Privacy policy

We build solidly. We consolidate sustainably.

Stral big construct

Privacy policy

Respecting the confidentiality of the personal data we operate with is a priority for us, as a personal data controller with the following identification and contact details:

Name: STRAL BIG CONSTRUCT S.R.L.,

Sediul: Mun. Piatra Neamt, Str. Bulevardul Dacia Nr. 10, Bl. 10, Sc. A, Et. 4, Ap. 18, Jud. Neamt,

Identification data: ORC J27/320/2021, C.U.I. RO43878790,

Contact details: +40 752 105.689, office@stralbigconstruct.ro

 

If you have any questions or concerns regarding this Privacy Policy or its implementation, you can contact our Data Protection Officer (DPO) by email at gdpr@stralbig.ro or by phone at +40 755 050270.

 

Preamble

Data processing carried out through this website complies with both Regulation (EU) 2016/679 (GDPR) and the provisions of Law No. 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector.

The use of cookies and similar technologies, as well as the sending of commercial communications by electronic means, is carried out appropriately, with the user’s consent, in accordance with applicable Romanian law.

1.    GENERAL PRINCIPLES

Our company applies the principles of the GDPR to all personal data processing operations within our field of activity, namely the execution of civil and industrial construction projects. These principles are set forth in Article 5 of the GDPR and address the data controller’s obligations regarding: lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality.

2.    CATEGORIES OF DATA PROCESSED

In addition to the data collected through the website, we process data in connection with the execution of projects:

  • Contact Information: Email, phone number, mailing/billing address.
  • Date de Contact: E-mail, telefon, adresă de corespondență/facturare.
  • Property Data: Property/land address, land registry extracts, cadastral maps (for obtaining a building permit or carrying out construction work), IP address, browser type, device used
  • Technical Data: Architectural plans and construction details that may contain references to the beneficiaries.
  • Recruitment Information: Resume, work experience, education, criminal record (where required by law for safety on the construction site).
  • Date de Recrutare: CV, experiență, studii, cazier judiciar (unde legea permite/impune pentru siguranța pe șantier).

We do not collect sensitive data and do not request information that is not necessary for the fulfillment of the contract between us and our business partners, regardless of the nature of the collaboration.

3.    PURPOSES AND LEGAL BASIS

The data is used exclusively for purposes related to the provision of our civil and industrial construction services, namely: responding to inquiries and requests for proposals, communicating for the purpose of entering into contracts, submitting technical and financial proposals, improving the functioning of the website, and complying with applicable legal obligations.

The legal basis for the data processing we perform may be your consent—when you fill out contact forms—the company’s legitimate interest—for website security and the prevention of abuse—or compliance with legal obligations—regarding contractual and tax records. Below is an overview of the legal bases associated with the purposes identified in our data processing system:

Purpose of ProcessingLegal Basis (Art. 6 GDPR)
Bidding & Quotes: Reviewing technical requests.Pre-contractual steps taken at the individual’s request.
Contract Execution: Actual construction, team management.Performance of the contract.
Legal Requirements: Billing, auditing, Occupational Health and Safety (OHS).Legal obligation.
Warranty and After-Sales Service: Handling of Hidden Defects/Maintenance.Legitimate interest / Performance of the contract.
Marketing: Newsletter, showcase of completed projects.Explicit consent.
Security: Video surveillance (CCTV) at offices or construction sites.Legal requirement or legitimate interest (protection of assets).

4.    DATA RETENTION PERIOD

Personal data is retained only for as long as necessary to fulfill the purposes for which it was collected, and thereafter, when the law requires retention or justifies its retention to protect our rights.

Specifically, the retention period varies depending on the nature of the relationship with the data subject:

  • Data submitted via the contact form or request for a quote that does not result in the conclusion of a contract is retained for a maximum of 12 months from the last interaction, to allow for the resumption of communication or the clarification of any subsequent inquiries.
  • Data related to accepted bids and concluded contracts are retained for the duration of the contract and thereafter, in accordance with the legal requirements for financial, accounting, and tax record-keeping, which typically range from 5 to 10 years.
  • Data included in business correspondence (emails, technical requests, clarifications) may be retained for the duration of the business relationship and thereafter, if necessary to protect the company’s legitimate interests, such as handling complaints, demonstrating compliance with contractual obligations, or defending against potential disputes.
  • Automatically collected technical data (security logs, IP addresses, website access information) is retained for limited periods, typically between 30 and 180 days, except in cases where it is necessary to retain it for a longer period to investigate security incidents.

