Privacy Policy
Last Updated: 22 July 2026
This Privacy Policy describes how Vatobe Xicepu ("we," "us," "our") collects, uses, stores, and protects personal data when you visit vatobe-xicepu.info (the "Website"). This policy is drafted in compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council (the General Data Protection Regulation, "GDPR") and Romanian Law no. 190/2018 on measures implementing Regulation (EU) 2016/679 at national level.
1. Controller Identity
The data controller for personal data processed through this Website is:
Vatobe Xicepu
Calea Dorobanți 133, Bucharest, Romania
Email: [email protected]
Phone: +40 744 227 435
As data controller, we determine the purposes and means of processing personal data collected through this Website. Any questions regarding the exercise of your data protection rights should be directed to the contact details above.
2. Legal Framework
Our data processing activities are governed by the following legal instruments:
Regulation (EU) 2016/679 (GDPR) applies directly in Romania as an EU Member State. Romanian Law no. 190/2018 supplements the GDPR with national implementation measures, including provisions on the processing of special categories of data, restrictions on data subject rights in specific contexts, and the supervisory authority's powers. The national supervisory authority responsible for data protection in Romania is the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), reachable at anspdcp.ro.
Directive 2002/58/EC (ePrivacy Directive), as implemented in Romanian law, governs the use of cookies and electronic communications. We comply with this Directive as transposed by Law no. 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector, as amended.
3. Data We Collect
We collect personal data only to the extent necessary for the purposes described in this policy. The categories of data we may collect are as follows:
Contact enquiry data: When you submit the contact form, we collect your email address, any name you choose to provide (optional), and the content of your message. This data is transmitted directly to our email inbox via your email client.
Automatically collected technical data: Our web hosting provider may automatically collect server log data including your IP address (which may constitute personal data), the date and time of your visit, the pages you accessed, your browser type and version, and the referring URL. This data is collected at the infrastructure level and is not actively used by us for profiling or marketing purposes.
Cookie data: Where you have consented, analytics cookies may collect anonymised information about your browsing behaviour on this Website. Your cookie preferences are stored in a browser cookie named "vxi_consent." See Section 5 for full details.
4. Purposes and Legal Basis
Each processing activity rests on one of the lawful bases established under Article 6 GDPR:
Responding to contact enquiries (Article 6(1)(b) GDPR — pre-contractual steps): When you contact us through the form, we process your email address and message content to review and respond to your enquiry. This processing is necessary to take steps at your request prior to any potential engagement.
Website operation and security (Article 6(1)(f) GDPR — legitimate interests): Server log data is processed to maintain the technical functioning and security of the Website. Our legitimate interest in operating a secure and functional website is balanced against the minimal intrusiveness of server-level logging.
Analytics (Article 6(1)(a) GDPR — consent): Where you have consented through our cookie consent mechanism, we may use analytics tools to understand aggregated usage patterns. This processing is conditional on your consent and may be withdrawn at any time.
Legal compliance (Article 6(1)(c) GDPR): We may process data to comply with applicable legal obligations, including responding to lawful requests from public authorities.
5. Cookies and Tracking
This Website uses cookies. A cookie is a small text file stored on your device by your browser. We use the following categories of cookies:
Strictly necessary cookies: These cookies are required for the Website to function and cannot be disabled. They include the cookie storing your consent preferences ("vxi_consent"). No personal data beyond your preference is stored in this cookie. These cookies do not require your consent under the ePrivacy Directive.
Analytics cookies (consent required): If you consent, anonymised analytics data may be collected to help us understand how visitors use the Website. This data is aggregated and does not identify individual users. You can withdraw consent at any time by clearing your browser cookies or revisiting the cookie consent interface.
We do not use advertising cookies, behavioural tracking cookies, or cookies that share data with third parties for marketing purposes. The cookie consent interface appears on your first visit. Your preference is stored for a period of twelve months, after which consent will be requested again.
6. Data Sharing
We do not sell, rent, or trade personal data. Data may be shared in the following limited circumstances:
Hosting and infrastructure providers: Our Website is hosted on servers provided by a third-party hosting company. That provider processes server log data as a data processor acting under our instructions, subject to a data processing agreement compliant with Article 28 GDPR.
Legal authorities: We may disclose personal data to competent public authorities (including law enforcement and supervisory authorities) when required to do so by applicable law, court order, or official request, and only to the extent required.
