Legal Documents

Privacy Policy

Last updated: February 24, 2026 · Version 1.0

Legal basis: Regulation (EU) 2016/679 (GDPR) · Law No. 190/2018 on GDPR implementation measures · Law No. 506/2004 · Directive 95/46/EC (repealed, replaced by GDPR)

1. Data Controller

The personal data controller is Emiliana Plus SRL, headquartered in Arad, Str. Preda No. 60, Romania.

  • GDPR Contact Email: office@emilianaplus.ro
  • Phone: +40 720 533 896
  • Data Protection Officer (DPO): Can be contacted at the email address above

2. What Data We Collect and Why

Data category Purpose Legal basis (GDPR) Storage period
Name, surname, email, phone Response to contact / quotation requests Art. 6(1)(b) — performance of a contract / pre-contract 3 years from last interaction
Site address, problem description DDD service delivery Art. 6(1)(b) — contract performance Duration of contract + 5 years (tax obligations)
Billing data (Tax ID, Reg. No.) Issuance of tax documents Art. 6(1)(c) — legal obligation (Law No. 82/1991) 10 years (Accounting Law)
IP address, browsing data Website security, anonymized statistics Art. 6(1)(f) — legitimate interest 90 days (server logs)

3. Your Rights (Art. 12–23 GDPR)

Right of access (Art. 15)

You can request a copy of the data held about you.

Right to rectification (Art. 16)

You can request correction of inaccurate or incomplete data.

Right to erasure (Art. 17)

"Right to be forgotten" — deletion of data when no longer necessary.

Right to restriction (Art. 18)

You can restrict processing of data under certain conditions.

Right to portability (Art. 20)

You can receive the provided data in a structured, accessible format.

Right to object (Art. 21)

You can object to processing based on legitimate interest.

To exercise your rights, contact us at office@emilianaplus.ro. We will respond within a maximum of 30 days in accordance with Art. 12(3) GDPR.

4. Data Transfer to Third Parties

Your data is not sold or transferred for marketing purposes to third parties. It may be shared exclusively with:

  • IT service providers who process data on our behalf (sub-processors under Art. 28 GDPR)
  • Public authorities, when legally required (ANAF, DSP, courts of law)
  • Contractual partners, exclusively for the execution of ordered services

All sub-processors are contractually obligated to maintain confidentiality and ensure the level of protection required by GDPR (Art. 28 GDPR).

5. Data Security

We implement appropriate technical and organizational measures in accordance with Art. 32 GDPR and Art. 10 of Law No. 190/2018:

  • HTTPS connection (TLS encryption) for all transmitted data
  • Restricted access to personal data
  • Regular backup systems
  • Monitoring of access and security incidents

In case of a security incident, we will notify you in accordance with Art. 33–34 GDPR (within max. 72 hours if there is a risk to your rights).

6. Cookies

For details about cookie usage, please see our Cookie Policy.

7. Policy Changes

We reserve the right to update this policy periodically. The updated version will be published on the website with the revision date. Continued use of the website after changes constitutes acceptance of the new version.

8. Supervisory Authority

If you believe your GDPR rights have been violated, you can file a complaint with:

National Supervisory Authority for Personal Data Processing (ANSPDCP)

Bd. Gen. Gheorghe Magheru 28–30, Sector 1, Bucharest

Tel: +40 318 059 211 · anspdcp.ro