Who we are
Evobits Information Technology SRL (“Evobits IT”, “we”, “us”) is a privately owned company registered in Romania, in the European Union. For the purposes of the GDPR we are the data controller of the personal data described in this policy.
- Company
- Evobits Information Technology SRL
- Registered office
- Strada 13 Septembrie 12A, 400126 Cluj‑Napoca, Romania
- VAT number
- RO33766781
- Email for privacy matters
- contact@evobitsit.com
This policy covers the website evobitsit.com (in English and Romanian) and the personal data we receive when you contact us through it, by email, or in the course of a business relationship that starts here. The video surveillance system at our premises has its own information notice.
What data we collect
Data you give us. When you write to us we receive what you choose to send: your name, your company, your email address, your phone number if you add it, and the content of your message. The same applies when you voluntarily give us feedback or answer a customer survey.
Data our web server records. Like every web server, ours writes a technical log line for each request: the IP address of your device, the date and time, the page or file requested, the page that referred you, the type and version of your browser, and the result code. We use these logs only to keep the site running and secure.
What we do not collect. We do not buy or otherwise obtain personal data about you from third parties, we do not build profiles of visitors, and we do not use advertising or analytics services. We collect nothing about you that you did not give us or that your browser did not have to send in order to load the page.
How we collect it
You provide most of the data directly, by choice. The contact form on this website does not send anything to our servers by itself: it opens your own email program with the fields you filled in, and you decide whether to send the message. Nothing leaves your device until you press Send in your mail client, and the message is then delivered to contact@evobitsit.com like any other email.
The server logs are created automatically by our web server when your browser loads a page, an image or a script. This is a technical necessity of serving a website, not a tracking mechanism.
Why we use it, and on what legal basis
The GDPR requires that every use of personal data rests on one of the legal bases in its Article 6. Ours are the following.
| Purpose | Data | Legal basis |
|---|---|---|
| Answering your enquiries, quotes, support requests and visit requests | Contact details and the content of your message | Steps taken at your request before entering into a contract, Art. 6(1)(b), and our legitimate interest in answering the people who write to us, Art. 6(1)(f) |
| Delivering and administering the services you contract from us | Contact details, contract and invoicing data | Performance of a contract, Art. 6(1)(b) |
| Sending you information about our products and services | Name and email address | Your consent, Art. 6(1)(a), which you may withdraw at any time (see note 08) |
| Keeping the website available and secure, detecting abuse, troubleshooting | Server logs | Our legitimate interest in operating a secure service, Art. 6(1)(f) |
| Meeting our legal obligations, for instance accounting and tax law, or a lawful request from an authority | Contract and invoicing data | Legal obligation, Art. 6(1)(c) |
We do not use your data for automated decision‑making or profiling, and we do not use it for any purpose other than the ones listed here without telling you first.
How long we keep it
- Contact data and correspondence: 2 years from our last exchange with you. Once this period has expired we delete your data automatically.
- Contract and invoicing data: for as long as the law requires us to keep it (Romanian accounting legislation requires invoices and supporting documents to be kept for 10 years). Where a legal retention period is longer than 2 years, the legal period applies.
- Marketing consent: until you withdraw it. When you do, we keep only the minimum needed to remember that you asked us not to contact you.
- Server logs: 30 days, then they are deleted automatically.
Where and how we store it
Your data is stored in our own, privately owned datacenters in Cluj‑Napoca, Romania. Physical access is restricted and logged, the systems are operated by our own engineers, and the data is managed through our custom‑made software suite. This website is also built and hosted in our own datacenter.
Your data stays in the European Union. We do not transfer it to countries outside the EU or the European Economic Area.
Who we share it with
We do not sell, rent or trade personal data, and we do not pass it to other companies for their own marketing. Your data is seen by:
- the members of our staff who need it to answer you or to deliver a service you contracted;
- service providers that process data on our behalf and under our instructions, bound by a data processing agreement, where we cannot reasonably do the work ourselves (for instance our accountants);
- public authorities, when the law requires us to disclose it.
Marketing
We would like, from time to time, to tell you about products and services of ours that we think you might find useful. We send such messages by email only if you have agreed to receive them, or, if you are already a customer, about services similar to the ones you have contracted, as Romanian law permits.
