ZADA WEB SYSTEMS S.R.L.

Policy on the Processing of Personal Data

shape
shape
shape
shape
shape
shape
shape
shape

POLICY ON THE PROCESSING OF PERSONAL DATA

Last updated: 27.04.2026

Respecting privacy and protecting personal data are important to us. This Policy explains how ZADA WEB SYSTEMS S.R.L. processes personal data when you visit https://zadawebsystems.com/, use our contact forms, request offers, create an account, use the client area, place orders, make payments, request support or interact with our services.

This Policy is supplemented by the Cookie Policy, the applicable Terms and Conditions, commercial contracts concluded with clients and, where applicable, data processing agreements concluded with our clients.

  • 1. Who is the data controller?

ZADA WEB SYSTEMS S.R.L., with its registered office in Str. Școala Floreasca no. 34, Room 1, Block Lot A, Floor 1, Apartment Lot 3, Bucharest, Sector 1, Romania, tax identification number 46368745, registered with the Trade Register Office under no. J40/12110/2022, processes your personal data as a controller within the meaning of Regulation (EU) 2016/679 (“GDPR”) for the activities described in this Policy.

For any question regarding data protection, you may contact us at: office@zadawebsystems.com.

At this time, ZADA WEB SYSTEMS S.R.L. has not appointed a separate Data Protection Officer (“DPO”). However, any request concerning personal data may be sent to the contact address mentioned above.

  • 2. Our role: controller or processor

Depending on the context, ZADA WEB SYSTEMS S.R.L. may have different roles:

  • Controller when we process data for our own purposes, for example for website administration, contacting potential clients, managing orders, invoicing, payments, support, client accounts, security, our own marketing and compliance with legal obligations.
  • Processor when a client uses our platforms or services, including Zada Shop, CRM, document modules, invoicing, hosting, maintenance, technical support or other services, and the client decides what data of its own users, customers, employees or partners is entered into the platform. In these cases, the client is usually the controller, and the processing is carried out according to the contract and/or the data processing agreement.
  • 3. What categories of data may we process?

Depending on your interaction with us, we may process the following categories of data:

  • Identification and contact data: first name, last name, email address, phone number, company, role, country, county/region, city, address.
  • Commercial and contractual data: requested services, selected packages, products added to cart, order history, offer details, notes/comments submitted, preferences regarding services such as hosting, domains, e-commerce, CRM, couriers, payments or other integrations.
  • Billing data: name/company name, VAT/tax number, registration number, billing address, tax data, order value, currency, invoiced products/services.
  • Payment data: selected payment method, amount, currency, internal order/payment identifiers, transaction status and billing details sent to the payment processor. We do not store full bank card details; these are processed by the authorised payment processor.
  • Account data: email address, password stored in encrypted/hashed form, first name, last name, organisation, roles, access rights, account status, preferences, language, acceptance of terms, active products, login and password reset data.
  • Support data: support tickets, issue descriptions, comments, uploaded attachments, screenshots, technical data required for investigation and communication history.
  • Technical and security data: IP address, user-agent, accessed URL, referrer, session ID, access date and time, device/browser information, technical and security logs, error or platform event data.
  • Data collected through cookies/local storage/session storage: cookie preferences, consent status, functionality options, analytics identifiers, session data and data required for cart or account operation, according to the Cookie Policy.
  • Data submitted through chatbot or external integrations: questions, messages, preferences and interactions submitted when using the chatbot or integrated external services, such as Google Cloud AI / Gen App Builder or Google Maps, to the extent these are activated.
  • Data required for special services: for services such as electronic signatures, electronic archiving, domains, hosting, payment integration, couriers or other technical services, additional data may be required depending on the ordered service and the requirements of the providers involved.
  • 4. Purposes and legal bases of processing

We process personal data only where we have a valid legal basis under the GDPR.

Purpose of processing

Categories of data

Legal basis

Responding to contact forms, offer requests, demo requests and commercial enquiries.

Identification and contact data, commercial details, message content.

Taking steps at your request before entering into a contract or our legitimate interest in responding to enquiries.

Creating and managing the Client Account.

Account data, identification data, contact data, roles, access rights, accepted terms.

Performance of a contract or taking steps before entering into a contract.

Processing orders, activating services, delivering digital services, licences, hosting, domains or custom projects.

