Who is responsible for your data
The controller of the personal data described in this policy is Solandrix S.R.L. (CUI RO52108197, Reg. Com. J2025/049507/008), Bucharest, Romania. We decide why and how that data is processed.
For anything relating to your personal data - questions, requests, or complaints - write to office@solandrix.com or call +40 754 492 028 or +40 724 070 818. We have not appointed a Data Protection Officer, because our processing does not meet the criteria in Article 37 GDPR; the address above reaches the people who handle these requests directly.
What data we collect
This is a marketing website. We do not sell anything through it, we have no user accounts, and we do not build profiles of visitors. There are a few ways data reaches us:
- Contact form. Your name, email address, and the message you write are required. Your phone number and company name are optional - the form works without them. You also choose which service your enquiry is about.
- Record of your consent. When you tick the consent box we store the fact that you did, and when. This is our evidence that we were entitled to process your message, as Article 7(1) GDPR requires us to be able to demonstrate.
- Technical logs. Our hosting provider records the usual server-side information for every request - IP address, approximate time, the page requested, and your browser’s user-agent string. This is how attacks and abuse are detected.
- Cookieless traffic analytics. Cloudflare Web Analytics reports aggregate traffic patterns for every visit. It sets no cookies, does not track you across sites, and does not store data that identifies you individually.
- Analytics and session insights, only with your consent. If you accept the Analytics category in the cookie banner, Google Analytics 4 and Microsoft Clarity start running through Google Tag Manager. They report which pages are viewed, general location and device type, and Clarity additionally shows anonymized recordings of on-page behavior. Neither loads before you accept, and both stop the moment you withdraw consent.
- Your cookie choice. Whichever you choose in the banner - accept or decline - CookieHub stores that choice on your device so you are not asked again on every visit.
We do not ask for and do not want any special-category data under Article 9 GDPR - health, biometric, political, religious or similar information. Please do not include any in your message.
Why we process it, and on what legal basis
Every purpose below is tied to a specific legal basis under Article 6(1) GDPR.
- Replying to your enquiry - consent, Article 6(1)(a). You tick the box on the form; you may withdraw that consent at any time, and withdrawing it does not affect the lawfulness of what we did before you withdrew.
- Following up on a business enquiry you started, and keeping a record of what we discussed - legitimate interests, Article 6(1)(f). Our interest is in conducting and documenting business correspondence you initiated; we have weighed it against your interests and consider it proportionate, because you contacted us and the data involved is ordinary business contact information.
- Keeping the site available and secure, and preventing spam and abuse - legitimate interests, Article 6(1)(f).
- Understanding how visitors use the site (Google Analytics 4, Microsoft Clarity) - consent, Article 6(1)(a), given separately through the cookie banner rather than the form. Declining, or withdrawing consent afterwards, stops this collection going forward.
- Meeting accounting and tax obligations if we go on to work together - legal obligation, Article 6(1)(c).
We do not use your data for automated decision-making or profiling within the meaning of Article 22 GDPR, and we do not send marketing email to addresses collected through this form unless you separately ask us to.
How long we keep it
We keep personal data only for as long as the purpose it was collected for still exists.
- Enquiries that do not lead to work: up to 24 months from our last exchange, then deleted. Business conversations often resume after a long gap, and starting from a blank page each time serves nobody.
- Enquiries that become a project: for the duration of the engagement, then for the periods Romanian accounting and tax law require of the resulting records.
- Consent records: for as long as we hold the underlying message, so we can show the processing was lawful.
- Server logs: a short rolling window, typically no more than 30 days.
- Analytics and session data: kept under each provider’s own retention settings once you consent - Google Analytics 4 defaults to 14 months and Microsoft Clarity to 12 months, both counted from collection.
- Your cookie choice: kept for 12 months, then the banner asks again.
If you ask us to erase your data sooner, we will - see your rights below.
Who else sees it
We do not sell personal data and we do not share it for anyone else’s marketing. A small number of suppliers process data on our behalf, under written contracts that meet Article 28 GDPR and permit them to act only on our instructions:
- Website hosting and content delivery - serves the pages and runs the form endpoint.
- Email delivery - transmits your enquiry to our inbox and our reply back to you.
- Business email and file storage - where correspondence is read and kept.
- Bot protection on the contact form - Cloudflare, Inc. provides the Turnstile check that tells a person apart from an automated script. It receives your IP address and basic browser information, and only when you begin filling in the form: the check is not loaded while you are simply reading the site. We use it to keep the form usable rather than drowned in automated submissions, and it does not profile you or follow you to other sites.
- Web analytics - Cloudflare Web Analytics, from the same supplier, tells us which pages are read and roughly where readers arrive from. Unlike the bot check above, it runs on every page. It sets no cookies, writes nothing to your browser’s storage, and does not identify you by your IP address or browser fingerprint; what we see are totals, never individuals or journeys.
- Consent management - CookieHub runs the cookie banner, records the choice you make, and tells our tag manager which categories you accepted. It sets the one cookie that remembers your answer, and nothing else.
- Tag management and analytics, only once you consent - Google Tag Manager loads Google Analytics 4 (Google Ireland Limited) and Microsoft Clarity (Microsoft Ireland Operations Limited) if, and only if, you accept the Analytics category. Google Analytics reports page views, general location and device type; Clarity additionally records anonymized on-page behavior. Neither runs before you consent, and both stop the moment you withdraw it.
We may also disclose data where the law requires it - for example to a court or a competent authority acting within its powers.
Some of these suppliers process data outside the European Economic Area. Where that happens, the transfer is covered by an adequacy decision of the European Commission or by Standard Contractual Clauses together with supplementary measures where those are needed. Write to us if you would like details of the safeguards for a specific supplier.
How we protect it
The site is served over HTTPS, form submissions are transmitted encrypted, and access to the mailbox that receives them is restricted to the people who need it and protected by multi-factor authentication. No system is perfectly secure, but these are the measures we consider appropriate under Article 32 GDPR for the kind of data involved. If a breach ever occurs that is likely to result in a high risk to your rights, we will notify you as Article 34 requires.
Your rights
Under the GDPR you have the following rights over your personal data:
- Access (Article 15) - a copy of the data we hold about you, and an explanation of what we do with it.
- Rectification (Article 16) - correction of anything inaccurate or incomplete.
- Erasure (Article 17) - deletion, where we no longer have grounds to keep it.
- Restriction (Article 18) - a pause on processing while a dispute about accuracy or grounds is resolved.
- Portability (Article 20) - the data you gave us, in a structured, commonly used, machine-readable format, and transmitted to another controller where technically feasible.
- Objection (Article 21) - you may object at any time to processing based on our legitimate interests, and we must stop unless we can demonstrate compelling grounds that override your interests.
- Withdrawal of consent (Article 7(3)) - as easy to withdraw as it was to give.
To exercise any of these, email office@solandrix.com. We will respond within one month, as Article 12(3) requires; if a request is unusually complex we may extend that by up to two further months and will tell you why within the first month. We may ask you to confirm your identity, but only where we genuinely cannot otherwise be sure who is asking. Exercising these rights is free of charge.
Complaints
If you think we have handled your data badly, please tell us first - most problems are quicker to fix directly. You also have the right under Article 77 GDPR to complain to a supervisory authority, and doing so does not require you to contact us first.
The competent authority in Romania is the National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28–30, Sector 1, 010336 Bucharest - anspdcp.ro. If you live or work in another EU or EEA country, you may complain to the authority there instead.
Changes to this policy
We update this page when our processing changes. The revision date at the top of the page always reflects the current version. Where a change materially affects your rights, we will make that clear rather than quietly amending the text.