GDPR Compliance Statement
Last updated: 29 July 2026
1. Our commitment to data protection
ADVAHOO SRL (“Advahoo”, “we”, “us” or “our”) is committed to protecting personal data and respecting the privacy rights of the individuals whose information we process.
We design and operate our systems with privacy, security, transparency and accountability in mind. Personal data is processed in accordance with Regulation (EU) 2016/679 — the General Data Protection Regulation (“GDPR”) — and other applicable data protection legislation.
This statement describes the principles and organisational practices through which Advahoo approaches GDPR compliance. Detailed information regarding the processing of personal data through this website is available in our Privacy Policy.
2. Company information
The data controller responsible for the processing activities described on this website is:
ADVAHOO SRL
Registered office: 37 Unirii Boulevard, Sector 3, Bucharest, Romania
Trade Register number: J40/1018/2011
Unique Registration Code: RO27977610
Email: advahoo@advahoo.ro
Privacy enquiries: dpo@advahoo.ro
3. Data protection principles
Advahoo processes personal data in accordance with the following principles:
- lawfulness, fairness and transparency;
- purpose limitation;
- data minimisation;
- accuracy;
- storage limitation;
- integrity and confidentiality;
- accountability.
We only collect and use personal data for specified, explicit and legitimate purposes and do not process more information than is reasonably necessary for those purposes.
4. Legal grounds for processing
Depending on the context, Advahoo may process personal data on one or more of the following legal grounds:
- the individual’s consent;
- steps taken at the individual’s request before entering into a contract;
- the performance of a contract;
- compliance with a legal obligation;
- the legitimate interests pursued by Advahoo or a third party, provided that such interests do not override the individual’s rights and freedoms.
The relevant purposes and legal grounds for website-related processing are described in our Privacy Policy.
5. Privacy by design and by default
Advahoo applies privacy by design and privacy by default principles when developing, configuring and operating digital systems and business processes.
Where appropriate, this includes:
- limiting access to personal data according to role and business need;
- assessing privacy and security risks before implementing new processing activities;
- maintaining appropriate internal records and procedures;
- selecting service providers that offer suitable privacy and security safeguards;
- incorporating data protection requirements into supplier and processor agreements;
- applying retention, deletion and access-control rules throughout the data lifecycle.
Where processing is likely to result in a high risk to individuals, Advahoo assesses whether a Data Protection Impact Assessment is required.
6. Security measures
Advahoo implements appropriate technical and organisational measures designed to protect personal data against unauthorised access, accidental or unlawful destruction, loss, alteration or disclosure.
Depending on the nature of the processing, these measures may include:
- access controls and authentication mechanisms;
- encryption in transit and, where appropriate, at rest;
- security logging and monitoring;
- backup and recovery procedures;
- vulnerability and incident management;
- confidentiality obligations for employees and authorised collaborators;
- periodic review of technical and organisational controls.
No system can guarantee absolute security. Advahoo continually evaluates its safeguards in relation to the risks, available technologies and nature of the data processed.
7. Service providers and international transfers
Advahoo may use authorised service providers to support website hosting, communications, security, analytics, recruitment or other legitimate business operations.
Such providers may process personal data only for the agreed purposes and under appropriate contractual and confidentiality obligations.
Where personal data is transferred outside the European Economic Area, Advahoo uses a lawful transfer mechanism, such as:
- an adequacy decision adopted by the European Commission;
- Standard Contractual Clauses;
- another safeguard or derogation permitted by applicable data protection law.
Further information regarding relevant categories of recipients and international transfers is provided in the Privacy Policy.
8. Data retention
Personal data is retained only for as long as necessary for the purposes for which it was collected, including the fulfilment of contractual, legal, accounting, security or reporting obligations.
Retention periods may differ depending on the category of information, the processing purpose and applicable legal requirements. When personal data is no longer required, it is deleted, anonymised or securely archived, as appropriate.
9. Individual rights
Subject to the conditions established by applicable law, individuals may have the right to:
- obtain information about the processing of their personal data;
- request access to their personal data;
- request the correction of inaccurate or incomplete data;
- request the deletion of personal data;
- request the restriction of processing;
- object to processing based on legitimate interests;
- withdraw consent at any time where processing is based on consent;
- receive certain personal data in a structured, commonly used and machine-readable format;
- request the transmission of eligible data to another controller;
- not be subject to certain decisions based solely on automated processing;
- lodge a complaint with a competent data protection authority.
Requests may be sent to dpo@advahoo.ro. Advahoo may request additional information where necessary to verify the identity of the person making the request.
Individuals may also lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing.
10. Personal data breaches
Advahoo maintains procedures for identifying, assessing, documenting and responding to personal data incidents.
Where required by law, Advahoo will notify the competent supervisory authority and, where the incident is likely to result in a high risk to the affected individuals, will communicate the incident to those individuals without undue delay.
11. Employee awareness and accountability
Access to personal data is limited to authorised persons who require it for legitimate professional purposes.
Advahoo promotes data protection awareness through internal policies, confidentiality obligations, guidance and training appropriate to the roles and responsibilities of its personnel.
12. Relationship with other privacy documents
This GDPR Compliance Statement provides an overview of Advahoo’s approach to data protection.
For detailed information about:
- the personal data collected through this website;
- processing purposes and legal grounds;
- recipients;
- retention periods;
- cookies and similar technologies;
- the exercise of individual rights,
please consult our Privacy Policy and Cookies Policy.
13. Updates to this statement
Advahoo may update this statement to reflect changes in legislation, regulatory guidance, technology or its processing activities.
The latest version will always be published on this page together with the date of the most recent update.
14. Contact
Questions regarding this statement or Advahoo’s processing of personal data may be sent to:
ADVAHOO SRL
Email: advahoo@advahoo.ro
Privacy enquiries: dpo@advahoo.ro