πŸ”’ GDPR Β· Data Protection Β· Transparency

Privacy Policy

πŸ“… Last update: March 28, 2026 πŸ“‹ Version 2.0 πŸ‡ͺπŸ‡Ί GDPR (EU) 2016/679 Compliant
πŸ‡ͺπŸ‡Ί
Compliant with Regulation (EU) 2016/679 β€” GDPR This policy explains simply and transparently how we treat your personal data.

Welcome to the Craiova City Break website (craiova-travel.go.ro). Your privacy and personal data protection are a priority for us. This policy explains what data we collect, how we use it, how long we keep it, and what your rights are according to the General Data Protection Regulation (GDPR β€” EU Regulation 2016/679).

By using this site, you confirm that you have read and understood this policy. If you do not agree, please do not use the site.

Article 01

Personal Data Controller

πŸ“‹ Identification Data

Name: Craiova City Break β€” Tourist Guide

Responsible Person: Alina Purcaru Nicoleta

Address: Craiova, Dolj County, Romania

Email: alina.purcaru.nicoleta@gmail.com

Website: craiova-travel.go.ro

Social Media: Facebook Β· Instagram

Craiova City Break is a personal tourist website, operated by a physical person. We are not affiliated with the Craiova City Hall or other public institutions.

Article 02

What Data We Collect

We collect only the data necessary for the operation of the site and communication with users. We never request sensitive data (SSN, bank details, medical data).

A. Data provided voluntarily by the user:

  • Contact form β€” Name, email address, and message content. This data is used exclusively to respond to your request.
  • Direct email β€” If you contact us directly via email, we collect the email address and information in the message.
  • Social media β€” If you contact us via Facebook or Instagram, data is managed according to Meta Platforms, Inc. policies.

B. Data collected automatically:

  • Browsing data β€” IP address (anonymized), browser type, pages visited, session duration. Collected through Google Analytics 4 (if enabled).
  • Technical cookies β€” Cookies strictly necessary for the site's operation (GDPR consent, language preferences).
  • Performance data β€” Information about technical errors and page performance, used exclusively for site improvement.

βœ… We do not sell, rent, or transfer your data to any third party for commercial purposes. Data is used exclusively for the purposes described in this policy.

Article 03

Purpose of Data Processing

We process your data exclusively for the following purposes:

  • Responding to requests β€” Data provided via the contact form or email is used exclusively to respond to received messages.
  • Improving the guide β€” Anonymous traffic data helps us understand which sections are more useful to visitors and improve content.
  • Technical operation β€” Necessary cookies ensure the correct functioning of the site (saving GDPR preferences, navigating between pages).
  • Social media sharing β€” Share buttons work via direct redirection and do not collect additional data beyond those managed by the respective platforms.
Article 04

Legal Basis for Processing

We process your data based on the following legal grounds provided by GDPR:

  • Consent (Art. 6 para. 1 lit. a GDPR) β€” For analysis and statistics cookies. Consent can be withdrawn at any time via the "Cookie Settings" button or by deleting cookies from the browser.
  • Legitimate interest (Art. 6 para. 1 lit. f GDPR) β€” For technical cookies strictly necessary for the site's operation and for securing it against unauthorized access.
  • Execution of a contract or pre-contractual measures (Art. 6 para. 1 lit. b GDPR) β€” For data provided via the contact form, for the purpose of managing requests.
Article 05

Data Storage Duration

  • Email messages and contact forms β€” Maximum 2 years from the last communication, after which they are permanently deleted.
  • Google Analytics data β€” Maximum 14 months, according to the recommended GDPR settings for GA4.
  • Technical cookies (GDPR consent) β€” 12 months from the date consent was granted.
  • Technical server logs β€” Maximum 30 days, after which they are automatically deleted.

Upon expiration of the storage period, data is irrevocably deleted or anonymized.

Article 06

Your Rights under GDPR

According to Regulation (EU) 2016/679, you benefit from all fundamental rights regarding personal data:

πŸ‘οΈ Right of access

You can request a copy of the data we hold about you at any time.

✏️ Right to rectification

You can request the correction of inaccurate or incomplete data.

πŸ—‘οΈ Right to erasure

"Right to be forgotten" β€” you can request the erasure of your data at any time.

⏸️ Right to restriction

You can request the restriction of processing in certain circumstances.

πŸ“¦ Right to portability

You can receive the data in a structured, machine-readable format.

🚫 Right to object

You can object to the processing of data based on our legitimate interest.

↩️ Withdrawal of consent

If the processing is based on consent, you can withdraw it at any time.

βš–οΈ Right to lodge a complaint

You can lodge a complaint with ANSPDCP, the supervisory authority in Romania.

