Privacy

Privacy Notice

Last updated: 25 July 2026

This notice explains how we handle personal data when you use this website or send us an enquiry. It sets out what we collect, why we use it, how long we keep it, and the rights available to you under the General Data Protection Regulation.

1. Who we are

This website is operated by CYBERSECURITY INITIATIVE S.R.L., a company registered in Romania and trading as CYBERSOL. CYBERSOL is the trading name used by CYBERSECURITY INITIATIVE S.R.L. and is not a separate legal entity.

For the processing described in this notice, CYBERSECURITY INITIATIVE S.R.L. is the data controller.

Legal name
CYBERSECURITY INITIATIVE S.R.L.
Trading name
CYBERSOL
Trade Registry no.
J40/6216/2023
CUI
47910690
Email
contact@cybersolsecurity.com

2. Scope of this notice

This notice covers personal data processed through:

  • this website;
  • the contact form;
  • business enquiries sent to us directly by email;
  • technical and security logs generated by the infrastructure serving this website.

Where we carry out a security engagement for a client, the handling of information encountered during that work is governed by the agreement, scope, and rules of engagement agreed with that client rather than by this notice. This notice does not describe that contractual processing.

3. Information we collect

Contact form

The form asks for the following. Fields marked as required are needed for us to understand and answer the request.

  • Name (required)
  • Work email (required)
  • Company (required)
  • Service (required)
  • What needs testing? (required, shown only when Penetration Testing is selected)
  • Cloud environment (required, shown only when Cloud Security Audit is selected)
  • Project context (required), the free-text description of what you need, its purpose, and any deadline you choose to mention

We also process limited anti-abuse signals generated when the form is submitted, such as an unfilled hidden field and the time spent on the form, which help us reject automated spam.

To protect the contact form from automated abuse, we use Cloudflare Turnstile. It processes limited technical information, such as IP address, browser and connection signals, to distinguish legitimate submissions from automated traffic and maintain service security. CYBERSOL does not use Turnstile for advertising or behavioural analytics.

Direct correspondence

When you email us, we process your email address, your name, your company and role where you give them, the content of your message and any attachments, and any later correspondence between us.

Technical and security information

Serving a website necessarily involves processing technical request data. Our hosting and network providers process information such as:

  • IP address;
  • date and time of the request;
  • the URL requested and the response status;
  • browser and device information sent by your browser, such as the user-agent string;
  • the referring page, where your browser sends one;
  • server, access, and security log entries;
  • error and diagnostic information where a request fails.

This data is used to serve the site, keep it available, and protect it against attack and misuse. We do not use it to build profiles of visitors.

This website also loads a small number of static resources, specifically web fonts, from a third-party content-delivery service. When your browser requests those files it connects directly to the provider, which necessarily receives your IP address and basic request information. Section 7 explains this further.

4. Why we use personal data, and our legal bases

Responding to enquiries and preparing proposals

We use the information you send to review your request, discuss scope with you, prepare a proposal, and take the steps you have asked us to take before any agreement is entered into.

Legal basis: Article 6(1)(b) GDPR where you are personally taking steps prior to entering into a contract with us, and Article 6(1)(f) GDPR, our legitimate interest in business communication, where we are corresponding with a representative of a prospective or existing business customer.

Business communication and records

We keep our correspondence, follow up on active requests, maintain an accurate record of what was discussed and agreed, and manage the professional relationship.

Legal basis: Article 6(1)(f) GDPR, our legitimate interest in operating and documenting our business-to-business activity.

Website security and abuse prevention

We use technical and log information to detect and investigate attacks, troubleshoot faults, protect the website and our communications, and prevent spam, fraud, misuse, and unauthorised access.

Legal basis: Article 6(1)(f) GDPR, our legitimate interest in securing our systems and services.

Legal obligations and legal claims

We process personal data where we must do so to comply with legal, tax, accounting, regulatory, or court requirements, and where it is necessary to establish, exercise, or defend legal claims.

Legal basis: Article 6(1)(c) GDPR where the processing is required by law, and Article 6(1)(f) GDPR where it is necessary in connection with legal claims or the management of a dispute.

We do not rely on consent to answer an ordinary enquiry, and submitting the form is not treated as consent to unrelated processing. Where any processing does rest on consent, we will say so and you may withdraw it at any time.

5. Information you must provide

The fields marked as required on the contact form are the minimum we need to identify who is asking, understand what is being asked, and reply usefully. If they are not supplied, we may be unable to review or answer the request.

You do not have to give us a deadline or target date. The form no longer asks for one as a separate field, and mentioning timing in the project description is entirely optional.

