Skip to content
Get a quote

Legal document

Privacy policy

What data we collect through the site's forms, on what legal basis, how long we keep it and what rights you have.

Master document, in Romanian. The English translation (the site’s primary version) and the Korean one are produced natively, by a translator or lawyer, not automatically; any difference of legal nuance between versions is a risk, especially in the sections on data transfers to South Korea and the United States. The Romanian file is the source content the translations start from.

This text is not legal advice and cannot be published as it stands. Every [TO BE COMPLETED] mention must be replaced with the company’s real details, and every [LAWYER VALIDATION] mention must be confirmed by a lawyer (ideally one experienced in data protection and, given the South Korean office, with access to local PIPA advice) before launch.

This source document was last updated: 5 September 2026.


1. Who we are and how to contact us

This site (alucardgroup.com) is operated by Alucard Solutions Ltd, with its registered office at 112 Morden Road, London, SW19 3BP, United Kingdom, registered at Companies House, England and Wales, under number 16241340 (“we”, “Alucard”, “the controller”).

Alucard Group is a group with a presence in several countries: Romania (head office, Bucharest), the United States of America (Chicago, IL) and South Korea (Seoul) [TO BE CONFIRMED with the client: the exact legal names, legal forms and addresses of each entity]. For the purposes of this policy, the entity named above is the data controller for the information collected through this site, whatever language you visit it in. The other group entities are mentioned on the site (footer, the “About” page) for transparency about our international presence, but as a rule they do not process the data you submit through this site’s forms, except in the situations explicitly described in Section 6 (international transfers).

[LAWYER VALIDATION]: confirmation of which group entity is correctly designated as the sole data controller for the site, particularly if the South Korean or US team has direct access to the leads collected through the form (in which case it could be considered a joint controller or a separate controller, not merely an internal recipient).

For any question about this policy or about your data, you can write to us at:

  • Dedicated data protection email: [TO BE COMPLETED e.g. privacy@alucardgroup.com]
  • General email: office@alucard.ro
  • Phone: +40 752 842 371

We do not currently have a formally appointed data protection officer (DPO); as a rule, an agency of our size does not fall under the obligation to appoint a DPO under Art. 37 GDPR. [LAWYER VALIDATION] whether the marketing and advertising work we carry out for clients involves, at the scale at which it is actually done, large scale processing of sensitive data on their behalf, which would change that conclusion.


2. What data we collect, and from where

2.1 The data you give us directly, through a form

The site has several types of form (quote request, general contact, question about a portfolio project, newsletter sign-up, job application), all built on the same basic structure. Depending on the form used, we collect:

Data Required? Why we ask for it
Name Yes So we know who we are replying to
Email address Yes The main channel for our reply
Phone number No Only if you prefer us to call you
Company No Context for the proposal we prepare
Your company website No Helps us understand the project before we reply
Services of interest No We route the request to the right team
Estimated budget No Helps us prepare a realistic proposal
Your message (max. ~2000 characters) Yes, for the general contact form The actual content of the request
The language of the page you submitted the form from Yes (automatic) So we reply in the right language
The box confirming you agree to the processing of your data under this policy Yes Confirmation that you have read this notice
The separate newsletter subscription box No Optional, unticked by default, distinct from submitting the form

Fields marked “no” can be left blank; we do not block your submission if you leave them out, except for those expressly marked “yes”.

2.2 Data collected automatically, technically, when a form is submitted

Along with the form, we also store a few technical items, needed for security, correct attribution of the request, and spam prevention:

  • The page the form was submitted from and, where applicable, the page you came from (referrer);
  • Campaign parameters (UTM), if you arrived on the site through a campaign link (utm_source, utm_medium, utm_campaign, utm_term, utm_content); these tell us which marketing channel brought you to us, so we know what works, not to profile you individually;
  • The IP address, but never in raw or readable form; we store a truncated hash of the IP address (an irreversible technical fingerprint, not the address itself), which is enough to limit the number of submissions from the same source within a short interval (anti-spam protection) and to investigate any abuse. We cannot reconstruct the original IP address from that hash;
  • The browser user agent (which browser or device you used), technically useful for troubleshooting and for detecting automated traffic (bots);
  • A score or result from the anti-bot verification system (Cloudflare Turnstile), which confirms that the form was submitted by a person rather than an automated script; it does not involve a Google account and does not set cross-site tracking cookies;
  • If a hidden “trap” field (a honeypot, invisible to real visitors) is filled in automatically by a bot, we flag that internally; it does not affect you as a real person.

2.3 Data from browsing the site (traffic analytics)

See the Cookie Policy (a separate document) for full details of which analytics tools we use, what data each one collects and how you can withdraw your consent. In short:

  • We use an analytics tool that is cookieless and free of personal data (for example Plausible/Fathom or equivalent), active by default, for aggregate traffic statistics; it does not identify you individually and does not require your consent.
  • We use, only if you give explicit consent through the cookie banner, Google Analytics 4 (with Google Tag Manager) for more detailed analysis and for tracking the effectiveness of advertising campaigns, and Microsoft Clarity for session recordings and interaction maps (heatmaps), with automatic masking of anything typed into form fields.

