PRIVACY POLICY
| Field | Value |
|---|---|
| Last updated | 01.05.2026 |
| Effective date | 01.05.2026 |
| Version | v 2.0 |
PREAMBLE
Thank you for your trust! The protection and confidentiality of your personal data represent a fundamental priority for us. We want to offer you full transparency regarding how we collect, process, and protect personal information when you use our website.
This Privacy Policy complements the Terms and Conditions of Use and the Cookie Policy and explains in detail our data-processing practices in accordance with the applicable legislation.
This Privacy Policy has been drafted based on a reasonable interpretation of the applicable legal provisions. However, the risk of a different interpretation by the competent authorities and/or courts of law cannot be excluded.
By using our website, you confirm that you have read, understood, and accepted this Privacy Policy.
ARTICLE 1 – IDENTIFICATION AND DEFINITIONS
1.1 Data Controller
| Field | Details |
|---|---|
| Company name | HOME INTEL S.R.L. |
| Legal form | Limited liability company |
| Registered office | Constanța County, Constanța Municipality, Poporului Street no. 36, 1st Floor, Room no. 4 |
| Trade Register No. | J20/602/2026 |
| Fiscal code (CUI) | 54427052 |
| GDPR email | contact@getyourconsultant.ro / contact@getyourconsultant.com (en) |
| Phone | 0750 288 398 |
| Website | www.getyourconsultant.ro (ro) / www.getyourconsultant.com (en) |
1.2 Data Protection Officer (DPO)
In accordance with Articles 37-39 of the GDPR, we have appointed a Data Protection Officer, whom you may contact at:
- Email: contact@getyourconsultant.ro with the subject line "DPO"
- Postal address: Constanța County, Constanța Municipality, Poporului Street no. 36, 1st Floor, Room no. 4
1.3 Important Definitions
| Term | Meaning |
|---|---|
| "Data" or "Personal data" | Any information relating to an identified or identifiable natural person |
| "Processing" | Any operation performed on personal data (collection, recording, organization, structuring, storage, use, transmission, etc.) |
| "Data subject" | You, as the natural person whose data is being processed |
| "User" | Any natural person who accesses the Website |
| "Client" | Any natural person who registers by creating an account on the Website |
| "Consent" | The freely given, specific, informed, and unambiguous indication of agreement to the processing of data |
| "GDPR" | General Data Protection Regulation (EU) 2016/679 |
| "Processor" | The natural or legal person who processes data on behalf of the Controller |
| "Website" | The website www.getyourconsultant.ro accessible at http://www.getyourconsultant.ro |
1.4 Applicable legal framework
The processing of personal data is carried out in strict compliance with:
- General Data Protection Regulation (GDPR) – EU 2016/679
- Law no. 190/2018 regarding measures for implementing the GDPR in Romania
- EU Directive 2002/58/EC (ePrivacy Directive)
- Relevant Romanian legislation on data protection
ARTICLE 2 – CATEGORIES OF DATA PROCESSED
2.1 Data collected from Users
| Category | Purpose | Legal basis for processing |
|---|---|---|
| The User's acceptance or refusal, IP address, date and time of access, visit duration, protocol (HTTP or HTTPS), browser type and version | Ensuring the recording of the User's consent | Legitimate interests – Art. 6(1)(f) GDPR |
| IP address, date and time of access, visit duration, protocol, browser type, settings and version, activities carried out on the website (collected through cookies) | Ensuring proper operation, maintaining security, and continuously improving the Website | Legitimate interests – Art. 6(1)(f) GDPR |
| Name, email address, phone number, data contained in the submitted message | Providing assistance and support through the Contact form | Legitimate interests – Art. 6(1)(f) GDPR |
| Email address (newsletter) | Sending marketing communications | User's explicit consent – Art. 6(1)(a) GDPR. Consent is separate from any contractual relationship |
2.2 Data collected from Clients
| Category | Purpose | Legal basis for processing |
|---|---|---|
| The Client's acceptance or refusal, IP address, date and time of access, visit duration, protocol, browser type and version | Ensuring the recording of the Client's consent | Legitimate interests – Art. 6(1)(f) GDPR |
| IP address, date and time of access, visit duration, protocol, browser type, settings and version, activities carried out on the website (collected through cookies) | Ensuring proper operation, maintaining security, and improving the Website | Legitimate interests – Art. 6(1)(f) GDPR |
| First name, last name, billing address, email address, ordered services, information included by the Client in the form submitted before the provision of services | Providing digital services in accordance with the Website Terms and Conditions | Performance of a contract – Art. 6(1)(b) GDPR |
| First name, last name, order ID, transaction ID, payment made / not made | Processing payments related to the services | Performance of a contract – Art. 6(1)(b) GDPR |
2.3 Data we do NOT collect
We explicitly state that we do NOT collect:
- Special categories of personal data (racial/ethnic origin, political opinions, religious beliefs, sexual orientation)
- Biometric or genetic data
- Health-related information
- Data regarding criminal convictions or offences
2.4 Separate consent for marketing
Consent for marketing communications (newsletter) is completely separate from the contractual relationship. Refusal or withdrawal of marketing consent does not in any way affect access to the platform services or the performance of the contract.
