1. Who We Are
XOCO WEB SRL (CUI 45465782, Registration No. J20/46/2022, EUID ROONRC.J20/46/2022), trading as xoco, operates xocoweb.com and is the data controller for the personal data described below, within the meaning of Article 4(7) of the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"). We follow the GDPR, applicable Romanian data protection law, and guidance from the Romanian supervisory authority (ANSPDCP).
For any privacy question or request, email hello@xocoweb.com. Our registered office is recorded in the Romanian Trade Register under the registration number above and is available on request.
We are not required to appoint a Data Protection Officer under Article 37 GDPR and have not done so. Privacy questions are handled directly by the people who run the studio.
2. The Short Version
- This site has no analytics, no advertising or tracking tools, no forms and no accounts.
- The only personal data we get from you is what you choose to send us by email, plus the basic technical data any web server receives.
- We use it to reply, to quote and deliver your project, and to keep the records the law requires. We never sell it.
3. Data We Collect
When you email us. Your name, email address, the content of your message, and anything you choose to include, such as your web address, your company name or details about your project.
When you become a client. Contact and billing details for you or your company, the quote and agreement we exchange, invoices and payment records, and the files, text, images and access details you share with us for the project.
When you visit the site. Our hosting provider, Cloudflare, processes standard request data such as your IP address, browser and device type, the page requested, the time and the referring page, so the site can be delivered securely. We do not use this to identify you.
From clients, about other people. When you hire us, you may give us personal data about other people, such as colleagues who should be contacted about the project, or content on your website that names people. You are responsible for having a lawful basis to share it with us and for informing those people where required (Article 14 GDPR).
In your browser. If you click the diamond on the home page to change the site's accent colour, your choice is saved in your own browser. It never leaves your device and does not identify you. See the Cookie Policy for details.
4. Why We Use It, and Our Legal Basis
- Replying to your email and preparing a quote: steps taken at your request before entering into a contract (Article 6(1)(b) GDPR), or our legitimate interest in answering enquiries (Article 6(1)(f)).
- Delivering your project and supporting you afterwards: performance of our contract with you (Article 6(1)(b)).
- Invoicing, accounting and tax records: our legal obligations under Romanian law (Article 6(1)(c)).
- Keeping the site secure and available: our legitimate interest in protecting our service and its visitors (Article 6(1)(f)).
Where we rely on legitimate interest, we have balanced that interest against your rights and only process what is reasonably needed. We make no automated decisions about you, including profiling, within the meaning of Article 22 GDPR.
Do you have to give us your data? No. You do not have to contact us, and using this site requires no personal data beyond what your browser sends automatically. If you want a quote or a project, we need your contact details to reply and, once we work together, the details the law requires for invoicing. Without them we cannot provide the service.
5. Data on Your Own Website
When we upgrade, build or look after your website, we may be able to see personal data that your site holds, such as form submissions, customer lists or user accounts. For that data you remain the controller and we act only as your processor, on your instructions and for the purposes of the project. On request, we put this in writing in a data processing agreement that meets Article 28 GDPR.
6. Who Processes Data for Us
We use a small number of providers, each bound by its own data protection terms:
- Cloudflare (website hosting, delivery and security). See Cloudflare's privacy policy (opens in a new tab).
- Our email provider, which stores the messages you send us and our replies.
- Our accountant and bank, for invoices and payments from clients.
We may also disclose data where the law requires it, for example to a tax authority. We do not sell, rent or trade personal data, and we do not share it for advertising.
7. Security
We protect personal data with appropriate technical and organisational measures, including encrypted connections (HTTPS) for this site, access restricted to the people who need it, strong authentication on our accounts, and reputable providers with their own security commitments. No transmission or storage is completely secure, however, and email in particular is not an encrypted channel.
Please do not send us passwords, payment card details or special categories of personal data (such as health information) by email. If a project needs access to your accounts, ask us and we will agree a secure way to share it. If a personal data breach occurs that is likely to put your rights at risk, we will notify the supervisory authority and, where required, you, as set out in Articles 33 and 34 GDPR.
8. International Transfers
Some providers, including Cloudflare, may process data outside the European Economic Area, including in the United States. Where a provider is certified under the EU-U.S. Data Privacy Framework, the transfer is covered by the European Commission's adequacy decision of 10 July 2023. Otherwise we rely on the European Commission's Standard Contractual Clauses, with any additional safeguards the transfer needs. You can ask which applies to a given provider by emailing hello@xocoweb.com.
9. How Long We Keep It
- Enquiries that do not lead to a project: up to two years after our last exchange, then deleted.
- Client correspondence and project files: for as long as we work together, and afterwards for as long as needed to support the site we delivered or to handle a claim, normally no more than five years.
- Invoices and accounting records: for the periods required by Romanian accounting law.
- Server request logs: kept by Cloudflare for a short period under its own retention policy.
10. Your Rights
Under Articles 15 to 21 GDPR you have the right to:
- access the personal data we hold about you and receive a copy;
- rectify data that is inaccurate or incomplete;
- erase your data, where there is no longer a reason for us to keep it;
- restrict how we use your data, for example while a correction is checked;
- object at any time to processing based on our legitimate interest;
- data portability: receive data you gave us in a structured, machine-readable format, or have it sent to someone else.
To exercise any of these rights, email hello@xocoweb.com. It is free of charge. We reply within one month, which may be extended by two further months for complex requests, in which case we will tell you why. We may ask you to confirm your identity first. Some rights have legal limits: for example, we cannot delete invoices we are required by law to keep.
If you believe we have not handled your data properly, you can complain to the Romanian supervisory authority, ANSPDCP, at dataprotection.ro (opens in a new tab), or to the supervisory authority in the EU or EEA country where you live. We would appreciate the chance to put it right first.
11. Children
Our services are for businesses and adults. We do not knowingly collect personal data from anyone under 16. If you believe a child has sent us personal data, email us and we will delete it.
12. Changes to This Policy
If our practices change, for example if we ever add analytics to this site, we will update this page and the date at the top before the change takes effect. Any optional tracking would only run after you agree to it.