Privacy Policy
Last updated: 17 July 2026
Ollia Consulting respects your privacy and is committed to processing personal data lawfully, fairly, transparently and only where necessary.
This Privacy Policy explains how personal data is collected, used, stored and protected when you visit www.olliaconsulting.com, submit an enquiry, request an initial call, communicate with us or enter into a business relationship with Ollia Consulting.
1. Who we are
The data controller responsible for the processing described in this Privacy Policy is:
- Trading name: Ollia Consulting
- Legal name: [TO COMPLETE: full individual or registered company name]
- Registered or correspondence address: [TO COMPLETE]
- Company registration number: [TO COMPLETE WHEN AVAILABLE]
- Tax identification number: [TO COMPLETE WHEN AVAILABLE]
- Email: contact@olliaconsulting.com
- Telephone: +40 752 525 003
Until a separate legal entity is registered, the individual legally operating this website should be identified above as the data controller.
2. Personal data we collect
Information you provide directly
When you contact us, submit a project request, request an initial call or otherwise communicate with us, we may collect:
- first and last name;
- business email address;
- company name and professional role;
- telephone number, where voluntarily provided;
- the service you are interested in;
- information about your platform, system, project or technical challenge;
- messages, correspondence and follow-up information;
- meeting details and scheduling preferences;
- documents or other information you choose to provide.
Please do not submit passwords, production credentials, payment-card information, health information or other sensitive personal data through website forms.
Information collected automatically
When you access the website, our website, hosting and security systems may automatically process:
- IP address;
- browser, operating system and device information;
- requested pages and referring URLs;
- date and time of access;
- server, security and error logs;
- cookie identifiers and privacy preferences;
- technical information required to operate and secure the website.
Client and contractual information
If a business relationship proceeds, we may additionally process:
- business contact details;
- proposal, contract and project information;
- billing, invoicing and transaction information;
- project correspondence and meeting notes;
- technical documentation and recorded decisions;
- access and activity records relevant to service delivery and security;
- information required to meet accounting, contractual and legal obligations.
3. Purposes and legal bases
We process personal data only where there is an appropriate purpose and legal basis.
| Purpose | Legal basis |
|---|---|
| Responding to enquiries and project requests | Legitimate interests in responding to relevant business enquiries and taking steps requested before entering into a contract |
| Assessing whether a potential engagement is suitable | Legitimate interests and pre-contractual steps |
| Scheduling and conducting initial calls | Pre-contractual steps and legitimate interests |
| Preparing proposals, assessments and commercial terms | Pre-contractual steps |
| Providing consulting, engineering, implementation or support services | Performance of a contract |
| Managing client relationships, projects and communications | Performance of a contract and legitimate interests |
| Issuing invoices and maintaining accounting records | Legal obligations and performance of a contract |
| Protecting the website, accounts, systems and communications | Legitimate interests in security, fraud prevention and service integrity |
| Establishing, exercising or defending legal claims | Legitimate interests and compliance with legal obligations |
| Sending newsletters, engineering insights or marketing communications | Your consent, where such communications are offered |
| Measuring website use through non-essential analytics | Your consent, where required |
Where processing is based on legitimate interests, we assess whether the processing is necessary and balance our interests against your rights, interests and reasonable expectations.
4. Contact and project request forms
Website forms allow you to contact Ollia Consulting and describe the issue you are trying to solve. Information submitted through these forms may be used to:
- review and respond to your request;
- assess whether Ollia Consulting is an appropriate fit;
- recommend an appropriate next step;
- arrange an initial call where relevant;
- prepare a proposal or other pre-contractual documentation;
- maintain a record of business communications.
Submitting a form does not create a contractual relationship and does not guarantee that Ollia Consulting will accept the proposed engagement.
Form submissions may be stored within WordPress, transmitted by email and recorded in our customer relationship management system. An automated confirmation email may be sent to acknowledge receipt.
