Difinepr

Privacy Policy

Last updated: 24 July 2026

This Privacy Policy explains how S.C. DIFINE PR S.R.L. collects, uses, stores and protects personal data when you visit this website or communicate with us. It is intended to provide the information required by the EU General Data Protection Regulation (“GDPR”).

1. Data controller

The controller is S.C. DIFINE PR S.R.L., VAT number RO38064095, with its registered office at B-dul Lascăr Catargiu no. 18, 1st floor, apartment 5, Sector 1, Bucharest, Romania. Privacy enquiries and requests may be sent to diana.iosu@difinepr.com.

2. Personal data we may process

  • Contact and identity data: name, organisation, role, email address, telephone number and any details you choose to provide.
  • Communication data: messages, requests, proposals, feedback and related correspondence.
  • Business relationship data: information required to discuss, prepare or perform a service engagement, maintain client and supplier relationships, and meet accounting or legal obligations.
  • Technical and usage data: IP address, browser and device information, timestamps, requested pages, referral information and security logs generated by the hosting environment or WordPress.
  • Public professional data: business contact information obtained from public sources or professional platforms where relevant to a legitimate business communication.

Please do not send special-category data, identity documents, financial credentials or other sensitive information unless we specifically request it and provide an appropriate secure method.

3. Purposes and legal bases

  • To respond to enquiries and discuss requested services — taking steps at your request before entering a contract and our legitimate interest in business communication.
  • To prepare, manage and perform contracts — performance of a contract and compliance with legal obligations.
  • To maintain professional relationships and communicate relevant business information — our legitimate interests, balanced against your rights; consent where legally required.
  • To operate, secure, troubleshoot and improve the website — our legitimate interests in providing a safe and effective website.
  • To keep financial, contractual and compliance records, establish or defend legal claims, and respond to authorities — legal obligations and legitimate interests.
  • To use non-essential analytics or marketing technologies — consent, where such tools are activated.

4. How we receive data

We generally receive data directly from you by email, telephone, website interactions, meetings or contractual communications. We may also receive professional information from your organisation, project partners, public registers, event organisers, media databases or publicly accessible professional sources where lawful.

5. Recipients and service providers

Access is limited to authorised DiFine PR personnel who need the information. We may share data with contracted hosting, IT, security, email, collaboration, accounting, legal or other professional providers; project partners where necessary and authorised; and public authorities where required by law. Providers act under appropriate confidentiality and data-protection obligations. We do not sell personal data.

6. International transfers

If a provider processes data outside the European Economic Area, we will use a lawful transfer mechanism where required, such as an adequacy decision, Standard Contractual Clauses and supplementary safeguards. You may contact us for information about safeguards relevant to your data.

7. Retention

We keep personal data only for as long as needed for the relevant purpose. Enquiry correspondence is normally reviewed for deletion after three years unless a relationship, legal requirement or dispute requires longer retention. Contractual, accounting and tax records are kept for the periods required by Romanian law. Technical logs are retained according to security needs and provider settings. Data may be retained longer where necessary to establish, exercise or defend legal claims.

8. Your rights

Subject to the conditions in the GDPR, you may request access to your data, rectification, erasure, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent at any time without affecting earlier lawful processing. You also have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. DiFine PR does not use this website to make such decisions.

Send requests to diana.iosu@difinepr.com. We may ask for information needed to verify your identity and will respond within the legally applicable period.

9. Complaints

You may lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) or another competent supervisory authority. Information is available at www.dataprotection.ro. We encourage you to contact us first so we can try to resolve the concern.

10. Security

We use reasonable organisational and technical measures designed to protect personal data against unauthorised access, alteration, loss or disclosure. No internet transmission or storage system can be guaranteed completely secure.

11. Children

This website is intended for a professional audience and is not directed to children. We do not knowingly collect personal data from children through the website.

12. Cookies and external services

The Cookie Policy explains the technologies used by the website. External websites and platforms linked from this site process data under their own privacy notices.

13. Changes to this policy

We may update this policy when our processing, providers or legal obligations change. The current version will be published on this page with a revised date.