Privacy Policy
Last updated: May 2026
This Privacy Policy explains how DUO DESIGN ADVERTISING S.R.L. collects, uses, stores, and protects personal data when you visit our website, contact us, request information about our services, or collaborate with us.
We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and Romanian Law no. 190/2018 on measures for the implementation of Regulation (EU) 2016/679, as well as other applicable data protection and privacy laws.
1. Data Controller
The data controller responsible for your personal data is:
- DUO DESIGN ADVERTISING S.R.L.
- Registration no.: J40/2378/27.02.2015
- VAT no.: RO34166750
- Registered address: Strada Tănase Dumitrescu nr. 13, Sector 2, Bucharest, Romania
- Phone: +40 771 190 628
- Email: contact@duoadv.com
2. Data Protection Officer
Based on the nature and scale of our data processing activities, we are not required to appoint a Data Protection Officer under Article 37 GDPR and Romanian Law no. 190/2018. For any questions or concerns regarding the processing of your personal data, please contact us directly using the details provided in Section 1.
3. What Personal Data We Collect
Depending on how you interact with us, we may collect the following types of personal data:
- Contact information, such as your name, email address, phone number, company name, and job title.
- Communication data, such as messages sent through contact forms, emails, phone calls, or other communication channels.
- Project and business information, such as details about your website, eCommerce project, HubSpot CRM/CMS needs, technical requirements, budget, timeline, and business goals.
- Website usage data, such as IP address, browser type, device information, pages visited, time spent on the website, referral source, and general analytics information.
- Technical and security data, such as logs necessary to keep the website secure and prevent misuse.
We do not intentionally collect sensitive personal data through our website.
4. How We Collect Personal Data
We may collect personal data directly from you when you:
- contact us through our website or by email;
- request a proposal, quote, consultation, or service information;
- communicate with us during a project or collaboration;
- subscribe to any newsletter or marketing communication, if available;
- browse our website and allow cookies or similar technologies.
We may also collect limited technical data automatically through cookies, analytics tools, hosting logs, and website security systems.
5. Why We Use Your Personal Data and Legal Basis
We process personal data only where we have a lawful basis to do so under GDPR Art. 6. The table below maps each purpose to the applicable legal ground:
- Responding to inquiries and messages — Legitimate interest (Art. 6(1)(f)) in managing business communications, or pre-contractual steps (Art. 6(1)(b)) where the inquiry relates to a specific project.
- Preparing proposals, estimates, contracts, and project documentation — Pre-contractual or contractual steps (Art. 6(1)(b)).
- Delivering and managing services — Contract performance (Art. 6(1)(b)).
- Communication about ongoing projects, support, and administrative matters — Contract performance (Art. 6(1)(b)) or legitimate interest (Art. 6(1)(f)).
- Accounting, invoicing, and tax obligations — Legal obligation (Art. 6(1)(c)), including Law no. 82/1991 on accounting and the Fiscal Procedure Code.
- Protecting the security and proper functioning of our website — Legitimate interest (Art. 6(1)(f)) in maintaining a secure online presence.
- Improving our website, services, and user experience — Legitimate interest (Art. 6(1)(f)), or consent (Art. 6(1)(a)) where analytics or tracking tools require it.
- Marketing communication, newsletters, and promotional activities — Consent (Art. 6(1)(a)) for individuals; legitimate interest (Art. 6(1)(f)) may apply in a B2B context where permitted. You may withdraw consent or object to legitimate-interest processing at any time.
6. Cookies and Analytics
Our website may use cookies and similar technologies to ensure proper functionality, analyze website traffic, improve user experience, and support marketing activities. Cookies may include:
- strictly necessary cookies required for the website to work;
- analytics cookies that help us understand how visitors use the website;
- marketing or tracking cookies, only where applicable and based on consent where required.
You can manage or disable cookies through your browser settings or through the cookie consent banner on the website. A separate Cookie Policy provides more detailed information about the cookies we use.
7. How Long We Keep Your Data
We keep personal data only for as long as necessary for the purposes described in this Privacy Policy. Specific retention periods are as follows:
- Contact form and inquiry data — up to 3 years from the date of last contact, in line with the general civil prescription period under Art. 2517 of the Romanian Civil Code.
- Client and project data — for the duration of the collaboration and for up to 3 years after its conclusion, for legitimate business, contractual, or legal purposes.
- Accounting registers and financial statements — 10 years from the end of the financial year, in accordance with Art. 25 of Law no. 82/1991.
- Supporting accounting documents (invoices, receipts) — minimum 5 years from the end of the financial year to which they relate, in accordance with Art. 25 of Law no. 82/1991 and the Fiscal Procedure Code.