2.4 Data received from third party sources

We do not buy or obtain contact lists from third parties. The only data we receive “indirectly” is what advertising platforms (Google Ads, Meta and others) send us in the form of aggregate campaign statistics, not individual personal data about visitors.


Purpose GDPR legal basis Explanation
Replying to a quote request or technical brief Art. 6(1)(b), steps taken at your request prior to entering into a contract You explicitly asked us for a commercial conversation
Replying to a general contact message Art. 6(1)(f), our legitimate interest in handling incoming enquiries efficiently We assessed that this interest does not override your rights; you can object at any time (Section 8)
Sending the newsletter Art. 6(1)(a), your explicit, separate consent Only if you ticked the distinct box, which is unticked by default
Preventing spam and abuse on the form (rate limiting, anti-bot verification) Art. 6(1)(f), legitimate interest in the security of the service Technically necessary, proportionate, and it does not profile you
Aggregate traffic analytics (the cookieless layer) No personal data involved GDPR does not apply to this layer, given the configuration used
GA4/GTM analytics and session recordings (Clarity) Art. 6(1)(a), your consent, given through the cookie banner Active only after you choose “Accept” for that category
Retaining financial and accounting documents for clients Legal obligation (the Romanian Fiscal Code and accounting legislation) A statutory 5 year term, not optional

We use no automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you (Art. 22 GDPR). If we ever introduce an automated lead scoring system that affects how we handle your request, we will update this section before switching it on.


4. Who we share your data with (recipients)

We do not sell or rent your data to third parties for other companies’ marketing. We share it only with the technical suppliers needed to run the site and our internal processes, each under its own data processing agreement (DPA) in line with Art. 28 GDPR:

  • Hosting of the site and of the lead database: [TO BE COMPLETED the chosen hosting provider and the server location].
  • Email sending (internal notifications and automatic confirmations to you): [TO BE COMPLETED the chosen email provider].
  • Traffic analytics: the cookieless tool used by default ([TO BE COMPLETED Plausible, Fathom or the chosen equivalent]) and, subject to consent, Google Analytics 4 / Google Tag Manager (Google Ireland Limited / Google LLC).
  • Interaction maps and session recordings, subject to consent: Microsoft Clarity (Microsoft Corporation).
  • Anti-spam and anti-bot verification: Cloudflare Turnstile (Cloudflare, Inc.).
  • CRM, if and when an integration is switched on: [TO BE COMPLETED the name of the CRM, if and when one is chosen].

Each of these suppliers acts as a data processor and handles the data exclusively on our instructions, under a processing contract, and does not use it for its own purposes.


5. How long we keep your data

Category of data Retention period
A lead that does not become a client (contact or quote form) [TO BE COMPLETED exact period agreed with management; recommendation 12-24 months from last contact], then deletion or anonymisation
A lead that becomes a client The data moves onto the basis of the contract signed with you; the related financial and accounting documents (invoices, contracts) are kept for 5 years, a statutory term
Newsletter subscriber Until you unsubscribe, plus a short technical clean-up period (up to 30 days)
Anti-spam logs / IP hashes for rate limiting A short, technical term; deleted automatically no later than 24 hours after collection
Traffic analytics data (GA4, if accepted) According to the retention window configured in the platform: [TO BE COMPLETED the exact value chosen in GA4]

We do not keep data “forever”. Once the period expires, the data is permanently deleted or irreversibly anonymised, so that it can no longer identify you.


6. International data transfers

Alucard Group has a presence in Romania (EU), the United States of America and South Korea. Depending on how the teams and the technical infrastructure are organised, your data may be transmitted to or accessible from outside the European Economic Area. Here are the mechanisms that apply:

  • South Korea benefits from a European Commission adequacy decision (adopted in December 2021), which means that, in principle, transferring personal data from the EU to South Korea is permitted without additional safeguards, for the data covered by that decision. [LAWYER VALIDATION]: confirmation that this site’s actual data flow (leads collected through the form, accessible to the team in Korea) falls entirely within the scope of the adequacy decision, or whether the Korean entity in fact acts as a separate data controller, in which case additional safeguards may be required (for example, Standard Contractual Clauses).
  • The United States of America: transfers to American suppliers or entities are made only to companies certified under the EU-US Data Privacy Framework (DPF), or on the basis of another valid mechanism (Standard Contractual Clauses). [TO BE COMPLETED / LAWYER VALIDATION]: the DPF certification of the American entities and suppliers involved (including, where applicable, the Alucard entity in Chicago) is to be confirmed before launch.
  • For visitors from South Korea who complete the form on the KO version of the site: if your data is transferred outside Korea (for example, to our infrastructure hosted in the EU), Korean law (PIPA) requires separate and explicit consent for that transfer, distinct from general consent to data processing. That dedicated consent is requested from you, where applicable, directly in the form on the Korean version, with details of the purpose of the transfer, the recipient and the retention period. [LAWYER VALIDATION by local Korean counsel].

