Data protection
Privacy Policy
This Policy explains how Falcon Trading SRL processes personal data when business clients and their representatives use the quote portal.
Effective date: 1 September 2026
Operator details
- Legal name
- Falcon Trading SRL
- VAT ID
- RO8151955
- Registered office
- Sos Pacurari nr 138, Iasi, Romania
- Contact
- [email protected] +40728282907
- Trade Registry number
- J22/239/1996
1. Controller and contact
Falcon Trading SRL, established at Sos Pacurari nr 138, Iasi, Romania, VAT ID RO8151955, is the controller for the personal data described in this Policy unless a separate agreement states that we act as a processor.
For privacy questions or to exercise a right, email [email protected], telephone +40728282907, or write to our registered office. We may ask for proportionate information to verify your identity and authority before responding.
2. Who and what this Policy covers
This Policy covers client contacts, authorised representatives, prospective clients, suppliers and other people whose personal data appears in quotes, correspondence, comments, approvals, declines, documents, invoices or technical portal records.
It applies to the client portal and the related quote workflow. Separate notices may apply to employee data, unrelated websites or services where we process data solely on a client’s documented instructions.
3. Personal data we process
- Identity and professional data: name, role, organisation, authority to represent a client, approval name and author labels.
- Contact data: business email address, telephone number, postal address and communication preferences.
- Client and billing data: legal-entity name, address, country, city, county, VAT/fiscal identifiers, quote and invoice details.
- Commercial data: requested services, line descriptions, quantities, prices, currency, tax, quote status, decisions and associated dates.
- Communications: comments, decline reasons, instructions, emails and other content you or your organisation provides.
- Portal and security data: client token association, session identifiers, login/logout activity, timestamps, IP address, browser/device information, server logs and security events where logged by the production environment.
- Document data: generated quote PDFs and information about their creation and download availability.
4. Where the data comes from
- Directly from you when you access the portal, enter a name, approve or decline, comment, email or contact us.
- From your employer, organisation, colleague or another legal entity in the same client group when they provide contact, billing or quote information.
- From our staff and systems when preparing quotes, recording work status, generating documents, invoicing and maintaining the client relationship.
- Automatically from the portal, browser, server and security infrastructure when you make a request or establish a session.
- From service providers or public records where necessary to verify business or invoicing information.
5. Purposes and legal bases
Our legitimate interests are efficient B2B quote administration, service delivery, system security, auditability, client support and protection of legal rights. We consider the professional context, reasonable expectations and safeguards before relying on this basis.
- To prepare, present, discuss, approve, perform and administer quotes and contracts, based on steps requested before a contract and performance of a contract (GDPR Article 6(1)(b)).
- To manage business contacts who act for a client legal entity, operate the portal, maintain records, secure links, prevent misuse, support clients and establish or defend legal claims, based on our legitimate interests (Article 6(1)(f)).
- To issue and retain invoices and accounting, tax and compliance records, based on legal obligations (Article 6(1)(c)).
- To send service and quote communications requested in the business relationship, based on contract steps or legitimate interests, as applicable.
- To use non-essential technologies or communications where consent is legally required, based on consent (Article 6(1)(a)); consent may be withdrawn without affecting earlier lawful processing.
6. Portal sessions and cookies
The portal uses a strictly necessary session cookie to keep the selected client session active and security mechanisms to protect form submissions. Without these technologies, signed-link access, navigation, approval, decline, comments and logout cannot function correctly.
The reviewed portal source does not contain advertising or analytics cookies. Strictly necessary storage does not require consent under the applicable electronic-communications exception, but it remains covered by this notice.
The current portal loads the Alpine.js interface library from the unpkg.com content-delivery network. A browser request to that provider may disclose technical request data such as IP address, browser information and referrer. The production provider, processing location and transfer safeguards must be confirmed before publication.
7. Recipients and service providers
We require processors to act under appropriate contractual, confidentiality and security obligations. The final production list of providers and their roles must be confirmed before this Policy is published.
