Logo
Bulevardul George Coșbuc 98, Bucharest
EN

Privacy Policy

This Privacy Policy (hereinafter referred to as the “Policy”) governs the procedure for processing the personal data of users of the website https://pravostandart.com/ (hereinafter referred to as the “Website”).

1. General provisions

1.1. The Administrator processes Users’ personal data in accordance with the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) and the applicable laws of the European Union and the countries where services are provided.

1.2. By using the Website and submitting a contact form, the User agrees to the terms of this Policy.

2. What data Is collected

When the User completes a contact form or uses the Website, we may collect the following data:

  • first and last name;
  • email address;
  • telephone number (including messaging applications, if provided);
  • country of residence or citizenship;
  • information contained in the inquiry (for example, a description of an immigration-related matter);
  • technical data (IP address, browser type, cookies, date and time of visit).

3. Purposes of data processing

Your data is processed solely for the following purposes:

  • establishing initial contact and forwarding your inquiry to an appropriate specialist (lawyer, attorney, notary, or translator);
  • arranging an initial consultation;
  • facilitating communication between the User and the Service Provider;
  • maintaining internal statistics and analytics;
  • ensuring the security and proper functioning of the Website.

4. Role of the administrator and service providers

4.1. The Website Administrator does not provide legal services and is not a party to any agreement between the User and the Service Provider.

4.2. Once the inquiry has been forwarded to a specialist (Service Provider), the Service Provider becomes an independent data controller with respect to the User’s personal data and bears full responsibility for data processing within the scope of the services provided.

4.3. The Administrator ensures only the technical transfer and initial processing of data necessary to connect the User with a specialist.

5. Legal bases for processing

Data processing is carried out on the basis of:

  • the User’s consent (Article 6(1)(a) GDPR);
  • the necessity of processing for the performance of a contract or pre-contractual measures (Article 6(1)(b) GDPR);
  • the Administrator’s legitimate interests in ensuring the operation of the Website (Article 6(1)(f) GDPR).

6. Data retention

Data submitted through the contact form is retained until it is transferred to the Service Provider and for no more than 90 days after the last contact if no agreement is concluded.

If an agreement is concluded, the storage and processing of data are governed by the Service Provider’s Privacy Policy.

Technical logs and analytical data are retained for no longer than 12 months.

7. Transfer of data to third parties

Your personal data may be transferred to:

  • the selected Service Provider for communication and consultation purposes;
  • payment service providers (if payment is made through the platform);
  • hosting providers and IT contractors servicing the Website;
  • government authorities in cases required by law.

All such parties are required to comply with GDPR requirements and enter into a Data Processing Agreement with the Administrator.

8. Data protection

8.1. General principles of protection

The Administrator implements all reasonable technical and organizational measures to protect Users’ personal data from loss, unauthorized access, alteration, disclosure, or destruction. These measures comply with the principles of confidentiality, integrity, and availability established under Articles 5 and 32 of Regulation (EU) 2016/679 (GDPR).

8.2. Technical security measures

The following technologies and methods are used to ensure data security:

  • SSL/TLS encryption to protect data transmission between the User’s browser and the Website server;
  • secure servers (located within the European Union or the European Economic Area) that comply with ISO/IEC 27001 standards;
  • firewalls and intrusion detection/prevention systems (IDS/IPS) to prevent unauthorized access;
  • regular software updates and implementation of security patches;
  • multi-factor authentication for administrators and specialists with access to the database;
  • activity logging and access control for confidential information.

8.3. Organizational measures

Access to personal data is granted only to authorized employees and Service Providers who have signed confidentiality agreements and received data protection training.

All individuals with access to personal data are granted access based on the need-to-know principle.

Internal audits and data processing risk assessments are conducted periodically.

A Data Protection Officer (DPO) has been appointed to monitor compliance with this Policy and GDPR requirements.

8.4. Security of data transfers to service providers

User data is transferred to Service Providers through secure communication channels using encryption and security protocols. Service Providers are required to maintain a level of protection equivalent to GDPR standards and to use the data solely for purposes agreed upon with the User.

8.5. Data storage and backup

Data is stored on servers located within the European Union or in countries recognized by the European Commission as providing an adequate level of data protection.

Regular backups are created to prevent data loss resulting from technical failures.

Access to backup copies is restricted and controlled.

8.6. Data protection Impact assessment (DPIA) and risk management

Where data processing is likely to result in a high risk to the rights and freedoms of individuals, the Administrator conducts a Data Protection Impact Assessment (DPIA) and documents measures implemented to mitigate such risks.

8.7. Security breaches (Data Breach Notification)

In the event of an incident involving the leakage of or unauthorized access to personal data, the Administrator shall:

  • immediately take measures to mitigate the consequences and protect the data;
  • notify the competent data protection supervisory authority within 72 hours, as required by Article 33 GDPR;
  • where necessary, notify Users if there is a high risk to their rights and freedoms (Article 34 GDPR).

8.8. Log Retention and access monitoring

To ensure transparency, technical access logs are maintained, recording all operations involving personal data. These logs are stored in a secure environment and are used exclusively for internal audits and incident investigations.

8.9. Transfers of data outside the EU

If data processing takes place outside the European Union (for example, where a Service Provider or contractor is located outside the EEA), such transfers are carried out only in compliance with Chapter V of the GDPR, including:

  • on the basis of an adequacy decision of the European Commission;
  • through the use of Standard Contractual Clauses (SCCs);
  • or based on the User’s explicit consent.

8.10. Accountability and oversight

The Administrator is responsible for ensuring that personal data processing complies with the GDPR principles (Article 5(2)) and for documenting all protective measures. Users may contact the Administrator or the Data Protection Officer (DPO) to obtain information regarding specific security measures.

8.11. User obligations

The User undertakes not to engage in any actions that may compromise the security of the Website or result in unauthorized access (including attempts to hack the Website, interfere with its code, or use malicious software).

9. Cookies and analytics

The Website uses cookies to ensure proper functionality and for statistical analysis purposes. For more information, see Section 9 “Cookies and Analytics” of the extended version (available upon request). You may manage cookies through your browser settings or the consent banner on the Website.

10. Your rights

In accordance with the GDPR, you have the right to:

  • access your personal data;
  • rectify inaccurate data;
  • erase your data (“right to be forgotten”);
  • restrict or object to processing;
  • data portability;
  • withdraw your consent at any time.

11. Changes to the policy

The Administrator reserves the right to amend this Policy. The updated version will be published on the Website with the date of amendment indicated.

12. Contact information

Website administrator:

Email: info@pravostandart.com

Bulevardul George Coșbuc 98, Bucharest
Get a consultation