Legal
Privacy Policy
1. Who's behind this site
filipsardi.com is operated by Filip Sardi, trading through Lansiraj d.o.o., based in Croatia. For all privacy questions, contact filip@filipsardi.com.
2. What data we collect on filipsardi.com
This is the marketing and writing surface of Client Flow. The data flows here are intentionally minimal:
- Newsletter signup: first name (optional) and email address, plus the page you signed up from. Used to send you the weekly Client Flow letter and add you to our newsletter platform.
- Contact form (letter pages): name, email address, your message, and the page you wrote from. Sent to Filip's inbox via Web3Forms.
- Flow Collective application: name, email, what you sell, where momentum is breaking, track preference, optional start-date and notes. Sent to Filip's inbox via Web3Forms.
- VIP Day enquiry: name, email, team size, what you'd want built, optional date and notes. Sent to Filip's inbox via Web3Forms.
- Analytics: aggregate page views and traffic sources via Plausible Analytics (cookieless, no personal identifiers, no fingerprinting).
If you use FlowOS at lab.filipsardi.com, that's a separate product with its own data flows. See the FlowOS privacy policy.
3. How we use your data
- Send you the weekly Client Flow letter (newsletter signups only)
- Reply to your message (contact and application forms)
- Understand which letters and pages resonate (aggregate analytics only)
We don't sell, rent, or share your data with third parties for marketing.
4. Where your data is stored
- Newsletter list: MailerLite (EU-based provider, GDPR-compliant)
- Newsletter mirror queue: Cloudflare KV (used internally to track which subscribers still need to be added to Substack - see §5)
- Substack subscriber list: Substack Inc. (US-based; we add new MailerLite subscribers to Substack manually so you receive both the newsletter and the public archive)
- Form submissions: Web3Forms (relays to Filip's inbox; Web3Forms does not retain submissions long-term)
- Email inbox: Google Workspace
- Analytics: Plausible (EU-hosted, cookieless)
5. Cookies and tracking
filipsardi.com does not use cookies for tracking, analytics, or advertising. Plausible Analytics is fully cookieless. We don't use Facebook Pixel, Google Analytics, or any cross-site trackers.
The only cookies that may exist are essential ones set by Cloudflare for security purposes (DDoS protection, bot mitigation).
6. Your rights (GDPR)
If you're in the EU/EEA you have the right to:
- Access: request a copy of any data we hold about you
- Rectification: correct inaccurate data
- Deletion: request permanent removal of your email and any associated data from MailerLite, Cloudflare KV, Substack, and Filip's inbox archive
- Export: receive your data in a portable format
- Object: object to specific processing
- Unsubscribe: every letter has an unsubscribe link, instant and one-click
To exercise any of these, email filip@filipsardi.com. We respond within 30 days, usually within 48 hours.
7. Data retention
We keep your data for as long as you're subscribed or actively in conversation with us. After unsubscribe or deletion request, your data is permanently removed within 30 days. Aggregate, anonymised analytics may be retained beyond that period.
8. Children
filipsardi.com is intended for business owners and professionals. We do not knowingly collect data from anyone under 18.
9. Changes to this policy
If we materially change how data is collected or used, we'll update this page and the "Last updated" date at the top. Significant changes are also communicated via the newsletter.
10. Contact
For any privacy-related question, email filip@filipsardi.com.