

POLICY ON THE PROCESSING OF PERSONAL DATA
Last updated: 27.04.2026
Respecting privacy and protecting personal data are important to us. This Policy explains how ZADA WEB SYSTEMS S.R.L. processes personal data when you visit https://zadawebsystems.com/, use our contact forms, request offers, create an account, use the client area, place orders, make payments, request support or interact with our services.
This Policy is supplemented by the Cookie Policy, the applicable Terms and Conditions, commercial contracts concluded with clients and, where applicable, data processing agreements concluded with our clients.
ZADA WEB SYSTEMS S.R.L., with its registered office in Str. Școala Floreasca no. 34, Room 1, Block Lot A, Floor 1, Apartment Lot 3, Bucharest, Sector 1, Romania, tax identification number 46368745, registered with the Trade Register Office under no. J40/12110/2022, processes your personal data as a controller within the meaning of Regulation (EU) 2016/679 (“GDPR”) for the activities described in this Policy.
For any question regarding data protection, you may contact us at: office@zadawebsystems.com.
At this time, ZADA WEB SYSTEMS S.R.L. has not appointed a separate Data Protection Officer (“DPO”). However, any request concerning personal data may be sent to the contact address mentioned above.
Depending on the context, ZADA WEB SYSTEMS S.R.L. may have different roles:
Depending on your interaction with us, we may process the following categories of data:
We process personal data only where we have a valid legal basis under the GDPR.
Purpose of processing |
Categories of data |
Legal basis |
|---|---|---|
Responding to contact forms, offer requests, demo requests and commercial enquiries. |
Identification and contact data, commercial details, message content. |
Taking steps at your request before entering into a contract or our legitimate interest in responding to enquiries. |
Creating and managing the Client Account. |
Account data, identification data, contact data, roles, access rights, accepted terms. |
Performance of a contract or taking steps before entering into a contract. |
Processing orders, activating services, delivering digital services, licences, hosting, domains or custom projects. |
Commercial and contractual data, account data, billing data, technical data, data required for the selected service. |
Performance of a contract. |
Issuing invoices, accounting records and tax reporting. |
Billing data, tax data, order data, payment status. |
Compliance with legal obligations. |
Processing payments, payment links, payment confirmations and transaction status. |
Payment method, amount, transaction identifiers, payment status, billing data. |
Performance of a contract and compliance with financial/accounting obligations. |
Providing technical support, maintenance, troubleshooting and client assistance. |
Support data, contact data, technical logs, screenshots, uploaded files, account/service data. |
Performance of a contract and legitimate interest in providing support and maintaining service quality. |
Ensuring website, platform, account and infrastructure security. |
IP address, logs, user-agent, access events, security events, account actions. |
Legitimate interest in protecting systems, users and services and, where applicable, legal obligations. |
Using strictly necessary cookies and storing cookie consent preferences. |
Session identifiers, cookieConsent, cookiesAccepted and similar technical preferences. |
Legitimate interest in operating the website and compliance with legal obligations regarding consent evidence. |
Using analytics, performance, functionality or marketing cookies. |
Cookie identifiers, usage data, device/browser data, preferences. |
Your consent, where required by law. |
Using Google Maps, chatbot/AI assistant or other optional external integrations. |
Technical data, interaction data, messages submitted by you, service-specific identifiers. |
Your consent for optional cookies/technologies, or performance of a service explicitly requested by you, depending on the context. |
Sending commercial communications, offers, newsletters or marketing messages. |
Name, email, phone, company, preferences, interaction history. |
Your consent, or legitimate interest where allowed by law for existing clients and similar services, with the right to object/unsubscribe. |
Defending rights, managing disputes, audits, contractual evidence and compliance. |
Contractual data, communication history, account data, technical logs, billing and payment data. |
Legitimate interest and, where applicable, legal obligations. |
When you use forms on the Website or in the Client Account, we process the data you provide in order to respond to your request, prepare an offer, provide the requested service, issue invoices, process payments or provide support.
If you upload files, screenshots or documents in a support ticket or through another available channel, please make sure you do not upload unnecessary personal data or confidential information that is not relevant to the request. Where possible, please anonymise sensitive information before sending it.
For card payments, the payment is processed through an authorised payment processor. ZADA may receive information such as payment status, amount, currency, payment identifier and billing details, but does not store full card data.
We use strictly necessary cookies and similar technologies for the operation of the Website, security, session management, cart/account operation and storage of cookie consent preferences.
