Confidentiality is part of how we practise law. This document explains what personal data we process when you visit stoian.biz or write to us through the contact form, why we process it, how long we keep it and what rights you have.
Last updated: 19 August 2026.
1. Who the controller is
The controller of the personal data processed through this website is STOIAN & PARTNERS, with its professional office at Calea Turzii nr. 231/2, Cluj-Napoca, Cluj County, 400491, Romania, registered with Cluj Bar Association, referred to below as “the Firm”, “we” or “Stoian & Partners”.
For any matter concerning your personal data, including to exercise the rights described in section 9, you may write to [email protected] or contact us at [email protected] or on +40 264 402 597.
2. What this policy covers
This policy applies to the processing carried out through the stoian.biz website: browsing the pages, sending a message through the contact form and the correspondence that follows from it.
The processing of data within a legal assistance relationship – that is, once a legal services agreement has been signed – is governed by that agreement, by the rules of the legal profession and by the professional secrecy obligation laid down in Article 11 of Romanian Law no. 51/1995, and not by this policy.
3. What we process, for what purpose and on what legal basis
3.1. Messages sent through the contact form
What we process: your name, company name (optional), e-mail address, phone number (optional), the area of interest you select and the content of your message, together with the time it was sent.
Why: to record your enquiry, to reply to it and, where applicable, to assess whether and on what terms we can provide legal assistance.
Legal basis: your consent, given by ticking the box in the form — Article 6(1)(a) of Regulation (EU) 2016/679 (“GDPR”) — and, to the extent your message concerns a possible engagement, steps taken at your request prior to entering into a contract — Article 6(1)(b) GDPR.
How it is stored: the message is saved as a private record in the website administration, accessible only to authorised persons within the Firm, and is sent in parallel by e-mail to the Firm’s official address.
Whether providing the data is required: your name, e-mail address and message are necessary for us to reply; the other fields are optional. Without the required data we cannot act on your enquiry.
3.2. Subsequent correspondence
If we reply, we process your contact details and the content of the correspondence for the same purpose and on the same legal bases as above. Messages are sent through the Firm’s own e-mail server, hosted on the stoian.biz domain.
3.3. Technical data and security logs
What we process: IP address, browser type and version, the page accessed, the date and time of access and any technical errors — data recorded automatically by the web server, as happens with any website.
Why: to keep the site working correctly, to diagnose technical problems and to protect the infrastructure against unauthorised access and abuse.
Legal basis: our legitimate interest in maintaining a functional and secure website — Article 6(1)(f) GDPR.
3.4. Protection against automated messages (anti-spam)
The contact form is protected by Cloudflare Turnstile, which checks whether a message is sent by a person rather than by an automated program. For this purpose Cloudflare, Inc. processes the IP address and a number of technical browser signals (device characteristics and the pattern of interaction with the page). According to the provider’s documentation, Turnstile does not use cookies to collect or store information and does not build user profiles.
In addition, we limit how many messages may be sent from the same connection within a short interval. For this we keep, for one hour, a counter associated with an irreversible cryptographic form (hash) of the IP address — not the IP address in clear text.
Legal basis: our legitimate interest in preventing automated messages, abuse and overloading of the infrastructure — Article 6(1)(f) GDPR.
3.5. Delivery of the website through the Cloudflare network
The website is delivered through the Cloudflare network, which encrypts traffic, filters attacks and speeds up page loading. In this process Cloudflare processes the IP address and the technical data of your requests, acting as our processor. The basis is our legitimate interest in the security and availability of the website — Article 6(1)(f) GDPR.
3.6. The map on the “Speak” page
What happens: a map provided by Google Maps is embedded on the contact page. The map loads automatically, together with the page, without any action on your part. At that moment your browser contacts Google’s servers directly, and those servers receive:
- your IP address — the address to which Google sends the map imagery back;
- the date and time of loading;
- the address of the referring page — our contact page, transmitted as the referrer;
- the type and version of your browser, your operating system and your configured language;
- technical characteristics of your device and window — the size of the displayed area and the screen density;
- if you are signed in to a Google account in the same browser, Google may associate this data with your account.
