Privacy Notice
This document was drafted in Romanian. This English version is a translation provided for convenience; in case of any discrepancy, the Romanian version prevails.
⚠ Work in progress. This text is a draft under legal review. Until it is validated by a lawyer, it is for information only. (This note will be removed when the validated version is published.)
Version 1.19 - draft of September 27, 2026
In short, so you don't read for nothing:
- On webid.ro we don't track you: no marketing cookies, no pixels, no third-party analytics (details).
- We collect data when you give it to us: when you ask to see your website, when you buy, when you write to us.
- We use it to deliver our services and to meet our legal obligations (invoices). We don't sell it to anyone.
- Some processing through AI tools does take place (that's how we generate your website) - we tell you exactly where and with what safeguards.
- For any request about your data: contact@webid.ro.
1. Who we are and how to contact us about your data
The controller of the data described here is FAMILIA TASE SRL (the WebID brand), Str. Erou Chivu Dumitru nr. 27, VILA 2, Voluntari, Ilfov County, 077190, Romania, CUI (tax ID) RO41641665, Trade Register No. J40/12194/2019.
⭐ Contact point for data protection: for any request concerning your personal data - access, rectification, erasure, objection, portability or a simple question - write to us at contact@webid.ro, with the subject "Personal data". This is the dedicated channel for exercising your rights; we reply within one month at most, as the law requires.
2. First, an important distinction: which data is "ours"
We build websites for businesses. The data of their clients passes through our clients' websites - for example, a clinic's patient appointments. For that data, the party responsible (the controller) is the business in question, not us: we only operate the infrastructure, on its behalf, under a data processing agreement.
In practice:
- Did you make a booking on the website of a business whose website is built by us? For your data, contact that business - it decides and it answers you. If you write to us by mistake, we forward the request to it without delay.
- Are you our client, or are you visiting webid.ro? Then you're in the right place - this notice is about your data.
3. What data we process, why, and how long we keep it - by situation
a. You visit webid.ro
The public website does not set cookies and does not load tracking scripts - no analytics, no marketing pixels, no third-party fonts. What does exist: a few interface preferences stored locally in your browser, which go nowhere, and - if you start an order - the cart and an identifier of your form, so you can pick it up where you left off; all of them are explained in the Cookie Policy.
Like any web server, the server that delivers the pages to you records technical logs (IP address, time, page requested, browser). We use them solely for security and diagnostics (legitimate interest), not for marketing profiles, and they are deleted through their normal rotation.
b. You ask to see how your website would look
In the "see for free how your website looks" flow, you give us data about your business (the tax identifier, based on which we retrieve the public company data from the official registers), the materials you choose to upload (texts, documents, images, links) and your contact details.
- Why: to generate the website you requested and show it to you - steps prior to a possible contract (Art. 6(1)(b) GDPR).
- Note on materials: what you upload may contain personal data (the names of people on your team, for example). For generation, the materials are processed through carefully selected AI providers - see §4 and §5.
- How long we keep it: it depends on where you stop. If you don't pay the deposit, the demo and the materials are deleted after 30 days. If you have paid the deposit but don't go further: the generated website proposal is deleted 45 days after you see it (the deposit expires with it), while your data (the uploaded materials, the information about your business and the analysis made for you) is kept for 12 months - so that coming back is quick, without starting from scratch. After the website is delivered, we keep the production materials (the uploaded files, the questionnaire answers, the proposal) for another 45 days - so that a change requested right after publication can start from the originals - and then we delete them; only the website content remains, which is yours. If you bought the website but didn't send us the materials, we archive the project and keep the materials and what we generated for 12 months from your last interaction, so we can pick it up where we left off; after that we delete them, and your right to the website remains (we resume it with new materials). If you request a refund of the deposit (within the window in T&C §5, "The content deposit"), what you filled in and uploaded becomes inactive immediately and is deleted completely, within 7 days of the refund; during that interval we can reactivate it only if you ask us to (you changed your mind again). After that, it no longer exists. You can request earlier deletion at any time - see §7. Payment-related data follows the invoicing regime below.
c. You become a client
For delivery, invoicing and support we process: your company's data, the contact person's data (name, email, phone), the order history, the correspondence with us and the proof of acceptance of the contract: who accepted, when, which version of the documents - together with the technical context of the checkbox (the IP address and the browser identifier at the moment of acceptance). The technical context exists for a single purpose: so that the acceptance can be proven and attributed, if it is ever disputed. We don't use it for anything else.
- Legal basis: performance of the contract (Art. 6(1)(b)); for invoices and records - legal obligation (Art. 6(1)(c)); for the evidence of acceptance - the legitimate interest in being able to prove that it was given (Art. 6(1)(f)).
