Data Processing Information
Last updated: April 17, 2026
This document supplements our Privacy Policy with detailed processing information as required under Article 28 of the GDPR.
Categories of personal data processed
| Category | Examples | Legal basis |
|---|---|---|
| Identification data | Name, email (when provided) | Consent / Contractual necessity |
| Contact data | Phone number, WhatsApp number | Contractual necessity |
| Communication data | Messages sent via WhatsApp, contact forms | Contractual necessity |
| Technical data | IP address, browser, device, pages visited | Legitimate interest (security, analytics) |
| Marketing data | Cookie preferences, opt-in status | Consent |
| Transaction data | Order details, billing info | Contractual necessity / Legal obligation |
Categories of data subjects
- Website visitors
- Prospective customers (inquiries, quotes)
- Customers (orders, contracts)
- Newsletter subscribers (if applicable)
Sub-processors
We work with the following third-party processors under appropriate Data Processing Agreements (DPAs):
| Sub-processor | Purpose | Location | DPA |
|---|---|---|---|
| Cloudflare, Inc. | Website hosting and CDN | USA (EU servers configured) | Yes |
| Lemon Squeezy | Digital plan checkout & payments | USA | Yes |
| WhatsApp (Meta) | Customer communication | USA / EU | Standard contractual clauses |
International transfers outside the EU are protected by Standard Contractual Clauses or other GDPR-approved mechanisms.
Retention periods
| Data type | Retention period |
|---|---|
| Inquiry messages | 2 years from last contact |
| Order/contract data | 10 years (legal accounting requirement) |
| Marketing consent | Until withdrawn |
| Cookie preferences | 12 months |
| Server logs | 90 days |
| Backups | 30 days |
Security measures
- HTTPS encryption (TLS 1.3) for all data in transit
- Encrypted backups
- Access controls and audit logs
- Regular security updates and patching
- Staff training on data protection
Data breach notification
In case of a personal data breach, we will:
- Notify the Romanian Data Protection Authority (ANSPDCP) within 72 hours
- Notify affected individuals if the breach poses high risk
- Document the breach internally
Your rights regarding data processing
See Privacy Policy for full details on your GDPR rights, including access, rectification, erasure, restriction, portability, and objection.
To exercise any right or for data processing inquiries, contact: +40 769 716 498 (WhatsApp).
This document is provided as a template and should be reviewed by a qualified Data Protection Officer or legal counsel before relying on it for compliance.