Privacy Policy

Last updated: 4 July 2026

1. Who we are

Flow Information Technology S.R.L. (“Flow”, “we”, “us”), with its registered office in Bucharest, Sector 2, Str. Italiană no. 21, postal code 020974, registered with the Trade Register under no. J40/24935/2022, VAT no. RO47360774.

We are the controller of the personal data collected through the website flowit.ro and in our relationship with our clients, within the meaning of Regulation (EU) 2016/679 (“GDPR”).

You can contact us with any question regarding your data at contact@flowit.ro or by post at the address above.

 

2. Who this policy applies to

This policy applies to:

  • visitors of the website flowit.ro (including its campaign landing pages);
  • persons who contact us through the forms on the website, by email or by phone;
  • representatives and contact persons of Flow’s clients and prospective clients (we operate exclusively business-to-business; the data we process is, as a rule, professional contact data).

 

3. What data we process, for what purpose and on what legal basis

3.1. Contact and quote request forms on the website

When you fill in a form on flowit.ro (quote request, contact), we collect: first and last name, email address, phone number, company name, your message and, depending on the form, options regarding the service or package of interest, as well as the page from which you submitted the form.

  • Purpose: to respond to your request, to prepare and send you the offer, to communicate with you during the pre-contractual stage.
  • Legal basis: steps taken at your request prior to entering into a contract (art. 6 par. 1 lit. b GDPR).
  • Retention: 2 years from the last interaction, if no contract is concluded; if you become a client, the data becomes part of the contractual records (point 3.4).

Submitting the form triggers a notification to our internal email and the recording of the request in the website’s system. Data from the forms is not used for automatic subscription to marketing communications.

3.2. Direct communication (email, phone)

If you contact us directly, we process your contact details and the content of the correspondence in order to respond and keep a record of the communication. Legal basis: our legitimate interest in responding to requests and managing the commercial relationship (art. 6 par. 1 lit. f). Retention: for the duration of the relationship and 3 years after it ends.

3.3. Traffic and advertising campaign measurement (cookies)

With your consent, expressed through the cookie banner (art. 6 par. 1 lit. a GDPR and ePrivacy legislation), we use on the website:

  • Google Analytics 4 — aggregate statistics about the use of the website (pages visited, traffic source, device type, events such as submitting a form). The data includes online identifiers and the IP address (truncated/processed by Google according to GA4 settings).
  • Google Ads (conversion measurement) — to know whether a visit coming from an ad led to a quote request. We do not receive your identity from Google, only campaign measurement data.
  • Google Tag Manager — the technical tool through which we load the services above.

Strictly necessary cookies (for example, those that remember your choice in the consent banner or support the functioning of the forms) do not require consent and cannot be disabled from the banner.

You can withdraw your consent at any time by deleting the cookies from your browser (on your next visit the banner will ask for your choice again) or by sending a request to contact@flowit.ro. Withdrawal does not affect the lawfulness of prior processing.

  • Retention: according to the lifetime of each cookie and the retention settings in Google Analytics (at most 14 months).

3.4. Clients: contract, invoicing, service delivery

For our clients we process the data of contact persons (name, role, email, phone, company), contractual and invoicing data, as well as the data necessary for delivering the contracted IT services (for example, user accounts, support requests, technical information about equipment and systems).

  • Legal basis: performance of the contract (art. 6 par. 1 lit. b); legal obligations — tax and accounting — for financial-accounting documents (art. 6 par. 1 lit. c); legitimate interest for the operational records of the services (art. 6 par. 1 lit. f).
  • Retention: for the duration of the contract; financial-accounting documents — for the legal archiving periods; operational records — 3 years after the end of the contract.

When, in delivering IT services, we access client systems containing personal data of the client’s employees or customers, we generally act as the client’s processor, on the basis of the contract — those processing activities are not covered by this policy, but by the contract with the respective client.

 

4. Who we disclose the data to

We do not sell your data. We disclose it only to:

  • Service providers (processors): Google Ireland Ltd. (Analytics, Ads, Tag Manager) and the providers of the software tools used on the website, who act on the basis of data processing agreements. The flowit.ro website and email are hosted on our own infrastructure, administered directly by Flow.
  • Public authorities, where the law requires us to.
  • Professional advisers (accountant, lawyer), to the extent strictly necessary.

Transfers outside the EEA: Google services may involve the transfer of certain data (online identifiers, measurement data) to Google LLC in the United States. These transfers are based on the EU–U.S. adequacy decision (EU–U.S. Data Privacy Framework) and, where applicable, on the European Commission’s Standard Contractual Clauses.

 

5. How long we keep the data

The specific durations are indicated for each purpose in section 3. As a rule: we keep the data for as long as necessary for the purpose for which it was collected, then we delete or anonymise it, except where the law requires a longer period (for example, the archiving of financial-accounting documents) or where retention is necessary for the establishment, exercise or defence of legal claims.

 

6. How we protect the data

We apply appropriate technical and organisational measures: encrypted communication (HTTPS) across the entire website, restricted access to the data in requests, updating and monitoring of the systems on which the website runs. As an IT services provider, information security is part of our core business.

 

7. Your rights

Under the GDPR, you have the following rights:

  • access to the data we hold about you and to information about the processing;
  • rectification of inaccurate or incomplete data;
  • erasure of the data (“the right to be forgotten”), under the conditions of art. 17 GDPR;
  • restriction of processing, under the conditions of art. 18 GDPR;
  • portability of data processed by automated means on the basis of consent or contract;
  • objection to processing based on legitimate interest;
  • withdrawal of consent, at any time, for processing based on consent, without affecting the lawfulness of prior processing;
  • the right not to be subject to a decision based solely on automated processing with legal effects — we do not use such decision-making processes.

To exercise your rights, write to us at contact@flowit.ro. We respond within one month of receiving the request; the period may be extended by two months in complex cases, in which case you will be informed. To protect your data, we may request reasonable information to verify your identity.

Providing the data marked as mandatory in the forms is necessary in order for us to be able to respond; the other data is optional.

You also have the right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) — B-dul G-ral Gheorghe Magheru no. 28-30, Sector 1, Bucharest, www.dataprotection.ro — or to bring the matter before the competent courts.

 

8. Third-party links

The website may contain links to third-party pages (for example, technology partners). We are not responsible for their privacy practices; we recommend that you review their policies before providing them with data.

 

9. Changes to this policy

We may update this policy to reflect changes in our services or practices. The current version, with the date of the last update, is permanently published on this page. In the case of significant changes, we will display a visible notice on the website.

 

This policy entered into force on 4 July 2026 and replaces the version dated 30 September 2020.