- How long we keep it: financial and accounting documents, for the period required by accounting legislation (currently, as a rule, 5 years); contractual data and the proof of acceptance - for the duration of the relationship plus the general limitation period of 3 years.
- The Google Fonts catalog in the admin panel. The fonts in the panel's list are installed on your website, and you see them without anything going to third parties. If you choose to open the full Google Fonts catalog, the previews load from Google's servers: while you browse, your IP address and browser data reach Google LLC (USA), a transfer based on the EU-U.S. Data Privacy Framework. Legal basis: your consent (Art. 6(1)(a)), given through a checkbox before opening; you can withdraw it at any time, from the same screen, and the fonts already installed remain. The font you choose is installed on your website - your website's visitors do not connect to Google.
d. We contact you (outreach)
Sometimes we take the first step: we pick a business that seems a good fit, build a website demo from its public information (its existing website, the public company profile, public pages) and contact it to show it.
- What data we use: professional contact details that are publicly available, and the business's public content - which may include the names of people in it.
- Legal basis: our legitimate interest (Art. 6(1)(f)) in presenting our services to businesses in a relevant way - we show you something built for you, not a generic leaflet.
- Your safeguards: we inform you about the processing from the first message (with a link to this notice); if you tell us "no, thank you" - a simple reply is enough - we immediately and completely delete the demo and the data and don't contact you again. Unsolicited demos that are not taken further are deleted after 90 days in any case.
e. You write to us or call us
We use the correspondence (email, phone) to answer you and as a record of what was said. Legal basis: pre-contractual steps or the contract, or respectively the legitimate interest in keeping a record of communications. We keep it for as long as it is relevant to our relationship with you, then delete it - at most 2 years after the last exchange, if you are not a client.
f. You pay for something
Payments are made by bank transfer against an invoice or through an authorized payment processor. Your card details never reach us - you enter them directly with the processor, which is an independent controller for them (it has its own privacy notice, shown at payment). We only receive the payment confirmation and the data needed for the invoice.
g. You use the Voice Assistant on webid.ro
If the voice assistant is active on webid.ro, when you start it you receive a short information notice, and you start the conversation only if you want to (consent - Art. 6(1)(a)). The rules it follows: it does not ask you for personal data by voice (it invites you to enter it in the form), and conversation transcripts are not kept - they serve only to guide the conversation, and are then discarded.
h. You connect your Google account (the SEO and Google modules)
If you have a module that works with Google (SEO Management, or the Google module for your business profile), you connect your Google account from the admin panel and give us access, through Google's consent screen, only to what your module uses:
- Google Analytics 4 - reading your website's traffic figures, for the monthly report; and at setup, if you ask us to, creating and configuring your website's property.
- Google Search Console - reading your website's searches and impressions on Google, for the report; and at setup, adding and verifying your website.
- Google Business Profile - the profile data, its statistics (calls, direction requests, website clicks, views), the reviews and the replies to them, so you can see them in the admin panel, reply, choose which reviews appear on your website, and publish posts.
- The email address of the connected Google account, so that you and we know which account is linked.
- How we use this data: only to provide these features to you, in your admin panel and your reports. To write the text of the monthly report, we send an AI provider (§4) only the aggregated figures of the report - no data about your website's visitors and not the text of the reviews.
- What we don't do with it: we don't use it for advertising, we don't sell it, we don't use it to train AI models, and we don't pass it on to anyone other than as described here. No one on our team reads it, with three exceptions: when you ask us to (for example, for support), when it's necessary for security, or when the law requires it.
- Legal basis and roles: performance of the contract for the module you bought (Art. 6(1)(b)). The email address of the Google account belongs to our relationship with you - for it, we are the controller. The data brought in from your Google properties (traffic figures, searches, reviews) we process on your behalf, under the DPA; the reviews also contain your clients' data, for which you are the controller.
- Where it's stored and for how long: the connection to Google goes through our server (webid.ro, hosted in Romania), not through your website's server: the access (the token received from Google) is stored there, encrypted, and only the results reach your website. We generate the monthly reports on our side and deliver them to your website's admin panel; once they get there, our copy is deleted (we rebuild the comparison with past months from the Google data, not from an archive of ours), and a report that can't be delivered is deleted after 90 days. The reports in your admin panel are yours and stay for as long as you keep the website. You can disconnect the account at any time - from the admin panel (we revoke the access at Google immediately and delete the token) or from your Google account, at myaccount.google.com/permissions. When the module ends, we automatically revoke the access the same day, and we delete the data brought in from Google within 30 days; the reports already delivered stay in your admin panel.
- The log of what we send. Everything we send to Google on your behalf (a reply to a review, a post, a setting) is recorded: what was sent, when, and who clicked - so we can show at any time what was published on your behalf and by whom. Each record is kept for 12 months, then deleted.