Our stated design intent is to keep the leads we collect in a single central database, hosted in the European Union, with access granted to the teams at our other offices where necessary, rather than uncontrolled copies or exports; that reduces the real surface of data transfer outside the EU.


7. Cookies and similar technologies

For full details of the cookie categories we use, the purpose of each, their lifetime and how you can withdraw or change your consent, see the Cookie Policy (the site’s “Cookies” page). This privacy policy covers only the processing of personal data resulting from the use of accepted cookies; the technical rules on consent are set out in full in that dedicated document.


8. Your rights

Under GDPR, you have:

  • the right of access, to find out what data we hold about you;
  • the right to rectification, to correct inaccurate or incomplete data;
  • the right to erasure (the “right to be forgotten”), to ask for your data to be deleted when there is no longer a legal basis for keeping it;
  • the right to restriction of processing, in certain situations (for example, if you contest the accuracy of the data);
  • the right to data portability, to receive your data in a structured format, so you can transmit it to another controller;
  • the right to object, to object to processing based on legitimate interest (for example, general contact);
  • the right to withdraw your consent at any time, for processing based on consent (newsletter, analytics or marketing cookies), without affecting the lawfulness of processing carried out before withdrawal;
  • the right to lodge a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP), www.dataprotection.ro, or with the supervisory authority in your country of residence if that is not Romania; for visitors from South Korea, the competent local authority is the Personal Information Protection Commission (PIPC), if Korean law applies to your particular situation (see Section 6).

To exercise any of these rights, write to [TO BE COMPLETED dedicated data protection email]. We will reply within 30 days of receiving your request (the statutory GDPR deadline), once we have verified your identity, to make sure we do not disclose data to someone not entitled to it.


9. Is providing your data mandatory?

Providing the data marked “required” in the form is necessary for us to be able to answer your enquiry; if you do not fill it in, we will not be able to process the request. Providing the optional data (phone, company, estimated budget and so on) is up to you and does not block your submission of the form.


10. Children under 16

The Alucard Group site and services are aimed at companies and professionals, not at minors. We do not knowingly collect data from people under 16. If we learn that we have unintentionally collected such data, we will delete it. [LAWYER VALIDATION] whether the careers page collects data from minor applicants (for example, internships for students under 16); unlikely, but to be confirmed.


11. Changes to this policy

We may update this policy from time to time, for example when we change a technical supplier, add a new type of form, or when the applicable legislation changes. The date of the last update is shown at the top of the document. In the case of significant changes (for example, a change to the main legal basis or to the recipients of the data), we will inform you through a visible notice on the site, not merely by silently updating the date.


12. Contact

For any question about this policy or about your personal data:

  • Email: [TO BE COMPLETED dedicated data protection email]
  • General email: office@alucard.ro
  • Phone: +40 752 842 371
  • Postal address: 112 Morden Road, London, SW19 3BP, United Kingdom

What has to be completed before publication

Company details ([TO BE COMPLETED]), 11 markers:

  1. The full legal name of the operating entity (Section 1)
  2. The registered address of the operating entity (Sections 1 and 12)
  3. The Trade Register number (Section 1)
  4. The VAT/registration code (Section 1)
  5. The legal names, legal forms and addresses of the US and South Korean entities (Section 1)
  6. The dedicated data protection email (Sections 1, 8, 12)
  7. The hosting provider and the server location (Section 4)
  8. The transactional email provider (Section 4)
  9. The chosen cookieless analytics tool (Section 4)
  10. The name of the CRM, if and when one is chosen (Section 4)
  11. The exact retention period for leads that do not become clients, agreed with management (Section 5)

Points for legal validation ([LAWYER VALIDATION]), 6 markers:

  1. Confirmation of the entity correctly designated as the sole data controller for the site (Section 1)
  2. Whether a formal DPO is required, depending on the real scale of the marketing processing carried out for clients (Section 1)
  3. The scope of the EU-South Korea adequacy decision for this site’s actual data flow (Section 6)
  4. The Data Privacy Framework certification of the American entities and suppliers involved (Section 6)
  5. The mechanism for separate consent to data transfer outside Korea, on the KO version of the form, validated with local PIPA counsel (Section 6)
  6. Confirmation that the careers page does not collect data from minors under 16 (Section 10)

To be confirmed with the client (not a legal marker, but it blocks the items above): the exact nature of the presence in South Korea and the US (own legal entity / partner / local office only); this determines who is a controller versus a mere internal recipient, with direct impact on Sections 1 and 6.