1 — Introduction & Controller Identity
This Privacy Policy explains how Irvako Newsroom (“we”, “us”) collects, uses, and protects personal data when you visit https://irvako.site (the “Site”), contact our newsroom, or submit information through our forms. The Site is operated by FADI B.V., which is the data controller for the processing described in this policy.
Data Controller: FADI B.V., Gessel 5, 3454 MZ Utrecht, Netherlands. Contact email: [email protected]. Telephone: +31 30 711 4829.
We do not appoint a Data Protection Officer for this Site because our activities, as described here, do not involve large-scale regular monitoring or large-scale processing of special categories of data. If that changes, we will update this policy and provide a direct DPO contact channel.
2 — Personal Data We Collect
The data we collect depends on how you use the Site. We aim to keep collection proportionate to a newsroom’s needs: receiving tips, responding to enquiries, and maintaining basic security and performance.
- Identity and contact data: name (if provided), email address, telephone number (if provided), and any organisation or role you include in your message.
- Form content: message text, subject lines, and any context you choose to share (for example timecodes, programme descriptors, and a description of what appeared on a feed).
- Technical data: IP address, browser type and version, device type, operating system, language settings, and approximate location inferred from IP (city/region level).
- Usage data: pages viewed, time on page, referrer (where available), and navigation paths within the Site.
- Cookies and identifiers: cookie identifiers and consent choices as described in Section 4.
- Conversion events: indicators that a message was submitted (for example a “form submitted” event), used to measure whether our pages and forms are functioning.
We do not intentionally collect special-category data (such as health data, religious beliefs, or political opinions), financial account details, or government identification numbers through this Site. If you include such information in a message, we will handle it with care and limit access, but we encourage you to avoid sharing sensitive personal data unless it is necessary for your enquiry.
3 — Why We Process Personal Data & Legal Bases (GDPR Art. 6)
We process personal data for the purposes below, using the lawful bases provided by the EU General Data Protection Regulation (GDPR).
- Handling contact and tip submissions: responding to your message, clarifying details, and communicating about potential commissioned work. Legal basis: Art. 6(1)(b) (steps prior to entering a contract) and Art. 6(1)(a) (consent) where you provide explicit consent via the form checkbox.
- Running analytics: understanding how the Site is used and improving performance and readability. Legal basis: Art. 6(1)(a) (consent) for analytics cookies and analytics-based measurement.
- Marketing and remarketing measurement: measuring advertising relevance and performance when we run campaigns and you consent to marketing cookies. Legal basis: Art. 6(1)(a) (consent).
- Security and abuse prevention: protecting the Site, preventing automated abuse, and investigating suspicious traffic patterns. Legal basis: Art. 6(1)(f) (legitimate interests) in maintaining site security.
- Legal compliance: meeting legal obligations and responding to lawful requests. Legal basis: Art. 6(1)(c) (legal obligation).
Automated decision-making and profiling (Art. 22): we do not engage in automated decision-making or profiling that produces legal or similarly significant effects for you.
4 — Cookies & Tracking
Cookies are small text files stored on your device. Some are essential for the Site to function; others are optional and used only if you consent. In addition to cookies, we may use pixel tags and similar technologies to measure performance, but we do not load advertising or analytics trackers until consent is granted through the banner or preferences panel.
Cookie categories
- Essential cookies (always on): required for core functionality such as session continuity and remembering your consent choice. Examples include _site_session and cookie_consent. Retention ranges from session to 12 months.
- Analytics cookies (consent required): used to understand Site usage and improve content structure. Example: Google Analytics 4 (GA4) with IP anonymisation. Examples include _ga and _ga_XXXXXXXXXX. Data retention: 14 months.
- Marketing cookies (consent required): used for advertising measurement and relevance, including remarketing and conversion attribution. Examples include _gcl_au, _fbp, and _fbc when click identifiers are present.
Beyond cookies, some measurement may occur through server-side logs (for example IP address and user-agent strings) for security and reliability. Where pixel tags or similar technologies are used for analytics or marketing, they are treated under the same consent category as their equivalent cookies.
5 — Consent (EEA/UK)
Users in the European Economic Area (EEA) and the United Kingdom receive a consent notice under GDPR/UK GDPR. Marketing and analytics cookies activate only after explicit, informed, freely given consent (Art. 6(1)(a)). Your choice is recorded in the cookie_consent browser cookie for 12 months.
You may withdraw consent at any time by using the “Manage cookie preferences” option in the footer or by clearing cookies in your browser settings. Withdrawal does not affect the lawfulness of processing carried out before you withdrew consent.
6 — Sharing With Advertising & Service Partners
We use a limited set of service providers to operate and measure the Site. We do not sell personal data. When you consent to analytics or marketing, we may share certain identifiers and events with the providers below, subject to your cookie choices.
- Google LLC: Google Analytics 4, Google Ads measurement/remarketing, and tag management, as configured. Data may include cookie IDs, usage data, and conversion events. Policy: https://policies.google.com/privacy.
