Privacy Policy
Last updated: 20 March 2026
This English version is provided for convenience. The Romanian version is the legally binding one. Versiunea în română
1. Data controller
The controller of personal data is SYTE.ro, with its registered office in Bucharest, Romania. You can contact us at hello@syte.ro for any request regarding your personal data.
2. What data we collect
We collect the following categories of personal data:
- Contact data: name, email address, phone number, provided voluntarily through the messages you send us
- Browsing data: IP address, browser type, pages visited, visit duration, collected automatically through cookies
- Billing data: the data needed to issue invoices for the contracted services
3. Purpose of processing
Personal data is processed for:
- Providing the contracted services
- Communicating with clients and potential clients
- Improving the website and the services
- Complying with legal obligations
- Direct marketing (only with the user's explicit consent)
4. Legal basis for processing
Processing is based on: your consent (art. 6(1)(a) GDPR), the performance of the contract (art. 6(1)(b) GDPR), legal obligations (art. 6(1)(c) GDPR) and legitimate interest (art. 6(1)(f) GDPR).
5. Retention period
Personal data is kept for the duration of the contractual relationship and afterwards in line with legal obligations (e.g. tax data, 10 years). Data received through contact messages is kept for a maximum of 2 years from the last interaction.
6. Your rights
Under the GDPR, you have the following rights:
- Right of access: you can request a copy of your personal data
- Right to rectification: you can ask for inaccurate data to be corrected
- Right to erasure: you can ask for your data to be deleted (“the right to be forgotten”)
- Right to restriction of processing
- Right to data portability
- Right to object, including to direct marketing
To exercise these rights, contact us at hello@syte.ro. We will reply within 30 days at most.
7. Data sharing
We do not sell your personal data. Data may be shared with: hosting providers, payment processors and public authorities (where the law requires it).
8. Data security
We implement appropriate technical and organisational measures to protect personal data, including SSL/TLS encryption, restricted access and regular backups.
9. Supervisory authority
If you consider that the processing of your data breaches the GDPR, you have the right to lodge a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP): www.dataprotection.ro