Privacy Policy
Politică de Confidențialitate și Prelucrare a Datelor cu Caracter Personal
Last Updated: September 13, 2026 · Effective Immediately
1. Identity of the Data Controller
This Privacy Policy applies to all personal data collected and processed through the website https://sales.cristianvaduva.com and associated private advisory operations. The Data Controller responsible for the processing of your personal data under Article 4(7) of the General Data Protection Regulation (EU) 2016/679 ("GDPR") and Romanian Law No. 190/2018 is:
Operator: Cristian Văduva
Professional Role: Luxury Real Estate Expert
Location / Jurisdiction: Bucharest, Romania
Privacy Inquiries Email: contact@cristianvaduva.com
Direct Email: cristianvaduva@duck.com
Primary Contact Phone: +40 767 110 439
Given the nature and scale of the private practice, a formal Data Protection Officer (DPO) is not mandated under Article 37 GDPR. All privacy matters and data subject requests are handled directly by the Controller.
2. Categories of Personal Data Collected
We collect and process only the minimum necessary personal data required to fulfill advisory requests, real estate mandates, insurance coverage structuring, and mortgage credit consulting:
- Identification & Contact Data: Full name, email address, telephone/WhatsApp number, legal entity representation details.
- Mandate & Search Specifications: Target property parameters, surface requirements, budget limits, location preferences, inquiry type (buyer representation, property sale, private consultation).
- Credit & Mortgage Parameters (Optional / Mandate-Specific): Target loan amount, financing status, debt-to-income (DTI) metrics, bank preferences (provided only when initiating a formal credit structuring engagement).
- Insurance Risk Engineering Data (Optional / Mandate-Specific): Insured asset specifications, building characteristics, existing policy expiration dates (provided only when requesting insurance policy reviews).
- Technical & Security Metadata: IP address (utilized strictly for rate limiting, DDoS mitigation, and spam bot prevention), browser user-agent header, request timestamps, and authentication session tokens (for authorized staff access).
3. Purposes and Legal Bases for Processing
In accordance with Article 6(1) of the GDPR, personal data is processed under the following lawful bases:
Purpose: Processing inbound inquiries from the contact form, property viewing requests, and buyer search matching.
Legal Basis: Article 6(1)(b) GDPR — processing is necessary for the performance of a contract or to take steps at the request of the data subject prior to entering into a contract.
Purpose: Coordinating property acquisitions, viewing schedules, formal offer negotiations, insurance underwriting, and mortgage file structuring.
Legal Basis: Article 6(1)(b) GDPR (Contractual execution) and Article 6(1)(f) GDPR (Legitimate interest in ensuring professional transaction integrity).
Purpose: Preventing automated bot spam (honeypot validation), IP-based rate limiting (10 requests/minute), and unauthorized server probing.
Legal Basis: Article 6(1)(f) GDPR — legitimate interest in safeguarding website availability and server infrastructure.
Purpose: Fulfilling statutory accounting, cadastral recording, anti-money laundering (AML/KYC) obligations, and responding to judicial authorities.
Legal Basis: Article 6(1)(c) GDPR — compliance with legal obligations under applicable Romanian and European laws.
Purpose: Transmitting off-market property releases, investment briefings, or newsletter bulletins.
Legal Basis: Article 6(1)(a) GDPR — explicit, freely given prior consent, which may be withdrawn at any time without affecting prior processing legality.
4. Data Recipients & Processors
We do not sell, rent, or trade personal data. Data is shared exclusively with authorized third-party service providers (processors) under strict Article 28 GDPR Data Processing Agreements, or institutional co-controllers strictly necessary for transaction completion:
- Hosting & Edge Infrastructure: Vercel Inc. (hosting and edge compute, operating under Standard Contractual Clauses and EU-US Data Privacy Framework).
- Database & Storage Vaults: Supabase Inc. (PostgreSQL database architecture with Row-Level Security, AES-256 encrypted at-rest storage in EU regions).
- Internal Operational Notifications (Telegram Alert Channel): When an inbound contact form or property inquiry is submitted, a minimized summary alert (limited strictly to submitter name, contact method, inquiry message excerpt, and timestamp) is forwarded via secure HTTPS API to the operator's private Telegram notification channel for real-time response coordination. No CRM records, private documents, or sensitive financial data are transmitted.
- Transaction Partners (Upon Explicit Mandate Only): Licensed Public Notaries (Notari Publici), Romanian banking institutions (for credit brokerage applications), and registered insurance underwriting partners (for policy issuance).
5. Retention Periods & Criteria
Personal data is retained only for the duration strictly necessary to fulfill the purposes for which it was collected:
- General Inquiries & Non-Contractual Leads: Retained for a maximum of 24 months from the last active communication, after which records are permanently deleted or anonymized.
- Contractual & Completed Transactions: Retained for 5 to 10 years in compliance with statutory Romanian fiscal, accounting, and cadastral statutory retention obligations.
- Security Logs & IP Rate Limits: Held in transient server memory / rolling cache for a maximum of 30 days.
- Marketing Consents: Retained until consent is revoked by the data subject.
6. Your Rights Under the GDPR
As a data subject under Chapter III of the GDPR, you are entitled to the following rights:
Request confirmation of processing and obtain a copy of your personal data.
Request correction of inaccurate or incomplete personal information.
Request deletion of data where legal retention grounds no longer apply ("Right to be Forgotten").
Request suspension of processing while data accuracy or objection claims are verified.
Receive your personal data in a structured, commonly used, machine-readable format.
Object to processing based on legitimate interests or direct marketing at any time.
For detailed instructions on exercising each right, review our dedicated GDPR Rights Guide.
7. Technical & Organizational Security Safeguards
Under Article 32 GDPR, we maintain robust security measures to protect personal data against accidental loss, destruction, alteration, or unauthorized disclosure:
- End-to-end transport encryption via TLS 1.3 / HTTPS with Strict Transport Security (HSTS).
- Granular Row-Level Security (RLS) policies isolating private client records from public queries.
- Strict private document vault access controls with time-limited signed download URLs.
- Continuous bot detection, honeypot filters, and automated rate limiting on public intake endpoints.
8. How to Submit Privacy Requests & Complaints
To exercise any of your data protection rights, transmit a written request to the Controller via email:
Privacy Request Desk:
Email: contact@cristianvaduva.com
Requests are processed free of charge within 30 calendar days as stipulated by Article 12(3) GDPR.
If you consider that the processing of your personal data infringes the GDPR, you have the right to lodge a complaint with the competent supervisory authority:
B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, cod poștal 010336, București, România
Email: anspdcp@dataprotection.ro | Website: www.dataprotection.ro