Legal
Privacy Policy
Last updated: May 2026
This policy describes how INITWIN collects, uses, stores and protects personal data when you visit our website, contact us, subscribe to our newsletter, or use digital services we provide (e.g. client portal). We comply with Regulation (EU) 2016/679 (GDPR) and applicable national data protection law, including Romanian Law no. 190/2018.
privacyPolicy.intro2
privacyPolicy.intro3
1. Data controller
The controller of personal data is INITWIN (referred to below as "we", "the controller" or "the company").
For data protection requests, use the email address above with the subject "Data protection" or "GDPR". We respond within the time limits set by law (usually up to 30 days, with justified extension where permitted).
- Privacy / contact email: contact@initwin.com
- Contact form: https://www.initwin.com/en/contact
privacyPolicy.s1p3
2. Scope
This policy applies to processing carried out through:
- the public INITWIN website (informational pages, blog, portfolio, services);
- contact forms and commercial enquiries;
- newsletter subscription;
- creation and use of user accounts (clients, partners, authorised staff);
- client portal (projects, documents, support tickets), where active;
- email or phone communications related to our services;
- cookies and similar technologies (details in the
- privacyPolicy.s2li8
- privacyPolicy.s2li9
This policy does not replace service contracts or data processing agreements (DPAs) with business clients. For custom software projects, additional instructions may apply to data processed on behalf of the client.
3. Categories of data processed
Depending on how you interact with us, we may process:
3.1. Identification and contact data
- first name, last name, company name;
- email address, phone number;
- job title / role in the company (for B2B contacts);
- postal address, tax ID (if you provide them for quotes or invoicing).
- privacyPolicy.s31li5
- privacyPolicy.s31li6
- privacyPolicy.s31li7
3.2. Data from forms and communications
- content of your contact form message;
- service of interest, estimated budget, timelines (if provided);
- email correspondence and internal notes related to your request.
- privacyPolicy.s32li4
- privacyPolicy.s32li5
- privacyPolicy.s32li6
- privacyPolicy.s32li7
privacyPolicy.s32p1
3.3. Account and authentication data
- account email, password (stored encrypted, not in plain text);
- role and permissions in the platform;
- login history, sessions, password reset (where applicable);
- client profile data (projects, documents, tickets) — only for users with active access.
- privacyPolicy.s33li5
- privacyPolicy.s33li6
3.4. Newsletter and marketing
- subscriber email address;
- subscription date, source (site form, footer);
- communication preferences, if indicated;
- open/click statistics (if we use email marketing with tracking — only with consent where required).
- privacyPolicy.s34li5
- privacyPolicy.s34li6
privacyPolicy.s34p1
3.5. Technical data and logging
- IP address, browser type, operating system, language;
- pages visited, time on site, traffic source (referrer);
- cookie identifiers (see cookie policy);
- server logs for security, troubleshooting and abuse prevention (access, errors, unauthorised attempts).
- privacyPolicy.s35li5
- privacyPolicy.s35li6
- privacyPolicy.s35li7
- privacyPolicy.s35li8
- privacyPolicy.s35li9
- privacyPolicy.s35li10
privacyPolicy.s35p1
4. Purposes and legal bases
We process data for the purposes below, on the indicated legal bases:
privacyPolicy.s41Title
privacyPolicy.s41p1
privacyPolicy.s42Title
privacyPolicy.s42p1
privacyPolicy.s43Title
privacyPolicy.s43p1
privacyPolicy.s44Title
privacyPolicy.s44p1
privacyPolicy.s45Title
privacyPolicy.s45p1
privacyPolicy.s46Title
privacyPolicy.s46p1
privacyPolicy.s47Title
privacyPolicy.s47p1
5. Recipients and processors
Data may be accessed, where strictly necessary, by:
| Purpose | Examples | Legal basis (GDPR) |
|---|---|---|
| Responding to enquiries | Contact, quote, demo | Art. 6(1)(b) — pre-contractual measures / contract |
| Providing services | Software projects, support, client portal | Art. 6(1)(b) — performance of contract |
| Newsletter / marketing | News, articles, offers (if you subscribe) | Art. 6(1)(a) — consent |
| Site security | Authentication, CSRF protection, logs | Art. 6(1)(f) — legitimate interest |
| Traffic analytics | Google Analytics (if you accept cookies) | Art. 6(1)(a) — consent |
| Legal obligations | Invoicing, document archiving | Art. 6(1)(c) — legal obligation |
| Defence of rights | Disputes, complaints | Art. 6(1)(f) — legitimate interest |
6. Transfers outside the EEA
We aim to use providers that process data in the European Union or in countries with an adequacy decision. If a provider processes data in the USA or other third countries, we rely on appropriate safeguards (Standard Contractual Clauses, Data Privacy Framework where applicable, or other mechanisms permitted by GDPR). You may request further information about transfers at the contact address above.
