GDPR Compliance

The General Data Protection Regulation (GDPR) applies both to the data we process on our own behalf and to the data we process on behalf of our clients as part of our security services. This page describes how we meet these obligations.

1. Our commitment

I.T. Embassy processes personal data in accordance with the GDPR and applicable Romanian legislation, including Law no. 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector. We maintain a data protection programme integrated into our information security management system, certified to ISO 27001.

2. The principles of Article 5

All our processing complies with the principles laid down by the GDPR: data is processed lawfully, fairly and transparently; it is collected for specified, explicit and legitimate purposes; it is adequate, relevant and limited to what is necessary; it is accurate and kept up to date; it is kept only for as long as necessary; it is protected by appropriate technical and organisational measures. We are able to demonstrate compliance with these principles.

3. When we are a controller

We are the data controller for data collected through this website, in correspondence with you, in contractual relationships and in marketing activities. Details of these processing operations, their legal bases and your rights can be found in the Privacy Policy.

4. When we are a processor

In providing monitoring, detection and response, risk assessment or consultancy services, we may have access to personal data in our clients' systems. In these situations we act as a processor, exclusively on the documented instructions of the client and on the basis of a data processing agreement that complies with Article 28 of the GDPR. We do not use this data for other purposes and we delete or return it at the end of the services, as provided in the contract.

5. Security measures

We apply technical and organisational measures appropriate to the risk: access control on a need-to-know basis, strong authentication, encryption of data in transit and at rest, logging and monitoring, incident response procedures, regular staff training and confidentiality obligations for all employees and contractors.

6. Sub-processors and transfers

We use sub-processors only with the prior consent of the client, under the conditions of the data processing agreement, and impose the same data protection obligations on them. Transfers outside the European Economic Area take place only with the safeguards provided by the GDPR, such as standard contractual clauses.

7. Security incidents

We have procedures in place for detecting, investigating and handling incidents affecting personal data. As a processor, we notify the client without undue delay after becoming aware of an incident, so that the client can meet its obligation to notify within 72 hours. As a controller, we notify the supervisory authority and, where applicable, the data subjects, within the deadlines set by law.

8. Rights of data subjects

We support the exercise of the rights provided by the GDPR: access, rectification, erasure, restriction, objection, portability and withdrawal of consent. Requests can be sent to privacy@it-embassy.ro. When we act as a processor, we forward requests to the client concerned and support them in resolving them.

9. Contact

For any question regarding data protection, you can write to us at privacy@it-embassy.ro or at the postal address: IT EMBASSY SRL, 4-6 Colonel Constantin Blaremberg St., 3rd floor, ap. 4B, District 1, 011879 Bucharest, Romania.

Last updated: 16 September 2026.