Privacy Policy
Last updated: October 9, 2026
In short: we collect as little as we can, and only what the directory needs to work. We don't sell your data to anyone and we don't use it for behavioural advertising. You can browse listings without an account, and if you do create one, you can ask for a copy of your data — or its deletion — at any time. This summary doesn't replace the full policy below.
1Who we are
The controller of personal data for this platform is [Denumire completă societate] S.R.L., a company registered in Romania with its registered office at [Stradă, număr, oraș, județ], entered in the Trade Register under no. [J__/_____/____], tax identification number [RO________] (“we”, “us”, “the Operator”).
For anything to do with your personal data or this policy, write to us at [contact@domeniul-tau.ro]. We haven't appointed a Data Protection Officer, as our activity doesn't fall within the cases that require one under Article 37 GDPR — your request goes straight to the team that runs the platform.
2What we collect
There are three categories, depending on how you use the platform.
Things you give us directly:
- your email address and password (stored only as a hash) when you create an account;
- your display name and, optionally, a profile picture;
- the details of a business you submit or claim: name, address, coordinates, phone, email, website, opening hours, services, description, photos;
- the content of reviews, ratings and messages you send;
- whatever you write in an email or a contact form you send us.
Things collected automatically when you visit:
- your IP address, browser type and version, operating system, language and device type;
- the pages you view, when you viewed them, and the page you arrived from;
- approximate location (city), derived from your IP address by our hosting provider to centre the map; we do not store it on our servers or link it to an account;
- precise location, only if you press "Arată locația mea" ("Show my location") and allow access in your browser; it stays in your browser and we do not receive it;
- technical data the site needs to work: your session identifier, your language preference, and the listings you've saved as favourites.
Things from other sources: public information about businesses — name, address, opening hours, public ratings — taken from open sources or mapping platforms and used to fill out directory listings. If you own a business and want that information corrected or removed, write to us at [contact@domeniul-tau.ro].
We don't knowingly collect special categories of data (health, political or religious beliefs, ethnic origin, sex life). Please don't put anything of that kind in a review, a listing description or a message to us.
3Why we process your data, and on what legal basis
Every purpose has a specific legal basis under Article 6 GDPR:
- Running the service — showing the directory, the map, the filters and the listings, creating and managing your account, publishing reviews. Basis: performance of a contract (Art. 6(1)(b)) for account holders; legitimate interests ((f)) in providing a working directory to visitors without an account.
- Showing your area on the map — centring the map on your approximate city and, at your request, marking your exact position. Basis: for the approximate city, legitimate interest (point (f)) — it is not stored on our servers or linked to an account; for the exact position, your explicit request, made by pressing the button and through the browser permission, which you can revoke at any time in your browser's site settings.
- Moderation and abuse prevention — reviewing submitted listings, rate-limiting automated submissions, blocking spam and unlawful content. Basis: legitimate interests ((f)) in keeping the platform accurate and safe.
- Security and reliability — technical logs, error detection, backups. Basis: legitimate interests ((f)).
- Account communications — confirming your email address, resetting your password, telling you what happened to a listing you submitted. Basis: performance of a contract ((b)).
- Marketing communications, if we ever send any — only where you've opted in, and you can unsubscribe in one click. Basis: consent ((a)).
- Legal obligations — accounting and tax records, and responses to lawful requests from authorities. Basis: legal obligation ((c)).
Where we rely on consent, you can withdraw it at any time. That doesn't affect the lawfulness of anything we did before you withdrew it.
4Cookies and similar technologies
We use a small number of cookies and browser storage entries, all of them strictly necessary: keeping you signed in, remembering the language you chose, keeping the listings you've saved as favourites, remembering your choice from the cookie banner and, for the life of the tab only, your approximate city and (if you asked for it) your exact position. These don't require prior consent, because without them the service can't do what you've asked it to do.
We don't use advertising cookies and we don't build advertising profiles. If you choose Accept in the banner shown on your first visit, we use Google Analytics (via Google Tag Manager) to understand how the site is used; if you choose Reject, your browser never contacts Google at all. Full detail is in our Cookie Policy.
You can delete or block cookies in your browser settings at any time, or change your choice from the "Cookie settings" link in the footer — but blocking the strictly necessary ones may stop you signing in or using some features.
In addition, when you visit a listing page we automatically record — regardless of your choice in the cookie banner — the view and any clicks on its contact buttons (call, directions, website, social media, booking), so the listed business can see how much attention it gets. This measurement is first-party (never sent to a third party), uses no cookie and stores nothing in your browser: the identifier is a salted hash that changes every day and cannot be traced back to a person; we never store an IP address. Individual records are deleted after 90 days — we only keep aggregate daily totals. This measurement is entirely separate from Google Analytics, which still runs only if you choose Accept, as described above.
