Legal

Privacy policy

How personal data is collected, used, protected and retained on crosstechit.com.

Last updated: 14 July 2026

This policy explains how CROSS TECHIT SRL, publicly operating as CROSSTECH IT, processes personal data through crosstechit.com. It is written for transparency and does not replace independent legal advice.

1. Data controller

CROSS TECHIT SRL
CUI 33978466
Trade Register J2015000059220
Iași, Iași County, Romania
contact@crosstechit.com

2. Scope

This policy applies to the English and Romanian pages of crosstechit.com, including project-enquiry forms and communications following an enquiry.

3. Data collected directly

When a visitor submits the contact form or communicates with us, we may process: name, email address, company when supplied, country when supplied, requested service, budget range when supplied, project description and the resulting communication history.

4. Technical data

The website and hosting infrastructure may process IP address, browser and device information, requested URLs, timestamps, security and server logs, and cookie and consent preferences. Optional analytics information is processed only after valid consent.

5. Purposes and legal bases

  • Responding to enquiries and taking steps requested before a potential contract — GDPR Article 6(1)(b).
  • Protecting the website, preventing abuse and maintaining security — legitimate interest under Article 6(1)(f).
  • Meeting applicable legal obligations — Article 6(1)(c).
  • Optional website analytics — consent under Article 6(1)(a).

6. No unsolicited marketing

Submitting the contact form does not automatically subscribe a visitor to marketing. The website does not currently operate a newsletter.

7. Recipients

Data may be processed by hosting and email infrastructure providers used to operate the website; specialists involved in reviewing or delivering a requested project, only when necessary; Google Analytics, only after valid analytics consent; and public authorities when legally required. Personal data is not sold.

8. Retention

  • Contact enquiries: up to 24 months after the last meaningful communication, unless a contractual or legal reason requires longer retention.
  • Security logs: normally up to 30 days, unless required to investigate an incident.
  • Cookie-consent preference: 6 months.
  • Google Analytics user-level and event data: the GA4 property must be configured to retain data for 2 months.
  • Contractual, accounting or legally required records: for the period required by applicable law.

9. International transfers

Some technology providers, including Google, may process data outside the European Economic Area. Where this occurs, applicable contractual and legal safeguards are used, such as European Commission standard contractual clauses and other transfer mechanisms available under data-protection law. We do not claim that all data always remains inside Romania.

10. Your rights

Depending on the circumstances, you may request access, rectification, erasure, restriction, portability where applicable, or object to processing. Where processing is based on consent, consent may be withdrawn at any time without affecting the lawfulness of processing before withdrawal. Requests can be sent to contact@crosstechit.com. Identity or additional context may be requested when necessary to handle a request securely.

11. Complaint to the supervisory authority

You may submit a complaint to the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal — ANSPDCP, 28–30 Bulevardul General Gheorghe Magheru, Sector 1, 010336 Bucharest, Romania. See the official complaints procedure and the official contact page.

12. Security

Appropriate organisational and technical measures are used to protect personal data, including access controls, secure transmission, server protections, validation and abuse-prevention measures. No internet service can promise absolute security.

13. Children

The website and services are directed toward businesses and professionals and are not intentionally designed to collect personal data from children.

14. Policy updates

When this policy is materially revised, the “Last updated” date will be changed. Material changes may also be highlighted on the website where appropriate.