Get In Touch

office@jordachewd.com
Assistance hours

Monday – Friday
10 am to 6 pm EET
Back

Privacy Policy

Version 1.0.0 – Effective date: September 22, 2026

In short: This website is a showcase for our software-engineering services. We process personal data in two situations only: when you contact us (through the form or by e-mail) and, if you accept analytics cookies, when we measure how the site is used. We do not sell data, run advertising, or create accounts. You can exercise your rights at any time by writing to office@jordachewd.com, and you can complain to the Romanian supervisory authority (ANSPDCP).

1. Who is responsible

The controller of personal data processed through jordachewd.com (the “Website”) is: FCI DEVELOPMENT SRL (trading as JordacheWD or JWD), registered office: Str. Drumul Pădurea Neagră, 19-85, Sect. 1, Bucharest, Romania, 014044; Trade register no: J2016004566408; Tax id code (CUI / EU VAT): 35873644; E-mail: office@jordachewd.com.

We have not appointed a data protection officer because we are not required to under Article 37 GDPR; the contact above handles all privacy requests.

2. What this policy covers

2.1 This policy applies to the Website only. Applications we build or demonstrate on other domains (for example jwd-apps.com) and any services we provide to clients under a written agreement have their own privacy notices or contractual data-protection terms.

2.2 We process personal data in accordance with Regulation (EU) 2016/679 (the “GDPR”), Law no. 190/2018 and Law no. 506/2004 on the processing of personal data and privacy in the electronic communications sector.

3. What we process, why, and on what legal basis

3.1 When you send us the contact / quote form
DataName, company, e-mail address, phone number (optional), subject, budget range, project details, the fact that you accepted the Website Terms, and the date and time of submission. The form does not ask for anything else; please do not include special-category data or third parties’ personal data.
PurposeTo read and answer your enquiry, assess whether we can help, prepare a proposal and communicate with you about it.
Legal basisArt. 6(1)(b) GDPR – steps taken at your request before entering into a contract. Where you write on behalf of a company, Art. 6(1)(f) – our legitimate interest in responding to business enquiries and in keeping a record of pre-contractual discussions; your interest in receiving an answer is aligned with ours.
RetentionIf no engagement follows: 24 months after our last exchange, then deleted. If an engagement follows: the data becomes part of the client file and is kept for the term of the contract and thereafter for the periods required by tax and accounting law (currently 5 years from 1 July of the year following the financial year under Law no. 82/1991, and 10 years for annual financial statements), and for the limitation period of claims (generally 3 years, Civil Code Art. 2517).
RecipientsOur e-mail and web-hosting provider HostX Web Services SRL (processor).
3.2 When you e-mail us directly

Same purposes, legal bases and retention as 3.1. Recipients: our e-mail provider.

3.3 Technical data when you visit the Website
DataIP address, date and time, pages requested, referrer, browser and operating system, recorded in server logs; strictly necessary cookies (Section 4).
PurposeDelivering the Website, security (detecting attacks and abuse), diagnosing errors.
Legal basisArt. 6(1)(f) GDPR – our legitimate interest in operating a secure website.
Strictly necessary cookies are exempt from consent under Law no. 506/2004 Art. 4(6).
RetentionServer logs: 30 days, unless needed longer to investigate a security incident.
RecipientsOur hosting provider HostX Web Services SRL (processor).
3.4 Usage statistics (only with your consent)
DataPseudonymous cookie identifiers (_ga, _ga_*), pages viewed, approximate location derived from a truncated IP address, device and browser type, referrer, interactions on the page.
PurposeUnderstanding how visitors use the Website in order to improve it.
Legal basisYour consent, given in the cookie banner (Art. 6(1)(a) GDPR; Law no. 506/2004 Art. 4(5)). You can withdraw it at any time via “Consent Preferences” (see the Cookie Policy). Withdrawal does not affect processing before withdrawal.
RetentionCookies: see the Cookie Policy. Analytics reports in Google Analytics: 14 months for user-level data (configured by us); aggregated reports are not personal data.
RecipientsGoogle Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) as processor under Google’s data-processing terms, with Google LLC (USA) as sub-processor. Google Tag Manager itself sets no cookies; it loads the tags we configure.
3.5 Embedded content

Fonts are loaded from Google Fonts (Google Ireland Limited); the request transmits your IP address to Google. Legal basis: Art. 6(1)(f), our interest in a consistent display; no cookies are set.

