This notice explains how CarMosi Business Park SRL (company in formation) processes the personal data of visitors to carmosibusinesspark.ro, in line with Article 13 of Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR) and applicable Romanian law.
1. Data controller
CarMosi Business Park SRL (company in formation), represented by Deian Carmazan. The registered office and registration details are published on the Legal notice page.
E-mail for any data protection question: [email protected]
The company is not required to appoint a data protection officer (Article 37 GDPR). Please send requests to the e-mail address above.
2. What data we process
- Data you send us through the contact form or by e-mail: name, e-mail address, organisation (if any), subject and message.
- Technical data, processed automatically by the hosting provider to deliver and secure the website: IP address, browser type, page requested, date and time. We do not keep logs containing IP addresses.
- Anonymous visit statistics: for each page view, the page, date, country (derived automatically from the IP address) and a pseudonymous identifier that changes daily are recorded. The identifier is computed with an irreversible cryptographic function from the IP address, browser type, date and a secret key. The IP address is not stored, and the identifier cannot identify you or follow you from one day to the next. We use this data only for aggregate figures (daily visits and unique visitors), without cookies.
We do not use cookie-based analytics, advertising or profiling, and we do not take decisions based solely on automated processing (Article 22 GDPR).
3. Purposes and legal basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Replying to your messages and requests | Art. 6(1)(b) – steps taken at your request before a possible collaboration; Art. 6(1)(f) – our legitimate interest in communicating with partners, authorities and the public |
| Delivering and securing the website, including access to the full content via a personal link until the public launch | Art. 6(1)(f) – our legitimate interest in a secure, working website |
| Anonymous, aggregate visit statistics | Art. 6(1)(f) – our legitimate interest in knowing the level of interest in the project |
| Compliance with legal obligations | Art. 6(1)(c) – legal obligation |
Providing data is voluntary. Without an e-mail address we cannot reply to you.
4. Recipients
Only the people in the company who need the data can access it. As processors (Article 28 GDPR), the following may process it:
- hosting provider: Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA (Cloudflare Pages and Workers services), for website delivery, security and the anonymous statistics;
- the company’s e-mail service provider, for receiving and storing messages.
Data may be disclosed to public authorities only where the law requires it. We do not sell or rent your data.
5. Transfers outside the European Economic Area
Cloudflare, Inc. is based in the USA. Transfers rely on the European Commission’s adequacy decision for the EU–US Data Privacy Framework (for certified providers) and, where applicable, standard contractual clauses (Articles 45 and 46 GDPR).
6. How long we keep data
- Messages and contact details: as long as needed to reply and for a possible collaboration, but no longer than 24 months after the last contact, unless the law requires a longer period.
- Anonymous visit statistics: up to 3 months (Cloudflare Workers Analytics Engine), then deleted automatically.
- Private access cookie: 90 days (see the Cookie Policy).
- Technical data processed by Cloudflare: under Cloudflare’s privacy policy, strictly for delivery and security.
7. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and the right to object, including to processing based on legitimate interest (Art. 21). To exercise them, write to [email protected]. We reply within one month of receiving your request (Art. 12(3)).
You have the right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral. Gheorghe Magheru nr. 28-30, sector 1, 010336 Bucharest, Romania, [email protected], www.dataprotection.ro.
8. Cookies
The website uses only strictly necessary cookies and local storage. Details in our Cookie Policy.
9. Security
The website is served over a secure connection (HTTPS). Fonts are hosted on the same server; the website does not load fonts, maps, videos or other content from third parties. We apply appropriate technical and organisational measures to protect data against unauthorised access, loss or alteration.
10. Changes
We may update this notice when the way we process data changes. The version in force is always the one published on this page.