Privacy Policy
Last updated: 19 September 2026
1. Who we are
This Privacy Policy explains how Xtreme Solutions S.R.L., a company registered in Romania with its registered office at Str. 1 Mai nr. 39, Otopeni, Ilfov County, Trade Register number J2020003593233, CUI RO42927488, trading as Xtreme IT ("Xtreme IT", "we", "us"), processes personal data as a controller within the meaning of Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR") and Romanian Law No. 190/2018 implementing the GDPR.
You can contact us about any matter relating to the processing of your personal data at office@xtremeit.ro, or by post at the address above.
2. Scope
This Privacy Policy applies to personal data processed through the website xtremeit.ro, through the forms available on it, and in the course of the business correspondence that follows from them. It does not apply to third-party websites linked from our website.
3. Personal data we process, purposes and legal bases
3.1 Enquiries and requests for consultation
When you contact us through the contact form, by email or by telephone, we process your name, company name, job title (if provided), email address, telephone number, the service and number of sites you indicate, and the content of your message.
Purpose: to respond to your enquiry, prepare a proposal and take steps at your request before entering into a contract.
Legal basis: Article 6(1)(b) GDPR (steps prior to entering into a contract) and, where you act on behalf of an organisation, Article 6(1)(f) GDPR (our legitimate interest in communicating with prospective and existing business clients).
3.2 Business relationship with clients and suppliers
Where you are a contact person of a client, prospective client, supplier or partner, we process your identification and professional contact data and the content of our communications.
Purpose: to conclude and perform contracts, manage projects and services, and administer the business relationship.
Legal basis: Article 6(1)(b) GDPR, where you are a party to the contract. Otherwise Article 6(1)(f) GDPR (our legitimate interest in performing contracts concluded with the organisation you represent).
3.3 Recruitment
When you apply for a position, we process the data in your application and CV: identification and contact data, education, professional experience, certifications, skills, and any other information you choose to include. We also process the notes of interviews and assessments carried out during the recruitment process.
Purpose: to assess your application and conduct the recruitment process.
Legal basis: Article 6(1)(b) GDPR (steps taken at your request prior to entering into an employment or service contract).
We do not keep applications for future vacancies.
Please do not include special categories of personal data (such as health data, religious or political beliefs) in your application unless required by law for the position.
3.4 Legal obligations
We process personal data where required to comply with legal obligations, in particular in the field of accounting and taxation, and to respond to lawful requests from public authorities.
Legal basis: Article 6(1)(c) GDPR.
3.5 Establishment, exercise or defence of legal claims
Legal basis: Article 6(1)(f) GDPR (our legitimate interest in protecting our rights).
3.6 Website operation, security and cookies
When you visit our website, technical data such as your IP address, browser type, device information and the pages accessed are processed to deliver the website and keep it secure.
Legal basis: Article 6(1)(f) GDPR (our legitimate interest in operating a secure website).
Cookies and similar technologies that are not strictly necessary are used only with your consent, in accordance with Article 4(5) of Romanian Law No. 506/2004 and Article 6(1)(a) GDPR. Details are set out in our Cookie Policy.
4. Source of personal data
We collect personal data directly from you. For contact persons of clients, suppliers and partners, data may also be provided by the organisation you represent.
5. Whether providing personal data is required
Providing personal data through our forms is voluntary. Without the data marked as mandatory in a form, we cannot respond to your enquiry or assess your application.
6. Recipients
We disclose personal data only to the extent necessary for the purposes described above, to:
- service providers acting as processors on our behalf, under written agreements in accordance with Article 28 GDPR, including:
- Wix.com Ltd., website hosting and form management;
- Microsoft (Microsoft 365), email services;
- professional advisers (such as accountants, auditors and lawyers), who are bound by confidentiality obligations;
- public authorities and courts, where required by law.
We do not sell personal data.
7. Transfers outside the European Economic Area
Some of our service providers may process personal data outside the European Economic Area. Where this is the case, the transfer takes place only on the basis of an adequacy decision of the European Commission under Article 45 GDPR or subject to appropriate safeguards under Article 46 GDPR, such as the Standard Contractual Clauses adopted by the European Commission.
You may request information on the safeguards applied by contacting us at the address in section 1.
8. Retention
We keep personal data only for as long as necessary for the purposes for which it was collected, using the following criteria:
- Enquiries that do not lead to a contract: only for as long as needed to respond to the enquiry and conclude the related correspondence.
- Client, supplier and partner business data: for the duration of the business relationship and, thereafter, for as long as required by applicable law or needed to establish, exercise or defend legal claims.
- Accounting and tax documents: for the periods required by applicable accounting and tax legislation.
- Recruitment: until the end of the recruitment process for the position applied for. Applications are not kept for future vacancies.
- Website technical data: only for as long as needed to operate and secure the website.
After these periods, personal data is deleted or anonymised.
9. Your rights
Under Articles 15 to 22 GDPR, you have the right to:
- access your personal data and obtain a copy of it;
- rectification of inaccurate or incomplete data;
- erasure of your data, in the cases provided by Article 17 GDPR;
- restriction of processing, in the cases provided by Article 18 GDPR;
- data portability, where processing is based on consent or contract and carried out by automated means;
- object at any time, on grounds relating to your particular situation, to processing based on our legitimate interests;
- withdraw your consent at any time, without affecting the lawfulness of processing carried out before its withdrawal.
To exercise these rights, contact us at office@xtremeit.ro. We will respond without undue delay and in any event within one month of receipt of the request. This period may be extended by two further months where necessary, taking into account the complexity and number of requests, in which case we will inform you of the extension within the first month (Article 12(3) GDPR). We may ask for information to confirm your identity before responding.
10. Right to lodge a complaint
You have the right to lodge a complaint with the supervisory authority of the Member State of your habitual residence, place of work or place of the alleged infringement. In Romania, this is:
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
B-dul G-ral Gheorghe Magheru nr. 28-30, Sector 1, postal code 010336, Bucharest, Romania
Telephone: +40 318 059 211
Email: anspdcp@dataprotection.ro
Website: www.dataprotection.ro
11. Automated decision-making
We do not take decisions based solely on automated processing, including profiling, which produce legal effects concerning you or similarly significantly affect you.
12. Security
We apply appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, in accordance with Article 32 GDPR.
13. Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes in our processing activities or in the law. The current version is always available on this page, together with its effective date.