This policy explains how OTELROM EXPORT S.R.L. processes personal data in accordance with Regulation (EU) 2016/679 ("GDPR") and Romanian Law no. 190/2018. It applies to our website, our online client portal and our commercial relationships.
OTELROM EXPORT S.R.L. · Registered office: Intrarea Gheorghe Simionescu, Nr. 19, Ap. B26, Sector 1, București, Romania · CUI 55420281 · Trade Register J2026049603006
Last updated: 28 August 2026
The controller is OTELROM EXPORT S.R.L., registered office at Intrarea Gheorghe Simionescu, Nr. 19, Ap. B26, Sector 1, Bucharest, Romania, CUI 55420281, Trade Register no. J2026049603006.
For any question concerning this policy or to exercise your rights, write to sales@otelrom.com. We have not appointed a Data Protection Officer, as our processing does not meet the criteria of Article 37 GDPR.
Website visitors: technical data recorded in server logs, namely IP address, date and time, page requested and browser identification.
Enquirers using the contact form: first name, surname, company, email address, telephone number and the content of the message.
Client portal users: username, email address, encrypted password, session data, the prices and selections submitted, and the activity record of actions performed in the portal.
Business contacts of clients, suppliers and partners: name, position, business email and telephone, and correspondence.
We do not process special categories of personal data and we do not carry out automated decision-making or profiling producing legal effects.
Responding to enquiries and preparing offers — Article 6(1)(b) GDPR (steps prior to entering a contract) and Article 6(1)(f) (our legitimate interest in commercial communication).
Performing contracts of sale and purchase, including delivery, invoicing and documentation — Article 6(1)(b) GDPR.
Operating the client portal, including authentication, submission of prices and the activity record — Article 6(1)(b) and Article 6(1)(f) GDPR, our legitimate interest being the security, traceability and evidential integrity of commercial transactions.
Security of our systems, prevention and investigation of misuse — Article 6(1)(f) GDPR.
Compliance with accounting, tax, customs and sanctions-screening obligations — Article 6(1)(c) GDPR.
Establishment, exercise or defence of legal claims — Article 6(1)(f) GDPR.
Our website does not use cookies, does not employ analytics or advertising technologies and does not track visitors across websites. For this reason no consent banner is displayed.
The client portal uses a single strictly necessary session cookie, which allows a signed-in user to remain authenticated. It contains no personal information beyond a random session identifier, expires when the session ends and requires no consent under Article 5(3) of Directive 2002/58/EC.
Personal data is accessible to our authorised personnel on a need-to-know basis and to the following categories of recipient: our hosting and infrastructure provider within the European Union; our email service provider; carriers and forwarders, for delivery data; banks, for payment data; and our accountants, auditors and legal advisers.
Processors act under written contracts meeting the requirements of Article 28 GDPR. We do not sell personal data and we do not disclose it for third-party marketing.
Data may be disclosed to public authorities where required by law.
Our servers are located within the European Union. Where a processor operates outside the European Economic Area, the transfer is based on an adequacy decision of the European Commission or on standard contractual clauses adopted under Article 46 GDPR, with supplementary measures where required.
Server logs: deleted on a regular cycle not exceeding six months, except where retained for the investigation of a security incident.
Contact-form enquiries: for the duration of the exchange and up to three years from the last contact, unless a contractual relationship arises.
Portal accounts and submitted prices: for the duration of the commercial relationship and for ten years thereafter, in accordance with accounting and evidential requirements.
Accounting and tax documents: ten years, in accordance with Romanian accounting legislation.
Data retained for the establishment or defence of legal claims: until the expiry of the applicable limitation period.
Subject to the conditions of the GDPR, you have the right of access (Article 15), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), data portability (Article 20) and the right to object to processing based on legitimate interests (Article 21), including at any time to processing for direct-marketing purposes.
To exercise these rights, write to sales@otelrom.com. We reply within one month, extendable by two further months for complex requests, and we may ask for information necessary to verify your identity.
Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
You may lodge a complaint with the Romanian supervisory authority: Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), B-dul G-ral. Gheorghe Magheru nr. 28-30, Sector 1, 010336 Bucharest, anspdcp@dataprotection.ro, www.dataprotection.ro. You may also lodge a complaint with the supervisory authority of your habitual residence or place of work, and you have the right to an effective judicial remedy.
We apply technical and organisational measures appropriate to the risk, including encryption of traffic in transit (HTTPS), storage of passwords using a salted key-derivation function, role-based access control, rate limiting and lock-out on repeated failed authentication, activity logging in the client portal, restricted server access, network filtering and regular software updates.
In the event of a personal data breach likely to result in a risk to the rights and freedoms of data subjects, we notify the supervisory authority within 72 hours in accordance with Article 33 GDPR and, where the risk is high, the data subjects concerned.
Where data is required for entering into or performing a contract, or by law, its provision is necessary and failure to provide it may prevent us from contracting or from delivering. In all other cases the provision of data is voluntary.
We may update this policy to reflect changes in our processing or in applicable law. The current version is always published on this page, with the date of the last update.