- The commitment Google requires, word for word: WebID's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4. Who we share data with
Only with those necessary for the services to work - never "in exchange" or for sale:
- The hosting provider - the infrastructure on which webid.ro and the services run.
- AI providers - for content generation (your website, articles): they receive the materials sent for generation. We choose them with a processing contract, and we handle their retention terms as described in §5.
- The payment processor - Stripe (Stripe Payments Europe, Ltd., Ireland - EU), an independent controller for the payment data (§3.f); it receives the email, the billing details (name, company, CUI, address) and the card, which you enter directly with it. It has its own privacy notice.
- Professional service providers (for example, accounting) - strictly what the law requires for financial records.
- Google - only if you open, with your checkbox, the full Google Fonts catalog in the admin panel: the IP address and browser data, while you browse (§3.c); and if you connect your Google account to the SEO or Google modules, through its APIs, so we can bring in the data from your account (§3.h).
- Public authorities - only upon a lawful, verified request.
Every provider that processes data on our behalf is bound by a processing contract (Art. 28 GDPR). For the services in which we are the processor for our clients, the complete list of sub-processors, with countries and transfer mechanisms, is published in the DPA.
5. Transfers outside the EU/EEA
Some providers (especially the AI ones) process data in the United States. Transfers take place only on bases recognized by the GDPR: the EU-U.S. Data Privacy Framework adequacy decision for providers certified under it, or the European Commission's standard contractual clauses, with supplementary measures where appropriate.
We do not use providers that process personal data in China. This is a deliberate choice, applying to all our services.
6. How long we keep data - summary
| Data | For how long |
|---|---|
| Technical server logs | Short periods, through normal rotation |
| Demo + materials, without the deposit paid | 30 days |
| The generated website proposal, with the deposit paid but no purchase | 45 days from when you see it (the deposit expires with it) |
| Your data (materials, information, the analysis), with the deposit paid | 12 months - or complete deletion within 7 days of the deposit refund, if you request it |
| Website bought, no materials sent (archived project) | 12 months from your last interaction; the right to delivery remains afterward |
| Production materials after the website is delivered (the uploaded files, the questionnaire answers, the proposal) | 45 days from delivery; after that only the website content remains, which is yours |
| Outreach demos that were declined | Immediate and complete deletion upon refusal; in any case max. 90 days |
| Correspondence (if you don't become a client) | Max. 2 years from the last exchange |
| Contractual data + proof of acceptance | Duration of the relationship + 3 years (limitation period) |
| Financial and accounting documents | The legal period (currently, as a rule, 5 years) |
| Data brought in from your Google account (§3.h) | The token: until disconnection or the end of the module (then we revoke it at Google and delete it the same day) · the reports: with us only until they're delivered to your admin panel (at most 90 days), then they stay on your website · when the module ends: deleted within 30 days |
| The log of what we send to Google (§3.h) | 12 months from each record |
| Backups (all the categories above) | Rotation by age tiers: at most 182 days after deletion from the active systems |
7. Your rights
Under the conditions of the GDPR, you have: the right of access to your data, of rectification, of erasure, of restriction of processing, of portability, of objection (including, at any time and without justification, to being contacted for the purpose of presenting our services - §3.d) and the right to withdraw your consent where the processing is based on it (withdrawal does not affect the processing carried out before it).
How to exercise them: an email to contact@webid.ro. We don't ask you for special forms. So that we don't give your data to someone else, we may ask for reasonable confirmation of your identity. We reply within one month at most (extendable by two months only for complex requests - and we tell you if that is the case).
If you are not satisfied with the answer, you can contact the National Supervisory Authority for Personal Data Processing (ANSPDCP) - Bd. General Gheorghe Magheru 28-30, Sector 1, Bucharest, Romania, www.dataprotection.ro - or the courts.
8. What we don't do
- We don't sell or rent out your data.
- We don't make decisions based solely on automated processing that have legal effects on you, and we don't do profiling for marketing purposes.
- We don't use the data of our clients or of their clients to train AI models.
- Our services are aimed at businesses; we do not knowingly collect data from minors.
9. Security
The public part of the websites is static (no exposed database), the admin panels are protected by authentication, communications are encrypted (HTTPS), internal access is limited to what is strictly necessary, and the data is backed up. The measures are described in detail in DPA §6.
10. Changes
When we change anything relevant in this notice, we update the version and date below; for significant changes, we notify clients by email. Previous versions remain available on request.
Language of this notice. This document was drafted in Romanian. This English version is a translation provided for convenience; in case of any discrepancy, the Romanian version prevails.
FAMILIA TASE SRL · Str. Erou Chivu Dumitru nr. 27, VILA 2, Voluntari, Ilfov County, 077190, Romania · CUI (tax ID) RO41641665 · contact@webid.ro · +40 770 618 344
Version 1.19 - draft of September 27, 2026.