Last updated: 25 July 2026
1. Who processes your personal data
The personal data controller is:
CITEDA S.R.L.
Unique Registration Code: 53864903
Trade Register No.: J2026008867003
Registered office: Bucharest, Sector 3, 27–33 Nerva Traian Street, office 6, Staircase B, 1st Floor, Romania
Email: office@citeda.ro
In this policy, CITEDA S.R.L. is referred to as “CITeda”, the “company” or the “controller”.
2. Who this policy applies to
This policy applies to individuals who:
- visit the
citeda.rowebsite; - use the contact form;
- communicate with CITeda by email;
- express their preferences regarding cookies and similar technologies.
This policy explains what data we process, for what purposes, on what legal basis, with whom it may be shared, how long it is retained and what rights you have.
3. What data we process
3.1. Data submitted through the contact form
Depending on the fields you complete, the contact form may collect:
- your name;
- your email address;
- your telephone number, if provided;
- the type of enquiry;
- the content of your message;
- confirmation that you have read the Privacy Policy.
Please do not submit sensitive personal data or information that is not necessary for us to review your enquiry.
3.2. Data associated with communications
When you communicate with CITeda, we may retain:
- messages sent and received;
- your contact details;
- the date and time of the communication;
- information required to review and respond to your enquiry;
- any documents subsequently provided as part of the communication.
3.3. Technical and security data
When you access the website or submit the contact form, the following information may be recorded automatically:
- IP address;
- browser type and version;
- device and operating system information;
- date and time of access;
- the page accessed or the page from which the form was submitted;
- information concerning message validation and delivery;
- technical errors and security events;
- the result of anti-spam checks.
3.4. Cookie preferences
The cookie management mechanism may retain:
- the preference you expressed;
- the date and time of your choice;
- the categories of cookies accepted or rejected;
- a technical identifier associated with the preference;
- technical information required to remember your choice.
4. Purposes and legal bases for processing
4.1. Managing enquiries and preparing a potential engagement
We process data in order to:
- review the message submitted;
- contact the person who submitted the enquiry;
- provide a response;
- clarify requirements;
- prepare a proposal or a potential contractual relationship.
Where the enquiry concerns a potential engagement, the legal basis for processing is taking steps at the request of the data subject prior to entering into a contract.
4.2. Managing general communications
For enquiries that are not directly related to entering into a contract, processing is based on CITeda’s legitimate interest in communicating with interested persons and managing incoming correspondence.
4.3. Website security and prevention of abuse
Technical data is used to:
- prevent automated messages and spam;
- detect unauthorised access attempts;
- prevent fraud and cyberattacks;
- diagnose errors;
- protect the website and information systems.
The legal basis for processing is CITeda’s legitimate interest in ensuring the security of its information systems and services.
4.4. Compliance with legal obligations and protection of rights
Certain data may be retained or disclosed where this is necessary to:
- comply with a legal obligation;
- respond to a request from a public authority;
- establish, exercise or defend legal claims;
- manage a security incident.
4.5. Optional cookies
Where the website uses cookies that are not strictly necessary, they are activated only after you express your choice through the cookie management mechanism.
Data submitted through the contact form is not used for newsletters, advertising or unsolicited marketing communications.
5. How the contact form is processed
The contact form is managed using Contact Form 7.
A copy of the message and the associated data may be stored in the WordPress system through the Flamingo plugin. The message is also sent to CITeda’s email address through the SMTP system configured for the website.
The confirmation included in the form confirms that the individual has read this policy. It does not represent consent to marketing and is not used for sending unsolicited commercial communications.
6. Anti-spam protection through Google reCAPTCHA
The website uses Google reCAPTCHA to detect and limit automated messages, spam and abusive use of the contact form.
For the purpose of carrying out its risk analysis, Google may receive technical information relating to:
- IP address;
- browser and device;
- date and time of interaction;
- the page accessed;
- how the user interacts with the website.
The service may place technical cookies required to perform its risk analysis.
This processing is carried out for the purpose of protecting the website and the contact form against abuse. The use of reCAPTCHA is subject to Google’s applicable privacy policy and terms of service.
