CORE829
Privacy Policy
Last updated: August 16, 2026
This Privacy Policy explains how CORE829 SRL collects, uses and protects personal data, in full compliance with the GDPR (EU Regulation 2016/679) and Romanian Law no. 190/2018 on personal data protection. This policy applies to the website core829.net and to all services offered by CORE829 SRL.
1. Data Controller
CORE829 SRL, with registered office at Str. Mihai Eminescu, 10, Roman, Romania, registered with the Trade Register under no. J2026029428009, CUI/CIF 54616345, is the data controller for the personal data processed through this website and through its services, in accordance with Art. 4(7) GDPR.
You can contact the controller by email at hello@core829.net or by telephone at +40 766 668 482 / +39 375 946 8881.
2. Data we collect
We collect only the data strictly necessary for the purposes described below:
- data you provide voluntarily through the contact, quote request and consultation forms: name, email address, company, service of interest, estimated budget and the content of your message;
- data you provide in the context of a contractual relationship: invoicing details, billing address, VAT number, contact data;
- minimal technical data collected automatically: IP address, browser type and version, device type, pages visited and timestamps, used exclusively for the security and correct operation of the website.
3. Purposes of processing
Your personal data is processed for the following purposes:
- responding to contact and quote requests and managing the pre-contractual relationship;
- providing and managing the requested services (Custom Servers, B2B Automations, Web Design, Web Apps, Executable Software, SEO Indexing, 360° Marketing Organic & Paid);
- invoicing, accounting and compliance with legal obligations;
- security and improvement of the website and services;
- sending commercial communications only where you have given your explicit consent.
We never sell or rent your personal data to third parties.
4. Legal basis
The processing of personal data is based on the following legal bases:
- the consent you give when submitting a form or subscribing to communications (Art. 6(1)(a) GDPR);
- the performance of a contract or pre-contractual measures taken at your request (Art. 6(1)(b) GDPR);
- compliance with a legal obligation to which the controller is subject (Art. 6(1)(c) GDPR), for example accounting and tax obligations;
- the legitimate interest of the controller in responding to business requests and ensuring the security of the website (Art. 6(1)(f) GDPR).
5. Recipients and data processors
Your personal data may be communicated, only where necessary and to the minimum extent required, to:
- providers of hosting, email and communication services;
- payment and invoicing providers;
- professional advisors (legal, accounting) bound by professional secrecy;
- competent public authorities, where required by law.
All data processors are bound by data processing agreements (DPA) and may process the data only on our documented instructions.
6. International transfers
We do not transfer your personal data outside the European Economic Area (EEA). Where third-party service providers process data on our behalf, they are bound by appropriate data processing agreements and, where a transfer outside the EEA occurs, by appropriate safeguards under Chapter V of the GDPR.
7. Data retention
Personal data collected through the forms is retained only for the time necessary to respond to requests and manage any contractual relationship, and in any case no longer than required by law.
Accounting and fiscal data are retained for the periods required by applicable law. At the end of the retention period, the data is securely deleted or anonymised.
8. Your rights
Under the GDPR you have the right to:
- access your personal data (Art. 15);
- rectify inaccurate data (Art. 16);
- erase your data (Art. 17);
- restrict processing (Art. 18);
- data portability (Art. 20);
- object to processing (Art. 21);
- withdraw your consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
You can exercise these rights by writing to hello@core829.net. We will respond within 30 days.
9. Data security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure or destruction, in accordance with Art. 32 GDPR. These measures include secure communications (HTTPS), access controls and periodic reviews of our security practices.
10. Changes to this policy
This Privacy Policy may be updated from time to time. Any change will be published on this page with the updated date. We invite you to review this page periodically.
11. Complaints
If you believe that the processing of your personal data violates the GDPR, you have the right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), Str. G-ral Gheorghe Magheru 28-30, Bucharest, Romania, or with the supervisory authority of your place of residence.