Skip to content Skip to footer

According to the requirements of Law no. 129 of June 15, 2018 for amending and supplementing Law no. 102/2005 on the establishment, organization and functioning of the National Supervisory Authority for Personal Data Processing, and for repealing Law no. 677/2001 for the protection of individuals with regard to the processing of personal data and the free movement of such data, SC Romleas SRL has the obligation to manage in secure conditions and only for the specified purposes, the personal data you provide us.

The purpose of data collection is: to provide services and products according to the current offer and according to customer orders.

They are necessary to be able to identify the recipient of the services or products provided, or to register domains in your name (as a customer).

Your refusal determines the impossibility of providing the service or product, or the registration of the domains ordered. The registered information is intended for use by the operator and, where applicable, is communicated only to the following recipients: national/European/worldwide web domain registration/administration authorities or their partners (ROTLD, EURid, Directi).

Any person has the right to object, free of charge and without any justification, to the processing of his/her personal data for direct marketing purposes.

In accordance with Law no. 677/2001, you have the right of access, the right to intervene on data, the right not to be subject to an individual decision and the right to go to court. You also have the right to object to the processing of personal data concerning you and to request the deletion of data. To exercise these rights, you can send a request to info@intellogic.ai.

You also have the right to go to court.

GDPR Regulations

On May 25, 2018 the European Regulation 2016/679 on the protection of individuals with regard to the processing of personal data and on the free movement of such data became applicable.

Its main purpose is to increase the level of protection of personal data and to create a climate of trust that allows each individual to control their own data.

With this document - Personal Data Protection Policy we inform you how we protect your personal data and how we comply with the provisions of the Regulation.

Who is Romleas SRL?

Romleas SRL is a legal entity under Romanian law, incorporated and operating under Romanian laws. Romleas SRL has its registered office in B-dul Stefan cel Mare 126 B, Oradea, Bihor, Romania, is registered at the National Office of the Trade Register with the number J05/766/1994, with unique registration number 5277445 and fiscal attribute RO.

How can you contact us?
For any complaints regarding the personal data processed by Romleas SRL you can contact us in writing, at the address of the registered office, by phone at +4 0756 439 365, by email at info@intellogic.ai or through the ticketing system accessible from the customer account.

What are personal data and what personal data does Romleas SRL process?

Personal data is information relating to a natural person who can be identified, directly or indirectly.

Romleas SRL processes the following categories of data:
- Identification data: name, surname, CNP, correspondence address, e-mail, telephone (fixed, mobile, fax), online identifier (IP address);
- Bank information: bank and branch, IBAN code.

The principle under which we collect and process this data is that we will only request on each occasion the minimum amount of personal data necessary to fulfill the contract and fulfill legal obligations.

What does it mean that Romleas SRL processes personal data?
Processing means operations such as: collecting, recording, organizing, storing, storing, modifying, retrieving, consulting, using, transmitting, combining, blocking, restricting, erasing, destroying, archiving personal data.

Who owns the personal data processed by Romleas SRL?
Romleas SRL processes personal data about customers.

In the case of legal entity clients, Romleas SRL processes the personal data of the client's contact persons.

Natural persons whose personal data are processed are referred to as „Data Subjects”.

Where does Romleas SRL obtain personal data?
In the case of individual customers, the data is obtained directly from the customer.

In the case of legal entity clients, the data are obtained from the client's representatives.

Romleas SRL does not obtain / collect personal data from third parties.

For what purposes does Romleas SRL process personal data?
The purposes for which Romleas SRL processes personal data are:

- provision of hosting and related services
- internet domain registration and management
- SSL certificate registration
- contacting the customer/other data subject via the communication media in order to resolve technical support requests
- invoicing of services rendered
- customer account management

On what grounds does Romleas SRL process personal data?
Romleas SRL processes your personal data for the purposes mentioned above, based on the following grounds:
- for the performance of the contract to which the client / the data subject is a party. The contract can be in both written and online form, signed by the client by accepting the Terms and Conditions of service provision.
- consent
- legitimate interest

To whom do we transmit your personal data?
For most of the services provided by Romleas SRL, personal data are not transmitted to third parties.

