Who is responsible. Glab IT Solutions SRL, a Romanian company (Trade Registry J05/2360/2008, CUI 24490341, VAT RO24490341), registered office Strada Tudor Vladimirescu nr. 64, ap. 1, 410203 Oradea, Bihor, Romania — “GlabIT”, “we”. Contact for anything in this notice: info@glabit.com. We have not designated a data protection officer: our activities do not meet the conditions of Article 37 GDPR that make one mandatory; questions about personal data go to the contact above.
This notice explains what personal data we process, why, on what legal basis, who receives it, how long we keep it and what your rights are. It applies under Regulation (EU) 2016/679 (GDPR) and Romanian Law no. 190/2018. It is written to match how our website and services actually work; where a fact is still being confirmed, we say so rather than state it as settled.
Environment note: a development preview of this website exists at prod.glabit-dev.com; it is not the production service and it is marked not-for-indexing. The preview form mode is verified at each deployment. It must remain disabled unless its processing, recipients and retention have been separately confirmed and accurately disclosed.
Please do not send us secrets or unnecessary sensitive data. The contact form and ordinary email are not a secure channel for passwords, MFA codes, API keys, private keys, access tokens, health or other special-category data, or confidential security evidence. Do not send credentials, vulnerability evidence, system exports or other sensitive technical material through the website contact form or ordinary email. Where an engagement requires such material, transfer may occur only after signed engagement documents identify an approved method and GlabIT has confirmed that method for the engagement (see section 6); we do not operate a standing secure portal or encrypted mailbox today. Vulnerabilities in our own systems go through the security-reporting page.
1. Visiting the website — server, application and system logs
- Web-server access log (intended explicit fields): the IP address of the connection, date and time, the request method, the requested path without any query arguments, the protocol version, the HTTP status code, the size of the response, the referring page if your browser sends one, and your browser/operating-system string. Our deployment template defines this as an explicit minimal log format; it records no query strings, no cookies (we set none) and no form content.
- Other logs that can contain the same identifiers: the web-server error log (failed or malformed requests, including the requesting IP address), the PHP-FPM / contact-relay error log (technical errors of the contact endpoint — our own application is written so that it does not intentionally place visitor input or message content in its error lines), the mail-transfer log of the system or provider that sends our contact-form notification (typically sender, recipient, time and delivery result; what that system or provider actually logs is not yet verified — see sections 2 and 8), and ordinary operating-system and security logs of the server (for example authentication and firewall events).
- Purpose: to operate and secure the site — detect abuse, diagnose errors, defend against attacks, investigate incidents.
- Legal basis: our legitimate interest in running a secure and reliable service (Art. 6(1)(f) GDPR).
- Required? These logs are generated by the web server and operating system for every request; you cannot use the site without them being written.
- Recipients: the provider hosting the web server (a processor — see section 8) and authorised GlabIT personnel.
- Retention: access and error logs are intended to be 30 days, deleted by log rotation; system and mail logs follow the host’s rotation settings.
- No cookies, no analytics, no third-party requests by design. This website is built to set no cookies, store nothing in your browser, run no analytics or advertising scripts, and load all fonts, styles, scripts and images from its own domain. Our release checks are designed to detect prohibited external resources and storage, and the launch checklist includes a runtime verification of requests, storage and response headers on each environment; if this ever changes, this notice — and, where the law requires it (Romanian Law no. 506/2004 and the ePrivacy rules), a consent mechanism — change first.
2. Contact form — what is created, where, and for how long
The form has two operating modes and the page always tells you which applies:
- Unavailable / disabled. The form returns a message telling you to email us and nothing you entered is stored — no enquiry record, no rate-limit entry. Preview: the intended mode for the development preview; its actual mode is verified and recorded at each deployment (see the environment note above).
- Live. Your submission creates more than one copy, each with its own storage and deletion path, listed below.
Data you submit: name (required), work email address (required), topic you select (required), message (required), company (optional), phone number (optional), the language of the page you used, and the time of submission. If you do not provide the required fields the form cannot be sent; you can always email us instead.
