Privacy policy
October 2026
The protection of personal data is an essential aspect of the activity of SCP Peticaru, David și Asociații. Respecting the confidentiality of the information entrusted to us by clients and by the persons who contact us is both a legal obligation and a professional obligation specific to the legal profession.
This Privacy policy explains how SCP Peticaru, David și Asociații processes the personal data collected through the website www.peticarudavid.ro, as well as the data transmitted through the contact form, e-mail, telephone or through any other means of communication used in the professional relationship.
Personal data is processed in accordance with Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data ("GDPR"), Law no. 190/2018, Law no. 51/1995 on the organisation and exercise of the profession of attorney, the Statute of the profession of attorney and the other applicable legal provisions.
1. The controller of personal data
The controller of personal data is SCP Peticaru, David și Asociații, a form of practice of the profession of attorney organised under Law no. 51/1995 on the organisation and exercise of the profession of attorney, with Tax identification number (CUI) 32648044 and registered office in Bucharest, Bd. Dacia no. 11, Building A, ground floor, ap. 3, Sector 1.
In this Policy, SCP Peticaru, David și Asociații will hereinafter be referred to as the "Firm" or the "Controller".
For any questions regarding the processing of personal data or to exercise the rights provided by the GDPR, you may contact us using the contact details provided at the end of this Policy.
2. Scope
This Privacy policy applies to persons who use the website www.peticarudavid.ro, submit requests through the contact form, e-mail or telephone, request information regarding the legal services offered by the Firm, or communicate personal data with a view to initiating or carrying out a professional relationship.
This policy applies exclusively to the website www.peticarudavid.ro and does not apply to third-party websites to which this website may contain links.
3. Principles of data processing
The Firm processes personal data in compliance with the principles laid down by the GDPR, namely:
- lawfulness, fairness and transparency;
- purpose limitation;
- data minimisation;
- accuracy of data;
- storage limitation;
- integrity and confidentiality;
- accountability.
Only data that is adequate, relevant and necessary for the purposes described in this Policy is processed, with appropriate technical and organisational measures implemented for its protection.
The processing of data in the context of providing legal services is also carried out in compliance with the obligations regarding professional secrecy and confidentiality specific to the profession of attorney.
4. The categories of personal data processed
Depending on how you interact with the Firm, the following categories of data may be processed:
- first and last name;
- e-mail address;
- telephone number;
- address and other contact details;
- identification data communicated for the purpose of providing legal services;
- the content of messages and correspondence;
- documents and information provided in connection with your request or case;
- data regarding your legal, professional, financial or family situation, where relevant to the legal services requested;
- IP address and other technical data generated through the use of the website, under the conditions described in this Policy and in the Cookies policy;
- any other data you decide to communicate to us.
If you give your consent through the cookie management mechanism available on the website, certain technical information regarding the use of the website may also be collected, including information about the browser, the device, the pages visited, the duration of the visit and other statistical information generated through the analytics tools used by the website.
To the extent necessary for the provision of the requested legal services, special categories of personal data within the meaning of art. 9 GDPR may also be processed, as well as data relating to criminal convictions and offences, under the conditions of art. 10 GDPR and the applicable legislation.