- Meta Platforms, Inc.: measurement and advertising relevance when marketing consent is granted. Data may include page views, conversions, audience membership, and hashed identifiers in server-side configurations. Policy: https://www.facebook.com/privacy/policy/.
- Cloudflare, Inc.: content delivery and security services that may process IP addresses for threat detection and performance. Policy: https://www.cloudflare.com/privacypolicy/.
We do not permit these providers to use Site data for their own independent commercial purposes beyond providing services to us, subject to their contractual terms and platform policies.
7 — International Transfers
Some of our providers are based outside the EEA, including in the United States. Where personal data is transferred internationally, we rely on recognised transfer mechanisms such as the EU–US Data Privacy Framework (where applicable), the UK Extension to the DPF, and Standard Contractual Clauses (EU 2021/914) as a fallback. We also apply technical and organisational measures appropriate to the data category and risk.
8 — Retention
We keep personal data only as long as necessary for the purpose it was collected. Retention periods vary by category:
- Contact and tip submissions: up to 2 years from the last interaction, unless a longer period is needed to manage an ongoing editorial or business relationship.
- Email correspondence: for the duration of the relationship plus 1 year, unless a longer period is justified by an active editorial record.
- Analytics: 14 months (as configured in GA4) after collection.
- Marketing cookies: retained according to the cookie lifetime (for example 90 days for certain advertising identifiers), and only when consent is provided.
- Server logs: typically 90 days for security diagnostics and abuse prevention.
- Cookie consent record: up to 3 years for audit and accountability purposes.
- Legal compliance: retained as required by applicable law (for example accounting records where relevant).
9 — Your Rights (GDPR & UK GDPR)
If GDPR applies to you, you have the right to request access to your personal data (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), and to object (Art. 21). Where processing is based on consent, you can withdraw consent at any time (Art. 7(3)).
To exercise your rights, email [email protected]. We aim to respond within 30 days; this can be extended by up to 60 days for complex requests, in which case we will tell you why.
You also have the right to lodge a complaint with a supervisory authority. For EU guidance, see https://edpb.europa.eu. In the Netherlands, the supervisory authority is the Autoriteit Persoonsgegevens: https://autoriteitpersoonsgegevens.nl.
10 — Children
This Site is not directed at individuals under 16. We do not knowingly collect personal data from minors. If we learn that we have received personal data from a child under 16 without verifiable parental consent, we will delete it promptly.
11 — Do Not Track Signals
This website does not respond to “Do Not Track” (DNT) browser signals. Some third-party providers may offer their own mechanisms for limiting tracking in their products.
12 — Data Deletion Requests
You may request deletion by emailing [email protected] with the subject line “Data Deletion Request”. We may ask for information to verify your identity and locate relevant records. Requests are handled within 30 days where feasible, subject to legal retention requirements.
13 — Business Transfers
If we undergo a merger, acquisition, asset sale, financing, or insolvency, personal data may be transferred to a successor entity. If such a transfer materially changes how your data is used, we will provide notice on the Site before the change takes effect.
14 — California (CCPA/CPRA)
Although we are based in the Netherlands, we may receive visitors from the United States. If you are a California resident and the CCPA/CPRA applies, the categories of personal information disclosed in the past 12 months may include identifiers (such as name, email, IP address), internet/network activity (such as browsing behaviour on our Site), and inferences (such as interests inferred for advertising relevance when marketing consent is granted).
We do not sell personal information as defined by CCPA. We may share information for cross-context behavioural advertising when you consent to marketing cookies; you can opt out through the cookie preferences panel. California residents may request access, deletion, or correction by emailing [email protected] with the subject line “California Privacy Request”. We will verify requests as required. Authorised agents must provide written proof of authorisation.
15 — Virginia (VCDPA)
If you are a Virginia resident and the VCDPA applies, you may request access, correction, deletion, portability, and opt out of targeted advertising. Submit requests to [email protected] with the subject line “Virginia Privacy Request”. We do not sell personal data or engage in profiling that produces legal or similarly significant effects. If you wish to appeal a refusal, email with the subject line “Appeal of Refusal — Privacy Request”; we will respond within 60 days.
16 — Nevada
Nevada residents may submit a verified opt-out request by emailing [email protected] with the subject line “Nevada Do Not Sell Request”. We do not currently sell personal information under Nevada Revised Statutes Chapter 603A.
17 — Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices, tooling, or legal requirements. If we make material changes, we will display a notice on the homepage at least 14 days before the changes take effect. The “Last Updated” date at the top of this page will change whenever we revise the policy.
18 — Contact
For privacy questions, requests, or complaints, contact:
FADI B.V.
Gessel 5
3454 MZ Utrecht, Netherlands
Email: [email protected]
Phone: +31 30 711 4829
Contact the newsroom
For privacy-related requests, email is the fastest route. For general tips and reporting enquiries, use the main contact channels below.