You may opt out at any time: every message we send includes an unsubscribe link, and you can also simply write to us. We will stop contacting you for marketing purposes as soon as we receive your request. Withdrawing your consent does not affect the lawfulness of what we did before you withdrew it.
Your rights
We would like to make sure you are fully aware of your rights under the GDPR. Every person whose data we process is entitled to the following.
- The right to access
- You may ask us for a copy of the personal data we hold about you. The first copy is free of charge; for further copies, or for requests that are manifestly unfounded or excessive, we may charge a reasonable fee based on our administrative costs, as Article 12(5) of the GDPR permits.
- The right to rectification
- You may ask us to correct any information you believe is inaccurate, or to complete information you believe is incomplete.
- The right to erasure
- You may ask us to erase your personal data, under the conditions of Article 17 of the GDPR (for instance when the data is no longer needed, or when you withdraw the consent it was based on).
- The right to restrict processing
- You may ask us to restrict the processing of your personal data, under the conditions of Article 18 of the GDPR.
- The right to object
- You may object at any time to processing that is based on our legitimate interest, and to any processing for direct marketing purposes. If you object to direct marketing we will stop without exception.
- The right to data portability
- You may ask us to transfer the data you gave us to another organisation, or directly to you, in a structured, commonly used, machine‑readable format, under the conditions of Article 20 of the GDPR.
- The right to withdraw consent
- Where processing is based on your consent, you may withdraw it at any time, with effect for the future.
- The right not to be subject to automated decisions
- We make no decisions about you by automated means, and we do no profiling.
To exercise any of these rights, write to us (note 14). We answer within one month of receiving your request; for complex or numerous requests the GDPR allows us up to two further months, and we will tell you within the first month if we need them. We may ask you to confirm your identity before we act, so that we do not hand your data to someone else. Exercising your rights is free of charge.
Cookies and similar technologies
Cookies are small text files that a website stores on your device to recognise you on later visits or to collect information about how you use it. This website sets no cookies. It has no login, no analytics, no advertising and no tracking of any kind, it stores nothing in your browser, and it loads nothing from third parties: every file, the typefaces included, is served from our own systems. Your choice of language is part of the address (/ro/ for Romanian), not a cookie, so there is nothing to remember and nothing to ask your consent for.
Should we ever need cookies for a feature of the site, we will update this policy and, where the law requires it, ask for your consent before setting any that are not strictly necessary.
You can set your browser to refuse all cookies or to warn you before one is stored. allaboutcookies.org explains how for every common browser.
Links to other websites
This website contains links to other websites, for instance those of the partners and community projects we present. This policy applies only to evobitsit.com. When you follow a link to another site, that site’s own privacy policy applies, and we recommend that you read it.
Security
We apply the same care to your data as to our customers’ servers. This site is served only over encrypted connections (HTTPS), from systems we design, build and operate ourselves, in datacenters with restricted, logged physical access and 24/7 monitoring. Access to personal data is limited to the staff who need it, and our systems are kept up to date and monitored for abuse.
Changes to this policy
We keep this policy under regular review and publish every update on this page. Material changes are marked by a new revision in the title block below.
- Rev B · 10 September 2026
- Rewritten for the new website: no cookies, no third-party requests, legal bases, retention periods, supervisory authority.
- Rev A · 5 April 2022
- First issue.
How to contact us
If you have any question about this policy or about the data we hold about you, or if you would like to exercise one of your rights, please do not hesitate to write to us. An engineer, not a form, answers.
- contact@evobitsit.com — put “GDPR” in the subject line
- Post
- Evobits Information Technology SRL, Strada 13 Septembrie 12A, 400126 Cluj‑Napoca, Romania
How to contact the supervisory authority
If you believe that we have not handled your data or your request properly, we would like to hear from you first so that we can put it right. You also have the right, at any time, to lodge a complaint with the Romanian data protection authority, or with the authority of the EU country in which you live or work.
- Authority
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Address
- B‑dul G‑ral. Gheorghe Magheru 28‑30, Sector 1, 010336 București, Romania
- Telephone
- +40 318 059 211
- Website
- www.dataprotection.ro