Part II
Privacy Policy
How WE AS WEB S.R.L. processes personal data on weasweb.com — what we collect, our lawful bases, recipients, retention, international transfers, and your GDPR rights.
Version 1.0 · Effective and last updated
1. Scope and controller
This Privacy Policy explains how WE AS WEB S.R.L. processes personal data when you visit https://weasweb.com, submit a Website form, contact us about the Website, or exercise a privacy right.
The data controller is:
WE AS WEB S.R.L.Registered office: Strada Fagului nr. 45/A, 400483 Cluj-Napoca, Cluj County, RomaniaCUI: 43690516Trade Registry no.: J12/597/2021 · EUID: ROONRC.J2021000597123Email: sales@weasweb.comTelephone: +40 757 152 921Website: https://weasweb.comThis Policy concerns the public Website. A separate notice or contract may apply if you become a customer, supplier, job candidate, worker, event participant, or other business contact.
2. Our privacy principles
We seek to process personal data lawfully, fairly, and transparently; collect it for specific purposes; limit collection to what is necessary; keep it accurate; retain it no longer than needed; protect it with proportionate safeguards; and remain accountable for our processing.
Our Website analytics configuration is privacy-first: no analytics before consent, EU hosting, pseudonymous identifiers, short retention, no contact-form content in analytics, and no session replay or advertising tracking.
3. Personal data we collect
3.1 Information you provide in a Website form
Depending on the form, we may collect:
- name and business email address, which are normally required to respond;
- company or organization;
- telephone number;
- service, industry, or area of interest;
- message and other information you choose to include; and
- the Website form or page from which the inquiry was submitted.
A hidden honeypot field is used to identify basic automated spam. A genuine user should leave it empty.
3.2 Correspondence and follow-up
If you communicate with us, we may process the content of the correspondence, contact details, timestamps, attachments, internal routing information, and records of our response. If an inquiry develops into a business opportunity, relevant information may later be processed under a separate business-contact, proposal, or contract process.
3.3 Security and delivery data
Our hosting, reverse-proxy, network, and security systems may process limited technical data needed to deliver and protect the Website, such as IP address, request time, requested path, response status, browser or user-agent information, referral header, and indicators of suspected abuse. Such logs are for availability, troubleshooting, fraud and abuse prevention, and security. They are not used by us for advertising.
3.4 Cookie-choice data
We process your analytics choice, the time of the choice, the notice version, and a limited consent identifier where needed to remember and demonstrate your preference. The strictly necessary preference mechanism does not itself enable analytics.
3.5 PostHog analytics data — only after consent
If you choose “Accept analytics”, we use PostHog Cloud EU to measure how the Website is used. The approved configuration is limited to consented page views: one event is recorded when a page loads, and no clicks, scrolling, or other interactions are captured. A page view may include:
- a random first-party pseudonymous browser identifier;
- event name and timestamp;
- Website hostname and path, excluding URL query strings and fragments;
- the title of the page viewed;
- previous Website or referring domain where supplied by the browser;
- general device type, operating system, browser type and version;
- screen and viewport dimensions;
- language and time-zone information; and
- the referring domain, after removal of query strings, fragments, and other unnecessary URL detail.
Analytics is configured not to collect or store names, email addresses, telephone numbers, companies, messages, form-field values, element text, credentials, or other free text. We do not call PostHog’s identify function, create identifiable person profiles, or combine analytics identifiers with contact-form or CRM records under this Policy.
Autocapture, session replay, heatmaps, surveys, automatic exception or error capture, form capture, and advertising or cross-site tracking are outside the approved configuration and are disabled. Raw client IP addresses and GeoIP enrichment are not retained as analytics data. Like any internet endpoint, PostHog may necessarily receive an IP address transiently to complete a network communication, but the analytics project is configured not to store it as an event property or use it for location enrichment.
If these analytics facts change, we will reassess the lawful basis and risk, update this Policy and the Cookie Policy, and obtain a new choice where required before enabling the change.
3.6 Information from third parties
The Website contains ordinary outbound links to third-party websites, including social networks. We do not receive data from those services merely because you view an ordinary link. If you click a link, the third party may receive technical and account information under its own policy.
We do not intentionally buy third-party consumer profiles or enrich Website analytics with brokered personal data under this Policy.
Submitting an inquiry does not subscribe you to a marketing list. Follow-up under this Policy is limited to the inquiry and a reasonably related business conversation. Separate electronic marketing requires a separate lawful basis and, where required, a distinct opt-in.
4. Purposes and lawful bases
We process personal data only where a lawful basis applies.
4.1 Responding to inquiries and taking requested pre-contract steps
- Purpose
- receive, validate, route, respond to, and follow up on your inquiry; arrange a meeting; understand requested services; and take steps you ask us to take before a possible contract.
- Data
- form fields, correspondence, and relevant contact details.
- Lawful basis
- Article 6(1)(b) GDPR where processing is necessary to take steps at your request before a possible contract with you; and Article 6(1)(f) GDPR where you contact us as a representative of an organization or make a general business inquiry. Our legitimate interests are to communicate with prospective customers and partners and operate responsible business-development processes. We do not require privacy consent merely to answer a requested inquiry.