5. The purposes, categories of data and legal bases of processing
| Processing activity | Purpose of processing | Categories of data | Legal basis |
|---|---|---|---|
| Handling requests submitted through the contact form, e-mail or telephone | Analysing the request, providing a response and, where applicable, assessing the possibility of initiating a professional relationship | First and last name, e-mail address, telephone number, the content of the message and other information provided | Art. 6 (1) (b) GDPR – taking steps at the request of the data subject prior to entering into a contract; where applicable, art. 6 (1) (f) GDPR – the legitimate interest of the Firm in handling the requests received |
| Providing legal services | Analysing the legal situation, concluding and performing the legal assistance contract, providing legal consultations, drafting documents, assisting and representing the client | Identification and contact data, documents and information necessary to resolve the case, as well as any other relevant data communicated or lawfully obtained | Art. 6 (1) (b), (c) and, where applicable, (f) GDPR; for special categories of data, where applicable, art. 9 (2) (f) GDPR; for data relating to criminal convictions and offences, art. 10 GDPR and the applicable legislation |
| Fulfilling legal and professional obligations | Complying with the obligations provided by Law no. 51/1995, the Statute of the profession of attorney, tax and accounting legislation, anti-money laundering legislation, where applicable, and other relevant regulations | Data necessary to fulfil legal and professional obligations | Art. 6 (1) (c) GDPR |
| Administration and security of the website | Ensuring the functioning, administration and security of the website, preventing incidents and protecting the IT infrastructure | IP address and other technical data regarding access to the website, browser and device information | Art. 6 (1) (f) GDPR – the legitimate interest of the Firm in ensuring the functioning and security of the website |
| Analysis of website traffic | Obtaining statistical information regarding the use of the website, measuring performance and improving the user experience | Data collected through the analytics tools used by the website and online identifiers | Art. 6 (1) (a) GDPR – the consent of the data subject |
Where processing is based on consent, consent may be withdrawn at any time, without the withdrawal affecting the lawfulness of the processing carried out previously.
The contact form is protected by an anti-spam verification provided by Cloudflare (Turnstile), which processes technical data, including the IP address, on the basis of the Firm's legitimate interest in preventing abusive use of the form [Art. 6 (1) (f) GDPR].
The contact page embeds a Google Maps map that loads automatically when the page is opened, at which point the browser transmits the IP address to Google; the legal basis for this processing is the Firm's legitimate interest in offering the map functionality [Art. 6 (1) (f) GDPR].
The Firm does not carry out automated individual decision-making or profiling within the meaning of art. 22 GDPR.
6. The source of data
Personal data is collected:
- directly from you;
- through the contact form;
- by e-mail;
- by telephone;
- through the documents and information communicated to the Firm;
- through cookies and similar technologies, under the conditions described in the Cookies policy.
In the course of providing legal services, certain data may also be obtained from other legitimate sources, including from clients, opposing parties, courts, public authorities and institutions, public registers and databases, other professionals involved in the case or other sources permitted by law.
7. The recipients of data
The Firm does not sell or disclose your personal data to third parties for commercial purposes.
To the extent necessary for carrying out the activity, data may be communicated to:
- web hosting service providers;
- e-mail and communications service providers;
- IT and cybersecurity service providers;
- website traffic analytics service providers, only where you have given your consent, when this is required;
- collaborators and other professionals involved in the provision of legal services, under the conditions provided by law;
- public authorities and institutions, when there is a legal obligation or the communication is necessary in the exercise of the professional activity;
- courts, criminal prosecution bodies, bailiffs, notaries public, experts, translators, interpreters or other professionals, when this is necessary for the provision of legal services or is provided by law.
Providers that process personal data on behalf of the Firm, as processors, are selected so as to offer sufficient guarantees regarding the implementation of appropriate technical and organisational measures for the protection of data.
The processors that process personal data on behalf of the Firm are:
- Vercel Inc. – hosting of the website;
- Resend – delivery of the messages transmitted through the contact form;
- Cloudflare, Inc. – anti-spam verification of the contact form (Turnstile);
- Google – Google Analytics (traffic statistics, solely with consent) and Google Maps (the map embedded on the contact page).
Authorities, courts, public institutions and other recipients that process data on the basis of their own legal powers do not acquire, by the mere communication of the data, the status of processors of the Firm.
The communication of information obtained in the context of the professional activity is carried out in compliance with the legal provisions applicable to the profession of attorney and the obligation to maintain professional secrecy.
8. Transfer of data outside the European Economic Area
In carrying out its activity, the Firm uses certain technological services and solutions provided by companies that are part of groups headquartered in the United States of America. Depending on the service used and the provider's technical infrastructure, certain personal data may be transferred to, or accessed from, states located outside the European Economic Area ("EEA").
