1.Who we are
The data controller for the processing described in this policy is:
- Legal name
- Cloud Craft SRL
- Fiscal identifier (CUI)
- 48476514
- Trade Registry
- J2023004551231
- EUID
- ROONRC.J2023004551231
- Registered office
- Str. Cernișoara nr. 8, room 1, postal code 077068, Tamași, Corbeanca commune, Ilfov county, Romania
- contact@cloudcraft.ro
- Phone
- +40 735 317 884
We have not appointed a data protection officer, as we are not required to do so. For any privacy matter, contact us directly using the details above.
2.What this policy covers
This policy covers the cloudcraft.ro website and the personal data we process when you contact us or engage us for services.
Our software product NoSignal (customer accounts, orders, licensing, and the software itself) has its own privacy policy, published at nosignal.ro. Where you use NoSignal, that policy applies to the product; this one applies to this website.
3.Data we process
3.1 When you visit this website
Our web servers keep standard access logs containing your IP address, the date and time of the request, the requested URL, the referring page, the browser identification string (user agent), and the response status. We use these logs to deliver the site, keep it secure, detect abuse, and troubleshoot problems.
- Legal basis: legitimate interest (Art. 6(1)(f) GDPR) in operating and protecting the website.
- Retention: logs are rotated automatically and kept for approximately 14 days, unless a specific security incident requires keeping an excerpt longer.
3.2 No cookies, no analytics, no tracking
3.3 When you contact us
If you email or call us, we process the data you provide: your name, email address, phone number, company, and the content of your message. We use it to reply, assess whether and how we can help, and take steps prior to entering into a contract.
- Legal basis: steps at your request prior to entering into a contract (Art. 6(1)(b) GDPR) and our legitimate interest in responding to enquiries (Art. 6(1)(f) GDPR).
- Retention: correspondence is kept for as long as it is relevant to the enquiry or the business relationship it leads to, then deleted.
3.4 When you work with us
For clients and suppliers we process the data needed to conclude and perform contracts: contact details of the persons involved, contractual documents, invoices, and payment records.
- Legal basis: performance of a contract (Art. 6(1)(b) GDPR) and compliance with legal obligations, in particular Romanian accounting and tax law (Art. 6(1)(c) GDPR).
- Retention: contractual and accounting records are kept for the periods required by Romanian accounting and fiscal legislation.
4.Recipients & processors
We do not sell personal data and we do not share it for advertising. Data is disclosed only to:
- Cloudflare, Inc. — provides DNS, content delivery, and security services in front of this website. Cloudflare processes technical data such as IP addresses in order to route, cache, and protect traffic, acting as our processor.
- IT and communications providers — the providers that host our infrastructure and email, bound by data processing agreements.
- Professional advisers — such as our accountants, to the extent required for invoicing and compliance.
- Public authorities — only where disclosure is required by law.
The website itself is hosted on infrastructure operated by us in the European Union.
5.International transfers
We process data primarily in the European Union. Because Cloudflare operates a global network, technical traffic data (such as IP addresses) may be processed on Cloudflare servers outside the EU/EEA, including in the United States. Such transfers are safeguarded by Cloudflare's certification under the EU–U.S. Data Privacy Framework and by the European Commission's Standard Contractual Clauses.
6.Retention
In summary:
- Server logs: approximately 14 days.
- Enquiry correspondence: for the duration of the enquiry or resulting business relationship.
- Contracts, invoices, accounting records: the periods required by Romanian accounting and fiscal law.
When data is no longer needed for these purposes, it is deleted or anonymised.
7.Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you (Art. 15);
- Rectify inaccurate or incomplete data (Art. 16);
- Erase your data where the conditions of Art. 17 apply;
- Restrict processing (Art. 18);
- Receive your data in a portable format (Art. 20);
- Object to processing based on legitimate interest (Art. 21).
To exercise any of these rights, email contact@cloudcraft.ro. We respond within one month.
You also have the right to lodge a complaint with the Romanian supervisory authority: Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28–30, Sector 1, 010336 Bucharest, Romania, www.dataprotection.ro — or with the courts. We would, of course, appreciate the chance to address your concern directly first.
8.Security
We apply the same engineering discipline to our own systems that we sell to clients: TLS encryption for all traffic, hardened Linux servers, least-privilege access, up-to-date software, and monitoring. Access to personal data is limited to the people who need it for the purposes described above.
9.Automated decisions
We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR.
10.Children
This website and our services are aimed at businesses and professionals. They are not directed at children, and we do not knowingly collect personal data from anyone under 16.
11.Changes to this policy
If we change how we process personal data, we will update this page and revise the “Last updated” date above. Significant changes will be highlighted on this page.
12.Contact
For any question about this policy or your personal data, contact Cloud Craft SRL at contact@cloudcraft.ro or +40 735 317 884.