Privacy policy
Last updated: 23 August 2026. This policy describes what personal data is processed through diox-digital.ro, for what purposes and on what legal bases, who it may be disclosed to, how long it is kept and what rights you have under Regulation (EU) 2016/679 (GDPR).
1. Who the data controller is
The controller of your personal data is NAGY FRANCISC-DANIEL PERSOANĂ FIZICĂ AUTORIZATĂ (sole trader), CUI 47133739, trade register no. F40/5694/2022, registered office: B-dul Bucureștii Noi 136, ground floor, ap. 5, Sector 1, Bucharest, Romania, referred to below as "DioxDigital". Main activity: IT consultancy (CAEN 6220) — website creation, maintenance, GA4/GTM implementation, AI implementation and automation for businesses.
For any question about this policy or your data, you can contact me directly at contact@diox-digital.ro or +40 750 455 437. Being an independent practice rather than a call center, the answer comes from the same person who actually processes the data.
2. A few definitions, briefly
"Personal data" means any information about an identified or identifiable natural person (name, email, phone, IP address). "Processing" means any operation performed on it: collection, storage, consultation, transmission, deletion. The "data subject" is you, the visitor or client whose data is processed. The "controller" is the one who decides the purpose and means of processing, that is, DioxDigital.
3. What data I process
Data you send voluntarily, through the contact form or by email/phone: name, email address, phone number (optional), the content of your message and the project details you choose to share (type, estimated budget, timeline). Fields marked "optional" can be left empty with no consequence.
Data collected automatically, technically: the hosting server records, like any web server, log data (IP address, date and time of the request, page accessed, browser used), needed for the operation and security of the site. These logs are not used to identify visitors.
Measurement data: only if you accept the Analytics category in the consent banner, the measurement tools (Google Analytics 4) collect aggregate data about how the site is used, according to the cookie policy. By default, measurement is off.
Data I do NOT process: the site has no user accounts, processes no online payments, collects no sensitive data (health, beliefs, biometric data) and is not directed at children under 16.
4. How I collect the data
- Directly from you, when you fill in the contact form or write to me by email
- Directly from you, when you contact me by phone or through social networks (LinkedIn, Facebook)
- Automatically and to a limited extent, through the server's technical logs and, only with your consent, through measurement tools
I do not buy databases, collect data from brokers, or enrich visitor profiles with information from other sources.
5. What I use the data for
- Answering your enquiry and preparing an offer or a recommendation for the project
- Running the collaboration, if it starts: communication, delivery, invoicing
- Meeting legal obligations, especially fiscal and accounting ones
- Keeping the site running and secure
- Understanding, in aggregate form and only with your consent, how the site is used
Your data is not used for unsolicited email marketing, is not sold and is not rented to anyone, for any purpose.
6. Legal bases for processing
Under art. 6(1) GDPR, each processing activity has a precise basis:
- Pre-contractual steps at your request (lit. b): answering form enquiries and preparing offers
- Performance of the contract (lit. b): communication and delivery of services, once a collaboration starts
- Legal obligation (lit. c): issuing and keeping fiscal and accounting documents
- Legitimate interest (lit. f): the operation and security of the site, including the server's technical logs
- Consent (lit. a): traffic measurement through analytics tools, activated exclusively through the consent banner and revocable at any time
7. Who the data may be disclosed to
Your data stays with DioxDigital, with the following limited exceptions:
- The hosting provider of the site and mailbox, which technically stores the data on servers in the European Union
- Google, exclusively for aggregate measurement data and only if you accepted the Analytics category
- The accountant, for fiscal documents related to invoiced collaborations
- Public authorities, only where the law requires it and within the limits it sets
I do not share data with commercial partners, advertising networks or other third parties for marketing purposes.
8. International transfers
Form data and correspondence are stored in the European Union. The only transfer outside the EU can occur with measurement data (Google Analytics), where Google may process data on servers in the United States under mechanisms recognised by the European Commission (the EU-U.S. Data Privacy Framework and standard contractual clauses). This transfer exists only if you accepted the Analytics category.
9. How long I keep the data
- Contact messages with no subsequent collaboration: at most 3 years from the last contact, then deleted
- Documents related to collaborations (accepted offers, invoices): for the period required by fiscal and accounting law, currently 10 years for financial-accounting documents
- Your consent choice: locally, in your browser, until you change or delete it
- The server's technical logs: for the short period configured by the hosting provider, for security purposes
10. How the data is protected
The site uses encrypted connections (HTTPS), access to the mailbox and the admin area is protected by authentication, and data is not stored in more places than necessary. As a general rule, transmitting information over the internet can never be guaranteed to be completely secure; I do however apply reasonable technical and organisational measures, proportionate to the small volume and low sensitivity of the data processed.
11. Minimisation, accuracy, no automated decisions
I collect only the data strictly necessary for the purposes above: the contact form has no mandatory fields beyond what is needed for an answer. Inaccurate data is corrected on request. I use no automated decision-making and build no profiles that produce legal effects on you.
12. Your rights under GDPR
For any personal data processed by DioxDigital, you have the following rights:
- The right of access (art. 15): to find out what data I hold about you and receive a copy of it
- The right to rectification (art. 16): correction of inaccurate data or completion of incomplete data
- The right to erasure (art. 17, "right to be forgotten"): deletion of the data, except what the law obliges me to keep
- The right to restriction of processing (art. 18): limiting the processing in the situations set out in the regulation
- The right to data portability (art. 20): receiving the data in a structured, commonly used format and transmitting it to another controller
- The right to object (art. 21): objecting to processing based on legitimate interest
- The right to withdraw consent (art. 7): at any time, for processing based on consent, without affecting the lawfulness of prior processing
- The right to lodge a complaint (art. 77): with the Romanian supervisory authority ANSPDCP, B-dul G-ral Gheorghe Magheru 28-30, Sector 1, Bucharest, dataprotection.ro, or with the supervisory authority of your own EU member state
To exercise any right, write to contact@diox-digital.ro. I reply within 30 days at most, free of charge. For your safety, I may ask for reasonable confirmation of identity before releasing data.
13. Cookies and similar technologies
The identifiers used by the site, their categories, lifetimes and the way you control your consent are fully described in the cookie policy.
14. Changes to this policy
The policy is updated whenever processing practices change: for example, when traffic measurement is activated or a new tool is introduced. The current version and the date of the last revision are shown at the top of the page; significant changes will be signalled visibly on the site.