4.2 Operating, securing, and troubleshooting the Website
- Purpose
- deliver Website pages, maintain availability, diagnose faults, prevent spam and attacks, enforce these Terms, and establish, exercise, or defend legal claims.
- Data
- limited request, log, honeypot, and security data.
- Lawful basis
- Article 6(1)(f) GDPR. Our legitimate interests are to provide a reliable Website and protect visitors, our systems, and our rights. Where processing is necessary to comply with a binding legal obligation, Article 6(1)(c) GDPR also applies.
4.3 Remembering and demonstrating cookie choices
- Purpose
- remember a rejection or consent, avoid repeatedly asking for the same choice, apply the choice, and demonstrate compliance.
- Data
- preference category, timestamp, notice version, and limited consent identifier.
- Lawful basis
- Article 6(1)(c) GDPR where necessary to demonstrate compliance and Article 6(1)(f) GDPR for operating an accountable preference mechanism. Storage that is strictly necessary to remember the requested privacy choice is used only for that purpose.
4.4 Optional Website analytics
- Purpose
- understand which pages are viewed; identify broad usage patterns; and improve navigation, content, and performance.
- Data
- the limited PostHog page-view data described in Section 3.5.
- Lawful basis
- your consent under Article 6(1)(a) GDPR. For storing or accessing information on your device, we also rely on prior consent under Article 5(3) of Directive 2002/58/EC as implemented by Article 4(5) of Romanian Law no. 506/2004. Rejecting analytics has no adverse effect on access to the Website.
4.5 Compliance, disputes, and corporate transactions
- Purpose
- comply with law or a valid official request; protect rights and safety; conduct audits; handle disputes; and evaluate or implement a lawful restructuring, financing, merger, acquisition, or transfer.
- Data
- only information reasonably necessary for the relevant matter.
- Lawful basis
- Article 6(1)(c) GDPR for legal obligations and Article 6(1)(f) GDPR for our legitimate interests in governance, legal protection, and responsible corporate transactions. Additional safeguards will be used where appropriate.
5. When data is required
Name and a valid email address are normally required for us to respond to a Website inquiry. Other form fields are generally optional unless clearly marked otherwise. If required information is missing or inaccurate, we may be unable to answer or take requested pre-contract steps.
Analytics consent is entirely optional. You can use the Website and submit an inquiry after rejecting analytics.
6. Recipients and processors
We disclose personal data only where necessary and subject to appropriate safeguards. Recipient categories may include:
- authorized WE AS WEB personnel who need the information for their work;
- Resend, which transmits Website form emails on our instructions;
- our business email, hosting, infrastructure, content-delivery, security, backup, and IT support providers;
- PostHog, acting as our analytics processor only after analytics consent and only for the limited configuration described above;
- professional advisers, auditors, insurers, and counterparties bound by duties of confidentiality;
- courts, regulators, law-enforcement bodies, and other public authorities where disclosure is legally required or justified; and
- a prospective or actual buyer, investor, lender, or successor in a lawful corporate transaction, subject to confidentiality and data-protection requirements.
We require processors to act under written instructions, protect personal data, assist with applicable GDPR obligations, and delete or return data as required by their contracts. We do not sell personal data and do not permit PostHog or Resend to use Website inquiry or analytics data for their own advertising.
7. International transfers
We aim to keep Website analytics data in the European Economic Area by using PostHog Cloud EU in Frankfurt. EU storage does not by itself eliminate every possible international-transfer issue, because provider group companies, support personnel, or subprocessors may be established elsewhere.
Where personal data is transferred outside the European Economic Area, we will use a lawful transfer mechanism as applicable, such as an adequacy decision, the European Commission’s Standard Contractual Clauses, and appropriate supplementary contractual, technical, and organizational measures. We will assess transfer risks and maintain required processor and transfer documentation.
You may ask us for information about the applicable transfer safeguard. We may provide a summary or a redacted copy where necessary to protect commercial confidentiality and security.
8. Retention
We retain personal data only as long as reasonably necessary for the stated purpose, taking account of legal obligations, limitation periods, security needs, and the need to establish, exercise, or defend claims.
Our Website retention schedules are:
- Contact inquiries and correspondence: normally up to 24 months after the last substantive interaction if no contract follows. Information relevant to a contract, dispute, legal obligation, suppression request, or established business relationship may be retained under the applicable separate schedule.
- Basic spam and security logs: normally up to 30 days, unless a longer period is reasonably necessary to investigate an incident, block abuse, comply with law, or protect legal claims.
- Cookie preference stored on the device: up to 180 days before the Website asks again, unless you delete it sooner or a material change requires a new choice.
- Proof of consent or withdrawal: for the life of the choice and normally up to three years after it expires or is withdrawn, unless a longer period is required for a specific legal claim or authority request. This proof will not be used to continue analytics after withdrawal.
- PostHog pseudonymous browser identifier: up to 180 days from the relevant setting, subject to earlier reset on withdrawal or browser deletion.