πŸ“¬ How to exercise your rights

Send a written request to: alina.purcaru.nicoleta@gmail.com

Response time: 30 calendar days (or 90 days in complex cases, with prior notification).

We do not charge fees for exercising GDPR rights.

πŸ›οΈ National Supervisory Authority

ANSPDCP β€” National Supervisory Authority for Personal Data Processing

Website: dataprotection.ro

Address: 28-30 G-ral Gheorghe Magheru Bld., District 1, Bucharest

Email: anspdcp@dataprotection.ro

Article 07

Cookie Policy

Cookies are small files stored on your device when you visit a site. We use cookies strictly within the limits necessary for the functioning and improvement of the guide.

Cookie Type Purpose Duration
craiova_gdpr_consent Necessary Saves your decision regarding GDPR consent β€” without this, the banner appears on every visit 12 months
_ga, _gid Analysis Google Analytics 4 β€” anonymous traffic statistics (pages visited, session duration, visitor's country). Enabled ONLY with your consent. 14 months / 24h
Session cookies Necessary Maintains navigation state (current page, language preference) during the session Session
Third-party cookies (Facebook, Pinterest) Functional May be set when using share buttons. Managed according to Meta and Pinterest policies. Variable

How to control cookies:

  • Our GDPR Banner β€” On the first visit, you can choose "Accept" or "Decline". Analysis cookies are enabled ONLY upon acceptance.
  • Browser settings β€” You can delete or block cookies in the settings of any modern browser (Chrome, Firefox, Safari, Edge).
  • Google Analytics Opt-out β€” You can disable GA4 tracking by installing the Google Analytics Opt-out Add-on.
Article 08

Services and Third Parties

Our site uses third-party services, each with its own privacy policies:

  • Google Analytics 4 β€” Anonymous traffic statistics. Google Policy. Data processed in the EU/USA with appropriate safeguards (Standard Contractual Clauses).
  • Google Fonts β€” Playfair Display and Source Sans 3 fonts are loaded from Google servers. Google Policy. The IP address may be transmitted to Google upon the first load.
  • Meta Platforms (Facebook, Instagram) β€” Facebook share and Instagram DM buttons. Meta Policy. Data managed by Meta upon clicking the button.
  • Pinterest β€” Pinterest share button. Pinterest Policy.
  • Hosting provider β€” The site is hosted on a secure server. Technical server logs may contain IP addresses, managed according to the hosting provider's policy.

We do not transfer your data to third countries (outside the EU/EEA) without the safeguards provided by GDPR. Where applicable, transfers are based on Standard Contractual Clauses approved by the European Commission.

Article 09

Data Security

We implement appropriate technical and organizational measures to protect your data:

  • HTTPS Connection β€” All data transmitted between the browser and the server is encrypted via the TLS/SSL (HTTPS) protocol.
  • Limited access β€” Data from emails and contact forms is accessible exclusively to the responsible person (Alina Purcaru).
  • Security updates β€” The site's infrastructure is regularly updated to prevent known vulnerabilities.
  • Anonymization β€” Analysis data is collected in anonymized form β€” IP addresses are truncated before storage.

⚠️ Security incident: In the event of an incident affecting your data, we will notify you within a maximum of 72 hours from the identification of the incident, according to Art. 33–34 GDPR.

Article 10

Minor Protection

The Craiova City Break website is intended for an adult audience and adolescents accompanied by parents/guardians. We do not intentionally collect personal data from persons under 16 years of age (minimum age for digital consent in Romania, according to GDPR).

If you are a parent or legal guardian and have reason to believe that a minor has provided us with personal data through our site, please contact us at alina.purcaru.nicoleta@gmail.com to delete this data immediately.

Article 11

Changes to the Policy

We reserve the right to periodically update this privacy policy to reflect legislative, technical, or operational changes. The updated version will be published on this page with a new effective date.

We recommend periodic checking of this page. Continued use of the site after the publication of changes constitutes acceptance of the new version of the policy.

Substantial changes will be announced through the site's notification banner or, if you have previously contacted us, via email.

Article 12

Data Protection Contact

For any question, request, or complaint related to the processing of your personal data, you can contact us via:

πŸ“¬ GDPR Contact Details

Email: alina.purcaru.nicoleta@gmail.com
Mention in the subject: "GDPR Request"

Response time: Maximum 30 calendar days (Art. 12 GDPR)

Contact page: craiova-travel.go.ro/contact.html

If you are not satisfied with the response received, you have the right to lodge a complaint with ANSPDCP (National Supervisory Authority for Personal Data Processing): dataprotection.ro.

πŸ“…
This policy came into effect on March 28, 2026 and replaces all previous versions. Current version: 2.0.
πŸ’¬