Privacy Policy
Effective date: January 1, 2025
Esentrysecurity SRL ("we", "our", "us") respects the confidentiality of your personal data. This policy explains how we collect, use, store, and protect information when you access our website or use our cybersecurity and IT audit services.
What data we collect
We only collect information strictly necessary for providing contracted services and for legal compliance (GDPR, Romanian legislation).
- Name, surname, job title, and contact details (email, phone) – from contact forms and contracts
- Technical data: IP address, browser type, operating system, pages visited – through strictly functional cookies
- Information about your company's IT infrastructure – only within audits and vulnerability tests, with prior consent
- Billing and fiscal data – for issuing invoices and fulfilling accounting obligations
Purpose of processing
We process data exclusively for determined, explicit, and legitimate purposes, without subsequently using it in a manner incompatible with these purposes.
- Provision of cybersecurity and IT audit services according to the contract
- Communication with you regarding services, offers, and security updates
- Fulfillment of legal obligations (GDPR, Law 362/2018, fiscal regulations)
- Improving the security of our platform and preventing fraud
Legal basis for processing
We rely on clear legal grounds, in accordance with Regulation (EU) 2016/679 (GDPR).
- Performance of a contract (Art. 6(1)(b)) – for the services provided
- Legal obligation (Art. 6(1)(c)) – for fiscal and accounting data
- Consent (Art. 6(1)(a)) – for cookies and promotional communications, where applicable
- Legitimate interest (Art. 6(1)(f)) – for network security and abuse prevention
Data storage and security
Data is stored on secure servers in Romania and the European Union, with restricted access and encryption in transit (TLS 1.3).
- Storage period: maximum 5 years from the end of the contract, in accordance with accounting legislation
- Technical measures: firewall, AES-256 encryption, multi-factor authentication, periodic security audits
- Access to data is strictly limited to authorized Esentrysecurity employees and our IT service providers, who adhere to the same confidentiality standards
Your rights
As a data subject, you benefit from all rights provided by the GDPR, which you can exercise free of charge.
- Right of access – you can request a copy of the processed data
- Right to rectification – you can correct inaccurate data
- Right to erasure ("right to be forgotten") – under the conditions of the law
- Right to restriction of processing – in case of contesting the accuracy of the data
- Right to data portability – in a structured, commonly used format
- Right to object – for processing based on legitimate interest
Cookies and similar technologies
We use strictly necessary cookies for the functioning of the site and anonymized analytical cookies (Google Analytics with IP masking).
- Session cookies – for authentication and maintaining user state
- Analytical cookies – to understand how the site is used, without identifying visitors
- We do not use advertising or cross-site tracking cookies
- You can manage cookie preferences from your browser settings
Disclosure to third parties
We do not sell, rent, or share your data with third parties, except as provided by law.
- Service providers (web hosting, payment processing) – who act as designated processors and adhere to strict contractual clauses
- Competent authorities – when there is a legal obligation (e.g., in case of a major cyber attack)
- In the event of a merger or acquisition – with prior notice and the right to request data deletion
Contact and Data Protection Officer
For any questions, requests, or complaints regarding the processing of your data, you can contact us.
- Email: info@esentrysecurity.com
- Phone: 0341284139
- Address: Aleea Crișan nr. 2A, bl. 26, sc. A, et. 7, ap. 1
- Data Protection Officer: Mioara Radoi – dpo@esentrysecurity.com
- Supervisory Authority: National Supervisory Authority for Personal Data Processing (ANSPDCP) – www.dataprotection.ro
Changes to this policy
We reserve the right to periodically update this policy. Any changes will be published on this page, and in the case of significant changes, you will be notified by email.
- Current version: 1.0 – January 2025
- Last revision: December 15, 2024
- We recommend you check this page periodically to stay informed of the latest updates