Through the content thus loaded, Google may also store information on your terminal equipment or access information already stored there.
Our role: we neither receive, see, nor can read this data. Google processes it as its own controller, not as our processor. For users in the European Union, responsibility lies with Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, under the Google Privacy Policy.
Legal basis: our legitimate interest in showing you easily where our professional seat is located — Article 6(1)(f) GDPR.
How to avoid this transmission: the map is a convenience, not a component necessary for the site to work — our full address is displayed in text both on the contact page and in the footer of every page. You can block the map from loading in your browser settings or with a third-party content blocker, without affecting the rest of the site. You may also object to this processing under Article 21 GDPR, by writing to [email protected]. Full details are in our Cookie Policy, section 3.4.
3.7. Our own visit statistics
What we process: once an hour, a program of ours reads the server logs described in section 3.3 and works out, for each day, how many pages were displayed and how many distinct IP addresses appeared. It keeps the totals and the list of the most-visited pages.
What does not happen: IP addresses are counted, not stored — once the number of distinct ones has been calculated, the list is discarded. No address, no identifier and nothing tied to a person is saved. No cookies are set, no code runs in your browser, and no external service is involved. The totals cannot be used to reconstruct who visited the site or what they read.
Why: to know whether the material we publish is being read, and to notice early an abnormal rise in traffic, which may signal a technical incident or an attempted abuse.
Legal basis: our legitimate interest in understanding, in aggregate form, the use of our own website — Article 6(1)(f) GDPR.
Retention: the daily totals are kept long term, as they contain no personal data. The logs they are calculated from are deleted automatically after 7 days.
4. What we do not do
- We do not use external traffic analytics services (such as Google Analytics) or advertising pixels. We work out visit numbers ourselves, from our own server logs, in aggregate form — see section 3.7.
- We do not carry out direct marketing and do not send newsletters without an express request from you.
- We do not sell, rent out or otherwise make your data available to third parties for commercial purposes.
- We do not create profiles and do not take automated decisions producing legal effects concerning you within the meaning of Article 22 GDPR.
5. Cookies and similar technologies
We do not place analytics, advertising or tracking cookies on visitors’ devices. When the public pages load, our website sets no cookies of its own.
Strictly necessary cookies may, however, be placed by Cloudflare for security purposes — for example during the anti-spam check on the contact page. These serve solely the operation and protection of the website and fall within the category for which Article 4(5) of Romanian Law no. 506/2004 does not require prior consent.
Session cookies are also used when logging into the website’s administration area, but these concern only authorised persons within the Firm, not visitors.
On the contact page, the Google Maps embed described in section 3.6 is content delivered by a third party: through it, Google may store information on your equipment or access information already stored there. That loading can be blocked in your browser, with no effect on the rest of the site.
You may block or delete cookies at any time from your browser settings; blocking strictly necessary cookies may affect the operation of the contact form.
A complete inventory of the technologies used on the site — with the name of each cookie, its purpose, duration and legal basis — is set out in our Cookie Policy.
6. Who has access to the data
Within the Firm, access is limited to the lawyers and staff who need the information in order to reply to you, all of whom are bound by confidentiality.
Outside the Firm, the data may be accessed by the following categories of recipients:
- The hosting infrastructure provider — the server running the website and the e-mail service is located in Romania.
- Cloudflare, Inc. — for delivering and securing the website and for anti-spam protection, acting as a processor.
- Google Ireland Limited / Google LLC — solely the technical data transmitted by your browser when the map on the contact page loads (section 3.6). Google acts here as its own controller, not as our processor; we transmit no data to it ourselves and have no access to what it collects.
- Public authorities — only where a legal obligation requires it and within the limits permitted by the lawyer’s professional secrecy.
We have data processing agreements in place with our processors under Article 28 GDPR, requiring them to process the data only on our instructions.
