Privacy policy
Last updated: 5 September 2026.
This policy explains what personal data DATA SPEED SRL processes through cantare.com.ro, why, on what legal basis, for how long and what rights you have under Regulation (EU) 2016/679 (“GDPR”) and Romanian Law no. 190/2018.
1. Controller
- Controller: DATA SPEED SRL
- Registered office: 115/33 Donath Street, Cluj-Napoca, Cluj County, Romania
- VAT number: RO 17394503
- Trade Register: J12/1071/2005
- Contact address: 103 Corneliu Coposu Street, Cluj-Napoca, RO-400235, Romania
- Privacy email: office@cantare.com.ro
- Telephone: +40 735 803 121
No data protection officer has been appointed because current processing activities do not, on our assessment, trigger mandatory designation. Requests are handled directly by the controller.
2. Scope
The policy covers visitors, people sending quotation requests or correspondence, individual clients and prospects, and representatives or contacts of corporate clients and suppliers. External websites linked from cantare.com.ro process data independently under their own policies.
3. Data categories
- Identity and contact: name, email, telephone, fax, company, address, city, postcode and country;
- Request details: subject, message, selected products, quantities, technical requirements and correspondence;
- Commercial data: quotations, orders, delivery, installation, warranty, service, invoicing and payments if a relationship continues;
- Technical and security data: user agent, source page, timestamps, session identifiers and a cryptographic digest of the IP address. The quotation form does not store the clear IP address;
- Cookie-notice data: notice version and saved time;
- Communications: information voluntarily provided through email, telephone or other legitimate channels.
Please do not send sensitive data or third-party data unless necessary and lawfully disclosed.
4. Sources and purposes
Data comes from you, from the device when technical functions are used and, for B2B contacts, from the represented organisation or public professional sources. We process it to answer and prepare quotations, conclude and perform contracts, deliver and service products, meet legal and accounting duties, secure the website, prevent abuse, handle complaints and defend legal rights.
5. Legal bases
- steps requested before entering into a contract and contract performance, Article 6(1)(b) GDPR;
- legal obligations, Article 6(1)(c);
- legitimate interests in B2B communications, security, service continuity, fraud prevention and legal claims, Article 6(1)(f);
- consent only where a future, specific activity legally requires it.
Required form fields are needed to process the request. Optional fields help configure a quotation. The website currently performs no newsletter marketing, behavioural advertising, profiling or solely automated decision-making.
6. Recipients
On a need-to-know basis, data may be disclosed to authorised DATA SPEED staff and contractors; hosting, IT maintenance, email, backup and security providers; manufacturers, carriers and installation/service partners needed for a request; accountants, auditors, lawyers, insurers and advisers; and public authorities or courts where disclosure is required or permitted. We do not sell or rent personal data.
7. International transfers
The website currently has no analytics or advertising tools deliberately sending data outside the EEA. If a necessary provider involves an international transfer, DATA SPEED will use a GDPR Chapter V mechanism, such as an adequacy decision or standard contractual clauses, with any necessary supplementary measures. Details of the applicable safeguard may be requested from the controller.
8. Retention
- unsuccessful quotation requests: while handled and generally no longer than 3 years after the last interaction, unless a dispute or legal obligation requires longer;
- contractual records: throughout the relationship and for applicable tax, accounting, warranty and limitation periods;
- complaint or dispute records: until final resolution and expiry of relevant periods;
- website session and form-security token: normally 2 hours after last activity;
- cookie-notice acknowledgement: 6 months;
- backups: until overwritten within the secure rotation cycle.
9. Security
Risk-based controls include restricted access, admin authentication, form validation and CSRF protection, abuse rate limits, updates, backups and encrypted transport when the website runs over HTTPS. No transmission can be guaranteed absolutely secure; incidents are assessed and notified where legally required.
10. Your rights
Subject to the GDPR, you may request information and access, rectification, erasure, restriction, portability, and object to legitimate-interest processing. You may withdraw consent prospectively where consent applies, and have the right not to be subject to qualifying solely automated decisions. The website currently performs neither profiling nor solely automated decisions.
11. Exercising rights and complaints
Email office@cantare.com.ro or write to the registered office, identifying the requested right. Reasonable identity verification may be required. We normally respond within one month; the GDPR allows up to two additional months for complex or numerous requests, with notice. Requests are free unless manifestly unfounded or excessive under the law.
You may complain to the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), another competent EU authority or the courts.
12. Children, cookies and updates
Professional products and quotation services are not directed to children, and we do not knowingly collect children's data. Essential device storage is explained in the Cookie policy. We may update this policy when activities, providers or law change; a new notice or consent will be obtained before any processing that requires it.