Commercial and contractual data, account data, billing data, technical data, data required for the selected service.

Performance of a contract.

Issuing invoices, accounting records and tax reporting.

Billing data, tax data, order data, payment status.

Compliance with legal obligations.

Processing payments, payment links, payment confirmations and transaction status.

Payment method, amount, transaction identifiers, payment status, billing data.

Performance of a contract and compliance with financial/accounting obligations.

Providing technical support, maintenance, troubleshooting and client assistance.

Support data, contact data, technical logs, screenshots, uploaded files, account/service data.

Performance of a contract and legitimate interest in providing support and maintaining service quality.

Ensuring website, platform, account and infrastructure security.

IP address, logs, user-agent, access events, security events, account actions.

Legitimate interest in protecting systems, users and services and, where applicable, legal obligations.

Using strictly necessary cookies and storing cookie consent preferences.

Session identifiers, cookieConsent, cookiesAccepted and similar technical preferences.

Legitimate interest in operating the website and compliance with legal obligations regarding consent evidence.

Using analytics, performance, functionality or marketing cookies.

Cookie identifiers, usage data, device/browser data, preferences.

Your consent, where required by law.

Using Google Maps, chatbot/AI assistant or other optional external integrations.

Technical data, interaction data, messages submitted by you, service-specific identifiers.

Your consent for optional cookies/technologies, or performance of a service explicitly requested by you, depending on the context.

Sending commercial communications, offers, newsletters or marketing messages.

Name, email, phone, company, preferences, interaction history.

Your consent, or legitimate interest where allowed by law for existing clients and similar services, with the right to object/unsubscribe.

Defending rights, managing disputes, audits, contractual evidence and compliance.

Contractual data, communication history, account data, technical logs, billing and payment data.

Legitimate interest and, where applicable, legal obligations.

  • 5. Forms, orders, payments and support tickets

When you use forms on the Website or in the Client Account, we process the data you provide in order to respond to your request, prepare an offer, provide the requested service, issue invoices, process payments or provide support.

If you upload files, screenshots or documents in a support ticket or through another available channel, please make sure you do not upload unnecessary personal data or confidential information that is not relevant to the request. Where possible, please anonymise sensitive information before sending it.

For card payments, the payment is processed through an authorised payment processor. ZADA may receive information such as payment status, amount, currency, payment identifier and billing details, but does not store full card data.

  • 6. Cookies, localStorage and similar technologies

We use strictly necessary cookies and similar technologies for the operation of the Website, security, session management, cart/account operation and storage of cookie consent preferences.

Optional cookies or similar technologies, such as analytics, functionality or marketing cookies, are used only based on your consent, where required by law. You can manage your preferences at any time through the cookie settings link available in the Website footer.

More information is available in the Cookie Policy.

  • 7. Google Maps, chatbot and external integrations

The Website may include optional external services, such as Google Maps for displaying locations and Google Cloud AI / Gen App Builder for the chatbot/AI assistant. These services may process technical data, interaction data and other data you submit through the integration.

These services should be loaded only after you consent to the relevant cookie/category, or after you expressly request the functionality, depending on the implementation and legal context. External providers may process data according to their own privacy policies.

  • 8. Phone calls and support communications

In certain situations, phone calls or support communications may be stored or recorded for the purpose of identifying your needs, proving the content of requests, ensuring service quality, training, security or resolving disputes.

Where a call is recorded, you will be informed before the recording starts. If you do not wish to be recorded, you may use other contact channels, such as email or the contact form. Call recordings, where applicable, will be kept only for as long as necessary for the stated purposes, unless a longer period is required to defend rights or comply with legal obligations.

  • 9. Recipients of personal data

We may disclose personal data, where necessary, to the following categories of recipients:

  • employees, collaborators and authorised representatives of ZADA, according to their role and access rights;
  • IT, hosting, maintenance, security and infrastructure providers;
  • payment processors, banks and financial service providers;
  • accounting, invoicing, legal, audit and consultancy service providers;
  • providers of domains, SSL certificates, email, DNS, courier or related technical services;
  • providers of electronic signature, trust services or electronic archiving, where applicable;
  • external service providers such as Google, where optional services are activated;
  • public authorities, courts or institutions, where disclosure is required by law or necessary to defend rights;
  • clients for whom we act as processor, in relation to data processed under their instructions.

