Privacy Policy
Last Updated: 22 July 2026
This Privacy Policy describes how Sovogu Suziza ("we", "us", "our"), operating the website sovogu-suziza.info, collects, processes, stores, and protects personal data. It applies to all visitors and persons who contact us through this website. This policy complies with Regulation (EU) 2016/679 of the European Parliament and of the Council (the General Data Protection Regulation, "GDPR") and with Romanian Law No. 190/2018 on measures implementing the GDPR.
1. Data Controller
The data controller for personal data processed through this website is:
Sovogu Suziza
Calea 13 Septembrie 90, Bucharest, Romania
Email: [email protected]
Phone: +40 21 403 3528
As data controller, we determine the purposes and means of processing personal data collected through sovogu-suziza.info.
2. Personal Data We Collect and Why
The following table describes the categories of personal data we collect, the source of that data, the legal basis for processing, and the purpose for which it is used.
| Data Category | Data Elements | Legal Basis (GDPR Art.) | Purpose |
|---|---|---|---|
| Contact enquiry data | Full name, email address, phone number, subject of enquiry, message content | Art. 6(1)(b) — performance of pre-contractual steps; Art. 6(1)(f) — legitimate interest | To read and respond to enquiries sent via the contact form |
| Technical / log data | IP address, browser type, operating system, pages visited, timestamps | Art. 6(1)(f) — legitimate interest | Website security, error monitoring, and aggregate usage analysis |
| Cookie preference data | Consent record stored in browser cookie (ssz_cookie_consent) | Art. 6(1)(c) — legal obligation (ePrivacy Directive) | Recording and honouring cookie consent choices |
| Analytics data (where consented) | Anonymised or pseudonymised browsing behaviour, page interactions | Art. 6(1)(a) — consent | Understanding how the website is used in aggregate to improve content |
We do not collect sensitive personal data as defined by GDPR Article 9, and we do not collect data from persons known to be under 18 years of age. If you believe we have inadvertently collected data about a minor, contact us immediately at [email protected].
3. How We Use Your Data
Personal data submitted through the contact form is used exclusively to read and respond to the enquiry submitted. We do not use contact form data for marketing purposes, we do not add enquirers to mailing lists without explicit separate consent, and we do not share this data with third parties for their own marketing purposes.
Technical log data is retained for security and fraud-prevention purposes and is not used to build individual behavioural profiles. Access to log data is restricted to authorised personnel.
Where analytics cookies are enabled by a visitor, usage data is processed to understand aggregate patterns of site use. This information is reviewed internally and is not sold or transferred to advertising networks.
4. Data Retention
| Data Type | Retention Period | Reason |
|---|---|---|
| Contact enquiry emails | Up to 24 months from last communication | To maintain continuity of correspondence; deleted thereafter unless ongoing relation requires it |
| Server log files | Up to 90 days | Security monitoring; overwritten on a rolling basis |
| Cookie consent record | 365 days (stored in browser) | To avoid requesting consent on every visit; renewed upon re-consent |
5. Data Sharing and Third Parties
We do not sell personal data. We do not share personal data with third parties for their own commercial purposes. Limited sharing may occur in the following circumstances:
- With hosting and infrastructure providers who process data on our behalf under a Data Processing Agreement (DPA) compliant with GDPR Article 28;
- With analytics service providers where analytics cookies are consented to, under DPAs that restrict use of data to the purposes we define;
- Where required by applicable Romanian or EU law, by court order, or by a competent supervisory authority.
Any processor receiving personal data on our behalf is bound by contractual obligations consistent with GDPR requirements and may not process that data for their own purposes.
6. International Data Transfers
Where personal data is transferred to countries outside the European Economic Area (EEA), we ensure that appropriate safeguards are in place as required by GDPR Chapter V. These safeguards may include Standard Contractual Clauses approved by the European Commission, or reliance on adequacy decisions. Details of applicable safeguards can be provided upon request.
7. Your Rights Under GDPR
As a data subject under GDPR and Romanian Law No. 190/2018, you have the following rights:
| Right | What It Means | How to Exercise |
|---|---|---|
| Access (Art. 15) | Obtain confirmation of whether we process your data and receive a copy | Email [email protected] with "Data Access Request" in the subject line |
| Rectification (Art. 16) | Have inaccurate personal data corrected | Email with "Rectification Request" in subject |
| Erasure (Art. 17) | Request deletion of personal data where no legal basis for retention remains | Email with "Erasure Request" in subject |
| Restriction (Art. 18) | Request that processing be restricted while a dispute is resolved | Email with "Restriction Request" in subject |
| Portability (Art. 20) | Receive data you provided in a structured, machine-readable format | Email with "Portability Request" in subject |
| Objection (Art. 21) | Object to processing based on legitimate interests | Email with "Objection" in subject |
| Withdraw consent (Art. 7) | Where processing is based on consent, withdraw it at any time | Email or update cookie preferences via the cookie banner |
We will respond to rights requests within 30 days as required by GDPR Article 12. If a request is complex, we may extend this by a further 60 days with notice. Requests are handled free of charge unless manifestly unfounded or excessive.
You also have the right to lodge a complaint with the Romanian national supervisory authority: Autoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal (ANSPDCP), Bulevardul General Gheorghe Magheru 28-30, Bucharest. Website: www.dataprotection.ro
8. Security Measures
We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures are reviewed and updated as appropriate given the nature, scope, context, and purposes of processing and the risks to individuals.
Despite reasonable precautions, no transmission over the internet or electronic storage method is entirely secure. In the event of a personal data breach that is likely to result in risk to individuals, we will notify the ANSPDCP within 72 hours of becoming aware, and affected individuals where required by GDPR Article 34.
9. Cookies
This website uses cookies. For detailed information about the cookies we use, their purposes, duration, and how to manage your preferences, please see our Cookie Policy.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our processing activities, legal requirements, or for other operational reasons. When material changes are made, the "Last Updated" date at the top of this page will be revised. We encourage you to review this page periodically. Continued use of the website following a material change constitutes acknowledgement of the updated policy.
11. Contact
For any questions, concerns, or requests relating to this Privacy Policy or our handling of your personal data, contact us at:
Email: [email protected]
Post: Calea 13 Septembrie 90, Bucharest, Romania
Phone: +40 21 403 3528