Documents
Privacy policy
What data we process, for what purpose, on what basis and for how long. This document covers both visiting this site and the client relationship for the RegioCloud service.
Last updated: 27.08.2026
The Romanian version governs the contractual relationship. The Hungarian and English translations are for information only; in case of discrepancy, the Romanian text prevails.
1. Who the controller is
REGIO DEVELOPMENT SRL, registered office Str. Dealul Rotund nr. 5, Sovata, jud. Mureș, România, J26/706/21.04.2021, RO44161343, is the controller of the data described below. For any data protection matter: contact@regio-cloud.ro.
2. The distinction that matters: controller or processor
We process data in two different capacities, and the difference has practical consequences:
- As CONTROLLER, for data relating to visits to this site, quote requests and the management of the commercial relationship. That is what this document is about.
- As PROCESSOR, for personal data contained in the files our clients store in the service. There the client is the controller, and we act solely on their instructions under a separate data processing agreement (DPA). We do not determine the purposes and means of those processing operations and do not access the content for any purpose other than operating the service.
3. What we process as controller
- From the contact form: name, company, email address, phone (optional), the estimated number of users, and the message.
- Minimal technical data generated by the web server: IP address, time of the request, page requested. These sit in ordinary server logs and are used for operation, security and abuse limitation.
- Contact and billing data of clients and their representatives, for the duration of the contractual relationship.
We use no traffic analytics and no advertising networks. Fonts and icons are hosted by us, not by a third party. The one exception is the contact page, where the Cloudflare Turnstile script loads, to tell a real person apart from a script filling in the form; it runs only there. Outside that case, no information about your visit reaches anyone else.
4. On what legal basis
- Performance of a contract or pre-contractual steps — for quote requests and subscription management (Art. 6(1)(b) GDPR).
- Legal obligation — for accounting and tax records (Art. 6(1)(c) GDPR).
- Legitimate interest — for infrastructure security and abuse prevention (Art. 6(1)(f) GDPR).
- Consent — for sending a message through the contact form, given via the checkbox in the form; it can be withdrawn at any time by writing to the email address above.
5. How long we keep it
- Contact form messages: 12 months from the last correspondence, if no contract results.
- Accounting documents: the periods required by law.
- Web server logs: at most 12 months.
- Client data in the service: for the duration of the contract, plus the handover period agreed on termination, after which it is permanently deleted, including from backups as those expire.
6. Who we disclose it to
We do not sell or rent data. We disclose it only where necessary:
- To the hosting provider of this site, so that it runs.
- To our accountant and, where applicable, legal advisers, under a duty of confidentiality.
- To authorities, where the law requires it.
The complete and current list of sub-processors used for the RegioCloud service is part of the data processing agreement and is provided before signature.
7. Transfers outside the EU
We make no transfers of data outside the European Economic Area. The service servers are in Romania, and this site is also hosted in the European Union. Should that ever change, we inform clients in advance.
8. Cookies
This site uses no tracking, advertising or analytics cookies. Only two strictly technical mechanisms are in use:
- A cookie named NEXT_LOCALE, which remembers the language you're reading the site in; it is set on every page you visit, for up to a year, and identifies no one.
- A value stored only for the current browser session (sessionStorage) if you choose to dismiss the language suggestion — it disappears when you close the tab or browser. It is not a cookie, it is not sent to the server, and it identifies no one.
Because there are no non-essential cookies, the site does not ask for your consent through a banner. The absence of the banner is not an omission — it is a consequence of there being nothing to ask you for.
9. Your rights
You have the right of access, rectification, erasure, restriction of processing, objection and data portability, under the conditions of the GDPR. Where processing is based on consent, you may withdraw it at any time.
To exercise these rights, write to contact@regio-cloud.ro. We respond within one month; if the request is complex we will tell you and may extend the deadline as the GDPR allows. If you are a user of one of our clients and your data is in their files, please contact that client directly — there they are the controller, and we support them in answering you.
10. Security
We apply technical and organisational measures proportionate to the risk: encrypted transport, limited and logged administrative access, separate and verified backups, security updates applied out of band. Details are on the service security page.
11. Complaints
If you believe the processing infringes your rights, please write to us first — most of the time that resolves it faster. You always have the right, however, to address the Romanian data protection authority (ANSPDCP, dataprotection.ro) or the competent court.
12. Changes to this document
We may update this policy. The version in force is always the one published here, with the last-updated date shown at the top of the page. Substantial changes are communicated to clients in advance.