Privacy policy
Last updated: 26 August 2026
GDPR DRAFT — complete the controller identity, legal bases, retention periods and providers before launch.
Controller
[LEGAL NAME AND CONTACT DETAILS]. Data-protection contact: [EMAIL].
Data collected
Contact, organisation, billing/delivery and enquiry data, consents, strictly necessary technical data and cookie preferences. Do not submit medical data.
Purposes and legal bases
Responding to enquiries and taking pre-contractual steps; legal obligations; assessed legitimate interests and security; newsletters and analytics only on the basis of consent where required.
Recipients and transfers
Netlify hosts the staging version and may process form submissions. Final email, payment, courier and analytics providers must be listed together with relevant transfer mechanisms.
Retention
[SPECIFIC PERIODS TO BE COMPLETED for forms, contracts, invoices, newsletters, security and backups].
Rights
Access, rectification, erasure, restriction, objection, portability and withdrawal of consent, subject to the GDPR. Complaints may be lodged with Romania’s National Supervisory Authority for Personal Data Processing.
Security
Restricted access, encryption in transit, provider controls and incident procedures. Operational details will be documented before launch.