Skip to main content
Legal

Privacy Policy

How we collect, use, and protect your personal data.

Last updated: 28 June 2026

Tilizy Digital S.R.L. ("Tilizy Digital", "we", "us", "our"), Trade Register number J05/527/2024, sole registration code RO49632336, with its registered office at Str. General Traian Moșoiu, Nr. 15, Ap. 1, Oradea, Bihor, Romania 410072, operates the website https://tilizy.digital (the "Site") and provides professional services to business clients.

This Privacy Policy explains how we process personal data for which we act as controller, namely data relating to visitors of the Site and to the representatives of our (prospective) business clients and suppliers. It is provided in accordance with Regulation (EU) 2016/679 ("GDPR") and Romanian Law no. 190/2018.

When we host and operate systems for our clients, we process personal data contained in those systems as a processor, on the client's instructions. That processing is governed by our Data Processing Agreement, not by this Policy. In that role the client is the controller.

1. Controller and contact

The controller is Tilizy Digital S.R.L.

  • Privacy contact: privacy@tilizy.com
  • General email: hello@tilizy.com
  • Phone: +40 774 583 595
  • Address: Str. General Traian Moșoiu, Nr. 15, Ap. 1, Oradea, Bihor, Romania 410072

We have not appointed a Data Protection Officer, as our processing does not meet the criteria in Article 37 GDPR. For any data-protection question you may contact us at privacy@tilizy.com.

2. Personal data we process

2.1 Data you provide directly

  • Contact and quote/order enquiries: name, email address, phone number, company name, role, and the content of your message or request.
  • Newsletter: email address (and any name you provide). You subscribe by submitting your address and consenting, and you can unsubscribe at any time using the link in every message. Newsletters are sent from our own mail infrastructure within the EEA.
  • Correspondence: any personal data you include when you contact us by email, phone, or other channels.
  • Client onboarding and administration: contact details of client representatives, contract and billing information.

2.2 Data collected automatically (measurement)

We use a first-party, cookieless analytics system that we operate ourselves. It does not set cookies, does not create persistent identifiers, and does not track you across websites or across days. It records aggregate measurement data such as pages viewed, referrer, approximate region derived from a locally hosted IP-geolocation database (the IP address itself is not stored), and general device or browser type. Daily identifiers are derived using a salt that is rotated and discarded every day, which makes visits unlinkable between days and between sites. The cookieless system runs regardless of your cookie choices.

We do not use Google Analytics or any other third-party cross-site tracking on the Site. See our Cookie Policy for details on cookies.

2.3 Server logs and security

Our infrastructure keeps standard technical logs (for example IP address, timestamp, requested resource, and user agent) for the time strictly needed to operate the Site securely, detect and prevent abuse, and diagnose faults.

3. Purposes and legal bases

PurposeLegal basis
Responding to your enquiries and preparing/performing contractsPerformance of a contract or pre-contractual steps, Art. 6(1)(b); for representatives of corporate clients, our legitimate interest in business communication, Art. 6(1)(f)
Sending the newsletterConsent, Art. 6(1)(a)
Operating, securing, and improving the Site (incl. cookieless measurement and security logs)Legitimate interest, Art. 6(1)(f)
Invoicing, accounting, and tax complianceLegal obligation, Art. 6(1)(c)
Establishing, exercising, or defending legal claimsLegitimate interest, Art. 6(1)(f)

Where we rely on legitimate interest, you may object at any time (see Section 7).

4. Recipients and sub-processors

We do not sell personal data. We share data only as necessary with:

  • Infrastructure provider hosting our systems within the EU: Hetzner Online GmbH (Germany/Finland, EEA).
  • Email delivery: transactional and newsletter messages are sent from our own self-hosted mail infrastructure within the EEA.
  • External accounting firm: our accounting services provider, which processes contact and billing data for invoicing and statutory accounting on our behalf under a written agreement.
  • Public authorities, where required by law.

Service providers acting on our behalf are bound by written agreements meeting Article 28 GDPR. A current list of the sub-processors used in our managed-hosting services (where we act as processor for clients) is maintained in our Sub-processor list.

5. International transfers

We host and process the personal data described in this Policy within the European Economic Area (EEA). We do not transfer it outside the EEA.

For the personal data we process as a processor on behalf of clients (hosted systems), the processing location is governed by the Data Processing Agreement; by default it is within the EEA, and any other location is only on the client's instruction with appropriate safeguards.

6. Retention

  • Enquiry and quote/order data (no contract): up to 24 months from the last contact, then deleted.
  • Newsletter: until you unsubscribe or withdraw consent.
  • Cookieless measurement: aggregate, non-identifying statistics only; no personal profiles are retained.
  • Server and security logs: up to 90 days, then deleted, unless needed longer to investigate a specific security incident.
  • Contract, invoicing, and accounting records: retained for the periods required by Romanian law. Accounting supporting documents are kept for 5 years, calculated from 1 July of the year following the financial year in which they were drawn up (Law no. 82/1991 as amended by Law no. 36/2023); certain documents may have longer statutory periods.

7. Your rights

Under the GDPR you have the right to: access your data (Art. 15); rectification (Art. 16); erasure (Art. 17); restriction of processing (Art. 18); data portability (Art. 20); object to processing based on legitimate interest, including direct marketing (Art. 21); and withdraw consent at any time without affecting processing carried out before withdrawal (Art. 7(3)).

To exercise any right, contact privacy@tilizy.com. We respond without undue delay and at the latest within one month of receipt, a period that may be extended by up to two further months for complex or numerous requests, in which case we will inform you (Art. 12(3)).

8. Complaints

If you consider that our processing infringes data-protection law, you may lodge a complaint with the ANSPDCP:

  • Website: www.dataprotection.ro
  • Address: B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336, Bucharest, Romania

You also have the right to an effective judicial remedy.

9. Security

We apply appropriate technical and organizational measures to protect personal data, including encryption in transit (TLS), access controls and least-privilege administration, network and application-layer protection, regular updates and patching, monitoring, and backups. No method of transmission or storage is completely secure, but we maintain measures appropriate to the risk under Article 32 GDPR.

10. Children

The Site and our services are directed to businesses and are not intended for children. Consistent with Romanian Law no. 190/2018, we do not knowingly process the personal data of children under 16.

11. Automated decision-making

We do not carry out automated decision-making, including profiling, that produces legal or similarly significant effects on you within the meaning of Article 22 GDPR.

12. Changes

We may update this Policy. The "Last updated" date reflects the latest version, and material changes will be highlighted on this page. Please review it periodically.

13. Contact

Privacy contact: privacy@tilizy.com. General: hello@tilizy.com, +40 774 583 595, Str. General Traian Moșoiu, Nr. 15, Ap. 1, Oradea, Bihor, Romania 410072.