- Raw PostHog analytics events: up to 12 months. We may retain statistics longer only after they have been aggregated or otherwise transformed so that they no longer identify or single out a visitor.
Backups may retain residual copies for a limited rolling period. Such copies remain protected, are not restored for ordinary use, and are deleted or overwritten according to backup schedules unless preservation is legally required.
9. Your rights
Subject to the conditions and exceptions in applicable law, you may have the right to:
- obtain confirmation whether we process your personal data and receive access to it;
- correct inaccurate data and complete incomplete data;
- request deletion;
- restrict processing;
- receive data you provided in a structured, commonly used, machine-readable format and transmit it to another controller where portability applies;
- object, on grounds relating to your situation, to processing based on legitimate interests;
- object at any time to direct marketing, although this Website Policy does not authorize marketing emails merely because you sent an inquiry;
- withdraw consent at any time, without affecting processing that was lawful before withdrawal;
- receive information about relevant international-transfer safeguards; and
- lodge a complaint with a competent supervisory authority.
9.1 Your right to object
Where we rely on legitimate interests under Article 6(1)(f) GDPR, you have the right to object at any time on grounds relating to your particular situation. We will stop the relevant processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is needed to establish, exercise, or defend legal claims. You may object to direct marketing at any time and, where such marketing occurs, we will stop it.
We do not use Website inquiry or analytics data for a decision based solely on automated processing that produces legal or similarly significant effects.
To exercise a right, email sales@weasweb.com or write to the registered office in Section 1. Please describe the request and the data or interaction concerned. We may ask for proportionate information to verify identity and authority, particularly where disclosure or deletion could affect another person. We will normally respond within one month. The period may be extended by up to two further months for a complex or numerous request, in which case we will explain the extension within the first month.
If we refuse all or part of a request, we will explain the reason and available complaint or judicial remedies unless law prevents us from doing so.
PostHog analytics is held only against a pseudonymous browser identifier and is not linked by us to your name or email. To locate analytics data for a rights request, we may ask you to provide the identifier stored on your device. If you cannot provide it and we cannot otherwise identify the relevant record, Article 11 GDPR may mean that we are unable to locate or act on that analytics data. We will not collect additional identifying information solely to identify an otherwise pseudonymous visitor unless law requires it.
10. Withdrawing analytics consent
You can reject analytics initially or later reopen “Cookie Settings” from the Website footer and switch analytics off. Withdrawal must be as easy as giving consent.
On withdrawal, the Website will stop future PostHog capture, clear or reset the PostHog analytics identifier and related analytics storage under our control, and retain only the minimum preference and proof needed to honor and demonstrate the choice. Withdrawal does not make processing before withdrawal unlawful. You may also request deletion of linked pseudonymous analytics data where it can reasonably be located and the right applies.
Deleting browser storage may remove the saved choice. If that happens, the Website may ask you again. Browser privacy settings and blockers can provide additional control but do not replace our consent mechanism.
11. Security
We use technical and organizational measures intended to provide a level of security appropriate to the risk. Measures include HTTPS in transit, field minimization and length limits, input validation, access controls, least-privilege practices, monitored business mailboxes, vendor review, processor terms, retention controls, backups, and incident-response procedures where appropriate.
No internet transmission or storage system is completely secure. Please do not send secrets or sensitive regulated data through the Website contact form. If you suspect misuse of your data or a security incident, contact us promptly.
12. Children and sensitive data
The Website is not directed to children, and we do not knowingly use Website analytics to profile children. If you believe a child has submitted personal data, contact us so that we can assess and, where appropriate, delete it.
Please do not submit special-category personal data, criminal-offence data, national identifiers, credentials, payment information, health data, or another person’s confidential information through a general contact form. If such data is submitted unexpectedly, we will limit use and delete or secure it as appropriate unless law requires otherwise.
13. Third-party sites
This Policy does not govern websites or services operated by third parties. When you follow an external link, the destination provider may collect data under its own notice. Review that notice and privacy controls before providing information.
14. Complaints
We encourage you to contact us first so that we can address a concern. You also have the right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (Autoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal — ANSPDCP) or another supervisory authority competent for your habitual residence, place of work, or the alleged infringement.
- ANSPDCP website
- https://www.dataprotection.ro
- ANSPDCP address
- 28-30 G-ral Gheorghe Magheru Boulevard, District 1, 010336 Bucharest, Romania
You also retain the right to an effective judicial remedy under applicable law.
15. Changes to this Policy
We may update this Policy when processing, providers, law, or guidance changes. We will publish the new version and effective date. If a change would materially expand consent-based analytics, we will not rely on the old consent where a new, specific choice is required.
16. Contact
Privacy questions and requests may be sent to:
WE AS WEB S.R.L.Registered office: Strada Fagului nr. 45/A, 400483 Cluj-Napoca, Cluj County, RomaniaCUI: 43690516Trade Registry no.: J12/597/2021 · EUID: ROONRC.J2021000597123Email: sales@weasweb.comTelephone: +40 757 152 921