Privacy policy
What data we receive through the website, why, how long we keep it and what rights you have over it.
Last updated:
Who processes your data
The controllers of your personal data are the two Romanian sole traders (PFA) operating under the Snow Globe Solutions brand:
POP ROBERT [DE COMPLETAT]
- Registered office
- [DE COMPLETAT]
- Trade Register no. (ONRC)
- [DE COMPLETAT]
- Tax ID (CUI)
- [DE COMPLETAT]
- VAT status
- [DE COMPLETAT: platitor / neplatitor]
- Phone
- 07xx xxx xxx
- contact@snowglobe.ro
BUTNARIU OVIDIU-IUSTINIAN [DE COMPLETAT]
- Registered office
- [DE COMPLETAT]
- Trade Register no. (ONRC)
- [DE COMPLETAT]
- Tax ID (CUI)
- [DE COMPLETAT]
- VAT status
- [DE COMPLETAT: platitor / neplatitor]
- Phone
- 07xx xxx xxx
- contact@snowglobe.ro
We decide jointly on the purposes and means of processing, so we are joint controllers within the meaning of Article 26 of Regulation (EU) 2016/679 (the General Data Protection Regulation, “GDPR”). The essence of our arrangement: we are both responsible for complying with the GDPR for the data received through the website, and either of us receives and deals with your requests. Write to our shared address contact@snowglobe.ro; you may exercise your rights against each of us.
We process data in accordance with the GDPR, Romanian Law no. 190/2018 implementing the GDPR and Romanian Law no. 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector. Our activity does not require us to appoint a data protection officer (DPO).
What data we collect and why
We collect only the data you send us through the website and a small amount of technical data needed to run and secure it. We do not ask for sensitive data (for example health data) or for your national identification number.
Contact form
- Data
- your name, your phone number or email address (as you choose), your message, the page language, the date and time it was sent.
- Purpose
- to reply to you and, if you ask, to prepare a quote.
- Legal basis
- Article 6(1)(b) GDPR — steps taken at your request before entering into a contract; for messages unrelated to a contract, Article 6(1)(f) — our legitimate interest in replying to people who write to us, which does not affect your rights, because we use the data only for the reply you asked for.
Booking a call
- Data
- the chosen day and time, the method (phone or email), your phone number or email address, the page language and, when one is sent to you, the 4-digit confirmation code — stored only as a cryptographic fingerprint (hash), never in plain text, until it is confirmed or, if it is not, for at most one day after the code expires.
- Purpose
- to check that the phone number or email address is yours, reserve the slot, send you the confirmation (by text message or by email, with an .ics calendar file) and contact you at the chosen time.
- Legal basis
- Article 6(1)(b) GDPR — steps taken at your request before entering into a contract.
Abuse prevention
- Data
- the IP address from which the form or the code request is sent (for IPv6, the /64 network it belongs to) and, when booking, the phone number or email address the code is requested for — used only in the server’s memory to count requests, never written to the database or to the application logs, and deleted automatically at the end of the one-hour period; a hidden field that detects bots.
- Purpose
- to limit the number of requests and prevent spam or the mass sending of codes by text message and email.
- Legal basis
- Article 6(1)(f) GDPR — our legitimate interest in protecting the website and the people whose details could be misused (for example, so that nobody can send large numbers of codes to someone else’s phone). We have weighed it against your rights: we use the minimum amount of data, only in memory, for one hour at most and for no other purpose.
Server logs
- Data
- in the web server logs: IP address, date and time, requested page, the page you came from (if your browser sends it), browser type and response code; the application logs (contact form and booking) contain no IP addresses, and phone numbers and email addresses appear in them masked (for example a***@example.com).
- Purpose
- website security, finding and fixing errors, investigating abuse.
- Legal basis
- Article 6(1)(f) GDPR — our legitimate interest in keeping the website running securely. We have weighed it against your rights: only we can access the logs, they are not used to track you and they are deleted automatically after 30 days.
Clients, once a contract is concluded
- Data
- the details in the contract and invoices, and project correspondence.
- Purpose
- performing the contract, invoicing and bookkeeping.
- Legal basis
- Article 6(1)(b) GDPR — performance of the contract, and Article 6(1)(c) GDPR — compliance with our legal accounting and tax obligations.
Providing your data through the website is voluntary and is not a statutory or contractual requirement, but without a phone number or email address we cannot reply to you or confirm a booking.
For clients, identification and billing details are necessary to conclude the contract, and some of them are required by tax law for issuing the invoice; without them we cannot conclude the contract or issue the invoice.