In case of domain registration and maintenance services, we will transmit personal data to authorized domain registrars.

For payment services we will transmit the necessary personal data to authorized payment processors.

Reseller services:
We ensure the protection of personal data submitted by our resellers in order to provide domain registration services, web hosting, SSL certificates, payment intermediaries, etc.. as set out in this document.

In the case of SSL certificate issuance services, we will transmit personal data to providers authorized to issue these types of services.

How long does Romleas SRL process personal data?
In order to fulfill the above-mentioned purposes, personal data will be processed by Romleas SRL throughout the contractual relationship and after its finalization in order to comply with the applicable legal obligations in the field, including, but not limited to, the provisions on archiving.

What are your rights and how can they be exercised?
The data subject has the following rights:

- The right to information - the right to receive detailed information on the processing activities carried out by Romleas SRL, as provided in this document;
- Right of access - you can request and obtain confirmation as to whether or not your personal data are processed by Romleas SRL, and if so, you can request access to them, as well as certain information. Upon request, Romleas SRL will provide a copy of the processed personal data free of charge;
- Right to rectification - the right to have inaccurate personal data rectified and incomplete personal data completed;
- The right to erasure of data (”right to be forgotten”) - in situations expressly regulated by law (in particular in the case of withdrawal of consent or if it is found that the processing of personal data was not lawful), you may obtain the erasure of such data. Following such a request, Romleas SRL will proceed with the deletion of the data, except in the cases provided by law.
- The right to restriction of processing - in the situations expressly regulated by law (in particular if the inaccuracy of the data is contested on the preluioada necessary to determine this inaccuracy or if the processing is unlawful, and you do not want the data deleted, but only restriction);
- The right to object - may object at any time, for reasons related to the particular situation in which they are, to processing based on the legitimate interest of Romleas SRL
- The right to data portability - can receive personal data in a structured, machine-readable format, or request that the data be transferred to another controller.
- The right to lodge a complaint - you can lodge a complaint about the way your personal data is processed by Romleas SRL to the National Supervisory Authority for Personal Data Processing;
- Right to withdraw consent - in cases where processing is based on consent, consent can be withdrawn at any time.
- Additional rights related to automated decisions used in the process of providing services Romleas SRL
- If Romleas SRL takes automated decisions in relation to personal data, the data subject may: (a) request and obtain human intervention with regard to such processing; (b) express his/her point of view with regard to such processing; (c) contest the decision.

The customer may exercise these rights, either individually or cumulatively by sending a written request, dated and signed, to Romleas SRL, B-dul Stefan cel Mare 126 B, Oradea, Bihor, Romania or by E-mail: info@intellogic.ai.

Automated decision-making processes
Romleas SRL does NOT use automated decision making processes, does NOT create profiles exclusively by automated means, resulting in customer decisions.

How do we apply GDPR to minors?
Romleas SRL does not offer services to minors under 16 years of age and does not collect personal data about minors.

Recording phone calls
With the consent of the Client / data subject expressed before each telephone call, Romleas SRL may record and store telephone calls to / from the Romleas SRL call center. Romleas SRL is to use this information exclusively for the purpose of investigating certain situations, to prove certain operations / instructions / agreements given by the Client / other data subject, to use it as evidence in court in case of litigation, and to improve its services.

Video monitoring
In order to ensure a high level of security appropriate for the data center activity, the server room operated by Romleas SRL is video monitored. In this location there are appropriate markings with specific symbols of video recording, followed by the message ”Area under video surveillance”.

How do we protect personal data?
For the safety of personal data, Romleas SRL has implemented a series of security measures that are in accordance with industry standards.