2.5 Consequences of refusing to provide data
We process only the personal data necessary to fulfill the legitimate purposes presented above. If you refuse to provide such data, we will not be able to interact properly, provide the services, or ensure their quality.
These consequences do not apply to data processed based on consent. Consent may be given freely, and refusal/withdrawal will not generate any negative consequences.
ARTICLE 3 – DATA PROCESSORS
In accordance with Art. 28 GDPR, we use the following data processors with whom we have concluded GDPR-compliant processing agreements:
| Processor | Service | Country/Area |
|---|---|---|
| Hosting/IT provider | Data storage and security | EEA |
| Email marketing services provider | Sending newsletters | EEA / USA (with adequate safeguards) |
| Web analytics provider (e.g. Google Analytics) | Statistics and optimization (pseudonymized data) | EEA / USA (Standard Contractual Clauses / SCC) |
| Payment services provider (e.g. Stripe, Smartbill) | Payment processing | EEA / USA (with adequate safeguards) |
All our processors provide sufficient guarantees regarding the implementation of appropriate technical and organizational measures so that processing complies with GDPR requirements. You may request an updated list of processors at contact@getyourconsultant.ro.
ARTICLE 4 – AUTOMATED DECISION-MAKING
Data provided by users may be processed by automated systems based on artificial intelligence for the purpose of generating personalized reports and analyses. These processes do not produce automated legal effects on users and do not involve exclusively automated decision-making within the meaning of Art. 22 GDPR.
The generated results are for informational purposes only and do not constitute professional, legal, or financial advice.
Right to human intervention: In accordance with Art. 22(3) GDPR, you have the right to obtain human intervention, express your point of view, and challenge any decision based on automated processing. You can exercise this right by contacting us at contact@getyourconsultant.ro.
ARTICLE 5 – DATA DISCLOSURE AND SHARING
5.1 Categories of recipients
| Recipient category | Purpose of disclosure | Type of Data |
|---|---|---|
| IT service providers | Hosting, website maintenance | Technical and browsing data |
| Email marketing service providers | Sending newsletters | Email, preferences |
| Web analytics providers | Statistics and optimization | Pseudonymized data |
| Payment service providers | Processing monetary transactions | Data required for payment processing |
| Competent authorities | Compliance with legal obligations | According to legal requests |
5.2 International transfers
Within the European Economic Area (EEA): We prefer providers located within the EEA. All transfers comply with GDPR standards.
Outside the EEA: If we decide to transfer data outside the EEA, we will use the safeguards provided by the GDPR: adequacy decisions of the European Commission or Standard Contractual Clauses. We will inform you in advance and you may obtain details at contact@getyourconsultant.ro.
ARTICLE 6 – DATA RETENTION AND DELETION
6.1 Retention periods
| Data category | Retention period | Justification |
|---|---|---|
| Browsing and consent data (IP, browser, access time, visit duration, protocol) | 3 years from the last interaction | Defence of rights in court; legal obligations |
| Contract data (first name, last name, billing address, email, ordered services, form information) | Duration of service provision and 5 years thereafter | Performance of the contract, tax/accounting obligations (Law 82/1991), and defence of rights in court |
| Marketing data (newsletter email) | Until consent is withdrawn | Consent – Art. 6(1)(a) GDPR |
Note: The 5-year period for contractual data is imposed by the tax and accounting obligations provided by Accounting Law no. 82/1991 and the Fiscal Code. The retention periods from the original document (3 years) were adjusted accordingly.
6.2 Deletion and destruction of Data
- Data is permanently deleted from all systems when the retention period expires
- Secure destruction of physical media is carried out
- Only anonymized data is retained for general statistics
- The process is documented according to internal procedures
ARTICLE 7 – SECURITY BREACH NOTIFICATION
In accordance with Articles 33-34 GDPR, in the event of a security breach that may generate a risk for your rights and freedoms:
- We will notify the National Supervisory Authority (ANSPDCP) within a maximum of 72 hours from becoming aware of the breach
- We will notify you personally, without undue delay, if the breach is likely to generate a high risk for your rights and freedoms
- The notification will include: the nature of the breach, the categories and approximate number of affected data subjects, the likely consequences, and the measures taken or proposed
- We maintain an internal register of all security breaches, regardless of whether they require notification to the authority
To report a potential data breach or security incident, you may contact us at: contact@getyourconsultant.ro with the subject line "SECURITY INCIDENT".
