Privacy Policy
1. Introduction
1.1. Welcome
Romania for Business (“the Company”, “we”, “us”, “our”) respects the privacy of everyone who visits our website at https://romania-for-business.com/ (“the Website”) or engages us for company formation, registered office, tax, accounting liaison, and business consultancy services. This Privacy Policy explains, in plain and accessible language, what personal data we collect, why we collect it, how we use and protect it, and what rights are available to you in connection with that data.
1.2. Relationship to Our Other Policies
This Privacy Policy sits alongside several more specialised documents that address particular aspects of our data protection framework in greater technical depth:
- Our GDPR Compliance Policy, which sets out our internal governance framework and legal bases for processing in more detail;
- Our Cookie Policy, which explains specifically how we use cookies and similar technologies on the Website;
- Our AML Policy, which explains how we handle identification and due diligence information for anti-money laundering purposes;
- Our Complaint Handling Policy, which explains how we deal with complaints, including complaints about how your data has been handled.
Where this Privacy Policy and any of the above documents overlap, they should be read together and interpreted consistently with one another.
1.3. Who This Policy Applies To
- Visitors browsing our Website, whether or not they go on to become clients;
- Prospective clients who contact us to enquire about our services;
- Clients for whom we are actively providing, or have previously provided, services; and
- Representatives, employees, or beneficial owners of corporate clients whose personal data we may need to process in the course of delivering our services.
2. Who We Are
2.1. Data Controller Identity
For the purposes of applicable data protection law, including Regulation (EU) 2016/679 (the “GDPR”) and Romanian Law No. 190/2018, Romania for Business is the data controller responsible for the personal data described in this Privacy Policy, except where we act as a data processor on behalf of a client under a separate written agreement.
2.2. How to Contact Us
- Email: info@romania-for-business.com
- Website: https://romania-for-business.com/
We welcome questions, concerns, or requests relating to this Privacy Policy at any time, and we encourage you to reach out to us directly using the details above before escalating any concern elsewhere.
3. What Personal Data We Collect
We collect different categories of personal data depending on the nature of your interaction with us. These generally fall into the following groups.
3.1. Information You Provide Directly
- Identification details, such as your full name, date of birth, nationality, and identification document numbers, typically collected when you engage us for company formation or related corporate services;
- Contact details, such as your email address, telephone number, and postal address;
- Business and engagement information, such as details of the company you wish to establish or already operate, your role within it, shareholding or beneficial ownership structure, and the nature of the services you are requesting;
- Communications, including the content of emails, messages, or forms you submit to us, and any documents you choose to share with us in connection with an engagement.
3.2. Information Collected Automatically
- Technical and usage data, such as your IP address, browser type and version, device information, operating system, referring website, and the pages you visit on our Website;
- Cookie-derived data, collected through cookies and similar technologies as described in detail in our separate Cookie Policy.
3.3. Information From Third Parties
- Where relevant and permitted by law, we may receive personal data about you from public registries (such as the National Trade Registry Office), from other advisers involved in an engagement (such as notaries or accountants), or from due diligence and screening tools used for anti-money laundering purposes, as described in our AML Policy.
3.4. Special Categories of Data
- We do not, as a general rule, seek to collect sensitive categories of personal data, such as information about health, religious beliefs, or political opinions. If such information becomes relevant to a specific engagement, for example incidentally through a politically exposed person screening check, we handle it with heightened care and only for the specific purpose for which it is required.
4. Why and How We Use Your Personal Data
We use personal data for a defined set of purposes, each of which is tied to a lawful basis for processing under Article 6 of the GDPR.
4.1. To Deliver Our Services
- We use client and engagement information to assess your requirements, prepare proposals, carry out company formation and related corporate services, and communicate with you throughout our engagement. This processing is generally necessary for the performance of a contract with you, or to take steps you have requested prior to entering into a contract.
4.2. To Comply With Legal Obligations
- We use identification and due diligence information to satisfy our obligations under Romanian and EU anti-money laundering legislation, tax law, and accounting and record-keeping rules. This processing is necessary for us to comply with a legal obligation to which we are subject, as explained further in our AML Policy.
4.3. To Respond to Enquiries
- We use the contact details and information you provide through our Website or by email to respond to your questions and, where appropriate, follow up on enquiries about our services. This processing is generally based on our legitimate interest in engaging with prospective clients, or on your consent where you have actively initiated contact.
4.4. To Operate and Improve Our Website
- We use technical and cookie-derived data to ensure our Website functions correctly, to maintain its security, and to understand, in aggregate form, how visitors use our content so that we can improve it over time. This processing is based on our legitimate interests, or on your consent where required for non-essential cookies, as described in our Cookie Policy.
4.5. To Handle Complaints
- Where you submit a complaint, we use the information you provide to investigate and resolve it, in accordance with our Complaint Handling Policy, and this processing is generally necessary for our legitimate interest in resolving disputes fairly, or to comply with applicable consumer protection obligations.
4.6. What We Do Not Do
- We do not use your personal data to make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you, and we do not sell your personal data to third parties.
5. Who We Share Your Personal Data With
5.1. Service Providers and Professional Advisers
- We may share personal data with trusted service providers who support our operations, such as IT hosting providers, accountants, translators, or notaries, always on a need-to-know basis and, where appropriate, subject to written confidentiality or data processing agreements.
