Privacy Policy
Last updated: 29 July 2026
BENTIL S.R.L. ("we", the "Controller") is committed to protecting personal data. In accordance with Articles 13 and 14 of Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR"), this policy explains how we process the personal data of visitors to bentil.ro and of our business partners.
1. Controller
BENTIL S.R.L.
Registered office: Jud. Harghita, Mun. Odorheiu Secuiesc, Int. Alba, Nr. 1, Ap. 1, Romania
VAT no. (CUI): RO50879861 · Trade Register: J2024040676005 · EUID: ROONRC.J2024040676005
E-mail: office@bentil.ro · Phone: +40 743 676 713
We are not required to appoint a Data Protection Officer and have not done so; for all data-protection matters please contact the Controller directly using the details above.
2. What data we process, for what purpose and on what legal basis
2.1. Contact form
When you submit our contact form we process: name, company, e-mail address, phone number, country, project description (message), your data-protection consent flag and – optionally – your newsletter consent. As technical data we record a SHA-256 hash of your IP address (the IP address itself is not stored in readable form), your browser identifier (user agent), language, source URL and any UTM parameters.
Purpose: answering your enquiry, preparing quotations and taking steps prior to entering into a contract. Legal basis: Art. 6(1)(b) GDPR (pre-contractual steps); for the newsletter, Art. 6(1)(a) GDPR (consent). The data is stored in our own database on our own server.
Spam protection: to protect the form against automated abuse we use Cloudflare Turnstile (Cloudflare, Inc., USA). Cloudflare processes technical connection data (e.g. IP address, browser characteristics); no advertising cookies are set. Legal basis: Art. 6(1)(f) GDPR (protection against spam and abuse); transfers to the USA are safeguarded by Standard Contractual Clauses and the EU-U.S. Data Privacy Framework.
2.2. E-mail contact
Enquiries sent to office@bentil.ro, and the personal data they contain, are processed to answer the enquiry and to manage the business relationship (Art. 6(1)(b) and (f) GDPR).
2.3. First-party analytics
We measure use of the website with our own, self-built first-party analytics – we do not use Google Analytics or any other third-party tracker. Data recorded: event name, page URL, language, SHA-256-hashed IP address and user agent. The data is pseudonymised and is not linked to an identified person. Legal basis: Art. 6(1)(f) GDPR – our legitimate interest in measuring site usage and improving our services.
2.4. Consent logging
In line with the accountability principle (Art. 5(2) GDPR) we record the visitor's cookie-consent choice and the version of the consent text. Legal basis: Art. 6(1)(c) and (f) GDPR.
2.5. AI chat assistant
Our website features an AI-based chat assistant. Messages you enter in the chat are transmitted to Anthropic PBC (USA, api.anthropic.com), acting as our processor, in order to generate the response. This constitutes a transfer to a third country (the United States). Transfer safeguards: The transfer is based on the Standard Contractual Clauses adopted by the European Commission (Art. 46(2)(c) GDPR); to the extent Anthropic is certified under the EU-U.S. Data Privacy Framework, the corresponding adequacy decision serves as an additional basis. Please do not enter special categories of data or unnecessary personal data in the chat. Legal basis: Art. 6(1)(b) and (f) GDPR.
2.6. Fonts (self-hosted)
All fonts on this website are served from our own server (self-hosting). No connections are made to Google servers and your IP address is not transmitted to Google.
2.7. WhatsApp links
The WhatsApp links on the website (wa.me) are plain outbound links; no Meta code is embedded in our pages. If you click such a link, WhatsApp's (Meta Platforms) own processing applies, governed by Meta's privacy policy.
2.8. Cookies and local storage
We only use items strictly necessary for operation: the Laravel session cookie (server-side sessions stored in our database, 120 minutes), XSRF-TOKEN (security), the "darkMode" preference in localStorage (display preference) and the consent state. We use no advertising or third-party tracking cookies. Details are set out in our separate Cookie Policy.
3. Recipients and processors
Our hosting provider is Contabo GmbH (Germany); the server is located in the European Union (France). For the chat assistant, Anthropic PBC (USA) acts as processor. We do not sell your data and do not pass it to third parties for marketing purposes; disclosure to authorities takes place only where required by law. Cloudflare, Inc. (USA) acts as a processor for network, security and bot-protection services (including Cloudflare Turnstile); transfers are based on the EU Standard Contractual Clauses. For audience measurement we use Google Analytics 4; the processor is Google Ireland Limited (Ireland). Measurement starts only after your consent, IP addresses are truncated, and advertising and personalisation features are disabled.
4. Retention
We keep enquiries and related data for as long as necessary for the purpose concerned and for the establishment, exercise or defence of legal claims. Consent records are kept for as long as needed to demonstrate compliance. Processing based on consent lasts until the consent is withdrawn. Data that is no longer needed is deleted or anonymised.
5. Your rights
You have the right of access, rectification, erasure ("right to be forgotten"), restriction of processing, data portability, the right to object (Art. 21 GDPR) and the right to withdraw consent at any time. The preferred channel for exercising your rights is the request form at /en/gdpr/request; you may also contact us at office@bentil.ro. Detailed information is available on our GDPR Information page.
6. Remedies
You may lodge a complaint with the Romanian supervisory authority: ANSPDCP – Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal, B-dul G-ral. Gheorghe Magheru 28–30, Bucharest, Romania, dataprotection.ro. You may also lodge a complaint with the supervisory authority of the EU Member State of your habitual residence or place of work, and you have the right to an effective judicial remedy.
7. Changes to this policy
We review this policy from time to time. The current version is always available on this page; in the event of material changes, the date of the update is shown at the top of the document.
Other legal documents
GDPR Data Request
Request access, deletion, or rectification of your personal data.