Privacy and Cookie Policy
Effective date: 17 August 2026 · Version 2.0
1. Who we are
This policy explains how INOVITEC DESIGN S.R.L. processes personal data when you use inovitec.eu or contact us through this website.
Controller: INOVITEC DESIGN S.R.L.
Unique registration code: 39350397
Trade Register number: J2018000607200
EUID: ROONRC.J2018000607200
Registered office: Piața Unirii no. 9, floor 1, room 25, Deva 330152, Hunedoara County, Romania
Email: office@inovitec.eu
Telephone: +40 746 684 832
This policy covers inovitec.eu. The Romanian-language site inovitec.ro has its own privacy notice because its content and technical configuration are managed separately.
2. What data we process
Depending on how you use the website, we may process:
- Technical and security data: IP address, date and time, requested URL, referrer, browser and device information, operating system, response status and security events;
- Contact and enquiry data: name, email address, company, telephone number, the content of your message and any information you choose to provide;
- Consultation request data: information needed to understand your request, arrange a discussion or prepare a proposal;
- Cookie and consent data: your cookie choices and technical evidence required to remember and demonstrate those choices;
- Analytics data: information about visits, sessions, approximate location, browser and device, where analytics is enabled and the required consent has been obtained.
Please do not send special-category data, passwords, access credentials, classified information or unnecessary personal data through the public forms.
3. Why we process data and our legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Deliver the website, maintain availability and diagnose errors | Technical and security data | Legitimate interests, Article 6(1)(f) GDPR |
| Protect the website, forms and users against abuse, spam and attacks | Technical and security data, hCaptcha signals | Legitimate interests, Article 6(1)(f) GDPR |
| Answer enquiries and arrange consultations | Contact and enquiry data | Steps requested before entering into a contract, Article 6(1)(b), and legitimate interests, Article 6(1)(f) GDPR |
| Perform a contract or meet legal obligations | Relevant contact, contractual and transaction data | Articles 6(1)(b) and 6(1)(c) GDPR |
| Measure and improve the website through non-essential analytics | Cookie and analytics data | Consent, Article 6(1)(a) GDPR and the applicable electronic-communications rules |
| Establish, exercise or defend legal claims | Data relevant to the matter | Legitimate interests, Article 6(1)(f) GDPR |
Where processing is based on consent, you may withdraw it at any time without affecting processing that was lawful before withdrawal. We do not use the contact form to enrol you in marketing communications without a separate lawful basis.
4. Cookies, analytics and embedded services
We use necessary technologies to operate the website and remember security or consent choices. Non-essential analytics or similar technologies should operate only according to the choices recorded through our consent interface.
The website uses an Axeptio consent interface. You can review or change your choices at any time through the Cookie preferences link in the footer. Withdrawing consent does not affect the lawfulness of earlier processing.
Depending on your choices and the page you visit, the website may use:
- Google Tag Manager and Google Analytics to manage tags and measure website use. A standard analytics implementation may process session statistics, approximate location, browser and device information and an online identifier;
- Google Maps to display an interactive map. Loading the map may transmit your IP address and device/browser information to Google;
- hCaptcha to distinguish legitimate users from automated abuse. hCaptcha may process technical and behavioural signals, including the IP address and interaction data, for security purposes;
- Axeptio to display the consent interface and store evidence of your choices.
You can also restrict cookies through your browser. Blocking necessary technologies may affect site functionality. The exact cookies, providers, purposes and durations shown in the consent interface take precedence over generic descriptions when they are more specific and reflect the live configuration.
5. Contact forms
When you submit a form, we use the data to understand and answer your request, arrange a consultation, prepare a proposal or take other steps you have asked us to take. Fields that are not marked as required are optional.
Messages may be delivered by email and may also be recorded in the WordPress environment for operational troubleshooting. Access is limited to authorised personnel. Do not use the public form to transmit credentials, security logs, personal identity documents or confidential project files; contact us first to agree a suitable secure channel.
6. Service providers and recipients
We disclose personal data only where necessary for the purposes described above. Categories of recipients may include authorised INOVITEC DESIGN personnel, hosting and technical-service providers, email providers, professional advisers and public authorities where disclosure is legally required.
Current website-related providers include:
- Infomaniak Network SA, hosting and infrastructure provider. Website data is hosted in Switzerland. The European Commission recognises Switzerland as providing an adequate level of data protection;
- Google, for Tag Manager, Analytics and Maps, depending on configuration, consent and page use;
- Intuition Machines, Inc., provider of hCaptcha anti-abuse services;
- Axeptio, provider of the consent-management interface.
We do not sell personal data.
7. International transfers
Some providers may process data outside the European Economic Area. Switzerland benefits from an adequacy decision. For other destinations, transfers are made only where an applicable legal mechanism is available, such as an adequacy decision, participation in the EU-US Data Privacy Framework or Standard Contractual Clauses, together with supplementary measures where required.
8. Retention
We retain data only for as long as necessary for the purpose for which it was collected and to meet applicable legal, security and evidential requirements. The criteria are:
- technical and security logs: for the period needed to operate and protect the service, investigate incidents and meet hosting or legal requirements;
- enquiries that do not lead to a contract: until the request is closed and for a limited follow-up period appropriate to the subject;
- contractual and accounting records: for the periods required by applicable law and relevant limitation periods;
- consent records: for as long as needed to apply and demonstrate the recorded choice;
- data related to a dispute or incident: until the matter and applicable retention obligations are resolved.
We periodically review the necessity of retained data. A legal hold, security incident or binding request may require longer retention.
9. Your rights
Subject to the conditions in the GDPR, you may request access, rectification, erasure, restriction, portability and information about recipients. You may object to processing based on legitimate interests and withdraw consent at any time. You also have the right not to be subject to a decision based solely on automated processing where it produces legal or similarly significant effects.
To exercise a right, email office@inovitec.eu. We may need to verify your identity and clarify the scope of the request. We normally respond within one month; the GDPR permits an extension for complex or numerous requests, in which case we will explain the delay.
You may lodge a complaint with the Romanian supervisory authority:
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Website: dataprotection.ro
10. Security
We use HTTPS and apply technical and organisational measures proportionate to the risks of the processing. No internet service can guarantee absolute security. If you believe information submitted through this website has been compromised, contact us promptly at office@inovitec.eu.
11. Children
This website is intended for organisations and professionals and is not directed to children. We do not knowingly collect children’s data through the website.
12. Automated decisions
We do not use website data to make decisions based solely on automated processing that produce legal or similarly significant effects for visitors.
13. Changes to this policy
We may update this policy when the website, providers or legal requirements change. The effective date and version at the top identify the current text. Material changes affecting consent-based processing will be handled through the consent interface or another appropriate notice.
14. Applicable framework
This policy is based primarily on Regulation (EU) 2016/679 (GDPR), Romanian Law no. 190/2018 and Romanian Law no. 506/2004, in the versions applicable on the effective date.