What we do not do with your data
- We do not send marketing messages or newsletters.
- We do not build profiles or take decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (Article 22 GDPR).
- We do not sell or rent out your data.
- We do not send your messages to artificial intelligence services.
- We do not use cookies, analytics, tracking pixels or advertising — see our cookie policy.
- We do not knowingly collect data about minors; the website is aimed at businesses and adults.
Who receives your data
Only the two of us and the providers who give us technical support receive the data sent to us through the website. They are processors (Article 28 GDPR): their contracts with us require them to process the data only on our instructions and to protect it.
- server hosting provider: [DE COMPLETAT: name and data-centre country];
- email provider, through which we receive messages and send codes and confirmations: [DE COMPLETAT: name and country];
- text-message (SMS) provider, through which we send the code and the confirmation when you choose the phone option: [DE COMPLETAT: name and country].
For clients, the details in contracts and invoices also go to whoever keeps our accounts, if we use an accountant, and to the tax authorities, to the extent the law requires. We disclose data to other public authorities only when the law requires us to.
Transfers outside the EEA
We aim to have data processed within the European Economic Area (EEA). If any of our hosting, email or text-message providers processes data outside the EEA, the transfer takes place only on the basis of a European Commission adequacy decision or of the standard contractual clauses adopted by the Commission (Articles 45–46 GDPR). On request, we will tell you which safeguard applies and how to obtain a copy of it.
How long we keep your data
- contact messages: 365 days from submission, and bookings: 365 days from confirmation; after that they are deleted automatically from the database;
- unconfirmed booking requests: the code is valid for 10 minutes, and an expired request is deleted automatically within one day;
- copies of messages received by email: for no longer than the same period of 365 days, after which we delete them;
- IP addresses (and, when booking, the phone number or email address) used to limit requests: only in the server’s memory, until the end of the one-hour period, after which they are deleted automatically;
- server logs: 30 days, after which they are deleted automatically;
- client data: for the duration of the contract and then for as long as accounting and tax law requires.
Your rights
- right of access: to find out whether we process your data and to receive a copy of it (Article 15 GDPR);
- right to rectification: to have inaccurate data corrected and incomplete data completed (Article 16);
- right to erasure: to have your data deleted when there is no longer a ground for keeping it (Article 17);
- right to restriction of processing (Article 18);
- right to data portability for the data you provided to us, where we process it for pre-contractual steps or to perform a contract, in a structured, commonly used and machine-readable format (Article 20);
- right to lodge a complaint with a supervisory authority and to go to court (Articles 77–79).
Right to object (Article 21 GDPR): you may object at any time, on grounds relating to your particular situation, to processing based on our legitimate interest — abuse prevention, server logs and replying to messages unrelated to a contract. We will then stop the processing, unless we demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or the data is needed to establish, exercise or defend legal claims.
How to exercise your rights
Write to us at contact@snowglobe.ro, stating which right you wish to exercise. If we have reasonable doubts about your identity, we may ask for additional information solely to confirm that the request comes from you (for example a message from the same phone number or email address).
We reply without undue delay and in any event within one month of receiving the request. This period may be extended by two further months for complex or numerous requests; in that case we will inform you of the extension, and of the reasons for it, within one month of receiving the request. Requests are dealt with free of charge, unless they are manifestly unfounded or excessive (Article 12 GDPR).
Complaints to the supervisory authority
If you believe that we are processing your data unlawfully, you can lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral Gheorghe Magheru 28–30, sector 1, 010336 București, Romania, www.dataprotection.ro (opens in a new tab). You may also complain to the supervisory authority of the EU Member State where you have your habitual residence, where you work or where the alleged infringement took place.
If you wish, you can write to us first so that we can try to resolve the matter together; this is not a precondition for lodging a complaint.
How we protect your data
- an encrypted connection (HTTPS) between your browser and the server;
- confirmation codes stored only as a hash, valid for 10 minutes and with a limited number of attempts;
- request rate limiting and bot filtering;
- no IP addresses in the application logs, and phone numbers and email addresses masked in them;
- automatic deletion of data at the end of the retention period;
- access to the server and the data only for the two of us.
No measure guarantees absolute security. If a personal data breach occurs that may affect you, we will notify the ANSPDCP and, where the law requires it, you as well (Articles 33–34 GDPR).
Changes to this policy
We update this policy when the law or the way we process data changes. The version in force is the one on this page, with the date of the last update shown at the top.