing.
10. International transfers
Built by Maksim operates from Georgia, while the website infrastructure and the server used to retain email-event data are located in the United States. Mailgun, Zoho and other providers may process data in the United States or other countries in which they or their subprocessors operate. As a result, personal data may be transferred outside your country and outside Georgia.
Where required, I rely on an applicable legal transfer mechanism and appropriate contractual, technical or organisational safeguards. However, privacy laws and government-access rules in a receiving country may differ from those in your country. You may contact me for further information about safeguards relevant to your data.
11. Retention
| Data | Typical retention |
|---|
| Enquiries and ordinary business correspondence | Up to two years after the last meaningful communication, unless a longer period is reasonably necessary for a contract, legal obligation or legal claim. |
| Client and project records | For the duration of the working relationship and afterwards for the period required by applicable contractual, tax, accounting and limitation rules. |
| Newsletter and marketing records | Until you unsubscribe, withdraw consent or the purpose ends. Consent and unsubscribe records may be retained as necessary to demonstrate compliance. |
| Suppression records | The minimum identifier needed to honour an opt-out may be kept for as long as reasonably necessary to prevent further marketing. |
| Email engagement events | Normally up to two years after the relevant interaction or last engagement, unless aggregated or anonymised earlier. |
| Server and security logs | For a limited period proportionate to security, troubleshooting and operational needs, unless an incident requires longer retention. |
Data may be deleted earlier when it is no longer needed. It may be retained longer where required by law, reasonably necessary for a dispute or legal claim, or needed to protect the systems from abuse.
12. Security
I use reasonable technical and organisational measures appropriate to the nature of the data and the size of the operation, including access controls, reputable infrastructure providers and limiting collection to what is needed. No online transmission or storage method is completely secure, so absolute security cannot be guaranteed.
13. Your rights
Depending on the law that applies to you, you may have the right to:
- receive information about the processing of your personal data and request access to it;
- request correction, updating, blocking, deletion or destruction of inaccurate or unlawfully processed data;
- request restriction of processing or data portability where the applicable law provides those rights;
- withdraw consent at any time, without affecting processing already carried out lawfully;
- object to processing based on legitimate interests and object at any time to direct marketing;
- ask about the source of data that was not collected directly from you;
- lodge a complaint with a competent supervisory authority or seek another remedy available under applicable law.
To exercise a right, email info@builtbymaksim.com. I may ask for information reasonably necessary to verify your identity and locate the relevant data. Rights are not absolute and lawful exceptions may apply.
14. Automated decision-making and children
I do not use personal data collected through the website to make decisions based solely on automated processing that produce legal or similarly significant effects. The website and services are directed to business users and are not intended for children. I do not knowingly collect children’s personal data through the website.
15. Complaints
Please contact me first at info@builtbymaksim.com so I can try to resolve the issue. You may also complain to the competent data protection authority. In Georgia, supervisory functions under the Law of Georgia on Personal Data Protection are exercised by the State Audit Office of Georgia. If another jurisdiction’s data protection law applies to your situation, you may also have the right to contact the relevant authority there.
16. Changes to this policy
I may update this policy when the website, services, providers or legal requirements change. The current version will be published on this page with a revised effective date. If a change materially affects processing based on consent, fresh consent will be requested where required.