Optional cookies or similar technologies, such as analytics, functionality or marketing cookies, are used only based on your consent, where required by law. You can manage your preferences at any time through the cookie settings link available in the Website footer.
More information is available in the Cookie Policy.
The Website may include optional external services, such as Google Maps for displaying locations and Google Cloud AI / Gen App Builder for the chatbot/AI assistant. These services may process technical data, interaction data and other data you submit through the integration.
These services should be loaded only after you consent to the relevant cookie/category, or after you expressly request the functionality, depending on the implementation and legal context. External providers may process data according to their own privacy policies.
In certain situations, phone calls or support communications may be stored or recorded for the purpose of identifying your needs, proving the content of requests, ensuring service quality, training, security or resolving disputes.
Where a call is recorded, you will be informed before the recording starts. If you do not wish to be recorded, you may use other contact channels, such as email or the contact form. Call recordings, where applicable, will be kept only for as long as necessary for the stated purposes, unless a longer period is required to defend rights or comply with legal obligations.
We may disclose personal data, where necessary, to the following categories of recipients:
We do not sell personal data to advertisers or data brokers.
As a rule, we aim to process data within the European Union/European Economic Area. However, certain external providers, such as cloud, analytics, map, chatbot or technical service providers, may process data outside the EU/EEA.
Where personal data is transferred outside the EU/EEA, we will rely on appropriate safeguards under the GDPR, such as adequacy decisions, Standard Contractual Clauses, contractual safeguards or other mechanisms recognised by applicable law.
We keep personal data only for as long as necessary for the purposes for which it was collected, taking into account contractual, legal, accounting, tax, security and dispute-related requirements.
Data category |
Indicative retention period |
|---|---|
Contact and offer requests |
For the period necessary to respond and follow up, generally up to 3 years from the last interaction, unless a contract is concluded or a longer retention is justified. |
Contracts, orders, invoices and accounting documents |
For the period required by accounting and tax legislation and for the period necessary to defend rights. |
Client Account data |
For the duration of the account/service and afterwards for the period necessary for legal, contractual, security or dispute-related purposes. |
Support tickets and related attachments |
For the period necessary to provide support and maintain evidence of interventions, generally up to 3 years, unless a longer period is justified. |
Technical and security logs |
For a limited period necessary for security, debugging and fraud prevention, unless longer retention is required for investigations or disputes. |
Cookie consent preferences |
Until you change/reset your preferences or clear your browser storage, subject to the technical validity configured in the consent mechanism. |
Marketing communications |
Until consent is withdrawn, you object/unsubscribe or the data is no longer necessary for the stated purpose. |
Under the GDPR, you may have the following rights, subject to the conditions and limitations provided by law:
You can exercise these rights by contacting us at office@zadawebsystems.com. We may request additional information to verify your identity before responding to the request.
If you believe that your personal data has been processed unlawfully, you have the right to lodge a complaint with the Romanian supervisory authority:
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Address: B-dul General Gheorghe Magheru 28-30, Sector 1, Bucharest, Romania
Website: https://www.dataprotection.ro/
Email: anspdcp@dataprotection.ro
You may also contact us first so that we can try to resolve your request directly.
We apply technical and organisational measures designed to protect personal data against unauthorised access, accidental loss, disclosure, alteration or destruction. These measures may include access control, account permissions, password hashing, secure hosting, backups, monitoring, logging, internal procedures and contractual obligations for providers.
However, no electronic transmission or storage system can be guaranteed to be completely secure. If you believe your account or data has been compromised, please contact us immediately.
Our services are intended for adults and businesses. We do not knowingly collect personal data from children through the Website. If you believe that a minor has provided us with personal data, please contact us so that we can take appropriate measures.
We do not use personal data for decisions based solely on automated processing that produce legal effects or similarly significant effects on you. Certain technical systems may automatically detect security events, spam, abuse, failed logins or suspicious activity in order to protect the Website and services.
We may update this Policy from time to time to reflect legal, technical, commercial or operational changes. The updated version will be published on this page and will apply from the date indicated above, unless stated otherwise.
For questions, requests or complaints regarding the processing of personal data, please contact:
ZADA WEB SYSTEMS S.R.L.
Str. Școala Floreasca no. 34, Room 1, Block Lot A, Floor 1, Apartment Lot 3,
Bucharest, Sector 1, Romania
Email: office@zadawebsystems.com