Information submitted through project enquiry forms is not used for unrelated marketing unless you have separately provided consent.
5. Business communications and marketing
We may contact you directly to respond to an enquiry, discuss a requested service, arrange a meeting, provide a proposal or manage an existing business relationship.
A project enquiry is not treated as consent to receive unrelated promotional messages.
If a newsletter or engineering insights subscription is made available, subscription will be voluntary and based on explicit consent. You may withdraw that consent at any time through the unsubscribe option provided or by contacting us.
6. Cookies and similar technologies
The website may use cookies or similar technologies required for:
- website operation and security;
- administrative login and session management;
- remembering technical and privacy preferences;
- form operation and spam prevention;
- performance, analytics or embedded third-party functionality, where enabled.
Strictly necessary cookies may be used without consent where required to provide a service requested by you or to protect the website.
Non-essential analytics, advertising, social-media or third-party cookies will be activated only after the appropriate consent has been obtained where required.
You can manage cookies through your browser settings and, where available, through the website’s cookie preference controls. Disabling necessary cookies may affect website functionality.
Further information about individual cookies, providers and durations may be provided in a separate Cookie Policy or cookie preference panel when non-essential cookies are introduced.
7. Website analytics
We may use website analytics tools to understand general website usage, identify technical problems and improve content and usability.
Where analytics involves non-essential cookies, device identifiers or similar technologies, it will be activated only after the required consent has been obtained.
Analytics information may include viewed pages, approximate location, browser type, device category, referral source and interaction information.
We do not use website analytics to make solely automated decisions that produce legal or similarly significant effects.
8. Embedded content and external links
Pages or articles may contain links to external websites or embedded content such as videos, images, documents, maps or social-media content.
External providers may collect information about your interaction with their services and may use cookies or similar technologies. Their processing is governed by their own privacy policies.
Ollia Consulting is not responsible for the content, security or privacy practices of third-party websites.
9. Service providers and recipients
We may disclose personal data only where necessary to trusted providers supporting the website and business, including:
- website hosting, infrastructure, domain and backup providers;
- email hosting and email-delivery providers;
- customer relationship management providers;
- website, form, security and anti-spam technology providers;
- calendar, meeting and communication providers;
- document storage, project-management and collaboration providers;
- accounting, invoicing, banking and payment providers;
- legal, accounting and other professional advisers;
- contractors or technical collaborators involved in an agreed engagement;
- public authorities where disclosure is required by law.
Providers currently used in connection with this website or business may include:
- ROMARG, for website and email hosting;
- WordPress and Avada technologies, for website operation and forms;
- HubSpot, for customer relationship management;
- FluentSMTP, for configuring authenticated email delivery;
- Google services, where Search Console, Analytics, Calendar or other services are enabled;
- [TO COMPLETE], for any additional provider introduced later.
The providers used may change when operationally necessary. Where a provider processes personal data on our behalf, it is expected to process that data only for agreed purposes and subject to applicable confidentiality and data-protection obligations.
10. Personal data received from third parties
We may receive professional or business contact information from:
- referral partners;
- existing or former clients;
- professional networking platforms;
- public company websites or business directories;
- agencies, suppliers or other professional contacts;
- other lawful business sources.
Where personal data is received indirectly, we use it only for relevant business communication, relationship management or evaluating a potential engagement, subject to applicable legal requirements and your right to object.
11. International data transfers
Some service providers may process personal data outside Romania or the European Economic Area.
Where personal data is transferred outside the European Economic Area, we rely on an applicable legal transfer mechanism, which may include:
- an adequacy decision issued by the European Commission;
- the European Commission’s Standard Contractual Clauses;
- another lawful safeguard permitted under applicable data-protection law.
You may contact us for further information about safeguards relevant to a particular transfer.
12. Retention periods
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, taking account of legal, contractual, accounting, security and dispute-resolution requirements.
- General enquiries and unsuitable leads: normally up to 12 months after the last meaningful interaction.