3.6 Social media links

The Website links to our profiles on LinkedIn, GitHub and Behance. These are ordinary links, not embedded plug-ins; no data is transmitted to those services until you click and leave the Website. Their own privacy policies then apply.

3.7 What we do not do

We do not create user accounts, sell or rent personal data, buy data from third parties, run advertising, profile visitors, make automated decisions with legal or similar effect (Art. 22 GDPR), or send marketing e-mail without prior consent.

4. Cookies

We use strictly necessary cookies without consent and analytics cookies only with your consent. Which cookies, for how long, and how to change your choice are set out in the Cookie Policy page.

5. Who receives your data

5.1 Processors acting on our instructions under Art. 28 GDPR agreements: hosting and e-mail provider HostX Web Services SRL; Google Ireland Limited (analytics and tag management, only with consent).

5.2 Professional advisers (accountant, lawyer) where an engagement follows and the law or the engagement requires it – as independent controllers bound by professional secrecy.

5.3 Public authorities where the law obliges us (for example tax authorities, courts, ANSPDCP).

5.4 We do not share data with anyone else. If our business is ever transferred, the acquirer would take over this data under the same purposes, and we would inform you.

6. Transfers outside the EU/EEA

6.1 Our own systems, hosting and e-mail are located in Romania.

6.2 Google may process analytics data in the United States. Google LLC is certified under the EU–US Data Privacy Framework, which the European Commission has found to provide adequate protection (Decision (EU) 2023/1795, Art. 45 GDPR). Google’s terms also provide the Standard Contractual Clauses approved by the Commission (Art. 46(2)(c) GDPR) as a fallback. You may request a copy of the applicable safeguards at office@jordachewd.com.

6.3 If you contact us from outside the EU/EEA, your data is transferred to us in Romania; this is necessary to reply to you (Art. 49(1)(b) GDPR).

7. How long we keep data

The retention periods are stated per purpose in Section 3. When a period ends we delete or anonymize the data. Backups are overwritten on a rolling basis within 30 days; data in a backup is not used for any other purpose until it is overwritten.

8. Your rights

8.1 You have the right to:

  • access the personal data we hold about you and receive a copy (Art. 15);
  • rectify inaccurate or incomplete data (Art. 16);
  • erase your data where there is no longer a lawful reason to keep it (Art. 17);
  • restrict processing in the cases set out in Art. 18;
  • data portability – receive data you provided to us in a structured, machine-readable format, for processing based on consent or contract (Art. 20);
  • object to processing based on legitimate interest, on grounds relating to your particular situation, and to object at any time to direct marketing (Art. 21);
  • withdraw consent at any time, where processing is based on consent, without affecting processing already carried out (Art. 7(3)).

8.2 To exercise a right, write to office@jordachewd.com from the address you used with us, or to the postal address in Section 1. We answer within one month; this may be extended by two further months for complex requests, and we will tell you if so (Art. 12(3)). We may ask you to confirm your identity when we cannot be sure the request is yours. Requests are free of charge unless manifestly unfounded or excessive (Art. 12(5)).

8.3 Complaints. You have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work or place of the alleged infringement (Art. 77). The Romanian authority is:

Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336 Bucharest, Romania
Tel. +40 318 059 211 · e-mail anspdcp@dataprotection.ro · www.dataprotection.ro (online complaint form under “Plângeri RGPD”)

We would appreciate the chance to resolve any concern first, but you are not obliged to contact us before complaining.

9. Security

We apply technical and organizational measures appropriate to the risk (Art. 32 GDPR): TLS encryption of the Website, access to the mailbox and hosting control panel restricted to authorized persons with strong authentication, regular software updates, and a policy of collecting only what the purposes require. No transmission over the internet is completely secure; if a personal-data breach were to affect you in a way likely to create a high risk, we would inform you as required by Art. 34.

10. Children

The Website is directed at businesses and is not intended for children under 16. We do not knowingly collect data from children. If you believe a child has sent us data, contact us and we will delete it.

11. Changes to this policy

Each version carries a version number and effective date at the top. We will publish material changes on this page before they take effect and, where we hold your e-mail address for an ongoing purpose, inform you directly.

Version history

  • 1.0.0 – September 22, 2026.