gdpr

Privacy policy

Last updated: 28 September 2026

In short: we use analytics cookies only if you agree in the site banner. Otherwise, the only personal data we receive is what you send us through the contact form.

Who we are

The data controller is MAGDALA GROUP S.R.L., CUI 35860270, J2016000479339, Str. Viitorului nr. 4, bl. P1, sc. B, et. 2, ap. 11, Suceava, jud. Suceava, 720269, which runs the magdalagroup.ro website ("Magdala", "we").

For any question about your data, write to us at office@magdalagroup.ro.

What the form collects

  • your name and, optionally, your company or brand;
  • your email address and/or phone number;
  • your message and the selected project type;
  • the page you sent the form from and, if present, campaign parameters in the address (utm_source, utm_medium, utm_campaign);
  • how long it took to fill in the form (used for spam protection).

Technical data

Like any web server, ours receives your IP address and browser type with every request. The IP address is used to limit the number of submissions and to protect against spam and abuse. In the form logs we do not keep the IP address in clear text, only a cryptographic fingerprint of it, and we do not keep the content of rejected messages.

Without your consent, the website sets no cookies and loads no third-party scripts or fonts.

Analytics cookies

If you click “Accept” in the cookie banner, we load Google Tag Manager and Google Analytics (Google Ireland Limited). They set cookies and show us, in aggregate, which pages are visited, from which devices and traffic sources, so we can improve the website. The legal basis is your consent (Art. 6(1)(a) GDPR). Data may be transferred outside the EU under the terms set by Google.

If you click “Decline”, nothing is loaded from Google. You can change your choice at any time from the “Cookie settings” link in the page footer.

Why we use the data

We do not use the data for newsletters or marketing and we do not sell it to anyone.

  • to reply to your request and prepare a quote — at your request, before a possible contract (Art. 6(1)(b) GDPR);
  • to protect the form and the server from spam and abuse — our legitimate interest (Art. 6(1)(f) GDPR).

Where the data goes

A message sent through the form passes through an anti-spam filter running on our server, then reaches an automation system also hosted by us. From there:

  • an automatic filter based on an AI model checks whether the message is spam — for this, the message text may be sent to an AI model provider;
  • we receive a phone notification through the Pushover service and an email with the details of the request.

How long we keep the data

We keep the request data for as long as needed to reply and discuss the project. If you become a client, the data needed for the contractual relationship is kept for the duration of the contract and as long as the law requires afterwards. Requests that do not lead anywhere are deleted periodically.

Your rights

Under the GDPR you have the right of access, rectification, erasure, restriction of processing, objection and portability. For any of them, write to us and we will reply within one month, as the law requires.

If you are not satisfied, you can file a complaint with the Romanian data protection authority (ANSPDCP), www.dataprotection.ro.

Security

The website is served over HTTPS only, with strict browser security policies. The form contains no keys or secrets in its public code, and all checks are done on the server.