6. Information you should not send us

Please do not send us, through the form or by email:

  • passwords, access tokens, API keys, or private keys;
  • production credentials of any kind;
  • personal data that is not needed for the enquiry;
  • health information or payment-card information;
  • confidential information belonging to your own clients or third parties;

If sensitive supporting material is genuinely necessary, contact us first and we will agree a more appropriate way to transfer it. Do not assume that any particular secure channel is already available.

7. Who we share information with

We do not sell personal data, and we do not share enquiries for marketing purposes. We do rely on service providers to operate this website and our business, and we disclose information where the law requires it.

The categories of recipient are:

  • Hosting and network infrastructure providers, which serve this website and process the technical log data described in section 3;
  • Content-delivery providers, which serve the web fonts this website loads. At present this is Google Fonts, for typefaces. Your browser requests those files directly, so the provider receives your IP address and basic request metadata. This website’s own JavaScript is served from the CYBERSOL website itself, not from a third-party library service;
  • Email and collaboration providers, which deliver and store our business correspondence;
  • Form-processing and anti-abuse providers, where used to receive and filter submissions from this website;
  • Security, logging, and error-monitoring providers, where used to protect and maintain the site;
  • Professional advisers, such as lawyers and accountants, where necessary for advice, compliance, or a legal claim;
  • Public authorities and courts, where disclosure is required by law or necessary to defend a legal claim.

We require providers acting on our behalf to process personal data only on our instructions and to protect it appropriately.

8. International transfers

Some of the providers described above, including the content-delivery services named in section 7, are established outside the European Economic Area or may process data outside it. Where personal data is transferred outside the EEA, we rely on a transfer mechanism permitted by Chapter V of the GDPR, such as an adequacy decision adopted by the European Commission or the Standard Contractual Clauses, together with any additional safeguards required in the circumstances.

If you would like information about the transfers relevant to a particular provider, contact us at contact@cybersolsecurity.com.

9. How long we keep information

Enquiries that do not lead to an engagement

Up to 24 months after the last meaningful interaction. We may delete sooner where we no longer need the information.

Enquiries that lead to an engagement

Relevant correspondence becomes part of the client record. It is retained for the duration of the engagement and afterwards for as long as necessary to meet our contractual, tax, accounting, and other legal obligations, and to manage potential claims.

Website and security logs

Up to 90 days, except where a specific entry is needed for an ongoing security or fraud investigation, to comply with a legal obligation, or in connection with a legal claim.

10. Security

We apply technical and organisational measures appropriate to the risks presented by the processing described here, including controls over who can access enquiries and correspondence. We keep those measures under review.

No method of transmission or storage can be guaranteed to be completely secure. We therefore ask you not to send credentials or sensitive technical material by email or through the form, as set out in section 6.

11. Your rights

Subject to the conditions and exceptions in the GDPR, you have the right to:

  • request access to the personal data we hold about you;
  • ask us to correct inaccurate or incomplete data;
  • ask us to erase data where there is no longer a lawful reason to keep it;
  • ask us to restrict processing in certain circumstances;
  • object to processing carried out on the basis of our legitimate interests;
  • receive certain data in a portable form, where the processing is based on contract or consent and carried out by automated means;
  • withdraw your consent, where a specific processing operation is based on consent.

To exercise a right, email contact@cybersolsecurity.com. We may need to ask you a small number of questions to confirm that the request comes from you before we act on it. We will not ask for more identification than is proportionate to the request.

12. Complaints

If you believe your personal data has been processed unlawfully, you may lodge a complaint with the Romanian supervisory authority, the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP).

Address
B-dul G-ral. Gheorghe Magheru nr. 28-30, Sector 1, 010336 Bucharest, Romania
Telephone
+40 31 805 9211
Email
anspdcp@dataprotection.ro
Website
www.dataprotection.ro

We would welcome the chance to address your concern first, so please consider contacting us before making a complaint.

13. Automated decision-making

CYBERSOL does not use information submitted through the website to make decisions based solely on automated processing that produce legal or similarly significant effects.

14. Cookies and browser storage

This website does not set cookies, does not write to local or session storage, and does not use analytics, advertising, marketing pixels, tag managers, chat widgets, or behavioural tracking of any kind. Because no non-essential storage is used, there is no consent banner to accept or reject.

As explained in sections 3 and 7, the site does load web fonts from a third-party content-delivery service. Those requests reveal your IP address to the provider, but based on our testing they do not place cookies or other storage on your device through this website.

If we later introduce anything that stores or accesses information on your device beyond what is strictly necessary, we will publish a separate cookie notice and obtain consent before it operates.

15. Changes to this notice

We may update this notice as our processing, providers, or legal obligations change. The date at the top of the page shows when it was last revised materially. Where a change significantly affects how we use personal data, we will take reasonable steps to make it clear.

16. Contact

Controller
CYBERSECURITY INITIATIVE S.R.L., trading as CYBERSOL
Email
contact@cybersolsecurity.com