Privacy Policy
Last updated: 1 September 2026
1. Controller
The controller of the personal data described in this policy is INFRASOFT DEVELOPMENT S.R.L., a limited-liability company under Romanian law, with its registered office at Șoseaua Nicolae Titulescu 10, bl. 20, sc. A, et. 9, ap. 41, Sector 1, Bucharest, Romania, fiscal identification code (CUI) 54138453.
For any question about this policy or about how we handle your personal data, write to contact@infrasoftdev.com. We have not appointed a data protection officer, because the nature and scale of our processing do not meet the thresholds of Art. 37 GDPR; privacy enquiries are answered directly at that address.
2. What data we process, and why
This policy covers the personal data we process when you visit infrasoftdev.com and when you contact us through it. It does not cover the data we process for clients under contract; that processing is governed by the data-processing agreement concluded with each client.
We collect no more than the operation of this website and the handling of your enquiry require. We make no automated decisions about you within the meaning of Art. 22 GDPR, we do not build profiles of visitors, and we do not sell personal data. Our processing activities are the following:
- Contact form — name, company, work email address, indicative budget and the text of your message. Purpose: answering your enquiry and taking steps prior to entering into a contract, at your request. Legal bases: Art. 6(1)(b) GDPR (pre-contractual steps) and Art. 6(1)(f) GDPR (our legitimate interest in responding to business enquiries addressed to us).
- Analytics — aggregated statistics about how visitors use this site. Analytics run only after you have consented in the cookie banner. Legal basis: Art. 6(1)(a) GDPR. If you decline, no analytics are loaded; the site works identically either way.
- Technical logs — IP address, requested URL, timestamp, and browser user agent, recorded in server logs by our hosting provider in order to deliver the site, detect abuse and diagnose faults. Legal basis: Art. 6(1)(f) GDPR (our legitimate interest in operating and securing the website).
3. Cookies
This site sets a single first-party cookie. It records the choice you make in the cookie banner — accepted or declined — so that we do not ask you again on every visit and so that analytics load only if you agreed.
The cookie contains no advertising identifier and is not used to follow you across other websites. Its name, exact contents and lifetime are listed in our cookie policy, where you can also change or withdraw your choice at any time.
4. Recipients and processors
We share personal data with a deliberately short list of service providers, each of which processes it only on our documented instructions and under a data-processing agreement pursuant to Art. 28 GDPR:
- Hosting — Netlify, Inc. (United States) hosts this website and processes the technical log data described in section 2 on our behalf.
- Form delivery — your contact-form submission is transported to our inbox by a form-delivery provider (a webhook endpoint or a transactional email provider), which processes it solely to deliver the message.
5. Transfers outside the EEA
Our hosting provider is established in the United States, so operating this site can involve transferring personal data outside the European Economic Area.
Where data leaves the EEA, we rely on the safeguards of Chapter V GDPR: the European Commission’s Standard Contractual Clauses concluded with the provider, supplemented by technical and organisational measures where necessary, or an adequacy decision of the European Commission where one applies to the recipient — for example, a valid certification under the EU–U.S. Data Privacy Framework.
You can request a copy of the safeguards that apply to a specific transfer at contact@infrasoftdev.com.
6. Retention
We keep personal data only for as long as the purpose it was collected for requires, and then delete or anonymise it. The periods we apply:
- Contact enquiries — no longer than 24 months after the last exchange with you. If your enquiry leads to a contract, the correspondence becomes part of the contract file and follows the retention periods that Romanian commercial and tax law imposes on contractual records.
- Consent cookie — 12 months, after which the site asks for your choice again.
- Technical logs — kept by the hosting provider for a short rolling period for security and operations, then deleted.
7. Your rights
The GDPR gives you the following rights over the personal data we hold about you:
- Access (Art. 15) — obtain confirmation that we process your data, and receive a copy of it.
- Rectification (Art. 16) — have inaccurate data corrected and incomplete data completed.
- Erasure (Art. 17) — have your data deleted where no legal ground for keeping it remains.
- Restriction (Art. 18) — have processing limited while a dispute about the data is resolved.
- Portability (Art. 20) — receive the data you provided to us in a structured, commonly used, machine-readable format.
- Objection (Art. 21) — object to processing based on our legitimate interest; we then stop unless we can demonstrate compelling legitimate grounds that override your interests.
- Withdrawal of consent (Art. 7(3)) — withdraw any consent you have given, at any time, with effect for the future; the lawfulness of processing before the withdrawal is not affected.
8. Supervisory authority
If you believe our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority. The authority responsible for us is the Romanian one: Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), B-dul G-ral Gheorghe Magheru 28-30, Bucharest, Romania, www.dataprotection.ro.
You may instead complain to the supervisory authority of the EU member state where you live or work. Contacting us first at contact@infrasoftdev.com is not a precondition, but it is usually the fastest way to resolve a concern.
9. Changes to this policy
We review this policy whenever our processing, our providers or the applicable law change, and we publish the current version on this page. The date at the top tells you when it was last revised.
If a change is material — a new purpose of processing, or a new category of recipients — we will signal it clearly on this site before it takes effect. We will not reduce the rights this policy gives you without asking for your consent.