1. Who controls your data
Tecoow Network SRL ("Tecoow", "Diloxy", "we", "us") is the data controller for the processing described in this notice. Our identification and contact details appear beside this policy. Diloxy is a trading name operated by Tecoow Network SRL.
Privacy and data-subject requests may be sent to office@diloxy.com. We have not designated a data protection officer because we do not currently consider the statutory appointment criteria to be met.
2. Data we process
- Enquiry data: name, work email, optional phone number, project message, selected industry context, and subsequent correspondence.
- Business relationship data: organisation, role, proposals, contracts, deliverables, billing and transaction records where you become a client, supplier, or partner.
- Technical and security data: IP address, browser and device information, timestamps, requested URLs, referrer information, diagnostic events, and security logs that our hosting or network providers may generate.
- Preference data: your optional-technology choice, its timestamp, and the consent-policy version, stored locally in your browser.
- External-media data: if you allow the Bucharest map, your browser connects to OpenStreetMap and may disclose technical connection data to that provider.
We do not intentionally request special-category data. Please do not include health data, identification numbers, passwords, trade secrets, or other unnecessary sensitive information in the contact form.
3. Purposes and legal bases
- Responding to enquiries and preparing a proposal: steps requested before entering a contract and, where applicable, our legitimate interest in responding to business communications (GDPR Article 6(1)(b) and (f)).
- Delivering contracted services and administering the relationship: contract performance (Article 6(1)(b)).
- Accounting, tax, regulatory, and legal compliance: compliance with legal obligations (Article 6(1)(c)).
- Website operation, troubleshooting, fraud prevention, and security: our legitimate interests in maintaining a reliable and secure service (Article 6(1)(f)).
- Loading optional external media: your consent (Article 6(1)(a)); you can withdraw it at any time through “Cookie Settings”.
- Establishing, exercising, or defending legal claims: our legitimate interests and applicable legal provisions (Article 6(1)(f)).
Where processing relies on legitimate interests, we assess necessity, proportionality, and the impact on your rights. You may object as explained below.
4. Whether providing data is required
Name, email, and a project description are required to prepare the contact message. Phone number is optional. The form opens a draft in your email application; the information reaches us only when you send that email. Without required information we may be unable to assess or answer your request.
5. Sources of data
We generally receive data directly from you, from the organisation you represent, from ordinary correspondence, and automatically from website and security infrastructure. We may also receive business contact information from public professional sources or a mutual contact where lawful and relevant.
6. Recipients and service providers
We do not sell personal data. Access is limited to people and providers who need it for the purposes above, including:
- authorised Tecoow personnel and contractors subject to confidentiality obligations;
- hosting, infrastructure, email, security, backup, and technical-support providers;
- professional advisers, insurers, auditors, banks, and payment or accounting providers where relevant;
- public authorities, courts, or regulators where disclosure is legally required;
- OpenStreetMap only when you choose to load the optional map;
- content delivery and image hosts used by pages containing externally hosted assets, which receive ordinary connection data when those assets load.
Providers processing personal data on our behalf are assessed and made subject to the applicable contractual and data-protection obligations.
7. International transfers
We prefer providers located in the European Economic Area. If a recipient processes data outside the EEA, we will use a lawful transfer mechanism where required, such as an adequacy decision or European Commission Standard Contractual Clauses, together with supplementary safeguards where appropriate. You may request information about applicable safeguards.
8. Retention
- Unsuccessful or preliminary enquiries: normally up to 24 months after the last substantive interaction, unless a shorter period is appropriate or retention is needed for a dispute.
- Client and contractual records: for the relationship and afterwards for applicable statutory accounting, tax, limitation, and legal-claims periods.
- Security and server logs: normally up to 30 days, unless an incident requires longer preservation.
- Consent preference: up to six months, after which the site asks again.
- Legal claims: until the relevant matter and applicable limitation periods expire.
We may anonymise information so it no longer identifies anyone; anonymised information may be retained for statistical or operational purposes.
9. Your GDPR rights
Subject to the conditions and exceptions in applicable law, you may request:
- access to your personal data and information about its processing;
- correction of inaccurate or incomplete data;
- erasure of data;
- restriction of processing;
- data portability for eligible data;
- objection to processing based on legitimate interests;
- withdrawal of consent at any time, without affecting earlier lawful processing.
We may need to verify your identity and clarify your request. We normally respond within one month, subject to lawful extensions. You also have the right to lodge a complaint with Romania's supervisory authority, the ANSPDCP, or with another competent EEA supervisory authority.
10. Automated decisions and marketing
We do not currently use personal data from this website for solely automated decisions producing legal or similarly significant effects. We do not currently deploy behavioural advertising cookies. If this changes, we will update this notice and request consent where required before activating the relevant technology.
11. Security
We use proportionate technical and organisational measures intended to protect data, including access controls, confidentiality obligations, software maintenance, backups where appropriate, and incident-management procedures. No internet transmission or storage system can be guaranteed completely secure.
12. Children
This business-services website is not directed to children. We do not knowingly solicit personal data from children. A parent or guardian who believes a child submitted information should contact us so we can assess and delete it where appropriate.
13. Changes to this notice
We may update this policy when our services, vendors, or legal obligations change. Material changes will be highlighted appropriately, and the effective date above will be revised. Where a new purpose requires consent, we will request it before beginning that processing.
14. Legal references
This notice is structured around the transparency requirements of the General Data Protection Regulation, particularly Articles 12-14, and Romanian data-protection law.