Professional advisors: We may share data with legal or technical advisors where strictly necessary to protect our legal rights, subject to professional confidentiality obligations.
No personal data is shared with third parties for advertising, marketing, or commercial profiling purposes.
7. International Transfers
Where personal data is transferred outside the European Economic Area (EEA), we ensure that adequate safeguards are in place in accordance with Chapter V of the GDPR. Such safeguards may include the European Commission's Standard Contractual Clauses (SCCs) as adopted by Commission Implementing Decision (EU) 2021/914, adequacy decisions issued by the European Commission, or other appropriate transfer mechanisms.
If you wish to obtain information about the specific safeguards applied to any international transfer of your data, please contact us at the address in Section 13.
8. Retention Periods
We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by applicable law. The following retention periods apply:
Contact enquiry data: Email correspondence, including enquiry data, is retained for a period of up to two years from the date of last contact, after which it is deleted or anonymised.
Server logs: Technical log data retained by our hosting provider is typically retained for a period of thirty to ninety days, in accordance with standard hosting practices and the provider's own retention policy.
Cookie preference data: The consent cookie ("vxi_consent") expires after twelve months. After expiry, your preference is no longer stored and consent will be requested on your next visit.
9. Your Rights
Under the GDPR and Romanian Law no. 190/2018, you have the following rights with respect to your personal data:
Right of access (Article 15 GDPR): You may request confirmation of whether we process personal data about you and, if so, access to that data and information about how it is processed.
Right to rectification (Article 16 GDPR): You may request correction of inaccurate personal data or completion of incomplete data.
Right to erasure (Article 17 GDPR): You may request deletion of your personal data in certain circumstances, including where the data is no longer necessary for the purposes for which it was collected.
Right to restriction of processing (Article 18 GDPR): You may request that processing of your data be restricted in certain circumstances, for example while the accuracy of the data is being contested.
Right to data portability (Article 20 GDPR): Where processing is based on your consent or a contract and carried out by automated means, you may request a copy of your data in a structured, commonly used, machine-readable format.
Right to object (Article 21 GDPR): Where processing is based on legitimate interests, you may object to that processing. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.
Right to withdraw consent: Where processing is based on your consent, you may withdraw that consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
Right to lodge a complaint: You have the right to lodge a complaint with the Romanian supervisory authority, ANSPDCP (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal), at anspdcp.ro, or with the supervisory authority of any EU Member State where you reside or work.
To exercise any of the above rights, please contact us using the details in Section 13. We will respond within thirty days of receiving a valid request, which may be extended by a further two months in complex cases, with notification.
10. Security Measures
We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures are reviewed and updated regularly in light of available technology and the nature of the data processed.
The Website uses HTTPS (TLS encryption) for all data transmissions. Access to email inboxes containing contact enquiry data is protected by access controls and strong authentication. Despite these measures, no transmission over the internet or electronic storage system is completely secure. We cannot guarantee absolute security.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ANSPDCP within 72 hours of becoming aware of the breach, in accordance with Article 33 GDPR. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly, in accordance with Article 34 GDPR.
11. Children's Data
This Website is not directed at children under the age of sixteen years. We do not knowingly collect personal data from children. Under Romanian Law no. 190/2018 implementing Article 8 GDPR, the minimum age for consent to information society services is sixteen years.
If we become aware that we have inadvertently collected personal data from a child under sixteen without verifiable parental consent, we will take steps to delete that data promptly. If you are a parent or guardian and believe your child has provided personal data to us, please contact us using the details in Section 13.
12. Policy Changes
We may update this Privacy Policy from time to time to reflect changes in our data processing practices, applicable law, or Website functionality. The "Last Updated" date at the top of this page indicates when the current version was adopted.
Material changes will be communicated by updating the date and, where appropriate, by a notice on the Website. Continued use of the Website after any update constitutes acknowledgement of the revised policy. We encourage you to review this page periodically.
13. Contact the DPO
For questions, requests, or concerns related to this Privacy Policy or the processing of your personal data, please contact us:
Vatobe Xicepu
Calea Dorobanți 133, Bucharest, Romania
Email: [email protected]
Phone: +40 744 227 435
You also have the right to lodge a complaint directly with the ANSPDCP at any time, regardless of whether you have first raised your concern with us.