Last Updated: 22 July 2026
This Privacy Policy describes how Wamoli Xifero ("we", "us", "our"), operating the website wamoli-xifero.info, collects, processes, and protects personal data. This policy is issued in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (the General Data Protection Regulation, "GDPR") and the Romanian national implementing legislation, including Legea nr. 190/2018 privind măsuri de punere în aplicare a Regulamentului (UE) 2016/679. We are the data controller for personal data collected through this website.
The data controller responsible for personal data processed through this website is Wamoli Xifero, located at Bulevardul Mareșal Alexandru Averescu 15b, Bucharest, Romania. You may contact us regarding any data protection matter by email at [email protected] or by telephone at +40 726 674 230. All data protection enquiries are handled directly by the responsible person within our organisation. We do not have a formally designated Data Protection Officer as we do not fall within the mandatory appointment categories under Article 37 of the GDPR, however we take data protection responsibilities seriously and have a designated contact point for all related enquiries.
We collect personal data in two ways: directly, when you voluntarily provide it to us through the contact form on this website, and indirectly, through technical data generated during your use of the site. Directly provided data includes your name, email address, and the content of messages you submit through the contact form, including any subject line or additional details you choose to include. Indirectly collected technical data may include your IP address, browser type and version, operating system, referring URL, pages visited, time and date of visit, and time spent on pages. This technical data is collected through server logs and, if you consent, through analytics cookies. We do not collect special categories of personal data as defined in Article 9 of the GDPR, nor do we collect data from individuals known to be under the age of sixteen.
We process personal data for the following purposes, each resting on a distinct legal basis as required by Article 6 of the GDPR. When you submit a contact form, we process your name, email address, and message content for the purpose of responding to your enquiry. The legal basis for this processing is Article 6(1)(b) GDPR, being the performance of steps at your request prior to entering into a relationship, or alternatively Article 6(1)(f) GDPR, our legitimate interest in communicating with individuals who contact us. We process technical data collected through server logs for the purpose of maintaining website security and diagnosing technical faults, on the basis of Article 6(1)(f) GDPR, being our legitimate interest in ensuring the functionality and security of our website. If you consent to analytics cookies, we process anonymised visit data for the purpose of understanding how visitors use our content so we may improve it, on the basis of Article 6(1)(a) GDPR. You may withdraw this consent at any time through the cookie preferences panel accessible on every page.
We retain personal data only for as long as is necessary for the purpose for which it was collected. Contact form submissions are retained for a period of twelve months from the date of submission, after which they are permanently deleted from our systems. If ongoing communication results from an initial enquiry, data related to that communication may be retained for as long as the communication remains active, plus a further period of twelve months after the last communication. Technical server log data is retained for a period of ninety days and then automatically overwritten. Anonymised analytics data, if consent is granted, is retained in aggregated form without any individual identification for a period of up to twenty-four months. Where a legal obligation requires us to retain data for a longer period, we will do so in compliance with that obligation.
We do not sell, rent, or otherwise transfer your personal data to third parties for their own commercial purposes. We may share your data with service providers who assist in operating this website, including web hosting providers. Any such providers are selected on the basis that they offer sufficient guarantees regarding technical and organisational data protection measures, and appropriate data processing agreements are in place where required by Article 28 of the GDPR. In the event that our hosting provider is located outside the European Economic Area, we ensure that appropriate safeguards are in place in accordance with Chapter V of the GDPR, which may include Standard Contractual Clauses as approved by the European Commission. We will disclose personal data where required to do so by applicable law, court order, or the request of a competent supervisory authority.
Under the GDPR and applicable Romanian law, you have the following rights in respect of your personal data: the right to access the personal data we hold about you (Article 15 GDPR); the right to rectification of inaccurate or incomplete data (Article 16 GDPR); the right to erasure of your personal data where grounds for erasure apply (Article 17 GDPR); the right to restriction of processing in specified circumstances (Article 18 GDPR); the right to data portability in a structured, commonly used, machine-readable format (Article 20 GDPR); the right to object to processing based on legitimate interests (Article 21 GDPR); and the right to withdraw consent for any processing based on consent, without affecting the lawfulness of processing prior to withdrawal. To exercise any of these rights, please contact us at [email protected]. We will respond to all rights requests within one month of receipt, as required by Article 12(3) of the GDPR. In complex or numerous cases, we may extend this period by a further two months, in which case we will notify you within the initial one-month period.
You have the right to lodge a complaint with a supervisory authority if you consider that the processing of your personal data infringes the GDPR. The competent supervisory authority in Romania is the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), located at Bulevardul General Gheorghe Magheru 28-30, Sector 1, Bucharest, Romania, website: dataprotection.ro. You may also lodge a complaint with the supervisory authority in the EU Member State of your habitual residence, place of work, or place of the alleged infringement. We encourage you to contact us directly in the first instance so that we may attempt to resolve any concern before a formal complaint is made.
This website uses cookies. A cookie is a small text file placed on your device when you visit a website. We use strictly necessary cookies that are essential for the operation of the website and which cannot be disabled without impairing functionality. We also use analytics cookies on the basis of your consent, which help us understand how visitors navigate the content. Full details of the cookies we use, their purpose, duration, and your choices regarding them are set out in our Cookie Policy, available at wamoli-xifero.info/cookies.html. You may manage your cookie preferences at any time using the cookie preferences panel accessible via the link displayed in the bottom-left corner of every page on this website.
We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures are reviewed and updated regularly. The website is served over HTTPS to protect data in transit. Access to any stored contact form data is restricted to authorised personnel only. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ANSPDCP within seventy-two hours of becoming aware of the breach, as required by Article 33 of the GDPR, and will notify affected individuals where the breach is likely to result in a high risk, as required by Article 34.
We may update this Privacy Policy from time to time to reflect changes in our practices, applicable law, or for other operational reasons. When we make material changes, we will update the "Last Updated" date at the top of this document. We encourage you to review this policy periodically. Continued use of the website following any update constitutes acknowledgement of the revised policy. Where changes are significant and affect data that has already been collected, we will take reasonable steps to bring such changes to your attention.