Privacy policy

Last updated: 21 July 2026

This Privacy Policy describes how UNICORE SRL (“we”, “UNICORE”) collects, uses, stores, shares, and protects personal data when you visit or interact with unicore.ro and our related services. It is drafted in accordance with Regulation (EU) 2016/679 (GDPR), Romanian Law no. 190/2018, and other applicable EU and Romanian rules.

1. Data controller

The controller of personal data is UNICORE SRL, a limited liability company headquartered at Transilvaniei Street 18A, Baia Mare, Maramureș, Romania, registered with the Trade Register under no. J2014000246249, Unique Registration Code 32888233.

For any data-protection request you may contact us at office@unicore.ro or by phone at +40 219 998. Website: https://unicore.ro.

We have not currently appointed a Data Protection Officer (DPO). Requests are handled internally by the UNICORE team within the deadlines set by the GDPR.

2. Scope

This Policy applies to: (a) visitors of unicore.ro; (b) persons who submit messages via the contact form; (c) persons who communicate with us by email or phone about our services; (d) clients, prospects, and partners in the course of business relationships.

It does not apply to third-party websites we may link to. Please review those operators’ policies. Details on cookies and similar technologies are in the Cookie Policy.

3. Categories of data subjects

  • Website visitors (including users who set language, theme, or cookie preferences).
  • Persons who complete the contact form or request a demo / proposal.
  • Representatives of clients, prospects, suppliers, and contractual partners.

4. Data we process

We process only the data needed for the purposes below. Depending on the interaction, this may include:

  • Identification data: first and last name.
  • Contact data: email address, phone number.
  • Content of the message sent via the form (including information you choose to include about your organization, project, or needs).
  • Automatically generated technical data: IP address, browser type/version, operating system, device type, server technical error logs, referrer.
  • Website usage data: pages visited, approximate session duration, navigation interactions — only if you enable analytics cookies.
  • Preferences stored locally on your device: language (URL path / locale cookie) and cookie consent choices.
  • Data from commercial and contractual correspondence (proposals, invoices, contracts) — within the business relationship.

5. Sources of data

  • Directly from you: contact form, email, phone, meetings, contracts.
  • Automatically, via technical means of the website and hosting infrastructure (logs, cookies, localStorage — as applicable and subject to consent).
  • Occasionally from partners or legitimate public sources (e.g. company contact details from the Trade Register), when needed for the business relationship.

6. Purposes and legal bases

We process data only where a valid legal basis exists (GDPR Art. 6):

  • Responding to contact-form requests and preparing proposals — basis: GDPR Art. 6(1)(b) (pre-contractual steps at your request) and/or Art. 6(1)(a) (consent ticked in the form).
  • Performing and administering IT service contracts (development, consulting, maintenance) — basis: GDPR Art. 6(1)(b).
  • Legal obligations (accounting, tax, responses to authorities) — basis: GDPR Art. 6(1)(c).
  • Website security, abuse prevention, and technical operation (logs, DDoS protection) — basis: GDPR Art. 6(1)(f) (legitimate interest).
  • Storing essential preferences (cookie consent, theme, language) — basis: Art. 6(1)(f) and, where applicable, Art. 6(1)(c) for proof of consent.
  • Traffic analysis and site improvement (analytics cookies / scripts) — basis: GDPR Art. 6(1)(a) (consent); not activated without your agreement.
  • Marketing and advertising (including pixels / campaigns) — basis: GDPR Art. 6(1)(a) (consent); you may withdraw at any time.
  • Defending our rights in court or before authorities — basis: GDPR Art. 6(1)(f).

7. Contact form

Mandatory fields (name, email, phone, message) are required so we can reply. Ticking the data-processing agreement is required to submit.

Messages are used solely to handle your request. We do not sell data and do not use it for automated marketing without a separate, clear, and informed consent.

8. Recipients and processors

Data may be accessed, only as needed, by:

  • UNICORE staff with sales, project, finance, or technical roles, on a need-to-know basis.
  • Hosting, email, IT maintenance, and security providers acting as processors (GDPR Art. 28), under contracts with data-protection clauses.
  • Analytics or marketing providers (e.g. Google Analytics, Meta), only if and after you have consented to the relevant category.
  • Public authorities, courts, or supervisory bodies when the law requires us to do so.
  • Legal counsel, auditors, or advisors under confidentiality obligations.

9. Transfers outside the EEA

We prefer storage and processing in the European Economic Area. If a provider transfers data outside the EEA (for example US analytics or marketing tools), the transfer occurs only with your consent for that category and with adequate safeguards: an EU Commission adequacy decision, Standard Contractual Clauses (SCCs), and supplementary measures where needed.

10. Retention periods

We keep data only as long as needed for the purpose for which it was collected:

  • Contact-form requests / pre-contractual correspondence: generally up to 24 months from the last contact, or sooner if you request erasure and no other retention basis applies.
  • Contractual and accounting data: according to Romanian legal deadlines (typically 5–10 years, depending on the document type).
  • Technical security logs: generally up to 12 months, unless investigating an incident.
  • Cookie / theme preferences: until the duration stated in the Cookie Policy expires or until you clear them in the browser.
  • Marketing data: until consent is withdrawn or for a maximum of 24 months of inactivity, whichever comes first.

11. Your rights (GDPR)

Subject to the law, you have the following rights:

  • Right of access (Art. 15) — you can learn whether we process data about you and obtain a copy.
  • Right to rectification (Art. 16) — correction of inaccurate or incomplete data.
  • Right to erasure / “right to be forgotten” (Art. 17) — under the conditions set by law.
  • Right to restriction of processing (Art. 18).
  • Right to data portability (Art. 20) — for data provided on the basis of consent or contract, in a structured format.
  • Right to object (Art. 21) — including to processing based on legitimate interest.
  • Right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects (Art. 22). Our website does not make such automated decisions with legal effects.
  • Right to withdraw consent at any time (Art. 7(3)), without affecting the lawfulness of prior processing.

12. How to exercise your rights

Send a request to office@unicore.ro, subject “GDPR — rights request”, stating your name, contact details, and the right you wish to exercise. We may ask for additional information to verify your identity.

We normally respond within one month of receiving a complete request. The period may be extended by two months for complex requests, with prior notice to you.

You have the right to lodge a complaint with Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral. Gheorghe Magheru no. 28-30, Sector 1, Bucharest, www.dataprotection.ro, email: anspdcp@dataprotection.ro.

13. Data security

We apply technical and organizational measures proportionate to the risk. No method of transmission or storage on the internet is 100% secure; we nevertheless take reasonable steps to reduce risks, including:

  • HTTPS / TLS communications on the website.
  • Role-based access control and authentication on internal systems.
  • Environment segregation, backups, and incident-response procedures.
  • Data minimization and retention only for as long as necessary.
  • Contractual clauses with processors on confidentiality and security.

14. Children

Our services and website are aimed at professionals and organizations. We do not knowingly collect data from persons under 16. If we learn that we have received such data without valid consent of a legal guardian, we will delete it as soon as possible.

15. Cookies and similar technologies

We use cookies, localStorage, and similar technologies for site operation, preferences, and — only with consent — analytics or marketing. Full details — categories, durations, third parties, and how to manage them — are in the Cookie Policy at /politica-cookies.

16. Changes to this policy

We may update this policy to reflect legal, technical, or operational changes. The version in force is the one published on this page, with the “Last updated” date. For material changes, we may display a notice on the site or, where possible, notify you by email.

17. Contact

UNICORE SRL · Transilvaniei Street 18A, Baia Mare, Maramureș, Romania · office@unicore.ro · +40 219 998 · https://unicore.ro