Information security and privacy statement of Romleas SRL

1. General note
Romleas SRL is committed to protecting the security and confidentiality of all customer and employee data.

Our information security and protection program is based on the ISO 27001 standard on information security and ISO 29100 and follows a risk-based approach that encompasses people, processes and technologies. The Information Security (IS) team within Romleas SRL is dedicated to data protection and reports directly to the company's management.

2. Information security measures for the protection of personal data
Information security policies - set of rules for information security, approved by the company's management, published and communicated to employees and relevant external parties.

Review of information security rules - to ensure effectiveness and continued appropriateness, we review our information security rules at planned intervals or when significant changes occur.

Information security roles and responsibilities - we establish and assign specific information security responsibilities to all employees and external collaborators.

Segregation of duties - we separate areas of responsibility to reduce the chances of unauthorized or unintended disclosure, alteration, or unauthorized or unintended use of organizational assets.

Information security in project management - we address information security in project management, regardless of the type of project.

Mobile Device Rules - we use rules and security measures to address the risks associated with the use of mobile devices. We use security rules and measures to protect information accessed, processed or stored on mobile devices.

Managing security during employment - we carry out checks for all applicants for available employment in accordance with relevant laws, regulations and ethics commensurate with business requirements, classification of information to be accessed and perceived risks. The contractual agreement between us and our employees specifies the responsibilities of both parties regarding information security. Information security, responsibilities and duties that remain valid after termination of employment or change of job within the organization are defined, communicated to the employee or external contractor and are enforceable.

Management Responsibilities - Company management requires that all employees and contractors comply with information security in accordance with the rules and procedures established by the organization.

Information security awareness, education and training - all employees of the organization are continuously made aware of the organizational rules and procedures relevant to their function.

Management and disposal of removable media - we use procedures that implement the management of removable media devices. When no longer needed, removable media devices are destroyed, ensuring that data can no longer be read.

Transfer of physical materials - materials containing information are protected against unauthorized access, misuse or unauthorized use and corruption in transit.

Access control and management - we use an access control policy that is reviewed based on business and information security requirements. Users are only given access to the networks/network services they have been authorized to use.

Management and use of user authentication passwords - we use a process to control the allocation of authentication information. Users follow best practices in the use of secret authentication information. We use the password management system to ensure quality passwords.

Restricting access to information - access to information and application functions is restricted according to access control rules.

Secure login - access to systems and applications is controlled through a secure authentication process.

Physical location and protection of equipment - IT&C equipment is located and protected to reduce the risks posed by environmental threats and hazards and the possibility of unauthorized access.

Utilities and cable security - equipment is protected from power failures and other interruptions caused by failures in utility support. Power and telecommunication cables carrying data are protected from interception, interference or damage.

Equipment maintenance - equipment is continuously and properly maintained to ensure its availability and integrity.

Verification and secure reuse of equipment - provide multiple data overwrites and low level formatting of storage media to ensure that sensitive information and licensed software is securely removed or overwritten before disposal or reuse of equipment.

Clear desk / clear screen - we have adopted clear desk rules for documents and removable storage media and a clear screen rule for information processing facilities.

Document operating procedures - we have defined operating procedures and made them available to all users who need them.

Separation of development, testing and operational environments - we use separate environments for development, testing and operations to reduce the risk of unauthorized access or changes to the operational environment.

Malware controls - we implement detection, prevention and recovery controls to ensure protection against malware and combine these controls with appropriate user awareness.

Backups - we regularly perform backups of information and systems. The number of backups is correlated to the potential risks of the information and systems backed up.

Event logging and log file protection - we produce, maintain and regularly review event logs that record user activities, exceptions, faults and information security events. Log files are protected.

Installation of software on operating systems - we have established rules governing the installation of software on operating systems, in particular installation by users.

Vulnerability management - Technical vulnerabilities are managed by mitigating them in a timely manner, assessing the organization's exposure and taking appropriate measures that address the associated risk.

