Alfa Rom Consulting

Data Protection Policy (GDPR)

How Alfa Rom collects, processes, retains personal data and your GDPR rights. Last updated:

1.0 INTRODUCTION

Alfa Rom Consulting SRL (“Alfa Rom”) is committed to protecting and respecting your privacy. This Policy explains how Alfa Rom collects, processes, retains, and protects your personal data in accordance with the EU General Data Protection Regulation (GDPR) and Romanian Law No. 190/2018.

2.0 WHAT IS PERSONAL DATA?

Personal data means any information relating to an identified or identifiable natural person, such as a name, identification number, location data, or online identifier. Sensitive personal data include data revealing racial or ethnic origin, political opinions, religious beliefs, health information, or sexual orientation.

3.0 DATA PROCESSING PRINCIPLES

Alfa Rom adheres to GDPR principles to ensure personal data is:

  • Processed lawfully, fairly, and transparently;
  • Collected for specified, explicit, and legitimate purposes;
  • Adequate, relevant, and limited to what is necessary;
  • Accurate and kept up to date as needed;
  • Retained only as long as necessary;
  • Secured by appropriate technical and organizational measures;
  • Demonstrably compliant with GDPR principles.

4.0 DATA PROTECTION OFFICER

Alfa Rom’s Data Protection Officer (DPO) oversees adherence to data protection laws and policies.

Contact: dpo@alfarom.eu

5.0 PURPOSES OF DATA PROCESSING

Alfa Rom collects and processes personal data for the following purposes:

  • Employee and contractor administration;
  • Fulfilling contractual and financial obligations;
  • Recruitment processes;
  • Client contact management and service provision;
  • Advertising, marketing, and public relations;
  • Handling emergency situations;
  • Processing of personal data submitted via the Website contact form (e.g., name, email, phone number, job ID, and inquiry details) used solely to respond to requests and provide relevant information or services.

Alfa Rom does not collect or process sensitive personal data unless explicit consent is given or required by law.

6.0 LAWFULNESS OF PROCESSING

  • Performance of a contract;
  • Compliance with a legal obligation;
  • Legitimate interests pursued by Alfa Rom;
  • Consent from the data subject, where required (e.g., marketing communications).

7.0 PRIVACY NOTICES

Alfa Rom provides clear, accessible privacy information at the point of collection or within a reasonable time when data is obtained indirectly, including disclosures for third-party sharing or further processing changes.

8.0 DATA SUBJECT RIGHTS

Under GDPR, you have the right to:

  • Access your personal data;
  • Request correction or deletion;
  • Object to or restrict processing;
  • Data portability;
  • Withdraw consent where applicable;
  • Lodge complaints with the Romanian supervisory authority (ANSPDCP).

Requests can be submitted via the Personal Data Request Form F-501 or by contacting the DPO.

9.0 DATA SECURITY

Alfa Rom commits to securing personal data with appropriate organizational and technical controls to prevent data breaches or unauthorized access.

10.0 DATA RETENTION

Personal data is kept only as long as necessary to fulfill the purposes for which it was collected or to comply with legal retention obligations.

11.0 DATA TRANSFERS

Any transfer of personal data outside the European Economic Area (EEA) is carried out only where appropriate safeguards are in place, as required by GDPR.

12.0 CHANGES TO THIS POLICY

This Data Protection Policy may be updated periodically. Changes will be notified on the Website’s footer link, with the effective date revised accordingly.

13.0 CONTACT INFORMATION

For questions about this policy or to exercise your data protection rights, please contact the Data Protection Officer at dpo@alfarom.eu.

14.0 FORMS & DOWNLOADS

Download »»»
F-501-ENG Form (Personal Data Request, English version, PDF file)
Download »»»
F-501-ROU Form (Personal Data Request, Romanian version, PDF file)
↑ Top
Scroll to Top