Any such transfer is carried out in compliance with the provisions of Chapter V of the GDPR and on the basis of an appropriate legal mechanism. As regards transfers to the United States of America, these may take place, where applicable, on the basis of European Commission Implementing Decision (EU) 2023/1795 on the adequate level of protection of personal data under the EU-US Data Privacy Framework, to the extent that the recipient of the transfer participates in this framework, or on the basis of other appropriate safeguards provided by art. 46 GDPR, including the standard contractual clauses approved by the European Commission.
The main service providers used by the Firm that may involve international data transfers are:
| Recipient | Country | Service used | Transfer mechanism |
|---|---|---|---|
| Google LLC | USA | Google Workspace, Gmail, Google Drive, Google Meet and other Google services | European Commission adequacy decision – EU-US Data Privacy Framework (Implementing Decision (EU) 2023/1795), to the extent applicable; where applicable, standard contractual clauses |
| Stripe, Inc. | USA | Payment processing and related services | European Commission adequacy decision – EU-US Data Privacy Framework (Implementing Decision (EU) 2023/1795), to the extent applicable; where applicable, standard contractual clauses |
| Cloudflare, Inc. | USA | Security, protection and optimisation of the functioning of the website | European Commission adequacy decision – EU-US Data Privacy Framework (Implementing Decision (EU) 2023/1795), to the extent applicable; where applicable, standard contractual clauses |
| Vercel Inc. | USA | Hosting of the website | European Commission adequacy decision – EU-US Data Privacy Framework (Implementing Decision (EU) 2023/1795), to the extent applicable; where applicable, standard contractual clauses |
| Resend | USA | Delivery of the messages transmitted through the contact form | European Commission adequacy decision – EU-US Data Privacy Framework (Implementing Decision (EU) 2023/1795), to the extent applicable; where applicable, standard contractual clauses |
| Meta Platforms, Inc. and/or the relevant companies of the Meta group | USA | WhatsApp and, where applicable, other Meta services used by the Firm | European Commission adequacy decision – EU-US Data Privacy Framework (Implementing Decision (EU) 2023/1795), to the extent applicable; where applicable, standard contractual clauses |
| Microsoft Corporation and/or the relevant companies of the Microsoft group | USA | Microsoft services and applications used in the Firm's activity | European Commission adequacy decision – EU-US Data Privacy Framework (Implementing Decision (EU) 2023/1795), to the extent applicable; where applicable, standard contractual clauses |
| Apple Inc. and/or the relevant companies of the Apple group | USA | Apple devices, applications and services used in the Firm's activity, to the extent that they involve the processing of personal data | European Commission adequacy decision – EU-US Data Privacy Framework (Implementing Decision (EU) 2023/1795), to the extent applicable; where applicable, standard contractual clauses |
The adequacy decision regarding the EU-US Data Privacy Framework allows personal data to be transferred to organisations in the United States of America that participate in this framework, without the need for additional safeguards for the transfer within the meaning of art. 46 GDPR.
Where the recipient or the transfer concerned is not covered by an adequacy decision, the Firm ensures that the appropriate safeguards provided by the GDPR are used, including, where applicable, the standard contractual clauses adopted by the European Commission, as well as any additional measures necessary to ensure an adequate level of data protection.
Further information on international data transfers, their recipients and the applicable protection mechanisms may be requested from the Firm using the contact details provided in this Policy.
9. Storage period
Personal data is kept only for the period necessary to fulfil the purposes for which it was collected and in compliance with the applicable legal and professional obligations.
Data and messages transmitted in order to request information or legal services, where no legal assistance contract is concluded, are kept for a reasonable period necessary to handle the request and, where applicable, to protect the legitimate interests of the Firm.
Where the request leads to the conclusion of a legal assistance contract, the relevant data will be incorporated into the records and documentation relating to the professional relationship.
The data transmitted through the contact form is kept, as a rule, for a period of no more than 3 years, except in situations where it becomes part of a legal assistance file or where legal obligations require a longer retention period.
Data processed in the course of providing legal services is kept for the periods provided by the legislation applicable to the profession of attorney and by the other relevant regulations, and, where applicable, for the period necessary for the establishment, exercise or defence of legal claims.
In determining the retention period, account is taken of the nature and purpose of the processing, the categories of data, the applicable legal obligations, limitation periods and the need to protect the legitimate rights and interests of the Firm and its clients.