Copies created in live mode and their retention:
- Server-side enquiry record. The submitted fields above are written as one line to a restricted file on our web server. We do not store your IP address or browser details with this record. Intended retention: enquiry records are intended to be deleted once older than 12 months by a scheduled maintenance job (intended to run daily). That job deletes only records it can read; a record it cannot parse is kept and counted so that it can be reviewed by a person, and if the job fails to run, deletion is delayed until it runs again.
- Mailbox notification. The same submitted fields are sent as an email to the mailbox(es) used by our enquiry team, so that a person sees your message. This copy lives in our mailbox and is not deleted by the maintenance job above. Its retention follows the criteria for direct email correspondence in section 3; no fixed period is stated.
- Mail-transfer and server logs. Sending the notification creates entries in the mail-transfer log of the sending system or provider (typically sender, recipient, time and delivery result) and the request creates web-server log entries (section 1). Our own application does not intentionally write your message text to its logs; what the mail system or provider logs is not yet verified. Retention: as in section 1 (intended/unverified).
- Backups. Server backups can contain copies of the record and of the notification for the backup retention period; they are not individually deleted by the maintenance job and expire with the backup rotation.
- Later client or proposal record. If a proposal or contract follows, the correspondence is kept with the proposal or client file (sections 4 and 5) under the criteria and periods stated there.
- Purpose: to answer your request and, where you ask for a proposal or an assessment, to take the steps that precede a contract.
- Legal basis: if you write to us in your own name about a contract you would personally enter into (for example as a sole trader or an individual client), Art. 6(1)(b) GDPR — steps at your request prior to a contract. If you write on behalf of a company or another organisation — as its employee, director or representative — we process your business contact details and message on the basis of our legitimate interest in responding to enquiries and preparing an engagement with that organisation (Art. 6(1)(f)); the contract, if any, is with the organisation, not with you. The checkbox on the form confirms you have read this notice; it is not a consent that we rely on for this processing.
- Anti-abuse inputs (transient): to limit automated abuse the form uses, for the request only, a hidden field that genuine visitors do not fill, the time the form was rendered (to reject instant machine submissions) and the requesting IP address. The endpoint keeps a keyed cryptographic hash of the IP address — derived from your IP and a secret key held on the server; it is pseudonymous data, not anonymous — together with the timestamps of recent submissions, in a separate store, with no content and no name. The active rate-limiting window is 10 minutes; entries that are no longer needed are removed by the scheduled maintenance job (intended to run daily), so their expected maximum operational retention is the window plus the interval of that job. The hidden-field value and render time are not stored.
- Recipients: authorised GlabIT personnel who handle enquiries; the provider hosting the web server and our mail server, as a processor (section 8). Access to the stored record is limited to authorised personnel and system maintenance processes.
3. Direct email correspondence
- Data: whatever you choose to write, plus the technical metadata that email systems create (addresses, dates, headers, attachments), and the mail-transfer logs of the systems involved.
- Purpose and legal basis: answering you and, where you personally would be the contracting party, preparing your contract (Art. 6(1)(b)); where you write for an organisation, our legitimate interest in handling business correspondence and preparing or administering an engagement with that organisation (Art. 6(1)(f)).
- Recipients: authorised GlabIT personnel; the provider hosting our mail server, as processor (section 8).
- Retention: we do not apply a fixed retention period to direct email. The criteria that determine how long correspondence may be kept are: a continuing need to deal with your enquiry; preparation of a contract; administration of an existing relationship; a legal obligation to keep it; or the establishment, exercise or defence of legal claims. Keeping correspondence is justified only while at least one of these needs continues. (Contact-form records are separate — they are subject to the intended scheduled clean-up described in section 2, which does not reach the mailbox copy.)
4. Prospective clients
- Data: business contact details, company details, the content of scoping calls and proposals.
- Purpose / basis: preparing and negotiating an engagement. Where you would personally be the contracting party: Art. 6(1)(b). Where you act for an organisation: our legitimate interest in preparing and following up a proposal with that organisation (Art. 6(1)(f)).
