CORE829

CORE829

GDPR

Last updated: August 16, 2026

This page provides detailed information on how CORE829 SRL processes personal data in compliance with the GDPR (EU Regulation 2016/679) and the applicable Romanian legislation on personal data protection (Law no. 190/2018).

1. Data Controller

CORE829 SRL, Str. Mihai Eminescu, 10, Roman, Romania, Trade Register no. J2026029428009, CUI/CIF 54616345, is the data controller. You can contact us by email at hello@core829.net or by telephone at +40 766 668 482 / +39 375 946 8881.

2. Data we process

We process the data you provide voluntarily through our contact, quote and consultation forms: name, email, company, services of interest, estimated budget and message content. During a contractual relationship we also process invoicing and billing data. We process minimal technical data (IP address, browser type, pages visited) for the security and operation of the website.

3. Legal basis for processing

We process personal data on the following legal bases:

- your consent (Art. 6(1)(a) GDPR) for commercial communications;

- the performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR) for quote requests and service delivery;

- compliance with legal obligations (Art. 6(1)(c) GDPR) for accounting and tax purposes;

- legitimate interest (Art. 6(1)(f) GDPR) for the security and improvement of the website.

4. Data subject rights

You have the right to access, rectify, erase, restrict and port your personal data, and to object to its processing. You may withdraw your consent at any time. You can exercise these rights by writing to hello@core829.net; we will respond within 30 days.

5. Data retention

Personal data is retained only for the time necessary to respond to requests and manage the contractual relationship, in accordance with legal retention periods. Accounting data is kept for the periods required by law, after which it is securely deleted or anonymised.

6. Recipients and data processors

Personal data may be shared, only where necessary, with hosting, email, payment and invoicing providers, professional advisors and public authorities where required by law. All processors are bound by data processing agreements in accordance with Art. 28 GDPR.

7. Data transfers

We do not transfer personal data outside the European Economic Area. Where a transfer occurs through a third-party processor, appropriate safeguards under Chapter V GDPR are applied.

8. Automated decision-making

We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you.

9. Data security

We implement technical and organisational measures to ensure a level of security appropriate to the risk, including encryption of data in transit, access controls and regular reviews, in accordance with Art. 32 GDPR.

10. Contact and complaints

For any question regarding the processing of your personal data, or to exercise your rights, write to hello@core829.net.

You also have the right to lodge a complaint with the Romanian supervisory authority ANSPDCP (www.dataprotection.ro) or with the supervisory authority of your place of residence.