Data controller
- Privacy contact
- contact@evia.ro
- Website
- evia.ro
01
Who this policy applies to
This policy applies to people who use the public evia.ro website, request information or an offer, arrange a viewing, or choose to contact EVIA by phone, email or WhatsApp. If the interaction progresses to reserving or purchasing a property, separate notices may be provided for the processing required at that stage.
02
Data we collect
- Offer form: name, phone number, email address, type of property of interest and an optional message.
- Viewing form: name, phone number, email address, selected apartment, requested date and time, and optional notes.
- Form security: IP address, a cryptographic fingerprint derived from it, the Turnstile token and technical signals needed to distinguish genuine users from automated traffic.
- Request source: campaign source or referring page when the browser provides this information.
- Only with consent: pages visited, interactions with apartments and filters, document access, clicks on contact details, device identifiers and campaign parameters. Limited session replay may operate on selected pages; forms are blocked and input fields are masked.
03
Why we use the data
| Purpose | Data used | Legal basis |
|---|---|---|
| Replying to enquiries and preparing an offer | Contact and request details | Pre-contractual steps requested by the individual; legitimate interests for general enquiries |
| Registering and confirming a viewing | Contact details, apartment and requested slot | Pre-contractual steps requested by the individual |
| Protecting forms and limiting abuse | IP, IP fingerprint, token and technical signals | Legitimate interests in website and service security |
| Measuring use and improving the website | Navigation events and online identifiers | Consent |
| Measuring advertising campaigns | Conversions, interactions and campaign parameters | Consent |
| Legal compliance and the defence of rights | Data relevant to the request and related communications | Legal obligation or legitimate interests, as applicable |
04
Required data and its source
Data is obtained directly from you, except for technical data and visit-source information generated automatically when you use the website. Fields marked as required are needed to identify and answer the request; without them the form cannot be submitted. Messages and notes are optional. Please do not include sensitive data or information unrelated to your request.
05
Who may receive the data
Data is accessible only to authorised personnel handling EVIA enquiries and to service providers supporting the website and its functionality. Depending on your actions and the consent you provide, recipients may include:
- Hosting, technical infrastructure and database service providers, for storing and managing enquiries and viewing requests submitted through public forms.
- Cloudflare Turnstile, for form security verification; the contents of completed fields are not transmitted to this service.
- Google Analytics, Google Tag Manager, Meta Pixel and Amplitude, only for the categories accepted in the cookie settings. Contact details entered in forms are not transmitted to these tools; after a form is submitted, a pseudonymous identifier may be used to measure conversions.
- Email and technical maintenance providers, professional advisers or public authorities, where access is necessary to provide the relevant service or is required by law.
06
Transfers outside the EEA
Some technology providers may process data outside the European Economic Area. Where such a transfer occurs, it must rely on a GDPR-recognised mechanism, such as an adequacy decision or standard contractual clauses, together with supplementary measures where required. Information about the applicable safeguards may be requested through the privacy contact shown above.
07
How long we keep data
The specific period is determined by the request status, the last relevant interaction, whether a contractual relationship exists and the applicable legal duties. Data is not kept longer than necessary for the purpose for which it was collected.
- Offer and viewing requests are kept for the time needed to handle them, provide requested follow-up and continue any pre-contractual steps. If a contractual relationship begins, the retention periods notified for that relationship apply.
- IP fingerprints used to limit abuse are automatically removed after no more than 48 hours.
- Analytics and advertising data is retained according to the accepted tools and durations described in the Cookie Policy; withdrawing consent stops future collection.
- Data required by law or necessary to establish, exercise or defend a claim may be kept for the relevant statutory period.
08
Your rights
Subject to the GDPR conditions, you may request access, rectification, erasure, restriction and portability, and object to processing based on legitimate interests. You may withdraw consent for analytics and marketing at any time without affecting processing carried out before withdrawal.
- Send your request to the privacy contact displayed at the top of this page.
- We may request reasonable information to verify your identity and protect the data.
- You may lodge a complaint with the Romanian supervisory authority, ANSPDCP, and apply to the competent courts.
09
Security and automated decisions
We apply technical and organisational measures proportionate to the risks, including access controls, request validation, anti-bot protection and limits on repeated submissions. No internet transmission can be guaranteed completely risk-free.
Data submitted through public forms is not used for solely automated decisions that produce legal or similarly significant effects.
10
Policy updates
This policy may be updated when website functions, providers or legal requirements change. The version in force is the one published on this page together with its last-updated date.