Privacy Policy
This policy explains how Societatea Civilă de Avocatură „Damian și Asociații” processes personal data of website visitors and people who contact us.
1. Data controller
The data controller is Societatea Civilă de Avocatură „Damian și Asociații”.
- Controller: Societatea Civilă de Avocatură „Damian și Asociații”
- Lawyers: Damian Leonard and Damian Mădălina
- Professional address: Iași, Strada Cucu no. 9, Bloc D11, Scara 2, Ground Floor, Ap. 1
- Contact details: [email protected] | [email protected] | +40 755 990 999 | +40 745 303 882
2. Categories of personal data
- Identification and contact data voluntarily provided in communications (name, phone, email, message content).
- Minimum technical data (IP, user-agent, server logs, and security identifiers such as cf_clearance) necessary for security, abuse prevention, and website operation.
- Cookie consent and language preference settings.
3. Purposes and legal bases
- Responding to requests, appointment discussions, and pre-contractual steps (Art. 6(1)(b) GDPR).
- Compliance with legal/professional obligations (Art. 6(1)(c) GDPR).
- Website security, abuse prevention and legal defence (Art. 6(1)(f) GDPR).
- Optional analytics and functional features only based on consent (Art. 6(1)(a) GDPR).
4. Recipients and processors
Data may be accessed by technical providers (hosting, content delivery, security, IT maintenance, email). To protect the website, we use Cloudflare services that may process technical data necessary for security, including IP address, security identifiers, and anti-bot check results. If you enable analytics, additional technical data may be sent to Cloudflare Web Analytics and/or Google Analytics 4 only after consent.
5. Storage period
Data is kept as long as necessary for the collection purpose. If an attorney-client relationship starts, retention continues according to applicable legal/professional obligations (including fiscal/accounting terms, where applicable).
6. Data subject rights
You have rights to information, access, rectification, erasure, restriction, objection, portability, withdrawal of consent, and the right not to be subject to solely automated decisions.
7. Right to lodge a complaint
You may lodge a complaint with the Romanian Data Protection Authority (ANSPDCP): ANSPDCP .
8. International transfers
We do not currently plan systematic transfers outside the EEA except where strictly necessary for technical services. If you enable third-party analytics services (for example Google Analytics 4), transfers to third countries (including the US) may occur, with GDPR safeguards applied.
9. Cookies and analytics
By default, only strictly necessary technologies are active. These may include Cloudflare security and abuse-prevention mechanisms, the cf_clearance cookie, and resources used to protect published email addresses. Cloudflare Web Analytics and Google Analytics 4 remain blocked until explicit consent is granted for the Analytics category.
10. Data security
We apply reasonable technical and organisational measures to protect data against unauthorised access, loss, destruction or alteration.
11. Automated decisions
We do not use automated decision-making, including profiling, that produces legal effects on you through this website.
12. Updates and contact
We may periodically update this policy. For rights requests or data-processing questions, contact us at [email protected] or [email protected].
13. Third-party resources loaded by default
Below is the explicit list of third-party resources relevant for browser loading:
- Automatic loading without consent: Cloudflare resources for security, anti-bot challenges, and protection of published email addresses may load automatically.
- Loaded only after Analytics consent: Cloudflare Web Analytics and Google Analytics 4.
- Loaded only after Functional consent: Google Maps on the contact page.
- Loaded only after voluntary user action (click): links to external websites (e.g., ANSPDCP, UNBR, Baroul Iași, WhatsApp).