7. Who may receive the data
Personal data may be accessed or processed, to the extent necessary, by:
- authorised persons within CITeda;
- the website hosting provider;
- the email service provider;
- providers of maintenance, security and backup services;
- Google, through the reCAPTCHA service;
- legal, tax or technical advisers, where access is justified;
- public authorities and institutions, where disclosure is required by law.
Service providers receive only the data necessary for the provision of their respective services.
CITeda does not sell or rent personal data.
8. International data transfers
The use of services supplied by international companies, including Google, may involve the processing of data outside the European Economic Area.
In such circumstances, the transfer must be based on a mechanism recognised under applicable law, such as an adequacy decision or standard contractual clauses, as appropriate.
Information on how Google processes and transfers data is available in its privacy documentation.
9. How long we retain the data
As a general rule, CITeda applies the following retention periods:
- enquiries that do not result in an engagement: 12 months from the last communication;
- copies of messages stored through Flamingo: 12 months from the last communication;
- technical, security and email delivery logs: up to 90 days, unless an incident is identified;
- cookie preferences: 12 months;
- data temporarily included in backups: until it is removed in accordance with the backup rotation cycle, but no longer than 90 days;
- data and documents relating to a contractual relationship: for the duration of the relationship and subsequently in accordance with legal obligations and the applicable limitation periods for the protection of legal rights.
Data may be retained for a longer period where this is required by law or necessary in connection with litigation, an investigation or a security incident.
Once the relevant retention period expires, the data is deleted, anonymised or archived in accordance with applicable law.
10. Data security
CITeda uses technical and organisational measures proportionate to the nature of the data and the risks associated with processing, including:
- secure HTTPS connections;
- access controls for website administration;
- protection against unauthorised login attempts;
- regular updates of website components;
- anti-spam protection;
- backups;
- limiting access to persons who need the data;
- monitoring technical errors and security incidents.
No method of electronic transmission or storage can completely eliminate all security risks.
11. Automated decision-making
CITeda does not use data collected through the website to make decisions based solely on automated processing that produce legal effects or similarly significant effects on individuals.
Google reCAPTCHA performs an automated assessment solely for the purpose of identifying the risk of spam or abuse.
12. Your rights
Subject to the conditions established by applicable data protection legislation, you may request:
- confirmation as to whether or not we process personal data concerning you;
- access to your data and information about the processing;
- correction of inaccurate data or completion of incomplete data;
- deletion of your data, where the legal conditions are met;
- restriction of processing;
- objection to processing based on legitimate interests;
- data portability, where applicable;
- withdrawal of consent for optional cookies, without affecting processing carried out before the withdrawal;
- information about the safeguards used for any international data transfers;
- the right to lodge a complaint with the supervisory authority.
To exercise your rights, please send your request to:
To protect personal data, CITeda may request additional information necessary to verify the identity of the person submitting the request.
Requests will be handled within the period required by applicable law, normally within one month.
13. Right to lodge a complaint
Where you believe that your personal data has been processed in breach of applicable legislation, you have the right to lodge a complaint with:
The Romanian National Supervisory Authority for Personal Data Processing — ANSPDCP
Address: 28–30 General Gheorghe Magheru Boulevard, Sector 1, Bucharest, postal code 010336, Romania
Email: anspdcp@dataprotection.ro
Telephone: +40 31 805 92 11
Before lodging a complaint, we encourage you to contact us at office@citeda.ro so that we may try to resolve the matter directly.
14. Cookies
The website may use:
- cookies that are strictly necessary for its operation and security;
- cookies required to remember user preferences;
- cookies associated with the reCAPTCHA service;
- other optional cookies, only where they are configured and accepted.
Cookie preferences may subsequently be changed through the cookie management mechanism available on the website.
Technical details and the active cookie categories are described in the cookie banner and in the cookie preference management panel.
15. Changes to this policy
This policy may be updated where there are changes to:
- the website’s functionality;
- the categories of data processed;
- the service providers used;
- the applicable retention periods;
- applicable legal requirements.
The current version and the date of the most recent update will be published on this page.