- Authorised Falcon Trading SRL staff and contractors who need the data for sales, delivery, administration, support, security, accounting or legal work.
- Hosting, database, backup, IT support, security and content-delivery providers used to operate the portal.
- Email and communications providers used to deliver quote and status messages.
- SmartBill and other invoicing/accounting providers when an authorised administrator creates or manages an invoice, together with accountants, auditors and professional advisers.
- Public authorities, courts, regulators, law-enforcement bodies or other parties where disclosure is required or legally justified.
- A purchaser, successor or adviser involved in a genuine corporate transaction, subject to appropriate confidentiality and legal safeguards.
8. International transfers
The project source does not establish every country in which production hosting, email, CDN, support and invoicing providers process data. This must be completed before publication.
Where personal data is transferred outside the European Economic Area to a country without an adequacy decision, we will use a lawful transfer mechanism, such as European Commission standard contractual clauses, and supplementary safeguards where required. You may contact us for information about the applicable safeguards.
9. Retention
The production retention schedule and backup periods are not represented in the project and must be confirmed before publication. We use the shortest period compatible with the stated purpose and applicable law.
- Quote, approval, decline, correspondence, contract and invoice records are kept for the business relationship and afterward for the periods needed to meet accounting, tax, contractual and legal-claims obligations.
- Portal sessions last until logout, invalidation or configured expiry. Portal access tokens remain associated with the client until rotated or the client record is deleted, subject to backup retention.
- Technical and security logs are kept for a limited period based on security, troubleshooting and legal needs.
- Data that is no longer required is deleted, anonymised or isolated from ordinary use, subject to backups and legal holds.
10. Security and your role
We use measures appropriate to the risk, including signed portal links, session controls, access checks, CSRF protection, private document storage and role-based administration. No internet service is completely secure, and we continuously assess reasonable safeguards.
- Keep portal links confidential and do not forward them outside the authorised client team.
- Log out on shared devices and protect the email account through which you received a link.
- Contact [email protected] promptly if a link is lost, misdirected or compromised, or if portal information appears incorrect.
11. Your data-protection rights
The portal does not make solely automated decisions with legal or similarly significant effects. Quote approval or decline is submitted by a person, and service decisions are handled by authorised people.
Rights may be limited where an exception applies, including another person’s rights, legal obligations or the establishment, exercise or defence of legal claims. We will explain a refusal where the law requires it.
- Access your personal data and obtain information about its processing.
- Correct inaccurate data and complete incomplete data.
- Request erasure or restriction where the legal conditions apply.
- Object to processing based on legitimate interests and object at any time to direct marketing.
- Receive data you provided in a structured, commonly used, machine-readable format and transmit it to another controller where portability applies.
- Withdraw consent at any time where processing relies on consent, without affecting earlier processing.
- Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, subject to GDPR exceptions.
12. Complaints
Please contact us first so we can investigate. You also have the right to lodge a complaint with the Romanian supervisory authority: Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336 Bucharest, Romania; [email protected]; www.dataprotection.ro. You may also contact the authority in your habitual residence, workplace or place of the alleged infringement where applicable.
13. Required data and third-party information
Some identity, authority, quote and contact information is necessary to identify the client, provide a quote, record a decision or meet legal obligations. If required data is not provided, we may be unable to provide portal access, process a decision, contract, invoice or respond to a request.
If you provide personal data about another person, you must be authorised to do so and should direct them to this Policy where appropriate. Avoid including personal or sensitive information that is not needed for the commercial purpose.
14. Children
The portal is designed for adult business representatives and is not directed to children. Do not provide a child’s personal data through the portal unless it is necessary, lawful and specifically agreed with us.
15. Policy changes
We may update this Policy when the portal, providers, processing or law changes. The effective date appears at the top. We will provide additional notice where a change materially affects people or where law requires it.
You may save or print this page using your browser for future reference.