--- title: "Privacy policy" description: "How we process personal data on lustro.ro: server logs, the contact form, cookies and your rights." url: "https://lustro.ro/en/privacy-policy" language: "en-GB" site: "Lustro SRL" updated: "2026-09-08" breadcrumb: "Home > Privacy policy" --- # Privacy policy How we process personal data on lustro.ro: server logs, the contact form, cookies and your rights. ## 1. Data controller **LUSTRO S.R.L.** Parcul Industrial Șura Mică, Parcela P30/2, 557270 Șura Mică, Sibiu County, Romania VAT no. (CUI): RO 23630579 · Trade register no.: J32/574/2008 Telephone: [+40 269 228 005](tel:+40269228005) · Mobile: [+40 746 227 325](tel:+40746227325) · Fax: +40 269 577 313 E-mail: [contact@lustro.ro](mailto:contact@lustro.ro) The controller is responsible for the processing of personal data on this website within the meaning of Regulation (EU) 2016/679 (GDPR). ## 2. What data we process and why ### 2.1 Server log files Every time the website is accessed, the server automatically records: the IP address (shortened or complete, depending on the server configuration), date and time, the page requested, the HTTP status code, the amount of data transferred, the referring page and the browser identifier. This data is needed to deliver the pages and to keep the system secure. The legal basis is our legitimate interest in operating a secure and stable website (Art. 6(1)(f) GDPR). The logs are deleted automatically after 30 days at the latest. ### 2.2 Contact form / request for a quote If you send us a request through the form, we process your name, company, e-mail address, telephone number and the text of your message, solely in order to answer the request. The message reaches us by e-mail; it is not stored in a database on the website. The legal basis is the performance of pre-contractual measures (Art. 6(1)(b) GDPR) and our legitimate interest in answering business enquiries (Art. 6(1)(f) GDPR). We keep the correspondence for as long as it takes to deal with the request and to meet statutory retention obligations. ### 2.3 Cookies The website uses strictly necessary cookies only. We use no analytics tools, no advertising cookies and no social-network buttons. Details are in the [cookie policy](https://lustro.ro/en/cookie-policy). ### 2.4 Google Maps On the page "How to find us" we provide a Google Maps map. The map is **not** loaded automatically: you first see only a button, and the connection to Google is made only after you press it. From that moment Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) receives your IP address and may set its own cookies. The legal basis is your consent (Art. 6(1)(a) GDPR), given by pressing the button. ## 3. Who has access to the data The website is hosted by **CUBUS ARTS S.R.L.**, Calea Cisnădiei nr. 64, 550408 Sibiu, Romania (VAT no. RO 13548146, trade register no. J2000000508324), acting as processor under a data processing agreement pursuant to Art. 28 GDPR. The servers are operated in the data centre of Hetzner Online GmbH in Falkenstein, Germany, as sub-processor; the data does not leave the European Union. Beyond that we pass personal data on to third parties only where the law requires it. ## 4. Your rights You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and the right to object to processing based on legitimate interests (Art. 21). Where processing is based on consent, you may withdraw it at any time with effect for the future. To exercise these rights, write to [contact@lustro.ro](mailto:contact@lustro.ro). You also have the right to lodge a complaint with a supervisory authority. The authority responsible for the operator is the Romanian data protection authority ANSPDCP, B-dul G-ral. Gheorghe Magheru 28–30, Sector 1, 010336 Bucharest, [www.dataprotection.ro](https://www.dataprotection.ro). You may also contact the supervisory authority of your habitual residence. ## 5. Security The connection between your browser and this website is encrypted with TLS (HTTPS). We apply appropriate technical and organisational measures to protect data against unauthorised access, loss or alteration. ## 6. Changes We update this policy whenever the processing described above changes. The current version applies from September 2026.