5Who we share it with
We don't sell, rent or trade personal data. We share it only with the providers that help us run the platform, as processors, contractually bound to handle it solely on our instructions:
- our database and authentication provider (Supabase) — hosts accounts, listings and published content;
- our hosting and delivery provider (Vercel) — serves the pages, keeps technical access logs and derives your approximate city from your IP address;
- OpenStreetMap Foundation — delivers map tiles to your browser (your IP address is visible to it); its Nominatim search service receives the name of your city, to frame the map, and your exact coordinates only if you press the locate button, to show your address;
- our transactional email providers — send confirmation, password-reset and notification messages.
- Google Analytics, via Google Tag Manager — only if you accept analytics in the cookie banner; processes aggregate visit statistics. See our Cookie Policy for detail.
We may also disclose data to public authorities where the law requires it, and to our professional advisers (legal, accounting) under a duty of confidentiality. If the business is reorganised or transferred, data may pass to the acquirer, with prior notice to the people concerned.
Remember that what you publish yourself — reviews, your display name, the details of a listing you've claimed — is public by nature and visible to any visitor, search engines included.
6Transfers outside the European Economic Area
We prefer providers that store data in the European Union. Some of them may nonetheless process data outside the EEA, particularly in the United States. Where that happens, the transfer relies on the safeguards in Chapter V GDPR — usually the Standard Contractual Clauses adopted by the European Commission, or an adequacy decision covering that provider. OpenStreetMap Foundation is based in the United Kingdom, for which the European Commission renewed its adequacy decision on 19 December 2025 (valid until 27 December 2031, with a review after four years). You can ask us for a copy of the safeguards that apply by writing to [contact@domeniul-tau.ro].
7How long we keep it
Only as long as the purpose requires:
- account data — for as long as the account exists, plus 30 days after you ask us to delete it, so the deletion can be reversed if it was a mistake;
- reviews and published content — for as long as they stay published; when you delete your account we may anonymise them instead, so they remain useful to other users;
- submitted and rejected listings — up to 12 months, to stop the same content being resubmitted over and over;
- technical and security logs — normally no more than 12 months;
- email correspondence — up to 3 years after the last message;
- records required by tax and accounting law — for the periods the law prescribes.
8Your rights
As a data subject, the GDPR gives you the following rights:
9How to exercise them
Send your request to [contact@domeniul-tau.ro] from the email address linked to your account. We'll reply within one month of receiving it; for complex requests that can be extended by two months, in which case we'll tell you why within the first month. Exercising your rights is free — though for manifestly unfounded or excessive requests we may charge a reasonable fee or refuse to act, giving our reasons.
If we can't confirm who's asking, we may request further information — only as much as we need to avoid handing your data to someone else.
If you believe we've infringed your rights, you can complain to the Romanian National Supervisory Authority for Personal Data Processing (dataprotection.ro, B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, Bucharest) or go to court. We'd appreciate hearing from you first, though — most things we can put right directly.
10Security
We apply technical and organisational measures appropriate to the risk: all traffic is encrypted (HTTPS), passwords are stored hashed and never in plain text, database access is restricted by row-level security policies, and administrative rights are limited to the people who need them. We take regular backups.
No system is completely secure, though. If a data breach occurs that is likely to result in a high risk to your rights, we'll tell you without undue delay and notify the supervisory authority within 72 hours, as Articles 33-34 GDPR require.
11Children
The platform isn't intended for anyone under 16 and we don't knowingly collect their data. If you become aware that a child under 16 has given us personal data without a parent's or guardian's consent, write to [contact@domeniul-tau.ro] and we'll delete it promptly.
12Automated decisions and profiling
We don't make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you. The way directory results are sorted and filtered follows technical criteria — relevance, distance, category, public ratings — and doesn't amount to profiling within the meaning of Article 22 GDPR.
13Third-party links and services
The platform links to the websites of listed businesses and integrates third-party services such as maps. This policy doesn't cover what those sites and services do with your data — please read their own privacy policies before giving them anything.
14Changes to this policy
We may update this policy as the platform develops or as legal requirements change. When the changes are significant we'll update the “last updated” date on this page and, where it's appropriate, let you know by email or with a notice on the platform. It's worth checking back from time to time.
15Contact
Questions about your data or about this policy? We're happy to help.