Upon expiration of the retention periods, the data is deleted or anonymized, unless their retention is required by law or justified by an overriding legitimate interest.

Data subjects may request the erasure of their data at any time prior to the expiration of the aforementioned time limits, provided there are no legal obligations requiring their retention.

5.    DATA RECIPIENTS (TRANSFERS)

The data may be transmitted to:

  1. Public Authorities: City Halls (for permits), ISC (State Construction Inspectorate), ANAF.
  2. Specialists and Subcontractors: Architects, structural engineers, MEP contractors, site supervisors.
  3. Service Providers: Courier companies (material delivery), accounting services, IT and cloud services.
  4. Banks/Insurance Companies: For mortgage loans or construction risk insurance.

5.    INTERNATIONAL DATA TRANSFER

Currently, we store data on servers located in the European Union. When we use cloud services (e.g., Microsoft 365, Google Workspace), we ensure that the providers offer adequate safeguards (Standard Contractual Clauses).

6.    DATA SECURITY AND PRIVACY

The company takes the security of personal data seriously and implements appropriate technical and organizational measures to ensure a level of protection commensurate with the risks associated with processing.

To this end, we implement internal policies and technical measures designed to prevent unauthorized access, misuse, loss, destruction, or accidental disclosure of data.

The measures implemented include, but are not limited to:

  • the use of secure, encrypted connections (HTTPS/SSL) for transmitting data through the website
  • restricting access to data to authorized personnel only
  • granular control of data access based on professional roles and responsibilities, so that each employee or contractor can access only the information strictly necessary to perform their duties
  • the implementation of different levels of permissions in IT systems and applications
  • user authentication using individual credentials and secure password policies
  • monitoring access to data and logging operations performed on it
  • protecting servers and IT systems with firewalls, regular updates, and security solutions
  • creating backups to prevent data loss
  • regular training of staff on data confidentiality and applicable legal obligations
  • entering into confidentiality agreements and data processing agreements with suppliers acting as data processors

The company periodically assesses the risks associated with data processing and reviews its security measures whenever technological, operational, or legislative changes occur.

În cazul producerii unui incident de securitate ce poate afecta drepturile persoanelor vizate, societatea va aplica procedurile interne de gestionare a incidentelor și, dacă este necesar, va notifica autoritatea de supraveghere și persoanele afectate, conform legislației aplicabile.

Although we implement appropriate data protection measures, the transmission of information over the internet cannot be guaranteed to be completely secure. Users are encouraged to avoid transmitting sensitive data via the website’s forms.

7.    RIGHTS OF THE DATA SUBJECT

In accordance with applicable law, you have the following rights:

 

Right of access: You have the right to obtain confirmation from us that your personal data is being processed by us, as well as information regarding the specifics of the processing, such as: the purpose, the categories of personal data processed, the recipients of the personal data, the period for which the personal data is retained, whether we transfer it abroad and how we protect it, your rights, the right to lodge a complaint with the supervisory authority, and where we obtained the personal data.

Right to rectification: You have the right to request the rectification of your personal data, provided that the applicable legal requirements are met. In the event of any errors, we will correct your personal data immediately upon notification.

Dreptul la ștergere: În anumite cazuri, aveți posibilitatea de a solicita ștergerea datelor cu caracter personal: (i) acestea nu mai sunt necesare pentru scopurile pentru care le-am colectat și le prelucrăm; (ii) ați retras consimțământul pentru prelucrarea datelor cu caracter personal și noi nu mai putem prelucra datele cu caracter personal în baza altor temeiuri legale; (iii) datele cu caracter personal sunt prelucrate contrar legii; (iv) dați curs unui drept legal de a vă opune. Nu vom putea da curs solicitării dumneavoastră de ștergere în cazul în care prelucrarea datelor cu caracter personal este necesară pentru respectarea unei obligații legale, sau pentru constatarea, exercitarea sau apărarea unui drept în instanță. De asemenea, există alte și circumstanțe în care nu suntem obligați să respectăm această solicitarea de ștergere a datelor cu caracter personal.

