1. Purpose and scope
This policy sets out how IGAMING S.R.L. (Szilaghi Consulting) complies with Regulation (EU) 2016/679 (GDPR) and Romanian Law no. 190/2018 across all its activities: the website, client engagements, regulatory filings, and services where we handle personal data on behalf of clients. How we use your own data is explained in our Privacy Policy.
2. Our roles
- Controller for data about our website visitors, enquirers, clients’ contacts, and the owners and key persons whose documents we collect for client due diligence and license applications.
- Processor where we handle personal data for a client and on its instructions — for example preparing regulatory reports, maintaining statutory registers or acting as local representative. We then act only on documented instructions under a data-processing agreement that meets article 28 GDPR.
3. Principles we apply
Under article 5 GDPR we process personal data lawfully, fairly and transparently; only for specified purposes; limited to what is necessary; accurately; for no longer than needed; and securely. We document how we meet these principles (accountability, article 5(2)).
- Data minimization: we ask only for documents the regulator or the law requires for your application.
- Privacy by design and by default (article 25): our website runs without tracking cookies or third-party scripts, and our forms collect only what we need to reply.
- Special care for sensitive data: criminal-record certificates are processed only where a licensing or AML law requires them (article 10 GDPR); national identification numbers are processed only under the safeguards of article 4 of Law no. 190/2018.
4. Records and impact assessments
We keep a record of processing activities (article 30). Before starting processing likely to result in a high risk to individuals we carry out a data-protection impact assessment (article 35) and, where required, consult the supervisory authority.
5. Security measures
- TLS encryption for the website and e-mail transport; encrypted storage for identity and due-diligence documents.
- Role-based access: only people working on a matter can open its files; multi-factor authentication on business accounts.
- Confidentiality undertakings for staff, contracted directors and partners.
- Secure channels for exchanging sensitive documents; no identity documents through the website form.
- Regular backups, patching, and review of these measures (article 32).
6. Our processors and partners
We use only processors that give sufficient guarantees, under written agreements meeting article 28 GDPR, and we keep a list of them. Partners who act as independent controllers in your matter — licensed counsel, notaries, testing laboratories, banks and regulators — process data under their own obligations.
7. International transfers
Transfers outside the EEA follow Chapter V GDPR: adequacy decisions where available, Standard Contractual Clauses (Decision 2021/914) with transfer impact assessments where needed, and article 49 derogations for filings that clients instruct us to make to non-EEA regulators.
8. Personal data breaches
- As controller, we notify ANSPDCP within 72 hours of becoming aware of a breach likely to result in a risk to individuals (article 33), and inform affected people without undue delay where the risk is high (article 34).
- As processor, we inform the client controller without undue delay and support its notifications (article 33(2)).
- Every breach is documented, including its effects and the remedial action taken.
9. Requests from individuals
Requests to exercise GDPR rights are answered within one month, extendable by two months for complex requests (article 12(3)). Where we act as processor, we pass requests to the client controller and assist it. Send requests to hello@szilaghi.com.
10. Retention and deletion
We keep data only as long as described in our Privacy Policy, then delete or anonymize it. Client files are returned or deleted at the end of a processing engagement, unless the law requires us to keep them.
11. People and training
Everyone who handles personal data for us is trained on these rules and bound by confidentiality. This policy is reviewed at least once a year.
Related: Terms and Conditions · Privacy Policy · Cookie Policy · GDPR Policy