Privacy policy
Last updated: 10 October 2026
1. Who we are
The data controller is IPSEC Networks S.R.L., registered office Principala nr. 130, Sălicea, Cluj County, 407236, Romania, VAT/tax ID RO39181301, Trade Register No. J1918001386126, email contact@x01.ro. This policy covers the x01.ro website. The client portal (portal.x01.ro) has its own terms of use.
We haven't appointed a Data Protection Officer because Article 37 GDPR doesn't require one for us. For any question about your data, write to the address above.
2. What data we process
- Contact form: name, email, phone (optional), company (optional), service of interest (optional) and your message, including anything else you choose to write.
- Correspondence that follows your message.
- Technical and security data Cloudflare processes when you visit the site or send the form: IP address, browser type, request metadata and Turnstile check signals. When you send the form, the message we receive also includes your IP address, browser, browser language, network (internet provider) and approximate location (city, region, country) as estimated by Cloudflare from the IP address; we use these only for security and to prevent abuse.
- Local preferences (the theme you chose), kept only in your browser and never sent to us.
3. Why, and on what legal basis
| Purpose | Basis (GDPR) |
|---|---|
| Replying and preparing an offer at your request | Art. 6(1)(b) – steps before entering a contract; for other messages and for company contact persons, Art. 6(1)(f) – our legitimate interest in answering messages |
| Website security and spam protection (Cloudflare, Turnstile) | Art. 6(1)(f) – legitimate interest in protecting the site and the form |
| Performing the contract, if we work together | Art. 6(1)(b) |
| Invoicing and accounting | Art. 6(1)(c) – legal obligation (tax and accounting law) |
| Defending legal claims | Art. 6(1)(f) – legitimate interest in defending our rights |
You don't have to give us any data. Without a name, email and message we can't reply; the other fields are optional. We make no automated decisions with legal effects on you; Cloudflare's scoring only filters automated traffic.
4. Who receives the data
- Cloudflare, Inc. (USA) – website hosting, DNS, protection, the Turnstile check and delivering the form message to our inbox (Cloudflare Email Service), as our processor. For improving bot detection through Turnstile, Cloudflare also acts as an independent controller.
- Google Ireland Limited (Google Workspace) – hosts the contact@x01.ro mailbox, as our processor.
- Public authorities when the law requires it, and advisers (accountant, lawyer) bound by confidentiality.
We don't sell data or use it for advertising.
5. Transfers outside the EEA
Cloudflare is a US company, and data may be processed in the USA and in Cloudflare's global network. Transfers rely on the EU–US Data Privacy Framework adequacy decision (Decision (EU) 2023/1795), as the company is certified (DPF list), and, as an additional safeguard, on the European Commission's standard contractual clauses (Decision (EU) 2021/914) included in their processing agreements. You can ask for a copy of the safeguards at contact@x01.ro.
6. How long we keep data
- Messages that don't lead to working together: up to 12 months after the last message, then deleted.
- Correspondence linked to a contract: for the contract term plus the general 3-year limitation period.
- Financial and accounting records: the periods set by Romanian Accounting Law 82/1991.
- Technical security data: short periods, under Cloudflare's policy.
7. Your rights
You have the right of access, rectification, erasure, restriction, portability (for data processed under a contract) and not to be subject to automated decisions.
Right to object: you can object at any time to processing based on our legitimate interest (Art. 21 GDPR).
To exercise your rights, write to contact@x01.ro. We answer free of charge within one month (extendable by two months for complex requests) and may ask for information to confirm your identity.
8. Complaints
You can complain to the Romanian data protection authority (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, postcode 010336, Bucharest, www.dataprotection.ro, or go to court.
9. Security
The site uses encrypted connections only (HTTPS), access to messages is limited to our team, and providers work under processing agreements (Art. 28 GDPR).
10. Cookies
We only use strictly necessary cookies. Details in the cookie policy.
11. Changes
The date of the last update is shown above. We announce significant changes on the site.