OLEGUM SRL - LEGAL
Privacy Policy
Effective date: 16 July 2026 · Jurisdiction: Romania / European Union (GDPR)
1. Data Controller
The Koral Solutions website is operated by OLEGUM SRL, a Romanian limited liability company registered in Romania, a member state of the European Union, and the controller of personal data processed through this website.
Company details: OLEGUM SRL · VAT ID RO52838329 · Brașov County, Brașov, Serii Street no. 2, 3rd floor, apt. 97, Romania · info@koral.solutions · +40741013460
References on this website to "EU-registered" describe the company's place of registration; they do not indicate approval, certification, or endorsement by an EU institution. We have not appointed a separate Data Protection Officer. Privacy requests can be sent to info@koral.solutions.
2. Personal Data We Collect
When you submit a lead or contact form, we collect the information you provide: name, business email address, inquiry topic, project details, and any information you include in the message.
Our forms also send the current page URL and a hidden anti-spam honeypot field named "website". Our lead API may process technical data such as IP address, request origin, user agent, timestamps, and standard server logs for security, spam prevention, rate limiting, troubleshooting, and abuse detection.
We store your cookie consent choice in local storage. If you accept optional analytics cookies, Google Analytics may process aggregate usage data such as page views, browser and device information, approximate geography, referral source, and interaction events. We do not intentionally collect special categories of personal data through this website.
3. How We Use Personal Data
We use personal data to respond to business inquiries, assess project fit, prepare proposals, maintain website and API security, prevent spam or abuse, troubleshoot service issues, and understand aggregate website performance when analytics consent has been granted.
We do not sell personal data and we do not share lead data with third parties for their own advertising purposes.
4. Legal Bases
Where applicable, we process inquiry data under GDPR Article 6(1)(b) when processing is necessary to take steps at your request before entering into a contract or to perform a contract with you. For other business inquiries, including communications made on behalf of an organization, we may rely on GDPR Article 6(1)(f) and our legitimate interest in responding to relevant inquiries and developing business relationships.
We process security, anti-spam, rate-limiting, troubleshooting, and abuse-prevention data under GDPR Article 6(1)(f), based on our legitimate interest in protecting the website, lead API, and business communications.
Optional analytics is processed under GDPR Article 6(1)(a), based on your consent. You can reject or withdraw optional analytics through Cookie Settings; rejecting analytics does not prevent you from using the website or contacting us.
5. Processors and Recipients
Lead form submissions are delivered to our internal team through the Telegram Bot API. Telegram therefore receives submitted lead details and processes them under its applicable service terms and privacy documentation. This policy does not characterize Telegram as acting exclusively in a particular data-protection role.
We may also use hosting, security, email, analytics, and professional service providers where necessary to operate the website, respond to inquiries, comply with law, or protect our rights. Each provider's role and obligations depend on the service used and the applicable contractual and legal arrangements.
6. International Transfers
Some providers, including Telegram and Google Analytics when enabled, may operate infrastructure or provide support outside Romania or the European Economic Area. Any international transfer is subject to the provider's applicable terms, transfer documentation, and the safeguards required for the relevant destination and processing context. You may contact info@koral.solutions to request information about transfer arrangements relevant to your personal data.
7. Retention
Business inquiry data is generally retained for up to 24 months after the last meaningful interaction, unless a contractual relationship is created or longer retention is required for legal, accounting, dispute, or security reasons.
Security logs, rate-limiting data, and troubleshooting records are generally retained for up to 12 months unless an incident, dispute, legal obligation, or abuse investigation requires longer retention. Cookie consent preferences are retained until you change them, clear site storage, or the consent version changes. Analytics data is retained according to the configured Google Analytics retention settings and only applies after consent.
8. Your GDPR Rights
Subject to GDPR conditions and exceptions, you may request access to your personal data, correction of inaccurate data, deletion, restriction of processing, portability, objection to processing based on legitimate interests, and withdrawal of consent for consent-based processing.
You can withdraw analytics consent at any time through Cookie Settings. To exercise other rights, contact info@koral.solutions. We aim to respond within one month, unless GDPR allows an extension for complex or numerous requests. You also have the right to lodge a complaint with Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) in Romania or another competent EU supervisory authority.
9. Security
We apply technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration, or disclosure. Our description of delivery as "security-conscious" means that security risks and appropriate controls are considered throughout engineering work; it is not a guarantee that every system will be free from vulnerabilities or incidents.
"GDPR-aware delivery" means that relevant data-protection requirements are considered and scoped with the client. It does not by itself certify OLEGUM SRL, a client, or a delivered system as compliant with every legal requirement. Responsibilities, controls, and any required assessments depend on the role, data, use case, and written project agreement. No internet transmission or storage system can be guaranteed to be completely secure.
10. Cookies and Analytics
The website uses necessary local storage to remember your cookie consent choice. Optional Google Analytics is loaded only after you accept analytics cookies. You can change or withdraw your analytics choice through Cookie Settings. For details about storage keys, analytics cookies, and browser controls, see the Cookie Policy.
11. Children
This website and our services are intended for business users and are not directed to children. We do not knowingly collect children's personal data through this website.
12. Updates to This Policy
We may update this Privacy Policy when our services, data practices, providers, or legal requirements change. The effective date below identifies the current version. Material changes will be highlighted or otherwise communicated where required by law.