ARTICLE 8 – PERSONAL DATA SECURITY
8.1 Technical Security Measures
| Category | Implemented measures |
|---|---|
| Encryption | Encryption of data in transit (TLS/SSL) and at rest |
| Authentication | Multi-factor authentication systems |
| Monitoring | Continuous monitoring for suspicious activity |
| Backup | Regular and secure backup copies |
| Firewall | Advanced perimeter protection |
| Updates | Regular security patches |
8.2 Organizational Measures
| Category | Implemented measures |
|---|---|
| Internal policies | Strict procedures for data processing |
| Staff training | Regular data protection training |
| Access limitation | Access based on the need-to-know principle |
| Contracts | Confidentiality clauses with all employees and processors |
| Audits | Periodic reviews of security measures |
| Incident management | Procedures for reporting breaches (Arts. 33-34 GDPR) |
ARTICLE 9 – RIGHTS OF DATA SUBJECTS
9.1 Your rights
| Right | Description | How to exercise it |
|---|---|---|
| Information | The right to be informed about the data processed and the processing operations | This policy |
| Access | The possibility to obtain confirmation of processing and a copy of the processed data | Request by email |
| Rectification | The possibility to have inaccurate data corrected | Request with the correct data |
| Erasure | The possibility to have data deleted in the cases provided by law | Reasoned request |
| Restriction | The possibility to limit processing operations | Specific request |
| Portability | The right to receive the data in a structured, commonly used, machine-readable format (JSON/CSV) and to transmit it to another controller | Request by email; delivery within 30 days |
| Objection | The right to object to processing in the cases provided by law | Notice of objection |
| Human intervention | The right to obtain human intervention and contest automated decisions | Request by email |
| Withdrawal of consent | The right to withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal | Click unsubscribe or send an email |
9.2 Procedure for exercising rights
- Email: contact@getyourconsultant.ro
- Phone: 0750 288 398
- Postal address: Constanța County, Constanța Municipality, Poporului Street no. 36, 1st Floor, Room no. 4
Response deadlines: acknowledgment of receipt within a maximum of 5 business days; full response within a maximum of 30 calendar days; extension by 60 days in complex situations (with notice).
9.3 Right to lodge a complaint
National Supervisory Authority for Personal Data Processing (ANSPDCP)
| Field | Details |
|---|---|
| Address | B-dul G-ral. Gheorghe Magheru no. 28-30, Sector 1, Bucharest |
| Phone | +40.318.059.211 |
| anspdcp@dataprotection.ro | |
| Website | www.dataprotection.ro |
ARTICLE 10 – COOKIES AND SIMILAR TECHNOLOGIES
Our website uses cookies to improve the user experience. Analytics and marketing cookies are used only after the user's consent is expressed. Full details are available in the separate Cookie Policy.
| Cookie type | Consent requirement |
|---|---|
| Essential cookies – basic website functionality | No consent required |
| Performance cookies – traffic and behaviour analysis | Consent required |
| Marketing cookies – content personalization | Consent required |
| Social media cookies – integration with social platforms | Consent required |
ARTICLE 11 – DIRECT MARKETING AND COMMUNICATIONS
Legal basis: The user's explicit consent – Art. 6(1)(a) GDPR. Newsletter consent is entirely independent from any contractual relationship with the platform.
You may unsubscribe at any time through the unsubscribe link in each email or at contact@getyourconsultant.ro. Withdrawal of consent will not generate negative consequences and does not affect the lawfulness of prior communications.
ARTICLE 12 – MINORS' PROTECTION
Our website is intended for persons over the age of 18. We do not intentionally collect data from minors under 18. If we discover such data, we will delete it immediately. Parents may contact us for clarification.
ARTICLE 13 – CHANGES TO THE POLICY
This policy may be updated to reflect changes in applicable legislation, technological developments, or improvements to the services offered.
| Type of change | Notification method |
|---|---|
| Major changes | Notification by email to Clients at least 7 days before entry into force |
| Minor changes | Updating the version on the Website |
ARTICLE 14 – CONTACT DETAILS
| Type of request | Contact method |
|---|---|
| Exercising GDPR rights / DPO | contact@getyourconsultant.ro with the subject DPO |
| General questions | 0720 288 398 |
| Urgent complaints | contact@getyourconsultant.ro with the subject URGENT GDPR |
| Security incident notification | contact@getyourconsultant.ro with the subject SECURITY INCIDENT |
| Postal correspondence | Constanța County, Constanța Municipality, Poporului Street no. 36, 1st Floor, Room no. 4 |
ARTICLE 15 – AI REPORT DISCLAIMER
Reports generated through the platform are based on public data and automated algorithms. We do not guarantee the complete accuracy, timeliness, or completeness of the information provided. The User understands that these reports are used at their own risk.
By using our Website, you confirm that you have read and understood this policy.
© 2026 GetYourConsultant. All rights reserved.