Restriction of processing: You may request that we restrict the processing of your personal data in the following situations: (i) if you contest the accuracy of the personal data, for a period that allows us to verify the accuracy of the personal data in question; (ii) if the processing is unlawful, and you oppose the erasure of the personal data, requesting instead that its use be restricted; (iii) if we no longer need the personal data for the purposes of processing, but you require it for legal proceedings; (iv) if you have objected to the processing, for the period during which we verify whether our legitimate interests as a controller override those of the data subject. We may continue to use personal data following a request for restriction if: (i) we have your consent; (ii) to establish, exercise, or defend legal claims; or (iii) to protect the rights of another natural or legal person.

Right to data portability: To the extent that personal data is processed based on your consent or for the performance of a contract, and the processing is carried out by automated means, you have the right to have your personal data provided to you in a structured, commonly used, and machine-readable format, and you have the right to transmit this personal data to another controller. This right does not adversely affect the rights and freedoms of others.

Your right to object to receiving commercial messages: You may also object to the processing of your personal data for the purpose of sending commercial messages.

Dreptul de a vă opune primirii de mesaje comerciale: De asemenea, vă puteți opune la prelucrarea datelor dumneavoastră cu caracter personal în scopul trimiterii de mesaje comerciale.

Right not to be subject to individual decisions: In certain circumstances, you have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. This right does not apply if the decision: (i) is necessary for the conclusion or performance of a contract between you and us; (ii) is authorized by law that also provides for appropriate safeguards for your rights and freedoms; (iii) is based on your explicit consent.

Dreptul de a nu fi supus unor decizii individuale: În anumite circumstanțe aveți dreptul de a nu fi supus unei decizii bazate exclusiv pe prelucrarea automată, inclusiv crearea de profiluri, care produce efecte juridice în privința dumneavoastră sau vă afectează în mod similar într-o măsură semnificativă. Acest drept nu este aplicabil în cazul în care decizia: (i) este necesară pentru încheierea sau executarea unui contract între dumneavoastră și noi; (ii) este autorizată de lege care prevede și garanții adecvate pentru drepturile și libertățile dumneavoastră; (iii) are la bază consimțământul dumneavoastră explicit.

Your right to contact the supervisory authority: You have the right to file a complaint with the National Authority for the Supervision of Personal Data Processing (“ANSPDCP”) regarding any violation of your rights concerning the processing of your personal data. The contact details for ANSPDCP are: 28-30 General Gheorghe Magheru Blvd., Sector 1, Postal Code 010336 Bucharest, Romania; email: anspdcp@dataprotection.ro.

8.    EXERCISING YOUR RIGHTS

The Data Protection Officer (DPO) is responsible for facilitating communication between you, us, and the National Supervisory Authority (ANSPDCP), acting as an extension of the ANS in the data controller’s processing of personal data to ensure compliance with GDPR requirements. Feel free to rely on their expertise to defend your right to privacy regarding the processing of your personal data by contacting them at the email address gdpr@strabig.ro.

Verificarea identității: Acordăm cea mai mare atenție confidențialității tuturor datelor cu caracter personal și ne rezervăm dreptul de a vă verifica identitatea în cazul în care faceți o cerere cu privire la datele cu caracter personal.

Fees: As a general rule, you may exercise your rights free of charge. However, we reserve the right to charge a reasonable fee if your requests are manifestly unfounded or excessive, particularly due to their repetitive nature.

Response time: We make every effort to respond to your requests within one month of receiving them. This period may be extended by two months when necessary, taking into account the complexity and number of requests, in which case we will inform you of any such extension and the reasons for the delay.

9.    ACTUALIZAREA POLITICII

Stral Big Construct SRL reserves the right to periodically update this Privacy Policy to reflect changes in legislation, technological developments, changes in service features, or in the way personal data is processed. Any updates will be made in accordance with the principles of transparency and information provided for by applicable European Union legislation.

The updated version of the policy will include the date of the last revision and will be permanently available for review.

Changes to this policy take effect as of the date of publication of the updated version, except in cases where the law requires prior notification or the obtaining of new consent. If the updates involve new processing activities based on consent, such consent will be requested before the changes are implemented.