5.2. Public Authorities and Registries
- Where necessary to deliver our services or comply with the law, we may share personal data with Romanian public authorities and registries, including the National Trade Registry Office (ONRC), the National Agency for Fiscal Administration (ANAF), and, where legally required, the National Office for Prevention and Control of Money Laundering (ONPCSB).
5.3. Legal and Regulatory Disclosures
- We may disclose personal data where required or permitted by law, for example in response to a court order, a request from a competent authority, or to establish, exercise, or defend legal claims.
5.4. Business Transfers
- If our business is reorganised, merged, or transferred, personal data may be transferred to the successor entity, subject to appropriate safeguards and, where required, prior notice to affected individuals.
5.5. International Data Transfers
- Some of our service providers may process personal data outside the European Economic Area. Where this occurs, we take steps to ensure an adequate level of protection is maintained, whether through an EU adequacy decision, the European Commission’s Standard Contractual Clauses, or another lawful transfer mechanism recognised under the GDPR.
6. How Long We Keep Your Personal Data
6.1. General Principle
- We retain personal data only for as long as reasonably necessary to fulfil the purpose for which it was collected, taking into account any applicable legal or regulatory retention requirements.
6.2. Specific Retention Periods
- Client due diligence and identification records are generally retained for a minimum of five (5) years following the end of our business relationship, in line with anti-money laundering legislation.
- Accounting and tax records are retained for the periods required under Romanian fiscal legislation.
- Records relating to complaints are retained for a minimum of three (3) years.
- Cookie-derived data is retained in accordance with the periods described in our Cookie Policy.
6.3. Secure Deletion
- Once the applicable retention period has expired and no overriding legal ground for continued retention exists, we securely delete or irreversibly anonymise the relevant personal data.
7. How We Protect Your Personal Data
7.1. Technical Safeguards
- We apply appropriate technical measures designed to protect personal data against unauthorised access, loss, or misuse, including access controls, secure storage, and, where appropriate, encryption.
7.2. Organisational Safeguards
- We limit access to personal data to those members of our team and associated professionals who genuinely need it to perform their role, and we provide relevant training on data protection and confidentiality obligations.
7.3. Third-Party Safeguards
- Where third parties process personal data on our behalf, we put in place appropriate contractual protections to ensure that data is handled with the same degree of care we apply ourselves.
7.4. Breach Response
- In the unlikely event of a personal data breach that poses a risk to your rights and freedoms, we will assess the situation promptly, notify the National Supervisory Authority for Personal Data Processing (ANSPDCP) where required by law, and inform you directly where the breach is likely to result in a high risk to you.
8. Your Rights
You have a number of rights in relation to the personal data we hold about you. These can be exercised, free of charge in most circumstances, by contacting us using the details in Section 2 above.
8.1. The Right to Be Informed
- The right to receive clear, transparent information about how your personal data is used, which this Privacy Policy is intended to provide.
8.2. The Right of Access
- The right to ask us whether we hold personal data about you, and, if so, to receive a copy of it together with information about how it is used.
8.3. The Right to Rectification
- The right to ask us to correct personal data that is inaccurate or incomplete.
8.4. The Right to Erasure
- The right to ask us to delete your personal data in certain circumstances, for example where it is no longer needed for the purpose it was collected for, subject to any legal obligation we may have to keep it.
8.5. The Right to Restrict Processing
- The right to ask us to limit how we use your personal data in certain circumstances, for example while we verify its accuracy following a challenge.
8.6. The Right to Data Portability
- Where technically feasible, the right to receive personal data you have provided to us in a structured, commonly used, machine-readable format, and to have it transferred to another organisation.
8.7. The Right to Object
- The right to object to our use of your personal data where we rely on legitimate interests, and an unconditional right to object where we use your data for direct marketing purposes.
8.8. The Right to Withdraw Consent
- Where our processing is based on your consent, the right to withdraw that consent at any time, without affecting the lawfulness of anything we did with your data before withdrawal.
8.9. The Right to Lodge a Complaint
- The right to lodge a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP), details of which are provided in Section 9 below, or with the courts, if you believe your data protection rights have been infringed.
8.10. Responding to Your Requests
- We aim to respond to any request to exercise these rights within one (1) month of receiving it, extendable by a further two months for particularly complex requests, in which case we will let you know why. We may need to verify your identity before responding, to make sure we don’t disclose personal data to the wrong person.
9. Supervisory Authority
9.1. Contacting Us First
We hope that, if you have any concerns about how we handle your personal data, you will contact us directly at info@romania-for-business.com so that we can try to resolve the matter promptly.
9.2. Right to Complain to the Regulator
- Independently of contacting us, you have the right to lodge a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP), whose details are available at https://www.dataprotection.ro/, or with the supervisory authority of the EU Member State where you live, work, or where the issue you are complaining about took place.
10. Children’s Privacy
10.1. Not Directed at Children
Our Website and services are intended for businesses and adult individuals engaging in a professional capacity. We do not knowingly collect personal data from children, and if we become aware that we have inadvertently done so, we will take steps to delete that information promptly.
11. Changes to This Privacy Policy
11.1. Periodic Review
We review this Privacy Policy at least annually, and more often where required by changes in the law, guidance from ANSPDCP, or changes to how we operate.
12. Contact Us
Romania for Business
Email: info@romania-for-business.com
Website: https://romania-for-business.com/
This Privacy Policy is published for the information of visitors to, and clients of, Romania for Business, and does not constitute legal advice. It may be updated from time to time without prior notice; the version published on our website at any given time is the version in force.

