Legal

Privacy Policy

Last updated: May 2026

This policy describes how INITWIN collects, uses, stores and protects personal data when you visit our website, contact us, subscribe to our newsletter, or use digital services we provide (e.g. client portal). We comply with Regulation (EU) 2016/679 (GDPR) and applicable national data protection law, including Romanian Law no. 190/2018.

privacyPolicy.intro2

privacyPolicy.intro3

1. Data controller

The controller of personal data is INITWIN (referred to below as "we", "the controller" or "the company").

For data protection requests, use the email address above with the subject "Data protection" or "GDPR". We respond within the time limits set by law (usually up to 30 days, with justified extension where permitted).

privacyPolicy.s1p3

2. Scope

This policy applies to processing carried out through:

  • the public INITWIN website (informational pages, blog, portfolio, services);
  • contact forms and commercial enquiries;
  • newsletter subscription;
  • creation and use of user accounts (clients, partners, authorised staff);
  • client portal (projects, documents, support tickets), where active;
  • email or phone communications related to our services;
  • cookies and similar technologies (details in the
  • privacyPolicy.s2li8
  • privacyPolicy.s2li9

This policy does not replace service contracts or data processing agreements (DPAs) with business clients. For custom software projects, additional instructions may apply to data processed on behalf of the client.

3. Categories of data processed

Depending on how you interact with us, we may process:

3.1. Identification and contact data

  • first name, last name, company name;
  • email address, phone number;
  • job title / role in the company (for B2B contacts);
  • postal address, tax ID (if you provide them for quotes or invoicing).
  • privacyPolicy.s31li5
  • privacyPolicy.s31li6
  • privacyPolicy.s31li7

3.2. Data from forms and communications

  • content of your contact form message;
  • service of interest, estimated budget, timelines (if provided);
  • email correspondence and internal notes related to your request.
  • privacyPolicy.s32li4
  • privacyPolicy.s32li5
  • privacyPolicy.s32li6
  • privacyPolicy.s32li7

privacyPolicy.s32p1

3.3. Account and authentication data

  • account email, password (stored encrypted, not in plain text);
  • role and permissions in the platform;
  • login history, sessions, password reset (where applicable);
  • client profile data (projects, documents, tickets) — only for users with active access.
  • privacyPolicy.s33li5
  • privacyPolicy.s33li6

3.4. Newsletter and marketing

  • subscriber email address;
  • subscription date, source (site form, footer);
  • communication preferences, if indicated;
  • open/click statistics (if we use email marketing with tracking — only with consent where required).
  • privacyPolicy.s34li5
  • privacyPolicy.s34li6

privacyPolicy.s34p1

3.5. Technical data and logging

  • IP address, browser type, operating system, language;
  • pages visited, time on site, traffic source (referrer);
  • cookie identifiers (see cookie policy);
  • server logs for security, troubleshooting and abuse prevention (access, errors, unauthorised attempts).
  • privacyPolicy.s35li5
  • privacyPolicy.s35li6
  • privacyPolicy.s35li7
  • privacyPolicy.s35li8
  • privacyPolicy.s35li9
  • privacyPolicy.s35li10

privacyPolicy.s35p1

4. Purposes and legal bases

We process data for the purposes below, on the indicated legal bases:

privacyPolicy.s41Title

privacyPolicy.s41p1

privacyPolicy.s42Title

privacyPolicy.s42p1

privacyPolicy.s43Title

privacyPolicy.s43p1

privacyPolicy.s44Title

privacyPolicy.s44p1

privacyPolicy.s45Title

privacyPolicy.s45p1

privacyPolicy.s46Title

privacyPolicy.s46p1

privacyPolicy.s47Title

privacyPolicy.s47p1

5. Recipients and processors

Data may be accessed, where strictly necessary, by:

Purpose Examples Legal basis (GDPR)
Responding to enquiries Contact, quote, demo Art. 6(1)(b) — pre-contractual measures / contract
Providing services Software projects, support, client portal Art. 6(1)(b) — performance of contract
Newsletter / marketing News, articles, offers (if you subscribe) Art. 6(1)(a) — consent
Site security Authentication, CSRF protection, logs Art. 6(1)(f) — legitimate interest
Traffic analytics Google Analytics (if you accept cookies) Art. 6(1)(a) — consent
Legal obligations Invoicing, document archiving Art. 6(1)(c) — legal obligation
Defence of rights Disputes, complaints Art. 6(1)(f) — legitimate interest

6. Transfers outside the EEA

We aim to use providers that process data in the European Union or in countries with an adequacy decision. If a provider processes data in the USA or other third countries, we rely on appropriate safeguards (Standard Contractual Clauses, Data Privacy Framework where applicable, or other mechanisms permitted by GDPR). You may request further information about transfers at the contact address above.