Restrictions on changes to software packages - we use rules on software modification, limiting this action to necessary changes.

Addressing security within supplier agreements - we review, document and agree with our suppliers information security requirements to mitigate the risks associated with supplier access to the organization's assets.

Reporting of information security events and incidents - when information security events are recognized, they are reported through appropriate management channels in a timely manner. Employees and contractors note and report any observed or suspected weaknesses in systems or services.

We evaluate and categorize the information security events we encounter accordingly. Respond in a timely manner and in accordance with our internal procedures to information security incidents. We use the knowledge we gain when analyzing and resolving information security incidents to reduce the likelihood or impact of future incidents. We have a process for identifying, collecting, acquiring and retaining information that can serve as evidence.

Intellectual property rights - we implement appropriate procedures to ensure compliance with legislative, regulatory and contractual requirements related to intellectual property rights and the use of proprietary software products.

Technical compliance review - IT systems are regularly reviewed to meet the organization's security rules and standards.

3. Privacy safeguards for the protection of personal data
Purpose identification and documentation - we identify and document the specific purposes for which personal data are processed.

Identifying the legal basis - we determine, document and comply with the legal basis for processing personal data for the identified purposes.

Determining when and how to obtain consent - we determine and document a process for demonstrating when and how to obtain consent from data subjects.

Obtaining and recording consent - we obtain and record the consent of data subjects in accordance with documented requirements.

Records related to the processing of personal data - we determine and maintain the necessary records to demonstrate compliance with our obligations regarding the processing of personal data.

The rights of personal data owners - we ensure that the rights of data subjects in relation to the processing of personal data are respected and provide the necessary means to exercise their rights.

Providing information to individuals - we provide data subjects with clear and easily accessible information about the personal data we process.

Provide a mechanism to change or withdraw consent - we provide mechanisms for data subjects to change or withdraw their consent.

Providing the mechanism to object to processing - we provide the mechanism for data subjects to object to the processing of their personal data.

Awareness of the rights exercised by the owners of personal data - we take steps to inform third parties to whom we have disclosed personal data about any changes, withdrawals or objections resulting from the exercise of data subjects' rights.

Correction or erasure - we implement a mechanism to facilitate the exercise of data subjects' rights to access, correct and delete personal data.

Providing a copy of the personal data processed - we are able to provide a copy of the personal data being processed, in accordance with the retention and erasure rules, upon request of the data subject.

Claims management - we have the means to deal with the legitimate claims of data subjects.

Automated decision making - we identify and resolve any obligations, including legal obligations, to data subjects resulting from decisions based solely on automated processing of personal data.

Limiting collection and processing - we limit the collection of personal data to the minimum that is relevant, proportionate and necessary for the identified purposes. We limit the processing of personal data to what is appropriate, relevant and necessary for the identified purposes.

Compliance with the objectives of minimization and anonymization of personal data - we identify and document the mechanism by which personal data is processed in a timely manner, so that the extent to which personal data can identify or be associated with data subjects meets the objectives of minimization and anonymization of personal data.

Deactivation and erasure of personal data - we either erase personal data or transform it into a form that does not allow the identification of data subjects, once the original personal data is no longer necessary for the identified purpose.

Temporary files - we ensure that temporary files and documents created as a result of processing personal data are deleted.

Retention - we do not keep personal data longer than is necessary for the purpose for which it is processed.

Collection procedures - we ensure that personal data is accurate, complete and up-to-date as necessary for the purposes for which it is to be processed, throughout the lifecycle of personal data.

Identifying the basis for the transfer of personal data - we identify and document the relevant basis for the transfer of personal data.

Countries and organizations to which personal data may be transferred - we specify and document the countries and international organizations to which personal data may be transferred.

Personal data transfer records - we record transfers of personal data to or from third parties and ensure cooperation with those parties to support the exercise of future access rights of data subjects.

Records of disclosures of personal data to third parties - we record disclosures of personal data to third parties, including what personal data has been disclosed, to whom and when.

