Privacy Policy

Last updated: 8 August 2026

This Privacy Policy explains how Hype Media System (“Hype”, “we”, “us”, or “our”) processes personal data when you visit www.hype.ro (the “Site”), contact us, or engage our professional services.

We process personal data in accordance with Regulation (EU) 2016/679 (GDPR), Romanian Law no. 190/2018, and other applicable Romanian and EU data-protection rules.

1. Data controller

The controller of personal data described in this Policy is:

2. Categories of personal data

Depending on how you interact with us, we may process:

  • Identity and contact data — name, company, role, email address, phone number
  • Communication data — messages and attachments you send via contact forms, email, or phone
  • Project and contract data — information needed to quote, contract, deliver, and invoice services (including business contact details of client representatives)
  • Technical and usage data — IP address, browser/device information, approximate location derived from IP, pages viewed, and similar logs generated when you use the Site
  • Cookie and similar technology data — identifiers and preferences stored on your device as described in the Cookies section below

We do not intentionally collect special categories of personal data (GDPR Art. 9) through the Site. Please do not submit such data unless necessary and agreed.

3. Purposes and legal bases (GDPR Art. 6)

We process personal data for the following purposes and legal bases:

  • Responding to enquiries and contact requests — Art. 6(1)(b) (steps at your request prior to a contract) and/or Art. 6(1)(f) (legitimate interest in answering business enquiries)
  • Preparing quotes and performing contracts — Art. 6(1)(b)
  • Invoicing, accounting, and legal compliance — Art. 6(1)(c)
  • Operating, securing, and improving the Site — Art. 6(1)(f) (legitimate interest in a secure, functional website)
  • Analytics and measurement (including via Google Tag Manager / analytics tags, where enabled) — Art. 6(1)(a) (consent), where required; otherwise only to the extent permitted as strictly necessary or under another valid basis
  • Marketing communications about our services (if we send any beyond transactional messages) — Art. 6(1)(a) (consent) or Art. 6(1)(f) where applicable soft-opt-in rules allow, with a clear right to object
  • Establishing, exercising, or defending legal claims — Art. 6(1)(f)

4. How we collect data

  • Directly from you (forms, email, phone, meetings, contracts)
  • Automatically through the Site (server logs, cookies, tags)
  • From client organisations that designate you as a project contact

5. Retention

We retain personal data only as long as needed for the purposes above, including:

  • Enquiry / contact form data — typically up to 24 months after the last meaningful contact, unless a project starts or a longer period is required
  • Contract, project, and invoicing records — for the duration of the relationship and thereafter as required by Romanian accounting and tax rules (often up to 5–10 years for financial records) and for limitation periods for legal claims
  • Technical logs — generally for a shorter operational period, unless needed for security investigations
  • Cookie / consent records — according to the consent tool settings and applicable guidance

When retention ends, we delete or anonymise data, unless a longer storage obligation applies.

6. Recipients and processors

We may share personal data with:

  • Service providers acting as processors (for example hosting, email, website platform/WordPress maintenance, security, and analytics vendors)
  • Professional advisers (legal, accounting) under confidentiality obligations
  • Public authorities where required by law
  • Advertising or analytics providers configured through our tag management (currently Google Tag Manager container GTM-58494PS3), which may load Google or other measurement tools subject to your consent settings where applicable

We require processors to process data only on our instructions and to implement appropriate security measures.

7. International transfers

Some providers (including Google services loaded via Tag Manager) may process data in countries outside the European Economic Area. Where transfers occur, we rely on appropriate safeguards under GDPR Chapter V, such as adequacy decisions or Standard Contractual Clauses, together with supplementary measures where required.

8. Cookies and similar technologies

The Site uses cookies and similar technologies to:

  • Ensure basic Site functionality and security (often strictly necessary)
  • Remember preferences where applicable
  • Measure traffic and campaign performance via analytics/marketing tags loaded through Google Tag Manager, where those tags are active

Where non-essential cookies or similar technologies are used, we seek your consent as required by ePrivacy rules and GDPR. You can withdraw or manage consent through any cookie banner or preference controls we provide, and/or through your browser settings. Blocking some cookies may affect Site features.

For more detail on Google’s processing, see Google’s own privacy documentation for Tag Manager and related products.

9. Your rights

Under the GDPR, you have the right to:

  • Access your personal data
  • Rectify inaccurate data
  • Erase data (“right to be forgotten”), where applicable
  • Restrict processing, where applicable
  • Data portability, where applicable
  • Object to processing based on legitimate interests, and to object to direct marketing
  • Withdraw consent at any time, where processing is based on consent (without affecting prior lawful processing)
  • Lodge a complaint with a supervisory authority

In Romania, the supervisory authority is:

To exercise your rights, email contact@hype.ro. We may need to verify your identity before responding. We aim to respond within one month, subject to GDPR extensions for complex requests.

10. Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or alteration. No method of transmission or storage is completely secure; please use strong unique passwords for any accounts related to projects with us.

11. Children

The Site and our services are directed at businesses and professionals. We do not knowingly collect personal data from children under 16. If you believe we have collected such data, contact us and we will take appropriate steps.

12. Changes to this Policy

We may update this Privacy Policy from time to time. The “Last updated” date at the top will change when we do. Material updates will be published on this page.

13. Contact

For privacy questions or requests:

Related: Terms and Conditions