privacyPolicy.s6p2

  • privacyPolicy.s6li1
  • privacyPolicy.s6li2
  • privacyPolicy.s6li3
  • privacyPolicy.s6li4
  • privacyPolicy.s6li5
  • privacyPolicy.s6li6
  • privacyPolicy.s6li7
  • privacyPolicy.s6li8
  • privacyPolicy.s6li9

privacyPolicy.s6p3

privacyPolicy.s6p4

7. Retention period

We keep data only as long as necessary for the purposes for which it was collected:

When retention periods expire, data is deleted, anonymised or securely archived.

  • Contact enquiries without a contract: usually up to 24 months from the last interaction, then deletion or limited archiving;
  • Contractual relationship: for the duration of the contract and thereafter as required by law (accounting, disputes) — usually 5–10 years for tax documents, under applicable law;
  • User account: until account deletion or prolonged inactivity (e.g. 24 months), with prior notice where possible;
  • Newsletter: until unsubscribe or withdrawal of consent;

privacyPolicy.s7p3

8. Data security

We implement reasonable technical and organisational measures, including for example:

No system is 100% secure. If you suspect an issue with your account or your data, contact us immediately.

  • encryption in transit (HTTPS/TLS) for the website;
  • passwords stored with appropriate hashing algorithms;
  • role-based access control in internal applications;
  • CSRF protection and rate limiting for public forms;
  • regular backups and monitoring;
  • training for staff with access to data;
  • procedures for security incidents (notification to authority and data subjects when mandatory).

privacyPolicy.s8p3

9. Your rights

As a data subject, you have the following rights (subject to legal limitations):

To exercise your rights, send a request to

  • Right to be informed and of access — to know what data we process and receive a copy;
  • Rectification — correction of inaccurate or incomplete data;
  • Erasure ("right to be forgotten") — under Art. 17 GDPR conditions;
  • Restriction — limiting processing in certain situations;
  • Portability — receiving data you provided, in a structured format, where applicable;
  • Objection — to processing based on legitimate interest, including direct marketing;
  • Withdrawal of consent — at any time, without affecting prior lawful processing;
  • Complaint — to your supervisory authority (in Romania: ANSPDCP —
  • privacyPolicy.s9li9
  • privacyPolicy.s9li10
  • privacyPolicy.s9li11

We may ask you to verify your identity to protect your data from unauthorised access.

10. Automated decisions and profiling

We do not make decisions with legal or similarly significant effect based solely on automated processing (including profiling) in connection with the public website. If we introduce such features in the future, we will update this policy and inform data subjects where required.

  • privacyPolicy.s10li1
  • privacyPolicy.s10li2
  • privacyPolicy.s10li3
  • privacyPolicy.s10li4
  • privacyPolicy.s10li5
  • privacyPolicy.s10li6

privacyPolicy.s10p2

privacyPolicy.s10p3

privacyPolicy.s10p4 Cookie Policy.

11. Minors

Our website and services are intended for people aged at least 16 (or the applicable digital consent age in your country). We do not knowingly collect data from minors without parental or legal guardian consent. If you learn that a minor provided data without consent, contact us for deletion.

  • privacyPolicy.s11li1
  • privacyPolicy.s11li2
  • privacyPolicy.s11li3
  • privacyPolicy.s11li4
  • privacyPolicy.s11li5
  • privacyPolicy.s11li6
  • privacyPolicy.s11li7
  • privacyPolicy.s11li8
  • privacyPolicy.s11li9 (www.dataprotection.ro).

privacyPolicy.s11p2 contact@initwin.com. privacyPolicy.s11p3

12. Links to third-party sites

The site may contain links to external websites (partners, documentation, social networks). We are not responsible for the privacy practices of those sites. Review their policies before providing personal data.

privacyPolicy.s12p2

13. Policy changes

We may update this policy to reflect legal, technical or business changes. The current version is published on this page with the update date in the header. For important changes, we may show a notice on the site or send information by email (for subscribers or clients, where applicable).

privacyPolicy.s13p2

14. Contact

For any questions about data protection or exercising your rights:

privacyPolicy.s14p2

privacyPolicy.s15Title

privacyPolicy.s15p1

privacyPolicy.s15p2

privacyPolicy.s15p3

privacyPolicy.s16Title

privacyPolicy.s16p1

privacyPolicy.s16p2

privacyPolicy.s16p3

privacyPolicy.s17Title

privacyPolicy.s17p1

Related documents: Cookie Policy · Terms & Conditions