CORE829
GDPR
Last updated: August 16, 2026
This page provides detailed information on how CORE829 SRL processes personal data in compliance with the GDPR (EU Regulation 2016/679) and the applicable Romanian legislation on personal data protection (Law no. 190/2018).
1. Data Controller
CORE829 SRL, Str. Mihai Eminescu, 10, Roman, Romania, Trade Register no. J2026029428009, CUI/CIF 54616345, is the data controller. You can contact us by email at hello@core829.net or by telephone at +40 766 668 482 / +39 375 946 8881.
2. Data we process
We process the data you provide voluntarily through our contact, quote and consultation forms: name, email, company, services of interest, estimated budget and message content. During a contractual relationship we also process invoicing and billing data. We process minimal technical data (IP address, browser type, pages visited) for the security and operation of the website.
3. Legal basis for processing
We process personal data on the following legal bases:
- your consent (Art. 6(1)(a) GDPR) for commercial communications;
- the performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR) for quote requests and service delivery;
- compliance with legal obligations (Art. 6(1)(c) GDPR) for accounting and tax purposes;
- legitimate interest (Art. 6(1)(f) GDPR) for the security and improvement of the website.
4. Data subject rights
You have the right to access, rectify, erase, restrict and port your personal data, and to object to its processing. You may withdraw your consent at any time. You can exercise these rights by writing to hello@core829.net; we will respond within 30 days.
5. Data retention
Personal data is retained only for the time necessary to respond to requests and manage the contractual relationship, in accordance with legal retention periods. Accounting data is kept for the periods required by law, after which it is securely deleted or anonymised.
6. Recipients and data processors
Personal data may be shared, only where necessary, with hosting, email, payment and invoicing providers, professional advisors and public authorities where required by law. All processors are bound by data processing agreements in accordance with Art. 28 GDPR.
7. Data transfers
We do not transfer personal data outside the European Economic Area. Where a transfer occurs through a third-party processor, appropriate safeguards under Chapter V GDPR are applied.
8. Automated decision-making
We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you.
9. Data security
We implement technical and organisational measures to ensure a level of security appropriate to the risk, including encryption of data in transit, access controls and regular reviews, in accordance with Art. 32 GDPR.
10. Contact and complaints
For any question regarding the processing of your personal data, or to exercise your rights, write to hello@core829.net.
You also have the right to lodge a complaint with the Romanian supervisory authority ANSPDCP (www.dataprotection.ro) or with the supervisory authority of your place of residence.