Electronic communications
Romleas will process personal data for the purpose of informing its customers and partners about changes or notifications necessary for the performance of contracted services.

These emails will not fall under the concept of Email Marketing because they are absolutely necessary for the contract to run smoothly.

The customer can ask Romleas to stop receiving the respective emails, assuming the consequences arising therefrom.

Email Marketing
Romleas offers its customers the possibility to choose both at account registration and later, in the customer account, if they agree to receive informative emails about Romleas products and services.

We will not use and we will not provide personal data of our customers to another provider or other entity except with the consent of each individual customer and for specific purposes or to bodies authorized to request such data under the law.

We will not use your personal data to send advertising emails for another company. We will limit ourselves strictly to products and services from Romleas portfolio.

Romleas will not provide personal data to any entity outside the EU unless that entity is a Romleas partner, supplier or subcontractor. Romleas will ensure that the partner complies with at least one of the GDPR rules in this regard.

Romleas undertakes to apply the same measures of protection and safe use to the personal data provided by the reseller as it does for the personal data of its direct customers. All personal data received by Romleas will be processed according to the provisions of this document.

Instructions for DATA PROCESSING

Romleas is obliged to the following:
- will process personal data in accordance with this document
- process your personal data in good faith, in accordance with the rules in force and in a transparent manner
- will collect personal data for accurate, legitimate and lawful purposes
- will collect personal data in a non-excessive way, strictly necessary for the provision of services
- collect personal data as accurately as possible and in an up-to-date form
- receive and transmit personal data in an exclusively secure way
- will take the necessary steps to verify and complete inaccurate or incorrect data
- take measures against accidental or unlawful use, processing, loss or disclosure of personal data
- will take measures to ensure the protection of personal data by employees by introducing access control by cards, encrypted keys, authentication passwords, etc.

Technical and Organizational Measures:
- definition of security zones
- restricting access roads
- establishing access procedures for employees and third parties
- access control systems (magnetic cards, encrypted keys, etc)
- locking doors, electric openers, etc
- video surveillance of access areas
- securing personal access devices used by employees
Virtual Access:
- user identification, authorization and authentication procedures
- password security (minimum length, special characters, two-step authentication, etc)
- automatic access restriction for incorrect login data
Access to Personal Data

Romleas undertakes to adopt the following measures to control and ensure that personal data are used by authorized persons:
- internal access and processing procedures
- differentiated access by departments, persons, levels etc
- supervision and access control
- issuing access reports

Transmission of Personal Data
Romleas will ensure that personal data transmitted to authorized partners will be in a secure manner so as to prevent unauthorized, accidental or unlawful disclosure.

Secure Storage of Personal Data
Romleas undertakes to take the following measures for the secure storage of personal data:

- providing a backup procedure for data
- ensuring mirroring of hard disks by RAID writing system
- ensuring continuous power supply through redundant and backup power sources (electric generator)
- archiving and remote storage
- firewall and antivirus protection
- reconstruction plans and business continuity plans in cases of force majeure and disaster

Separation of processing types
Romleas ensures through its systems architecture a clear separation of personal data managed according to specific purposes of use. The production and testing environments, differentiated access of personnel and internal regulations are some of the organizational measures implemented by Romleas to separate the personal data processing process.

Staff Training:
Romleas provides regular and compliant training to staff who have access to personal data or who ensure the protection and supervision of access.

Romleas ensures the training of staff on the purposes of data processing, the separation of data processing each according to the strict purpose for which they were requested.

Romleas ensures through regular checks and by means of documents, clauses and confidentiality agreements, that the personnel employed is aware of and complies with the personal data protection rules as they have been defined and presented in this document.

Server Security
Romleas uses three levels of access control on its own servers on which it provides services and stores personal data.
- Linux encrypted key access
- Secret linux port access
- Access from strictly defined static ip
The administration level access on linux servers exclusively is done by authorized and trained personnel in accordance with the requirements of Linux administration.

