Who is responsible for your data
The data controller is Nemeș & Asociații S.P.A.R.L., with its registered office at 2B Mărășești Blvd., Building C, Entrance 4, 1st Floor, Office 31, Bucharest, District 4.
For any question about your data, write to us at office@nemes-asociatii.ro or call us on (+40) 21 335 16 22.
What data we receive
Through the contact form we receive the details you fill in:
- your name;
- your organisation, if you fill it in;
- your email address;
- your phone number, if you fill it in;
- the practice area you choose and your message.
Please describe your situation briefly and do not send documents or sensitive data, such as health information, through the form. We will go through the details at the meeting.
When you visit the website, the hosting server automatically records some technical data: your IP address, browser type, the page visited, and the date and time. This is needed for the website to work and to protect it against abuse.
Why we use your data and on what legal basis
- To reply to your request and, if you wish, to arrange a meeting. The legal basis is the consent you give by ticking the box in the form (Art. 6(1)(a) GDPR) and the steps taken at your request before a possible legal services contract (Art. 6(1)(b) GDPR).
- We use technical data to run and secure the website, based on our legitimate interest (Art. 6(1)(f) GDPR).
We do not use your data for advertising, we do not sell it and we do not profile visitors.
Cookies
The website does not use analytics or advertising cookies and does not track visitors. That is why we do not ask for your consent to cookies.
The map link opens Google Maps, where Google’s privacy policy applies.
Who else has access to your data
Messages are read only by the people at the firm who handle requests. To run the website and the form, we work with three providers, who process the data only on our behalf:
- Netlify, Inc. (USA), which hosts the website;
- Resend (USA), which delivers form messages to our email address through servers located in the European Union (Ireland);
- Google (Gmail), where we receive these messages.
Where data leaves the European Economic Area, the transfer relies on the standard contractual clauses approved by the European Commission or on the EU-US Data Privacy Framework.
We disclose data to public authorities only when the law requires us to.
How long we keep your data
We keep messages received through the form for as long as we need to reply and follow up on your request. If no legal services contract follows, we delete them within 12 months at the latest.
If we become your lawyers, your data becomes part of the case file and we keep it for as long as the law and the rules of the legal profession require.
Technical data is kept by the hosting provider for a short period, under its own policy.
Professional secrecy
As lawyers, we are bound by professional secrecy under Law no. 51/1995. Sending a message through the form does not create a lawyer-client relationship, which starts only once a legal services contract is signed. We nevertheless treat every message we receive as confidential.
Your rights
You have the right of access, to rectification, to erasure, to restriction of processing, to data portability and to object, as well as the right to withdraw your consent at any time. How to exercise them and where to lodge a complaint is explained on the GDPR page.
Data security
The website runs only over an encrypted connection (HTTPS), and access to messages is limited to the people who handle requests. No transmission over the internet is completely secure, however, so we recommend keeping confidential details for your conversation with the lawyer.
Children
The website is not aimed at people under 16 and we do not knowingly collect their data.
Changes
If we change this policy, we publish the new version here and update the date at the top of the page.