Pronet Design Pronet Design Pronet Design Pronet Design Pronet Design Pronet Design Pronet Design Pronet Design

0

Loading ...

Privacy Policy

SCROLL

This is an English translation provided for convenience. The Romanian version is the legally binding one: Politica de confidentialitate.

1. Data controller

For the purposes of the General Data Protection Regulation (GDPR) and applicable Romanian law, the data controller is:

 

SC PRONET DESIGN SRL

Company ID (CUI) / EU VAT: RO37360220

Trade Registry no.: J2017000474324

Registered office: Sibiu County, Selimbar, Doamna Stanca street, no. 5c, building B, flat 22, Romania

Place of business: Octavian Goga no. 29C, Sibiu, Romania

Phone: +40 775 211 299

Email: dpo@pronetdesign.ro

Website: https://pronetdesign.ro

 

2. Data protection contact

For questions about data protection, or to exercise your rights, write to dpo@pronetdesign.ro.

 

3. General information about how we process data

This policy explains what personal data we collect through our website, why we use it, the legal basis for processing, who we share it with, how long we keep it, and what rights you have under the GDPR.

 

4. Scope of processing

We collect and use personal data only as far as it's needed to run the site's features and to answer enquiries. Data may come from contact forms, from server log files, and from cookies or embedded third-party services such as Google Maps and Google reCAPTCHA.

 

5. What data we collect

We may collect the following categories of data:

  • data you give us directly: first name, last name, email address and the content of the message sent through the contact form;
  • technical data: IP address (stored temporarily in logs), browser type and version, operating system, internet provider, date and time of access, pages viewed, referrer;
  • data from cookies: preferences (theme colour), essential functional cookies, and non-essential cookies used by third-party services such as Google reCAPTCHA and Google Maps.

 

6. Legal basis for processing

Processing on this site relies on the following legal grounds:

  • consent (art. 6(1)(a) GDPR) - for data submitted through contact forms and for non-essential cookies (Google Maps, reCAPTCHA), only after you have given consent through an unticked checkbox or through the consent interface;
  • legitimate interest (art. 6(1)(f) GDPR) - for server logs and other processing strictly necessary for the operation, security and optimisation of the site (temporary IP storage, attack detection, anonymised internal analysis).

 

7. Log files and IP addresses

Your IP address and log file information are stored temporarily so the site runs correctly, so we can detect and prevent attacks, and for maintenance. This is based on our legitimate interest in the security of our systems.

Retention period for log files and IP addresses: 30 days at most, after which the data is deleted or anonymised, unless a longer period is needed to investigate a security incident.

 

8. Contact forms

The contact form collects whatever you type into its fields. When you submit it, we also store the following technical data: IP address, referring page, date and time of submission, browser and operating system.

The form can only be sent after you give explicit consent by ticking an unticked checkbox with wording along these lines:

"By sending this form you consent to us using the data you provide in order to contact you. The data will not be used for other purposes and is stored on our server. Details about the processing of personal data are in the Privacy policy."

Retention period for contact form data: 12 months at most from the last interaction, unless legal or contractual obligations require us to keep it longer.

 

9. Cookies and the consent management platform (CMP)

The site runs its own consent management platform, in line with the ePrivacy Directive and the GDPR. On your first visit, a non-dismissible banner explains your options across four cookie categories:

  • Necessary - always on, essential to the site working at all (pnet_consent, PHPSESSID, reCAPTCHA)
  • Preferences - Google Maps (interactive map on the Contact page)
  • Statistics - Google Analytics 4, Microsoft Clarity, Hotjar (if enabled)
  • Marketing - Facebook Pixel, TikTok Pixel, LinkedIn Insight, Google Ads (if enabled)

We use Google Consent Mode v2: before consent, every Google signal is set to denied; once you consent, the relevant signals are updated in real time through gtag('consent','update',...).

Your consent choices are stored in the first-party cookie pnet_consent (duration: 1 year) and recorded in our audit log (SHA-256 salted IP hash, the real IP is never stored), as required by article 7 of the GDPR - the obligation to demonstrate consent.

You can change your choices at any time using the Cookie Preferences button on the side of the page. Withdrawing consent takes effect immediately for the current session and applies to future ones.

For full details on each cookie we use, see the Cookie Policy.

 

10. Google services and international transfers

The site uses services provided by Google, such as Google reCAPTCHA for spam protection and Google Maps for displaying maps. These services may involve transfers of data to Google servers in the United States or other countries. Transfers to third countries take place on the basis of standard contractual clauses (SCCs) and the safeguards put in place by the provider.

Where relevant, the legal basis for this processing is your consent (for non-essential cookies) or legitimate interest in security (for bot detection, where such processing is justified). In practice, we ask for your consent before loading Google reCAPTCHA and Maps.

 

11. Data recipients

The following parties may access or process the data:

  • Hosting provider: Romarg SRL (servers located in Romania);
  • Third-party service providers: Google LLC (Maps, reCAPTCHA) and other technical suppliers involved in running the site, such as email, backup and maintenance services;

Any transfer to a third party happens under secure conditions and under contracts that set out GDPR-compliant obligations (processor agreements, SCCs for transfers outside the EU, as applicable).

 

12. Security measures

We apply reasonable technical and organisational measures to protect personal data against unauthorised access, disclosure, loss or destruction - restricted access to data, backups, secure transmission protocols. Only authorised staff and processors bound by confidentiality obligations can access personal data.

 

13. Your rights

Under the GDPR you have the following rights:

  • Right of access (art. 15 GDPR);
  • Right to rectification (art. 16 GDPR);
  • Right to erasure, the "right to be forgotten" (art. 17 GDPR);
  • Right to restriction of processing (art. 18 GDPR);
  • Right to data portability (art. 20 GDPR);
  • Right to object (art. 21 GDPR);
  • Right to withdraw consent at any time (art. 7 GDPR) - withdrawal does not affect the lawfulness of processing carried out beforehand;
  • Right not to be subject to automated decision-making, including profiling (art. 22 GDPR), where applicable.

To exercise these rights, send a request to dpo@pronetdesign.ro or to the company's postal address. We'll reply within the deadline set by the GDPR, normally one month, which can be extended in certain circumstances.

 

14. Complaints

If you believe the processing of your data breaches the GDPR, you have the right to lodge a complaint with the Romanian data protection authority (ANSPDCP):

ANSPDCP, Bd. G-ral Gheorghe Magheru nr. 28-30, Sector 1, Bucharest, Romania

Phone: +40 318 059 211

Email: anspdcp@dataprotection.ro

Website: https://www.dataprotection.ro

 

15. Retention periods

The main retention periods are:

  • Contact form data: 12 months from the last interaction;
  • Log files and IP addresses: 30 days (longer only in the event of a security incident or a legal obligation);
  • Cookies and data held by third-party services: as set by those providers, for example Google.

 

16. Updates to this policy

We may update this policy whenever it's necessary, for instance after a change in legislation or in the services we use. Any change is published on this page together with the date of the latest update.

 

17. Additional information

Checkboxes in the contact forms are unticked by default and require an explicit action from you before the form can be sent. The consent platform technically blocks every non-essential tracking script until you give consent for the matching category.

 

18. Contact

For any question about this policy or about the processing of personal data: dpo@pronetdesign.ro

More information on how Google processes data is available in their own policies: Google privacy policy, Google terms of service, Google Maps terms and the reCAPTCHA policy.

FOLLOW US