Privacy Policy

We respect the confidentiality of your data and process it with the same rigour we apply to the security of the organisations we protect. This page explains what data we collect, why, how long we keep it, what rights you have and how you can exercise them, in accordance with the General Data Protection Regulation (GDPR).

1. Our commitment

We treat personal data with care, lawfulness and transparency. As a provider of cybersecurity services, data protection is not a formality for us, but part of the value we deliver to our clients.

2. The data controller

The controller that determines the purposes and means of processing the data collected through this website is IT EMBASSY SRL, with its registered office at 4-6 Colonel Constantin Blaremberg St., 3rd floor, ap. 4B, District 1, 011879 Bucharest, Romania. Contact: cybersecurity@it-embassy.ro, telephone +40 31 640 00 55.

For any question regarding data protection, you can write to us at privacy@it-embassy.ro.

3. The principles we apply

  • Lawfulness, fairness and transparency in processing.
  • Collection of data for specified and legitimate purposes.
  • Minimisation of the data processed.
  • Accuracy and updating of data.
  • Limitation of the storage period to what is strictly necessary.
  • Integrity and confidentiality, through appropriate security measures.
  • Accountability, through the ability to demonstrate compliance.

4. What data we process

We process two categories of data:

  • Data you provide to us directly, through the forms on the website, by email or by telephone: your name, organisation, job title, email address, telephone number and the content of your message.
  • Data collected automatically when you visit the website, in minimal volume: IP address, browser type and pages accessed, used for the operation and security of the website.

5. Purposes and legal bases of processing

We process your data in order to:

  • respond to requests and communicate with you, on the basis of our legitimate interest in conducting correspondence (Article 6(1)(f) GDPR);
  • take steps prior to entering into a contract, at your request (Article 6(1)(b));
  • send you our newsletter, if you have subscribed, on the basis of your consent (Article 6(1)(a)), which you may withdraw at any time;
  • comply with our legal obligations (Article 6(1)(c));
  • ensure the security and proper functioning of the website, on the basis of legitimate interest.

6. Our roles

For data collected through this website and in correspondence, we act as controller. In our relationship with our clients, when we process personal data on their behalf as part of our services, we act as processor, on the basis of data processing agreements.

7. Disclosure of data

We do not sell or rent your data. We may entrust it to suppliers who support us, such as hosting and email services, acting as processors under contracts that impose the same protection obligations on them. We may disclose data to authorities when required by law.

8. International transfers

If some of our suppliers process data outside the European Economic Area, we apply the safeguards provided by law, such as the standard contractual clauses approved by the European Commission.

9. Storage period

We keep data only for as long as necessary for the purpose for which it was collected or as required by law. Commercial correspondence is kept for the duration of the relationship and a reasonable period afterwards, after which it is securely deleted or anonymised.

10. Security of processing

We apply appropriate technical and organisational measures to protect data against unauthorised access, loss or disclosure. As an ISO 27001 certified cybersecurity company, we take this responsibility with the utmost seriousness.

11. Incident notification

In the event of a security incident affecting personal data, we act in accordance with the legal obligations to notify the authority and, where applicable, the data subjects, within the deadlines set by the GDPR.

12. Your rights

As a data subject, you have the following rights:

  • the right of access to your data;
  • the right to rectification of inaccurate data;
  • the right to erasure of data, under the conditions of the law;
  • the right to restriction of processing;
  • the right to object to processing based on legitimate interest;
  • the right to data portability;
  • the right to withdraw consent, where processing is based on it;
  • the right to lodge a complaint with the supervisory authority.

13. How to exercise your rights

You can send a request to privacy@it-embassy.ro. We usually reply within one month of receiving the request, in accordance with the GDPR. We do not charge fees for exercising your rights, except in the situations expressly provided by law.

14. Supervisory authority

If you consider that the processing of your data does not comply with the law, you may contact the National Supervisory Authority for Personal Data Processing (ANSPDCP), based in Bucharest.

15. Changes

We may update this page to reflect changes in the way we work or in legal requirements. The version in force is the one published here, with the date of the last update indicated below.

Last updated: 16 September 2026.