02 / Data protection
Privacy Policy (GDPR)
Protecting your personal data is a core engineering principle at AKQ Developing. This Privacy Policy details the categories of information we collect, the lawful bases under which we process them, the security measures we deploy, and the rights available to you under the General Data Protection Regulation (GDPR).
1. Data Controller Identification
Pursuant to the General Data Protection Regulation (Regulation EU 2016/679), the data controller responsible for the processing of personal data collected via akqdevs.xyz is AKQ Developing, operating from Romania.
For all data privacy requests, access inquiries, or rectifications, our designated privacy contact channel is: support@akqdevs.xyz.
2. Categories of Data Collected
We restrict data collection exclusively to information strictly necessary for technical operations and project fulfillment:
- Contact & Identification Details: Name, organization name, and email address provided voluntarily via our project inquiry form.
- Project Scope Data: Inquiries, technical briefs, and configuration parameters generated through our interactive quote calculator (project type, scale, feature selections, target timeline).
- Technical Telemetry & Security Logs: Client IP address, access timestamp, and user-agent string. These technical parameters are processed automatically at the server gateway to defend against malicious traffic, apply sliding-window rate limits, and filter automated spam.
- Browser Preferences & Cookie Consent: User consent state regarding necessary and optional performance cookies.
Note: We do not process sensitive personal data (special categories of personal data as defined under Article 9 of the GDPR).
3. Purposes of Processing
Your personal data is processed solely for legitimate and clearly defined purposes:
- Inquiry Resolution & Proposal Drafting: Reviewing client requirements submitted through our contact form and preparing itemized technical proposals and estimates.
- Direct Technical Communication: Responding to questions and conducting engineering consultations regarding requested software solutions.
- Infrastructure Security & Cyber Defense: Mitigating automated bot attacks, brute-force exploits, and Distributed Denial of Service (DoS/DDoS) attempts to ensure high availability.
- Statutory Accounting & Compliance: Fulfilling mandatory tax, invoicing, and commercial recordkeeping duties in Romania when formal agreements are entered.
4. Lawful Bases Under GDPR
All processing activities conducted by AKQ Developing are justified under Article 6 of Regulation (EU) 2016/679:
- Article 6(1)(b) GDPR (Pre-contractual Steps): Processing is necessary in order to take steps at your request prior to entering into a custom software development contract.
- Article 6(1)(a) GDPR (Consent): By submitting your inquiry form or configuring cookie preferences on our platform.
- Article 6(1)(f) GDPR (Legitimate Interests): Our legitimate interest in preserving cybersecurity, securing API endpoints against malicious injection, and preventing spam abuse.
- Article 6(1)(c) GDPR (Legal Obligations): Compliance with Romanian statutory fiscal and accounting obligations for finalized client invoices.
6. Data Retention Schedules
Personal data is retained only for as long as necessary to accomplish the underlying processing purpose:
- Contact Inquiries: Stored during pre-contractual negotiations and retained for a maximum of two (2) years from the date of last communication in the absence of an executed contract.
- Technical Security Logs (IP, Timestamps): Retained in automated sliding-window log rotations for 30 to 90 days, after which they are purged.
- Accounting & Invoicing Records: Retained for statutory periods mandated by Romanian tax legislation (customarily 5 to 10 years for fiscal documentation).
7. Your Rights Under GDPR
Under Chapter III of the GDPR, you enjoy the following fundamental privacy rights:
Right of Access (Art. 15)
You may request confirmation as to whether we process your data and obtain a copy of that personal data.
Right to Rectification (Art. 16)
You may request the correction of inaccurate personal data or completion of incomplete records.
Right to Erasure (Art. 17)
The "right to be forgotten" — request erasure of your data when it is no longer required or consent is withdrawn.
Restriction of Processing (Art. 18)
Request temporary suspension of processing while accuracy or lawful grounds are contested.
Data Portability (Art. 20)
Receive your personal data in a structured, commonly used, and machine-readable format (e.g., JSON, CSV).
Right to Object (Art. 21)
Object at any time to processing carried out under legitimate interest grounds on considerations relating to your situation.
You also have the right to lodge a complaint with the national supervisory authority:
National Supervisory Authority for Personal Data Processing (ANSPDCP)
B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, Bucharest, postal code 010336, Romania
Website: www.dataprotection.ro • E-mail: anspdcp@dataprotection.ro
8. Exercising Your Rights & Contact Information
To exercise any of the rights outlined above, please submit a written request to our data protection contact:
Data Protection Officer • AKQ Developing
Official E-mail: support@akqdevs.xyz
Statutory response window: within 30 calendar days of receipt.