Privacy and personal data
Privacy policy.
Dorobanti Media is operated by DOROBANTI NETWORK S.R.L.. This policy explains how the company processes personal data when you visit its public pages or send a project inquiry.
Controller and contact details
The controller responsible for the public Dorobanti Media website is DOROBANTI NETWORK S.R.L., trading as Dorobanti Media, with its registered office at 9 Aleea Tomești, Block 15, Staircase 2, 7th floor, Apartment 63, Sector 4, 042144 Bucharest, Romania, unique registration and tax code (CUI) 51010254, VAT ID RO51010254, Trade Register number J2024047810002, and EUID ROONRC.J2024047810002. The company provides custom software development services under CAEN 6210 Rev. 3 (equivalent to 6201 Rev. 2).
For questions or requests concerning personal data, email contact@dorobantimedia.com, call +40 730 000 064, or use the public contact page.
Email contact@dorobantimedia.comCall +40 730 000 064Use the contact pageScope and sources
This notice applies to visitors of the public website and people who send a project inquiry. It does not replace any privacy information provided separately to clients, suppliers, employees, or authorized CRM users.
We receive information directly from you when you use the contact form or correspond with us. Limited technical, security, and analytics information may be generated automatically when you use the website.
Personal data we process
Project inquiries: name, phone number, optional email address, optional company or product name, selected service, message, interface language, a random submission identifier used to prevent duplicate records, submission and update times, and the internal status assigned to the inquiry. If you send a request from the project configurator, we also store your selected project configuration and the non-binding estimate calculated on the server from the applicable pricing rules. We also process later correspondence and any information you choose to include in it. If you call us, this includes your telephone number, the time of contact and information you provide to handle your request.
Security and operation: request metadata needed to deliver and protect the website. For contact-form rate limiting, the IP address and phone number are converted into one-way hashed keys before the rate-limit record is stored; the raw values are not stored in that record. Hosting providers may process IP addresses, request headers, timestamps, and diagnostic logs as part of delivering and securing the service.
Preferences and measurement: the website stores your cookie choice and appearance preference. If you consent to analytics, Google Analytics tags delivered through Google Tag Manager may process a cookie identifier, pages viewed, page title and URL, approximate location, browser and device information, referrer, session statistics, a pseudonymous server-issued inquiry ID used to deduplicate genuine form conversions, IP address during transmission, and related measurement data. If you separately consent to Google Ads conversion measurement, the corresponding Google Ads tag is delivered through Google Tag Manager and advertising storage and ad-user data are enabled for campaign attribution. Values entered in inquiry form fields are not sent as analytics or conversion-event parameters. Ad personalization and Google Signals remain disabled.
Purposes and legal bases
If you inquire for yourself as a potential client, we use the inquiry data to review your request, contact you, prepare a proposal, and take steps you request before entering a contract (Article 6(1)(b) GDPR). If you contact us on behalf of an organization or another person, we rely on our legitimate interest in answering business communications and evaluating a possible project (Article 6(1)(f) GDPR).
If you send a configurator estimate with your inquiry, we use the selected configuration and server-calculated estimate to assess the requested scope, respond to you, and prepare the next pre-contractual steps. The estimate remains non-binding until the project scope and commercial terms are confirmed in writing.
We process limited technical and security data to provide the website, prevent abuse, troubleshoot failures, and protect our systems and users. The legal basis is our legitimate interest in operating a secure and reliable service (Article 6(1)(f) GDPR). Where information must be retained or disclosed under tax, accounting, company, or other law, the basis is compliance with a legal obligation (Article 6(1)(c) GDPR).
Optional analytics and Google Ads conversion measurement are each based on your consent (Article 6(1)(a) GDPR and Article 4(5) of Romanian Law 506/2004). You can refuse or withdraw either choice at any time without affecting the lawfulness of processing carried out before withdrawal.
Required and optional information
Name, phone number, service selection, and project message are required to submit an inquiry because we need them to understand the request and reply. We cannot receive the form without them. Email address and company name are optional. The privacy notice is displayed next to the submit action; no consent is requested for processing that is necessary to answer your inquiry. Providing an inquiry does not create a contract or require either party to proceed with a project.
Recipients and international transfers
Within the company, correspondence is accessible only to authorized personnel. We use Apple iCloud Mail for email and Vodafone for telephone service. Providers process the data needed to supply those services under their applicable terms and policies.
Other recipients include providers that support hosting, database infrastructure, security, and technical operations. Professional advisers or public authorities may receive data where reasonably necessary to establish, exercise, or defend legal claims or comply with law. We do not sell personal data.
Google receives Analytics or Google Ads conversion-measurement data only after the corresponding consent. Some providers may process data outside the European Economic Area. Where this occurs, we use an applicable European Commission adequacy decision, including the EU–U.S. Data Privacy Framework where available, or safeguards such as the European Commission standard contractual clauses. You may request information about the safeguard relevant to your data by contacting us.
Retention
Support correspondence and project inquiries that do not lead to a client relationship are retained for 30 days after the last contact, then deleted from the mailboxes and working records we control. A saved configurator configuration and estimate form part of the related inquiry and are deleted with it under the same retention rules. The period runs from the last contact, not from an internal status change. If a project proceeds, relevant correspondence, contracts, invoices, and accounting records are kept for the periods required by Romanian law and for the limitation periods applicable to legal claims.
The provider’s backup deletion timing remains unverified. Deleting correspondence from the mailboxes and working records we control does not establish that every provider backup copy is erased at the end of the same 30-day period. Records required by law or for an active legal claim are kept separately, limited to what is necessary and for the applicable period.
Rate-limit records contain hashed keys, counters, and timestamps. The active rate-limit window is no longer than one hour. Records become eligible for deletion 24 hours after their last update and are removed by a daily maintenance job, normally within 48 hours of that update. Hosting and security logs are retained according to the provider configuration and only for as long as reasonably necessary. Your cookie choice is stored for six months. The appearance cookie is stored for one year, while the matching local-storage preference remains until you change it or clear browser data. Google Analytics cookie durations and controls are described in the cookie policy.
Security
We use measures appropriate to the nature of the data and the risks involved, including access controls, encryption in transit, request validation, rate limiting, restricted administrative access, and security headers. No internet service can guarantee absolute security.
Your rights and complaints
Subject to the conditions in the GDPR, you may request access, rectification, erasure, restriction, or portability of your data, and you may object to processing based on legitimate interests. You may withdraw consent at any time. Rights requests are normally answered within one month and are free unless a request is manifestly unfounded or excessive. We may request reasonable information to verify identity.
You also have the right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul General Gheorghe Magheru 28-30, Sector 1, 010336 Bucharest, Romania, or with the supervisory authority in the EU or EEA country where you live or work.
ANSPDCP complaints and contact informationAutomated decisions and children
We do not use the personal data covered by this notice to make solely automated decisions that produce legal or similarly significant effects. The public website is intended for business and professional inquiries and is not directed to children.
Changes to this notice
We may update this notice when the website, providers, processing activities, or legal requirements change. Material changes will be highlighted where appropriate. The current version and its update date remain available on this page.