Privacy policy

How STRATEQUO collects, uses and protects personal data.

Oct 5, 2026

1. Controller

The controller for personal data processed on this website is STRATEQUO, Timișoara, Romania. Contact for privacy questions: the contact form.

2. What data we process and why

Situation Data Purpose Legal basis (GDPR)
Quote request name, email, optional company, phone, country, project details, attachments preparing and sending an offer, communication about it Art. 6(1)(b) — steps prior to a contract
Contact form name, email, optional company, message answering your message Art. 6(1)(f) — legitimate interest / (b)
Account name, email, password (stored only as a secure hash), language, optional profile data providing the client account, tracking requests and proposals Art. 6(1)(b)
Security IP address (short-lived, hashed for rate limiting), session identifiers, audit logs for important actions protecting the service against abuse Art. 6(1)(f)
Analytics (only with consent) anonymous usage events: pages viewed, clicks, device type; a daily-rotating, non-reversible visitor hash improving the website Art. 6(1)(a) — consent

We do not sell personal data and do not use it for automated decision-making.

3. Retention

  • Quote requests and related messages: up to 3 years after the last interaction, or longer where accounting or legal obligations require it.
  • Contact messages: up to 2 years.
  • Accounts: until you delete your account. Deleting an account removes your profile, sessions and notifications; quote records are anonymised.
  • Security logs and rate-limit records: up to 12 months.
  • Analytics events: up to 25 months.

4. Recipients

Data is processed by service providers acting on our behalf (hosting, database, email delivery) under data-processing agreements. Where a provider is located outside the EEA, transfers are based on appropriate safeguards such as Standard Contractual Clauses. Embedded videos (YouTube, Vimeo) load only after you click play.

5. Your rights

You have the right to access, rectify, erase and port your data, to restrict or object to processing and to withdraw consent at any time. Signed-in users can download and delete their data from Account → Settings. You may also lodge a complaint with your data protection authority — in Romania, the ANSPDCP (www.dataprotection.ro).

6. Security

Passwords are hashed with Argon2id, connections are encrypted (HTTPS), access to client data is restricted by role and important actions are logged.

7. Changes

We update this policy when our processing changes. The current version is always published on this page.

Esc