Privacy policy
Privacy policy.
This GDPR-oriented policy explains how personal data may be handled through this website and related communications.
Controller
The controller is Teodoru & Associates, registered with the Bucharest Bar Association. Contact details: 12 Nerva Traian Street, Suite 1, Bucharest, Romania, +40722316022, contact@teodoru.com.
Data processed
The website may process personal data submitted through the contact form, including name, email address, optional phone number, message content and consent confirmation. Basic technical data is used for security and anti-spam checks.
Newsletter signup may process an email address, consent confirmation and related technical data. Email communication may process the information contained in correspondence.
Purposes
Data may be processed to respond to enquiries, assess whether the firm can act, manage communications, maintain website security, prevent spam and send newsletter updates where consent has been given.
Legal basis
Depending on the context, processing may rely on consent, steps requested before entering into an engagement, legitimate interests in communication and security, or legal obligations applicable to a Romanian law firm.
No database storage
Forms submit by email only. The website does not store contact or newsletter submissions in a database. Contact messages and newsletter signup requests are sent to configured firm email addresses through SMTP.
Server logs and rate limiting
Server logs and file-based rate-limit records may process technical request data for security, error diagnosis and anti-spam protection. The form rate limiter uses a salted IP hash and does not store raw IP addresses in its rate-limit files. Minimal form-security logs may record the event type, form name, time and salted IP hash, but not full message content.
Google Analytics
Google Analytics may be used only after analytics consent is accepted through the cookie banner.
Recipients and transfers
Personal data may be processed by hosting, email, analytics or IT providers as needed. Any cross-border transfers are assessed according to GDPR requirements and the relevant provider terms.
Retention
Contact messages, email correspondence, newsletter consent records, logs and analytics data are retained only as long as necessary for their purpose, legal obligations or legitimate interests.
Newsletter withdrawal
Newsletter consent may be withdrawn by contacting the firm or through unsubscribe links included in future newsletters, once that mailing process is configured.
Your rights
Under GDPR, you may have rights of access, rectification, erasure, restriction, objection and data portability, depending on the circumstances. You may withdraw consent where processing is based on consent.
Contact for privacy requests
Privacy requests may be sent to contact@teodoru.com.