- Retention: for proposals that are not accepted, the criteria are: a reasonable prospect that the proposal may still be taken up, or a need to establish, exercise or defend legal claims. No fixed period is stated.
5. Clients and contract administration
- Data: business contact details of the client’s staff involved in an engagement, contract, billing and correspondence records.
- Legal basis: where the client is an individual contracting in their own name, performance of the contract (Art. 6(1)(b)); where the client is an organisation, our legitimate interest in administering the engagement and communicating with the people the client designates (Art. 6(1)(f)); legal obligations, in particular accounting and tax law, for the records those laws require (Art. 6(1)(c)); our legitimate interest in establishing, exercising or defending legal claims for the records needed for that purpose (Art. 6(1)(f)).
- Retention: contract and correspondence for the duration of the engagement plus the applicable limitation period; accounting and supporting documents for the periods required by Romanian accounting and fiscal law for each document category.
6. Data we receive indirectly in our services — roles, sources and your information rights
In security and engineering work we handle data that we do not obtain from you directly. Depending on the service, that can include:
- business contact and staff identifiers of our client’s people (names, roles, work email addresses, phone numbers);
- account, directory and identity data from the client’s systems (user accounts, group membership, authentication events);
- security logs and telemetry collected from endpoints, identities, cloud and network for monitoring;
- vulnerability findings and test evidence from penetration testing, including screenshots or records that may show user data;
- open-source intelligence (OSINT) gathered from public sources during an authorised red-team exercise;
- data generated by phishing or other social-engineering exercises and by awareness or simulation results;
- material reviewed during an AI-security assessment (prompts, outputs, configuration, logs);
- personal data contained in client systems that we assess, configure or build.
Our role is determined for each documented activity, not globally.
- Processor (Art. 28 GDPR): where the client determines the purposes and the essential means — for example monitoring the client’s telemetry, testing the client’s application, running a phishing exercise on the client’s staff at the client’s instruction, or holding evidence during an assessment — we may process only on the client’s documented instructions, and only after the applicable Article 28 terms have been signed as part of the engagement documents; the client remains controller and is responsible for informing its staff and users. Those terms must name any subprocessor (for example a partner security operations centre), the security measures, deletion or return at the end of the engagement, audit assistance and breach support.
- Controller: where we determine our own purpose — our own engagement records (who we worked with, what was agreed, what we delivered), our own security, and any activity where we decide what to collect and why. Where we are controller of data we did not obtain from you (Art. 14 GDPR) you are entitled to know the categories of data, their source (our client, public sources, or the client’s systems), the purpose and legal basis (normally our legitimate interest in delivering the engagement and in the security of the systems we operate, Art. 6(1)(f)), the recipients (section 8), any transfer (section 9), the retention criteria (as set out in the engagement documents and sections 5 and 7), and your rights (section 11). We provide that information within a reasonable period after obtaining the data and in any event no later than one month; if we use the data to communicate with you earlier, at the latest at that first communication; and if we disclose the data to another recipient earlier, at the latest when it is first disclosed (Art. 14(3) GDPR). Any exception under Art. 14(5) — for example where you already have the information, or where providing it proves impossible or would involve a disproportionate effort or would seriously impair the objectives of the processing — is never assumed: it is decided for each processing activity, supported by the exact applicable paragraph, reviewed with our counsel, recorded with reasons, and accompanied by the safeguards and appropriate measures the GDPR requires, including making the information publicly available where Art. 14(5)(b) is relied on.
- Secure evidence channel: evidence must not be transferred to us until the engagement documents define, in writing, the channel, encryption, storage location, access list and deletion date for it. Do not send it through the contact form or ordinary email.
- Retention: as set out in the engagement documents — evidence is deleted or returned at the end of the engagement unless a longer retention is agreed in writing or required by law. Our own engagement records follow section 5.