The statistical data collected through Google Analytics is retained according to the retention period configured within the Google Analytics service, and the technical and security logs are retained by the hosting provider for short periods of time.
10. Data security
The Firm implements appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction, alteration, disclosure, or accidental or unlawful access.
These measures are reviewed periodically and adapted according to the nature and risks of the processing, the evolution of technology and the applicable legal requirements.
11. Professional secrecy and confidentiality
The Firm's activity is subject to the special rules on the professional secrecy of attorneys.
The information and documents communicated to the Firm in the context of a request for, or the provision of, legal services are treated in compliance with the obligations of confidentiality and professional secrecy provided by Law no. 51/1995, the Statute of the profession of attorney and the other applicable legal provisions.
Access to this information is limited to the persons for whom access is necessary for carrying out the professional activity, under the conditions and within the limits provided by law.
12. The rights of data subjects
Under the conditions provided by the GDPR, you have the following rights:
-
The right of access – the right to obtain confirmation that your data is being processed and to receive information regarding this processing, as well as, under the conditions of the law, a copy of the data.
-
The right to rectification – the right to request the correction of inaccurate data or the completion of incomplete data.
-
The right to erasure of data – the right to request the erasure of data in the cases provided by the GDPR.
This right is not absolute. The request may not be granted where there are legal or professional obligations to retain the data, where processing is necessary for the establishment, exercise or defence of a legal claim, or in other situations provided by the GDPR.
-
The right to restriction of processing – the right to request the limitation of the processing of data in the situations provided by the GDPR.
-
The right to object – the right to object to processing based on the legitimate interest of the Firm, on grounds relating to your particular situation, under the conditions provided by the GDPR.
-
The right to data portability – the right to receive the data provided in a structured, commonly used and machine-readable format and to request its transmission to another controller, when the conditions provided by law are met.
-
The right to withdraw consent – when processing is based on consent, it may be withdrawn at any time, without affecting the lawfulness of the processing carried out prior to the withdrawal.
-
The right to lodge a complaint – the right to lodge a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP) or to address the competent courts.
To exercise your rights, you may send a request to office@peticarudavid.ro.
Where there are reasonable doubts as to the identity of the person making the request, the Firm may request the additional information necessary to confirm that person's identity.
13. The processing of data belonging to minors
In the course of its professional activity, the Firm may process personal data relating to minors where this is necessary for the provision of legal services, for the protection of their rights and interests or in other situations permitted by law.
In such cases, processing is carried out only to the extent necessary and in compliance with the applicable legal requirements, having regard to the specific protection enjoyed by minors in the processing of personal data.
The website does not seek to collect personal data of minors for marketing or profiling purposes.
14. Cookies policy
The website uses cookies strictly necessary for its functioning and may use, only under the conditions permitted by law and, where necessary, on the basis of your consent, analytics and performance measurement cookies.
Cookies that are not strictly necessary will not be used before the user has expressed their choice, where the applicable legislation requires consent to be obtained.
Independently of the cookie options, the contact page embeds a Google Maps map provided by a third party, which loads automatically when the page is opened (see the Cookies policy).
Complete information regarding the categories of cookies used, their purposes, their duration and the way to manage preferences is available in the Cookies policy.
15. Amendment of the Privacy policy
The Firm reserves the right to update this Privacy policy periodically in order to reflect legislative, jurisprudential, technical or organisational changes regarding the processing of personal data.
Any updated version will be published on this page, and the date of the last update will be modified accordingly.
16. Contact details
For any questions regarding the processing of personal data or to exercise the rights provided by the GDPR, you may contact us using the following details:
- SCP Peticaru, David și Asociații
- Tax identification number (CUI): 32648044
- Registered office: Bd. Dacia no. 11, Building A, ground floor, ap. 3, Sector 1, Bucharest
- Secondary office: Str. Gheorghe Danielopol no. 1, ap. 1, Sector 4, Bucharest
- Phone: +40 765 399 253
- E-mail: office@peticarudavid.ro
- Website: www.peticarudavid.ro