Legal · updated 29 September 2026
Personal data processing policy
In short: we receive only what you leave in the form yourself — your phone number and, if you wish, a comment. No analytics, no cookies, no tracking. We will not sell your data or pass it to anyone for their own purposes. Any question about your data — [email protected].
1. Who processes your data
The data controller is Digitme SRL, address: Bucharest, Sector 6, 3 Arieșul Mare Street, ground floor, room 1, space no. 49, block I10, staircase 5, apt. 63.
Processing is carried out in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, GDPR), which has applied since 25 May 2018, and Romanian Law no. 190/2018 on measures implementing it.
For any question about your data, write to [email protected] or call +40 764 671 177.
2. When we receive your data
We process data in the following cases:
- You fill in the form on the site
- A request for a call back or for a review of your situation.
- You write or call us
- By email or on the phone number given on the site.
- You simply browse the site
- The site does not track you: no analytics, no cookies, no advertising pixels. The server only keeps ordinary technical logs (see section 3.3).
- We start working together
- The data needed to conclude and perform a contract.
3. What data we process
- 3.1. Your phone number
- The only required field of the form.
- 3.2. Your comment and the page address
- The text you write in the optional comment field, and the address of the page from which the form was sent. We do not collect advertising tags, click identifiers or analytics identifiers.
- 3.3. Technical logs
- Like any web server, ours records the IP address, browser type, the address requested and the time of the request. The site is delivered through Cloudflare, which processes the same technical data to protect the site and deliver it quickly.
- 3.4. Data for performing a contract
- Company registration details, contact persons and the information needed to issue documents, if we begin working together.
4. What we do not collect
We do not request and deliberately do not process special categories of data: health information, religious or political beliefs, biometrics. Please do not enter such information in the comment field.
5. Why we process data
- 5.1. To answer your enquiry
- To call you back, clarify the task, prepare and send a proposal.
- 5.2. To provide the services
- To carry out the work under the contract, correspond with you and report on results.
- 5.3. To meet our legal obligations
- Accounting and tax records, retention of source documents.
- 5.4. To keep the site running and secure
- To detect faults and defend against spam, attacks and abuse.
6. On what grounds we do this
- Steps prior to a contract and the contract itself
- When you leave an enquiry, we process the data because you asked us to reply and prepare a proposal (Article 6(1)(b) GDPR).
- A legal obligation
- Retention of accounting and tax documents for the statutory periods (Article 6(1)(c) GDPR).
- Our legitimate interest
- Protecting the site from abuse, keeping an internal record of enquiries and defending our rights in the event of a dispute (Article 6(1)(f) GDPR). We weigh that interest against your rights.
7. Cookies and analytics
We do not use them. This site sets no cookies — neither our own nor anyone else’s — and has no analytics, counters or advertising pixels. That is why there is no consent banner: there is nothing to ask consent for.
If this ever changes, we will update this policy and the cookie page first, and ask for your consent where the law requires it.
8. Who we pass data to
We do not sell your data and do not pass it to third parties for their own purposes. Access is granted only to those without whom the service is impossible:
- Our own staff
- Only those who need it to work on your enquiry.
- The Bitrix24 CRM
- Enquiries from the site land in our CRM, where they are worked on.
- Telegram
- An internal notification about a new enquiry, so that we do not miss it.
- Cloudflare
- Protection and delivery of the site; it processes technical data about requests.
- Public authorities
- Only on a lawful basis and to the extent provided for by law.
9. Transferring data outside the EU and the EEA
Some of the services we use may process data outside the European Union and the European Economic Area. Data is transferred there only where there is a lawful basis under GDPR: an adequacy decision of the European Commission or appropriate safeguards, such as standard contractual clauses.
10. How long we keep data
Once the period expires, the data is deleted or anonymised.
- Enquiries that did not become a working relationship
- No longer than three years from the last contact — for keeping a record of enquiries and defending our rights.
- Client data under a contract
- For the term of the contract and thereafter for the periods set by law for accounting and tax documents.
- Technical logs
- For a short period needed for security, after which they are deleted.
11. How we protect data
We apply technical and organisational measures proportionate to the risks: access to data is segregated and granted only where needed, the connection to the site is encrypted, system credentials are protected and reviewed regularly, and backups are made.
If a breach occurs that could create a risk to your rights, we will notify the supervisory authority and, where the law requires it, you.
12. Your rights
In respect of your data you have the rights listed below. To exercise any of them, write to [email protected]. We will reply within one month, as GDPR requires. We may ask you to confirm your identity — so as not to hand your data to someone else.
- To be informed and to have access
- To find out what data of yours we hold and what we do with it.
- To rectify inaccurate data
- And to complete incomplete data.
- To erase data
- Where there is no lawful basis for continuing to process it.
- To restrict processing
- In the cases provided for by law.
- To object to processing
- Where it is based on our legitimate interest.
- To receive data in a portable form
- And to transfer it to another controller.
- To lodge a complaint
- With the supervisory authority or in court.
13. Where to complain
If you believe we have infringed your rights, write to us first — we will try to sort it out. That does not deprive you of the right to approach the supervisory authority directly:
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), B-dul G-ral. Gheorghe Magheru nr. 28-30, Sector 1, București. Email: [email protected], phone: +40 318 059 211, website: www.dataprotection.ro.
14. Changes to this policy
We may update this policy: our tools, our services and the requirements of the law change. The current version is always published on this page, and the date of the last update is shown next to the heading.
If the changes are material, we will announce them in a visible way.
Digitme SRL
Bucharest, Sector 6, 3 Arieșul Mare Street, ground floor, room 1, space no. 49, block I10, staircase 5, apt. 63
[email protected] · +40 764 671 177