- Tax-relevant records — 5 years from the date the corresponding tax obligation arose, in accordance with the Romanian Fiscal Procedure Code.
- Technical and security logs — up to 12 months, as necessary for website security and maintenance.
- Consent records — for as long as the consent remains relevant, or for up to 3 years after the last interaction, to demonstrate compliance.
When personal data is no longer needed, we will delete it, anonymize it, or securely archive it where required by law.
8. Who We Share Personal Data With
We do not sell your personal data. We may share personal data only where necessary with:
- hosting providers and website infrastructure providers;
- email and communication service providers;
- analytics and marketing tools, where applicable;
- accounting, legal, or administrative service providers;
- trusted collaborators or subcontractors involved in delivering our services;
- public authorities, courts, or institutions when required by law.
Where third-party service providers act as data processors on our behalf, we enter into Data Processing Agreements (DPAs) in accordance with Art. 28 GDPR to ensure they process personal data only for the agreed purposes and with appropriate safeguards.
9. International Data Transfers
Some tools or service providers we use may process data outside the European Economic Area. Where this happens, we take reasonable steps to ensure that appropriate safeguards are in place, such as adequacy decisions, Standard Contractual Clauses (SCCs) under Art. 46 GDPR, or other lawful transfer mechanisms required under GDPR.
10. Data Security
We apply reasonable technical and organizational measures to protect personal data against unauthorized access, loss, misuse, alteration, or disclosure.
However, no website, email system, or online transmission method is completely secure. We encourage you not to send confidential or sensitive information through unsecured channels.
11. Data Breach Notification
In the event of a personal data breach, we will act in accordance with our obligations under GDPR Art. 33–34 and Romanian Law no. 190/2018:
- We will notify the National Supervisory Authority for Personal Data Processing (ANSPDCP) within 72 hours of becoming aware of a breach that is likely to result in a risk to the rights and freedoms of natural persons.
- Where a breach is likely to result in a high risk to your rights and freedoms, we will communicate it to you without undue delay, unless an exemption under Art. 34(3) GDPR applies.
12. Minors
Our website and services are directed at businesses and adult professionals. We do not knowingly collect personal data from persons under 16 years of age. Under Art. 5 of Romanian Law no. 190/2018, the minimum age for valid digital consent is 16. If we become aware that we have inadvertently collected personal data from a person under 16 without appropriate parental consent, we will delete it promptly.
13. Your Rights Under GDPR
Under GDPR and Romanian Law no. 190/2018, you have the following rights, where applicable:
- the right to be informed about how your personal data is processed;
- the right to access your personal data (Art. 15 GDPR);
- the right to request correction of inaccurate or incomplete data (Art. 16 GDPR);
- the right to request deletion of your personal data (Art. 17 GDPR);
- the right to request restriction of processing (Art. 18 GDPR);
- the right to object to processing based on legitimate interest (Art. 21 GDPR);
- the right to data portability (Art. 20 GDPR);
- the right to withdraw consent at any time, where processing is based on consent (Art. 7(3) GDPR);
- the right not to be subject to decisions based solely on automated processing, including profiling, where applicable (Art. 22 GDPR).
We do not carry out automated decision-making or profiling that produces legal or similarly significant effects on data subjects.
14. How to Exercise Your Rights
To exercise your rights, you can contact us at:
- Email: contact@duoadv.com
- Phone: +40 771 190 628
- Address: Strada Tănase Dumitrescu nr. 13, Sector 2, Bucharest, Romania
We may ask you to provide information necessary to confirm your identity before processing your request.
We will respond to your request within the timeframe required by applicable law. Under GDPR Art. 12(3), controllers must respond within one month of receipt, with a possible extension of two further months where necessary due to the complexity or number of requests.
15. Right to Lodge a Complaint
If you believe that your personal data has been processed unlawfully, you have the right to lodge a complaint with the Romanian supervisory authority:
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal — ANSPDCP
- Address: Bulevardul General Gheorghe Magheru nr. 28–30, Sector 1, București, 010336
- Email: anspdcp@dataprotection.ro
- Website: www.dataprotection.ro
Complaints may be filed in writing, in Romanian or English, and may be submitted by post, email, or through the online form available on the authority's website. You also have the right to pursue judicial remedies in competent Romanian courts.
16. Links to Other Websites
Our website may contain links to third-party websites. We are not responsible for the privacy practices, content, or security of those websites. We recommend reading the privacy policies of any external websites you visit.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our services, website functionality, legal requirements, or data protection practices.
The updated version will be published on this page with a revised "Last updated" date.