- Qualified opportunities, proposals and pre-contractual discussions: normally up to 24 months after the opportunity is closed.
- Client and project records: for the duration of the relationship and for a reasonable period afterwards, taking account of contractual and legal limitation periods.
- Invoices, accounting and tax records: for the period required under applicable accounting and tax laws.
- Security, server and email logs: for a limited operational period determined by security, hosting and troubleshooting requirements.
- Marketing consent records: while consent remains valid and afterwards where necessary to demonstrate compliance.
- Suppression and unsubscribe records: for as long as necessary to ensure that communication preferences continue to be respected.
Information may be retained for longer where required by law, necessary for an active dispute or needed to establish, exercise or defend legal claims.
13. Data security
We use reasonable technical and organisational measures designed to protect personal data against unauthorised access, accidental loss, misuse, alteration, disclosure or destruction.
These measures may include:
- encrypted website and email connections;
- access controls and unique credentials;
- multi-factor authentication where supported;
- software and security updates;
- backups and recovery measures;
- logging and security monitoring;
- least-privilege access;
- controlled credential sharing;
- limiting access to people who require it for a legitimate business purpose.
No method of internet transmission or electronic storage is completely secure. We therefore cannot guarantee absolute security.
14. Personal data breach procedures
If we become aware of a suspected or confirmed personal data breach, we will investigate the incident, document relevant facts and take reasonable steps to contain and reduce its impact.
Where required by applicable law, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of the breach.
Where a breach is likely to result in a high risk to affected individuals, we will also communicate relevant information to those individuals without undue delay, unless an applicable legal exception applies.
15. Your data-protection rights
Subject to the conditions and limitations of applicable law, you may have the right to:
- request access to your personal data;
- request correction of inaccurate or incomplete data;
- request erasure of personal data;
- request restriction of processing;
- object to processing based on legitimate interests;
- object at any time to direct marketing;
- receive certain personal data in a portable format;
- withdraw consent at any time, without affecting processing carried out before withdrawal;
- lodge a complaint with a competent data-protection authority.
These rights are not absolute. In some circumstances, we may need to retain or continue processing information to comply with legal obligations, perform a contract or establish, exercise or defend legal claims.
To exercise your rights, contact contact@olliaconsulting.com. We may request information reasonably necessary to verify your identity and protect personal data against unauthorised disclosure.
16. Complaints
We encourage you to contact us first so that we can try to resolve any privacy concern.
You also have the right to lodge a complaint with the Romanian supervisory authority:
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal
B-dul General Gheorghe Magheru 28-30
Sector 1, Bucharest, Romania
Website: www.dataprotection.ro
17. Children’s privacy
The website and services are intended for business and professional users and are not directed at children.
We do not knowingly collect personal data from children through this website. If you believe that a child has submitted personal data, please contact us so that the information can be reviewed and deleted where appropriate.
18. Automated decision-making and profiling
We do not use personal data submitted through the website for solely automated decision-making that produces legal or similarly significant effects.
We may use ordinary business tools to organise contacts, record interactions or classify enquiries. Material decisions about whether and how to respond to an enquiry or enter into an engagement are made with human involvement.
19. Data Protection Officer
Ollia Consulting has not currently appointed a Data Protection Officer because its current processing activities do not fall within the circumstances in which appointment is mandatory under Article 37 GDPR.
Privacy questions and data-subject requests may be sent directly to contact@olliaconsulting.com.
20. Changes to this Privacy Policy
We may update this Privacy Policy when the website, services, providers, processing activities or legal requirements change.
The revised version will be published on this page with an updated revision date. Material changes may also be communicated through another appropriate channel where required.
21. Contact
For questions about this Privacy Policy or the processing of your personal data, contact:
Ollia Consulting
Legal name: [TO COMPLETE]
Address: [TO COMPLETE]
Email: contact@olliaconsulting.com
Telephone: +40 752 525 003
