Privacy Policy

Last updated: 27 mai 2026

Back to home

This policy explains how we process personal data collected through the forms on yolalac.ro, in accordance with Regulation (EU) 2016/679 ("GDPR") and Legea 190/2018. For information about cookies and similar technologies, see the cookie policy.

1. Data controller

YOLA LAC is a project operated by Tiron Alexandru Adrian PFA (Persoană Fizică Autorizată, sole trader), an entity registered in Romania. The controller's contact details:

  • Name: Tiron Alexandru Adrian PFA
  • CUI: RO30946672
  • Professional office: Strada George Doja nr. 5, Voluntari, Ilfov, Romania
  • General email: contact@yolalac.ro
  • Email for data protection requests: gdpr@yolalac.ro
  • Telephone: +40 774 216 403

Tiron Alexandru Adrian PFA has no legal obligation to designate a Data Protection Officer (DPO) under Art. 37 GDPR, since its main activity does not involve systematic monitoring of individuals on a large scale or the processing of special categories of data. Questions about the processing of personal data may be sent to gdpr@yolalac.ro.

2. What data we collect

The categories of personal data we collect depend on how you interact with the site:

  • Through the contact and register interest forms: name, email address, telephone number (optional), message, time of submission.
  • Automatically, when visiting the site: IP address, browser type, pages visited, time of the visit (in the hosting's technical logs, for security purposes).
  • Through optional cookies: full details in the cookie policy.

3. Purposes of processing and legal basis

We process your personal data for the following purposes, each with a specific legal basis:

PurposeLegal basisCategories of data
Responding to requests for information about the YOLA LAC projectArt. 6(1)(b) GDPR — pre-contractual measures at the request of the data subjectForm data
Sending updates about launches and availabilityArt. 6(1)(a) GDPR — explicit consent; Legea 506/2004 art. 12 (opt-in for commercial communications)Email, name, preferences
Ensuring the security and operation of the siteArt. 6(1)(f) GDPR — legitimate interests in maintaining secure infrastructureTechnical logs, IP address
Compliance with legal obligations (responding to authorities, keeping records)Art. 6(1)(c) GDPR — legal obligationAs applicable

4. How long we keep the data

We keep personal data only for as long as is necessary for the purpose for which it was collected:

  • Leads (information requests with no subsequent conversion): 24 months from the last contact, after which they are erased or anonymised.
  • Marketing lists: until consent is withdrawn or the recipient unsubscribes.
  • Technical security logs: a maximum of 12 months.
  • Data relating to any contracts: for the duration of the contract plus the applicable limitation and archiving periods (as a rule, up to 10 years under Romanian accounting and tax legislation).

5. Who we share the data with

Certain service providers process personal data on our behalf, as processors, under Art. 28 GDPR. The current list:

RecipientRoleLocationTransfer mechanism
Vercel Inc.Website hosting, serverless function execution, technical security logsUSA, with EU regions availableStandard Contractual Clauses (Decision 2021/914) + Vercel Data Processing Agreement
Resend, Inc.Email delivery for messages sent through the website formsUSAStandard Contractual Clauses (Decision 2021/914) + Resend Data Processing Agreement
Google Workspace (Google Ireland Ltd. / Google LLC)Email receipt and storage on the contact@yolalac.ro mailboxEU, with transfers to the USAStandard Contractual Clauses + EU-US Data Privacy Framework
Google Ireland Ltd. (Google Analytics, Google Maps)Anonymised measurement and interactive maps, only after the user's consentEU, with transfers to the USAStandard Contractual Clauses + EU-US Data Privacy Framework
ANSPDCP / Romanian judicial authoritiesOnly upon a formal legal requestRomaniaLegal obligation (Art. 6(1)(c) GDPR)

We do not sell personal data and we do not share it with advertisers outside the processors listed above. All providers are contractually bound to process the data solely in accordance with our instructions and to comply with GDPR requirements.

6. International transfers

Some of our processors are established in the United States of America. For these transfers, we rely on the Standard Contractual Clauses adopted by Decizia (UE) 2021/914 of the European Commission and, where applicable, on the supplier's participation in the EU-US Data Privacy Framework. You may request a copy of these safeguards at gdpr@yolalac.ro.

7. Your rights

Under the GDPR, you have the following rights in relation to your personal data:

  1. Right of access (Art. 15) — to find out what data we process about you.
  2. Right to rectification (Art. 16) — to correct inaccurate or incomplete data.
  3. Right to erasure („the right to be forgotten”) (Art. 17).
  4. Right to restriction of processing (Art. 18).
  5. Right to data portability (Art. 20).
  6. Right to object (Art. 21), in particular to direct marketing.
  7. Right to withdraw consent at any time, without affecting the lawfulness of prior processing.
  8. Right not to be subject to a decision based solely on automated processing — we confirm that we do not use automated decision-making or profiling.

Requests may be sent to gdpr@yolalac.ro and will receive a response within one month (extendable by a further two months for complex requests, with notice). The response is free of charge, except for manifestly unfounded or excessive requests. Consent to marketing communications may be withdrawn at any time through the unsubscribe link in every email or by a request to gdpr@yolalac.ro, without affecting the lawfulness of processing carried out before the withdrawal.

8. Complaints to the supervisory authority

You have the right to lodge a complaint with the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP):

You also have the right to a judicial remedy under Art. 79 GDPR.

9. Security of processing

We apply technical and organisational measures appropriate to the risk: HTTPS connections, access control, limited storage, encrypted transmissions through our providers. In the event of a security breach that may give rise to risks for data subjects, we notify ANSPDCP within 72 hours under Art. 33 GDPR and, where applicable, inform the affected persons directly under Art. 34 GDPR.

10. Whether providing data is mandatory

Providing data through the website's forms is voluntary. Without this data, we cannot respond to your request. Refusing consent to marketing does not in any way affect the response to a request for information.

11. Automated decision-making and profiling

We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR. All responses to requests are drafted manually.

12. Children

The website is not intended for persons under 16. We do not knowingly collect data from children. If we learn that we have collected such data, we erase it immediately.

13. Changes to this policy

This policy may be updated periodically. The „Last updated” date at the top reflects the most recent change. Material changes will be communicated, where applicable, by email to those who have subscribed to updates.

14. Contact

For general questions, you can contact us at contact@yolalac.ro. For requests relating to the processing of personal data (access, rectification, erasure, withdrawal of consent, etc.), use gdpr@yolalac.ro. Written correspondence may be sent to the professional office: Strada George Doja nr. 5, Voluntari, Ilfov, Romania.