Skip to content
Nomad TechConsulting

Privacy policy

Last updated: 2 September 2026

This policy explains what personal data we process through nomadtech-consulting.com, for what purpose, on what legal basis, and what rights you have under Regulation (EU) 2016/679 (GDPR).

Company identification

Legal name
NOMAD TECH CONSULTING S.R.L.
VAT identification number
RO41583629
Trade register number
J23/3839/2019
Registered office
Str. Rezervelor nr. 68E, et. 1, ap. 4, Sat Roșu, Com. Chiajna, Jud. Ilfov, 077042, România
Email
contact@nomadtech-consulting.com
Phone
0730 320 067

These documents cover the software development services provided by Nomad Tech Consulting SRL. Project-specific agreements (data processing on your behalf, licensing, SLAs) are concluded separately.

1. Data controller

The controller is Nomad Tech Consulting SRL, identified above. For any request concerning your personal data, write to the email address in the identification section.

We have not appointed a Data Protection Officer, as our activity does not meet the conditions in Art. 37 GDPR. Requests are handled directly by company management.

2. What we collect and why

  • Quote form: name, email, phone (optional), company (optional), project description and uploaded documents. Purpose: evaluating the request, sending a quote and contacting you. Basis: Art. 6(1)(b) GDPR — steps taken at your request prior to entering into a contract.
  • Technical request data: a hashed form of your IP address, browser type, referring page. Purpose: limiting abuse and spam on the form. Basis: Art. 6(1)(f) GDPR — our legitimate interest in keeping the site's only contact channel working.
  • Subsequent correspondence by email or phone. Purpose: running the commercial relationship. Basis: Art. 6(1)(b) and (f) GDPR.

3. What we do not do

  • We do not store your IP address in the clear — only a salted hash, from which the address cannot be recovered.
  • We do not use Google Analytics or any other behavioural tracking tool.
  • We do not profile you and take no automated decisions with legal effect (Art. 22 GDPR).
  • We do not sell, rent or trade your data with third parties for marketing.
  • We do not send newsletters without an explicit request from you.

4. Recipients and processors

Data is hosted on our own infrastructure located in the European Union. Access is limited to the people evaluating your request.

We use Cloudflare Turnstile for anti-spam verification of the form. It processes a technical signal about the page interaction and does not install tracking cookies. Cloudflare acts as a processor under the Standard Contractual Clauses approved by the European Commission.

For transactional email — confirming your request, sending your panel link and telling you when documents are ready to sign — we use Resend. It processes your name and email address as a processor, on infrastructure located in the European Union (Ireland). We do not track email opens and we do not rewrite the links inside them.

We may disclose data to public authorities where the law requires it.

5. Transfers outside the EEA

We do not routinely transfer data outside the EEA. Where a supplier we use processes data outside the EEA, the transfer relies on a European Commission adequacy decision or on Standard Contractual Clauses, under Chapter V GDPR.

6. Retention

  • Quote requests that do not become contracts: 24 months from the last interaction, then deleted.
  • Documents uploaded through the form: deleted together with the request they belong to.
  • Data relating to concluded contracts: for the term of the contract and afterwards per statutory archiving periods (10 years for accounting records under Romanian Law 82/1991).
  • Technical abuse-prevention data: 30 days at most.

7. Your rights

Under the GDPR you have the right of access, rectification, erasure, restriction of processing, objection and data portability, and the right to withdraw consent where processing is based on it.

Exercise these rights by writing to the email address in the identification section. We respond within 30 days.

You have the right to lodge a complaint with the Romanian supervisory authority (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Bucharest, dataprotection.ro, or with the supervisory authority in your country of residence.

8. Security

  • All site traffic is encrypted with TLS.
  • The private link you use to track your request works as an access key: our database stores only a cryptographic fingerprint of it, never the link itself.
  • Uploaded documents are stored under opaque internal names, in a separate directory per request, reachable only through that private link.
  • Administrative access is password protected with rate-limited login attempts.
  • In the event of a personal data breach posing a risk to your rights, we notify the supervisory authority within 72 hours and inform you without undue delay.

9. Processing within projects

When we develop or host an application for you and thereby process your users' personal data, we act as processor and you are the controller. That relationship is governed by a separate Data Processing Agreement concluded under Art. 28 GDPR before processing begins.