7. Transfers outside the European Economic Area
Cloudflare, Inc. is a company established in the United States of America, and the processing may involve transfers of technical data outside the European Economic Area. These transfers rely on the European Commission’s adequacy decision regarding the EU–U.S. Data Privacy Framework, under which the provider is certified, and, in the alternative, on the standard contractual clauses adopted by the European Commission.
The same safeguards are relied on for Google: in relation to users in the Union the controller is Google Ireland Limited, established in Ireland, but the processing of the technical data transmitted when the map loads (section 3.6) may involve transfers to Google LLC in the United States, relying on the same adequacy decision and, in the alternative, on the standard contractual clauses.
On request, we can provide further information about the safeguards applicable to these transfers.
8. How long we keep the data
- Messages received through the form and the related correspondence: 24 months from the last communication, if the enquiry does not turn into a contractual relationship.
- If a legal services agreement follows: the data becomes part of the file and is kept in accordance with the professional and legal obligations applicable to the practice of law.
- Web server logs: 7 days, through automatic rotation.
- The anti-abuse counter associated with the hashed IP address: one hour.
- Data processed by Cloudflare for security purposes: in accordance with the provider’s retention policies.
- Technical data reaching Google through the map on the contact page: in accordance with Google’s own retention policies — we neither control it nor have access to it.
Once these periods expire, the data is deleted or anonymised, except where keeping it is necessary for the establishment, exercise or defence of a legal claim.
9. Your rights
As a data subject, you have the following rights:
- the right of access — to find out whether we process your data and to obtain a copy of it (Article 15 GDPR);
- the right to rectification — to have inaccurate or incomplete data corrected (Article 16 GDPR);
- the right to erasure — in the cases provided by law (Article 17 GDPR);
- the right to restriction of processing (Article 18 GDPR);
- the right to data portability — for data you provided, processed on the basis of consent or of a contract (Article 20 GDPR);
- the right to object — to processing based on our legitimate interest (Article 21 GDPR);
- the right to withdraw your consent at any time, without affecting the lawfulness of processing carried out before the withdrawal.
You may exercise these rights by a request sent to [email protected] or in writing at the professional office indicated above. We reply within one month of receiving the request; this period may be extended by up to two further months for complex requests, in which case we will inform you beforehand (Article 12(3) GDPR). To avoid disclosing data to persons who are not entitled to it, we may ask you for additional information needed to confirm your identity.
Complaint to the supervisory authority
If you consider that we have infringed your rights, you may lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing:
B-dul G-ral. Gheorghe Magheru 28–30, Sector 1, postal code 010336, Bucharest
Phone: +40.318.059.211 / +40.318.059.212
E-mail: [email protected]
Web: www.dataprotection.ro
You also have the right to bring proceedings before the competent courts.
10. Data security
Traffic between your browser and the website is encrypted (HTTPS). Access to the administration area is restricted, additionally protected by an anti-bot check and limited to authorised persons. We apply security updates on an ongoing basis, and messages received through the form are stored as private records, visible only to authenticated users of the Firm.
11. Please do not send confidential information through the form
Sending a message through this website does not create a lawyer–client relationship and does not oblige us to take on the matter. Until a legal services agreement is signed and any conflicts of interest have been checked, we recommend describing the context in general terms and not sending us confidential documents or information through the form or by unsecured e-mail.
Once the professional relationship is established, all information received is covered by the lawyer’s professional secrecy under Article 11 of Law no. 51/1995 and the Statute of the legal profession.
12. Minors
The website is addressed to professionals and the business community and is not intended for persons under the age of 16. We do not knowingly collect data relating to minors; should such data nevertheless reach us, we delete it as soon as we become aware of it.
13. Changes to this policy
We may update this policy whenever the way we process data changes or the applicable legal requirements change. The version in force is always the one published on this page, and the date of the last update is shown at the top.
14. Applicable legal framework
- Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data (GDPR);
- Romanian Law no. 190/2018 on implementing measures for Regulation (EU) 2016/679;
- Romanian Law no. 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector;
- Romanian Law no. 51/1995 on the organisation and practice of the legal profession, and the Statute of the legal profession.