7. Vulnerability and security reports
- Scope: the public reporting process concerns systems operated by GlabIT. Client and third-party systems are outside its testing scope; if a report concerns a client system, we may pass the information to that client. Receiving a report never authorises testing of any system.
- Data: the reporter’s contact details, the report content, and any evidence provided.
- Purpose / basis: triaging and remediating security issues in GlabIT-operated systems, and passing on information that concerns a client — our legitimate interest in the security of the systems we operate and in meeting our duties to clients (Art. 6(1)(f)).
- What to send: see the security-reporting page. Do not include client or third-party personal data; if you encounter it, stop and tell us.
- Recipients: authorised GlabIT personnel; where necessary, an affected client, the relevant service provider, our legal or security advisers, an insurer, or a competent authority, on a need-to-know basis and subject to confidentiality and applicable law. We do not publish reporter names without permission unless disclosure is required by law.
- Retention: report records are kept according to objective criteria: while the issue is under investigation or remediation; afterwards as evidence of how the report was handled; for the period in which legal claims can be established, exercised or defended; where a legal or regulatory duty requires it; and while a legal hold applies. Sensitive payloads that are no longer needed (exploit detail, credentials, personal data encountered) are deleted earlier than the case record. No fixed period is stated.
8. Recipients, processors and partners
- Hosting provider for the website, the contact-form record and the server logs — a data-centre provider acting as our processor under its data processing terms.
- Email: the contact-form notification and our correspondence are handled on our own mail server; no external email provider handles them.
- Backups: server backups made through our hosting provider’s backup service, under the same processor terms; backup copies expire with the backup rotation (section 2).
- Maintenance and remote access: GlabIT personnel only.
- Service partners and subprocessors: for some services — in particular monitoring delivered together with a partner security operations centre — service partners or subprocessors may process client data where necessary to deliver the service; any such partner is named and governed in the data processing agreement for that service before the processing begins. No subprocessors are used for the website, the contact form or our correspondence.
- Other recipients: professional advisers (accountants, lawyers) bound by confidentiality; insurers where a claim requires it; public authorities where required by law.
- Where a provider acts as a processor for us, the required Article 28 terms must be in place before the associated processing begins. We do not sell personal data and do not use it for advertising.
9. International transfers
All processing described in this notice takes place within the European Union / EEA; we do not transfer personal data outside it. Should a future service partner require such a transfer, it will take place only under a mechanism permitted by Chapter V GDPR, and the data processing agreement for that service will state the country and the mechanism.
10. Security
We apply measures appropriate to the risk (Art. 32 GDPR): encryption in transit, restrictive server configuration and security headers, access limited to authorised personnel and system processes, restrictive file permissions on stored enquiry records, and logging. A periodic security review of the production service is an intended control that will be owned, scheduled and evidenced before it is described here as operating. No measure removes risk entirely, and we do not claim that any system is invulnerable.
11. Your rights
Where the legal conditions are met, you have the right to access your data, to rectification, to erasure, to restriction of processing, to data portability, and to object to processing based on legitimate interest (Arts. 15–21 GDPR) — including, at any time, the processing of your business contact details described in sections 2 to 5; where you object we stop unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed for legal claims. To exercise a right, email info@glabit.com. We may need to verify your identity in a proportionate way before acting. We act on requests without undue delay and in any event within one month; where the GDPR allows it (complex or numerous requests) that period may be extended by up to two further months, and we will tell you within the first month if that is the case and why.
You also have the right to lodge a complaint with a supervisory authority — in Romania, the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28–30, Sector 1, 010336 București, www.dataprotection.ro — or with the authority of the EU country where you live or work.
12. Automated decisions, children
We do not use automated decision-making or profiling that produces legal or similarly significant effects. Our website and services are directed at businesses; we do not knowingly process data of children under 16.
13. Changes and versions
We update this notice when our processing changes. The version, review date, effective date and approval status are shown at the bottom of the page.
Document
Privacy notice · Version 1.1
Effective
2026-08-19
Last reviewed
2026-08-19
Legal approval
Romanian legal counsel, 2026-08-19