privacyPolicy.s6p2
- privacyPolicy.s6li1
- privacyPolicy.s6li2
- privacyPolicy.s6li3
- privacyPolicy.s6li4
- privacyPolicy.s6li5
- privacyPolicy.s6li6
- privacyPolicy.s6li7
- privacyPolicy.s6li8
- privacyPolicy.s6li9
privacyPolicy.s6p3
privacyPolicy.s6p4
7. Retention period
We keep data only as long as necessary for the purposes for which it was collected:
When retention periods expire, data is deleted, anonymised or securely archived.
- Contact enquiries without a contract: usually up to 24 months from the last interaction, then deletion or limited archiving;
- Contractual relationship: for the duration of the contract and thereafter as required by law (accounting, disputes) — usually 5–10 years for tax documents, under applicable law;
- User account: until account deletion or prolonged inactivity (e.g. 24 months), with prior notice where possible;
- Newsletter: until unsubscribe or withdrawal of consent;
privacyPolicy.s7p3
8. Data security
We implement reasonable technical and organisational measures, including for example:
No system is 100% secure. If you suspect an issue with your account or your data, contact us immediately.
- encryption in transit (HTTPS/TLS) for the website;
- passwords stored with appropriate hashing algorithms;
- role-based access control in internal applications;
- CSRF protection and rate limiting for public forms;
- regular backups and monitoring;
- training for staff with access to data;
- procedures for security incidents (notification to authority and data subjects when mandatory).
privacyPolicy.s8p3
9. Your rights
As a data subject, you have the following rights (subject to legal limitations):
To exercise your rights, send a request to
- Right to be informed and of access — to know what data we process and receive a copy;
- Rectification — correction of inaccurate or incomplete data;
- Erasure ("right to be forgotten") — under Art. 17 GDPR conditions;
- Restriction — limiting processing in certain situations;
- Portability — receiving data you provided, in a structured format, where applicable;
- Objection — to processing based on legitimate interest, including direct marketing;
- Withdrawal of consent — at any time, without affecting prior lawful processing;
- Complaint — to your supervisory authority (in Romania: ANSPDCP —
- privacyPolicy.s9li9
- privacyPolicy.s9li10
- privacyPolicy.s9li11
We may ask you to verify your identity to protect your data from unauthorised access.
10. Automated decisions and profiling
We do not make decisions with legal or similarly significant effect based solely on automated processing (including profiling) in connection with the public website. If we introduce such features in the future, we will update this policy and inform data subjects where required.
- privacyPolicy.s10li1
- privacyPolicy.s10li2
- privacyPolicy.s10li3
- privacyPolicy.s10li4
- privacyPolicy.s10li5
- privacyPolicy.s10li6
privacyPolicy.s10p2
privacyPolicy.s10p3
privacyPolicy.s10p4 Cookie Policy.
11. Minors
Our website and services are intended for people aged at least 16 (or the applicable digital consent age in your country). We do not knowingly collect data from minors without parental or legal guardian consent. If you learn that a minor provided data without consent, contact us for deletion.
- privacyPolicy.s11li1
- privacyPolicy.s11li2
- privacyPolicy.s11li3
- privacyPolicy.s11li4
- privacyPolicy.s11li5
- privacyPolicy.s11li6
- privacyPolicy.s11li7
- privacyPolicy.s11li8
- privacyPolicy.s11li9 (www.dataprotection.ro).
privacyPolicy.s11p2 contact@initwin.com. privacyPolicy.s11p3
12. Links to third-party sites
The site may contain links to external websites (partners, documentation, social networks). We are not responsible for the privacy practices of those sites. Review their policies before providing personal data.
privacyPolicy.s12p2
13. Policy changes
We may update this policy to reflect legal, technical or business changes. The current version is published on this page with the update date in the header. For important changes, we may show a notice on the site or send information by email (for subscribers or clients, where applicable).
privacyPolicy.s13p2
14. Contact
For any questions about data protection or exercising your rights:
privacyPolicy.s14p2
privacyPolicy.s15Title
privacyPolicy.s15p1
privacyPolicy.s15p2
privacyPolicy.s15p3
privacyPolicy.s16Title
privacyPolicy.s16p1
privacyPolicy.s16p2
privacyPolicy.s16p3
privacyPolicy.s17Title
privacyPolicy.s17p1
- Privacy / contact email: contact@initwin.com
- Form: https://www.initwin.com/en/contact
Related documents: Cookie Policy · Terms & Conditions