Privacy policy
What data we collect, why we collect it, how long we keep it and what rights you have over it. In plain language.
Last updated: 26 August 2026 · Version 2.0
In short
- We collect only the data we need to answer you and deliver the service.
- We never sell or rent data to anyone.
- Data is stored on servers inside the European Union.
- You can ask for access, correction or deletion at any time, at contact@sndteam.ro.
1. Who controls your data
SND Team is the data controller under Regulation (EU) 2016/679 (GDPR) and Romanian Law 190/2018.
- Email for data protection matters: contact@sndteam.ro
- Phone: +40 792 222 882
2. What we collect and why
2.1. Data you send through the contact form
What: name, company name (optional), email address, phone number (optional), the service you are interested in and the content of your message.
Why: to answer your enquiry and send you a quote.
Legal basis: steps taken at your request prior to entering into a contract — Article 6(1)(b) GDPR.
Retention: a maximum of three years from the last interaction, then deleted.
2.2. Technical access data
What: IP address, browser type and version, operating system, pages visited, date and time of access, referring page.
Why: to keep the site running and secure, prevent abuse and diagnose technical problems.
Legal basis: our legitimate interest in maintaining a secure, functioning service — Article 6(1)(f) GDPR.
Retention: a maximum of twelve months in server logs.
2.3. Usage data (analytics cookies)
What: aggregated statistics about how the site is used.
Why: to understand which content is useful and improve the site.
Legal basis: your consent, given through the cookie banner — Article 6(1)(a) GDPR. You can withdraw it at any time.
Full detail in our cookie policy.
2.4. Client data under contract
What: billing details, contact details of nominated people, and information needed to deliver the service.
Why: to perform the contract and meet our tax and accounting obligations.
Legal basis: performance of a contract — Article 6(1)(b) GDPR — and legal obligation — Article 6(1)(c) GDPR.
Retention: financial and accounting records are kept for the period required by law, generally ten years.
3. What we do not do
- We do not sell or rent your data.
- We do not use it for automated profiling with legal effects on you.
- We do not send you newsletters you did not ask for.
- We do not collect special categories of data such as health, political opinions or biometrics.
4. Who we share data with
Access is limited to members of our team who need it, and to the following categories of processors, under processing agreements compliant with Article 28 GDPR:
- Our web hosting provider — for storing the site and the messages received. Servers located in the European Union.
- Our email service provider — for receiving and sending correspondence.
- Our accounting provider — for financial records, limited to what the law requires.
We may also disclose data to public authorities where the law requires it.
5. Transfers outside the EU
We do not transfer personal data outside the European Economic Area. Should that become necessary, we would do so only under Chapter V of the GDPR (an adequacy decision or standard contractual clauses) and we would update this policy.
6. How we protect data
- Encrypted HTTPS/TLS connections across the whole site.
- Role-based access, using keys rather than shared passwords.
- Regular backups, stored separately.
- Security updates applied promptly.
- The contact form is protected against automated submissions.
7. Your rights
Under the GDPR you have the following rights:
- Access — to find out what data we hold about you and receive a copy.
- Rectification — to have inaccurate or incomplete data corrected.
- Erasure — to have data deleted where there is no longer a basis for keeping it.
- Restriction — to have our use of the data limited temporarily.
- Portability — to receive the data in a structured, commonly used format.
- Objection — to object to processing based on legitimate interest.
- Withdrawal of consent — at any time, without affecting the lawfulness of earlier processing.
- Complaint — to lodge a complaint with the supervisory authority.
How to exercise them: send an email to contact@sndteam.ro with your request. We reply within 30 days, free of charge. We may ask for additional information to confirm your identity.
Supervisory authority: the Romanian National Supervisory Authority for Personal Data Processing, ANSPDCP, Bucharest.
8. Children
Our services are aimed exclusively at businesses and professionals. We do not knowingly collect data from anyone under 16. If you become aware that a minor has sent us data, write to us and we will delete it.
9. Changes to this policy
We may update this policy when the way we work or the applicable law changes. The current version, with the date it was last updated, is always published on this page. For significant changes we notify active clients by email.
Want to exercise a right?
Send us an email and we will resolve it within 30 days, free of charge. No complicated forms and no being passed between departments.