Privacy Policy
1. Who we are
DUOMIND S.R.L. ("Duomind", "we") is a company registered in Romania (trade registry no. J2026009533004, fiscal code 53901823), with its registered office in Voluntari, Ilfov, Romania. For any privacy matter, contact contact@duomind.eu. We respond to verified requests within the deadlines set by Regulation (EU) 2016/679 ("GDPR").
2. Scope
This policy describes how we process personal data through our website and through the services we provide to our customers. Where a specific service involves additional terms, those are made available to the customer within that service.
3. Website visitors
Our website is informational. We do not set tracking cookies, run advertising, or profile visitors. Technical connection data (such as IP addresses) may be processed in server logs by our infrastructure providers for security and delivery purposes. If you contact us by e-mail, we process your address and message content in order to reply, on the basis of our legitimate interest in responding to enquiries.
4. Data processed in our services
Depending on the service, we process:
- Customer account data — identification and contact details of our business customers and their configuration of the service. For this data we act as a controller, processing it to perform our contract with the customer (GDPR art. 6(1)(b)) and to meet our legal obligations (art. 6(1)(c)).
- Data supplied by customers for processing — information our customers submit to, or route through, our services in order to obtain the contracted results. For this data we act as a processor on the customer's documented instructions; the customer remains the controller.
- Service and security logs — limited technical records needed to operate the services securely, processed on the basis of our legitimate interest (art. 6(1)(f)).
We apply data minimisation in all cases: we process only the data necessary to deliver the contracted service, and we do not use personal data for advertising, profiling, or resale.
5. Where data is stored
Personal data stored by our services is hosted on managed infrastructure with European Union data residency; our operations are located in Romania. We do not transfer personal data outside the EU/EEA on our own initiative. Where a customer instructs us to exchange data with a third-party platform of their choice, that exchange is governed by the customer's relationship with that platform.
6. Recipients
We share personal data only with: (a) infrastructure and service providers acting as our sub-processors under GDPR-compliant data processing agreements; (b) third parties to whom a customer instructs us to deliver data as part of the service; and (c) public authorities where disclosure or submission is required by law. We never sell personal data.
7. Retention
We keep personal data only as long as necessary for the purposes above. Customer account data is deleted within 30 days of the end of the customer relationship. Records that we or our customers are legally required to keep (for example documents subject to statutory retention under applicable tax or commercial law) are retained for the legally mandated period and then deleted. Technical logs are kept for a short rolling window.
8. Your rights
Subject to the conditions of the GDPR, you have the right to access, rectify, erase, restrict, or object to the processing of your personal data, and the right to data portability. Where we act as processor, we assist the responsible controller in fulfilling these rights and redirect requests to them where required. To exercise any right, write to contact@duomind.eu. You also have the right to lodge a complaint with a supervisory authority — in Romania, the National Supervisory Authority for Personal Data Processing (ANSPDCP), or the authority of your habitual residence.
9. Security
We maintain an information security program appropriate to our size and architecture, including encryption of data in transit and at rest, least-privilege access control, multi-factor authentication on administrative accounts, continuous monitoring of dependencies and code, and a documented incident response process. In the event of a personal data breach we notify the competent authority and affected parties as required by GDPR articles 33–34.
10. Changes
We review this policy at least annually. Material changes are published on this page with an updated version number and effective date.