Servers are protected by antivirus and firewall configured in a responsible way.

Personal Data Storage Location
Personal customer data is stored securely on our servers in Europe. Certain specific personal data, such as email, telephone, first and last name, will also be stored with international partners when using international domain services (.eu, .com, .net, etc). Personal data specific to .ro domains will also be stored by the official partner ICI Rotld. Access data such as e-mail will also be stored on servers in Europe.

Responsibility of CLIENTS
Romleas informs customers that they are fully responsible for the management of personal data collected by them through their websites.

According to the relevant technical specifications and according to the software used by Romleas, access between accounts is not possible on Linux systems on which our services run.

The software and scripts used by clients to build and run their own websites are the sole responsibility of the client.

Account security, account protection, retention and backup of access data are also the responsibility of the customer. The customer is responsible for maintaining and updating the scripts used, configuring ftp services, ssh, email etc is a complex action that also involves the responsibilities of the customer who owns the account.

Software used by Romleas:
- cPanel
- Cloudlinux
- Litespeed
- CSF
- Mod_Security
- WHMCS
Facilities available to customers to protect data:

- Authentication with complex passwords
- 2-step authentication (Google Auth)
- Authentication notifications
- Technical assistance for additional protection

If you choose to use our Service, you consent to the collection and use of information in connection with this policy. The personal information we collect is used to provide and improve the Service. We will not use or share your information with anyone except as described in this Privacy Policy.

Terms used in this Privacy Policy have the same meanings as in our Terms and Conditions, which are accessible at https://intellogic.ai/termeni-si-conditii unless otherwise defined in this Privacy Policy.

Collection and use of information
For a better experience while using our Service, we may ask you to provide us with certain personally identifiable information, including but not limited to Location, IP Address, Language, Android Advertising ID. The information we request will be retained by us and will be used as described in this Privacy Policy.

The application uses third party services that may collect information used to identify you.

Link to the privacy policy of third party service providers used by the application

Google Play Services
Firebase Analytics
AppStore Services
Logbook data
We would like to inform you that whenever you use our Service, in the event of a bug in the application, we collect data and information (through third party products) on your phone, referred to as Log Data. This Log Data may include information such as your device's IP address, device name, operating system version, application configuration when using our Service, the time and date of use of the Service and other statistics .

Cookies
Cookies are small data files commonly used as anonymous unique identifiers. They are sent to your browser from the websites you visit and are stored in your device's internal memory.

This service does not explicitly use these cookies. However, the application may use third party code and libraries that use „cookies” to collect information and improve the service. You have the option to accept or decline these cookies and to find out when a cookie file is sent to your device. If you choose to decline our cookies, you may not be able to use certain portions of this service.

Security
We appreciate your trust in providing us with your personal information, so we strive to use commercially acceptable means to protect the application. But please note that no method of transmission over the Internet or method of electronic storage is 100% secure, and we cannot guarantee its absolute security.

Links to other websites
This service may contain links to other websites. If you click on a third party link, you will be directed to that site. Please note that these external sites are not operated by us. We therefore strongly advise you to review the privacy policy of these websites. We have no control over and assume no responsibility or liability for the content, privacy policies or practices of third party sites or services.

Confidentiality of children
These services are not intended for anyone under the age of 13. We do not knowingly collect personally identifiable information from children under the age of 13. If we discover that a child under the age of 13 has provided us with personally identifiable information, we immediately remove that information from our servers. If you are a parent or guardian and you are aware that your child has provided us with personal information, please contact us so that we may take appropriate action.

Changes to this privacy policy
We may update this Privacy Policy from time to time. You are therefore advised to review this page periodically for any changes. We will notify you of any changes by posting the new Privacy Policy on this page. These changes are effective immediately after they are posted on this page.

Contact us
If you have any questions or suggestions about our Privacy Policy, please do not hesitate to contact us.