We do not sell personal data to advertisers or data brokers.

  • 10. International transfers

As a rule, we aim to process data within the European Union/European Economic Area. However, certain external providers, such as cloud, analytics, map, chatbot or technical service providers, may process data outside the EU/EEA.

Where personal data is transferred outside the EU/EEA, we will rely on appropriate safeguards under the GDPR, such as adequacy decisions, Standard Contractual Clauses, contractual safeguards or other mechanisms recognised by applicable law.

  • 11. How long do we keep personal data?

We keep personal data only for as long as necessary for the purposes for which it was collected, taking into account contractual, legal, accounting, tax, security and dispute-related requirements.

Data category

Indicative retention period

Contact and offer requests

For the period necessary to respond and follow up, generally up to 3 years from the last interaction, unless a contract is concluded or a longer retention is justified.

Contracts, orders, invoices and accounting documents

For the period required by accounting and tax legislation and for the period necessary to defend rights.

Client Account data

For the duration of the account/service and afterwards for the period necessary for legal, contractual, security or dispute-related purposes.

Support tickets and related attachments

For the period necessary to provide support and maintain evidence of interventions, generally up to 3 years, unless a longer period is justified.

Technical and security logs

For a limited period necessary for security, debugging and fraud prevention, unless longer retention is required for investigations or disputes.

Cookie consent preferences

Until you change/reset your preferences or clear your browser storage, subject to the technical validity configured in the consent mechanism.

Marketing communications

Until consent is withdrawn, you object/unsubscribe or the data is no longer necessary for the stated purpose.

  • 12. Your rights under the GDPR

Under the GDPR, you may have the following rights, subject to the conditions and limitations provided by law:

  • Right of access – to obtain confirmation as to whether we process your data and access to that data.
  • Right to rectification – to request correction of inaccurate or incomplete data.
  • Right to erasure – to request deletion of data, where legal conditions are met.
  • Right to restriction of processing – to request limitation of processing in certain cases.
  • Right to data portability – to receive data in a structured, commonly used and machine-readable format, where applicable.
  • Right to object – to object to processing based on legitimate interest or to direct marketing.
  • Right to withdraw consent – where processing is based on consent, you may withdraw it at any time, without affecting the lawfulness of processing carried out before withdrawal.
  • Right not to be subject to automated decisions – where applicable, not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
  • Right to lodge a complaint – with the competent supervisory authority.

You can exercise these rights by contacting us at office@zadawebsystems.com. We may request additional information to verify your identity before responding to the request.

  • 13. Supervisory authority

If you believe that your personal data has been processed unlawfully, you have the right to lodge a complaint with the Romanian supervisory authority:

Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Address: B-dul General Gheorghe Magheru 28-30, Sector 1, Bucharest, Romania
Website: https://www.dataprotection.ro/
Email: anspdcp@dataprotection.ro

You may also contact us first so that we can try to resolve your request directly.

  • 14. Security of personal data

We apply technical and organisational measures designed to protect personal data against unauthorised access, accidental loss, disclosure, alteration or destruction. These measures may include access control, account permissions, password hashing, secure hosting, backups, monitoring, logging, internal procedures and contractual obligations for providers.

However, no electronic transmission or storage system can be guaranteed to be completely secure. If you believe your account or data has been compromised, please contact us immediately.

  • 15. Children’s data

Our services are intended for adults and businesses. We do not knowingly collect personal data from children through the Website. If you believe that a minor has provided us with personal data, please contact us so that we can take appropriate measures.

  • 16. Automated decision-making

We do not use personal data for decisions based solely on automated processing that produce legal effects or similarly significant effects on you. Certain technical systems may automatically detect security events, spam, abuse, failed logins or suspicious activity in order to protect the Website and services.

  • 17. Updates to this Policy

We may update this Policy from time to time to reflect legal, technical, commercial or operational changes. The updated version will be published on this page and will apply from the date indicated above, unless stated otherwise.

  • 18. Contact

For questions, requests or complaints regarding the processing of personal data, please contact:

ZADA WEB SYSTEMS S.R.L.
Str. Școala Floreasca no. 34, Room 1, Block Lot A, Floor 1, Apartment Lot 3,
Bucharest, Sector 1, Romania
Email: office@zadawebsystems.com

0 RON 0