Privacy Policy
Last updated: 5 October 2026 · English translation; in case of any difference, the Romanian version prevails
This policy applies to the processing of personal data through the ekogroup-vila.ro website and at Vila Tătărescu, 19 Polonă Street, Bucharest, operated by EKO GROUP. Please read it carefully before using the website or sending us any personal data.
1. Who we are — the data controller
- Name: EKO TRADE BUSINESS S.R.L.
- VAT ID: RO44243761
- Trade Register no.: J2021008266405
- Registered office: 19 Polonă Street, Sector 1, Bucharest, postcode 010491, Romania
- Email: office@ekogroup.ro
- Email for personal data requests: corporate@ekogroup.ro
- Phone: +40 771 303 303
Under Regulation (EU) 2016/679 (GDPR), EKO GROUP acts as the data controller.
2. What data we collect and how
2.1 Data you give us directly
When you fill in the contact or quote request form, we collect your full name, email address, phone number (optional), company name and tax ID (optional), preferred date and estimated number of guests (optional), and your message (details of the event you are planning). If you book the guided tour on comenzi.artdecocafe.ro or buy tickets through our partner ticketing platforms, the booking data is processed on that platform.
2.2 Data collected automatically when you browse
The hosting server may automatically record your IP address, browser type and operating system, the pages you visit and the length of your visit, and the referring URL. The website is delivered through the Cloudflare network, which protects it from attacks and automated traffic: to do this, Cloudflare processes the IP address and technical data of each request and may set a security cookie (see the Cookie Policy). On pages with a form, the Cloudflare Turnstile anti-spam check analyses technical signals from your browser to tell people from bots. Our fonts are hosted on our own server. The preview images of the videos on the home page load from YouTube’s servers, without cookies; the video itself loads only when you click it, in youtube-nocookie.com mode.
2.3 Data collected with your consent
At present the website uses no analytics or marketing cookies. If we introduce them, we will turn them on only with your explicit consent, asked for through a banner, and we will update this policy.
3. Purposes of processing and legal basis
| Purpose | Data | Legal basis (Art. 6 GDPR) |
|---|---|---|
| Replying to enquiries and preparing quotes | Name, email, phone, message | (b) pre-contractual steps |
| Managing bookings | Name, email, event details | (b) performance of a contract |
| Accounting and tax obligations | Identification and financial data | (c) legal obligation |
| Website security and spam protection | Browsing data, IP address, technical browser signals (Cloudflare) | (f) legitimate interest |
| Audience statistics (not currently used) | Browsing data (aggregated) | (a) consent |
| Direct marketing / newsletter (not currently used) | Email, browsing data | (a) explicit consent |
4. How long we keep data
- Quote requests that do not lead to a contract: 12 months from the last interaction.
- Contract-related data: 5 years after the service (or 10 years for accounting documents).
- Browsing data / server logs: up to 12 months.
- Data processed on the basis of consent: until you withdraw consent, or for up to 24 months.
5. Who we share data with
We do not sell your data. Our contracted processors may access it, only to the extent needed for the service they provide:
- Hetzner Online GmbH (Germany): hosting of the website and of the database where enquiries are stored;
- Cloudflare: delivery and protection of the website, anti-spam check on forms;
- Google (Gmail, Google Workspace): confirmation emails sent to you and notifications to our team;
- the online tour booking platform (comenzi.artdecocafe.ro) and the card payment processor;
- partner ticketing platforms;
- our accountant and auditor.
Where the law requires it, data may be disclosed to public authorities (the tax authority ANAF, the police, the courts).
6. Transfers outside the EU
The website and the database are hosted in the European Union (Germany). Cloudflare and Google are US companies, and data may reach their servers outside the European Economic Area; such transfers rely on the safeguards provided by the GDPR (the EU–US adequacy decision, known as the Data Privacy Framework, and Standard Contractual Clauses).
7. Your rights under the GDPR
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21), the right to withdraw your consent and the right to lodge a complaint with the ANSPDCP.
How to exercise your rights: send a written request to corporate@ekogroup.ro or office@ekogroup.ro. We reply within 30 calendar days at most (extendable by 2 months in complex cases, after notifying you).
8. Supervisory authority — ANSPDCP
The National Supervisory Authority for Personal Data Processing (ANSPDCP), 28–30 G-ral Gheorghe Magheru Boulevard, Sector 1, Bucharest, anspdcp.ro.
9. Data security
We apply appropriate technical and organisational measures: encrypted HTTPS (TLS) connections, access restricted on a need-to-know basis and regular reviews of our security measures.
10. Minors
Our services are intended for people aged 16 or over. We do not knowingly collect data from children under that age.
11. Changes to this policy
We may update this policy. The date of the latest update is shown at the top of the page.
12. Contact
Email: corporate@ekogroup.ro · Phone: +40 771 303 303 · Address: 19 Polonă Street, Sector 1, Bucharest.