Privacy Policy
Last updated: 9 October 2026
Notice on the processing of personal data, in accordance with Article 13 of Regulation (EU) 2016/679 (the General Data Protection Regulation, “GDPR”).
In short
- The solanord.ro website is an information-only site. It has no user accounts, sells nothing online and has no newsletter.
- We do not use traffic analytics, advertising, social media plugins or any other tracking services.
- Like any website, it automatically receives your IP address and some technical data, which are needed to display the pages and for security.
- We receive other personal data only if you write to us through the contact form or by email. We use it to reply to you.
- The contact form is protected by a security check from Cloudflare (Turnstile), which runs when the form comes into view on the page.
- Your choice about cookies is managed with CookieYes, a service of CookieYes Limited. Each time a page opens, this service receives your IP address and some technical data.
- We do not sell your data. We do not give it to other companies for their own purposes, with one exception: Cloudflare also uses the technical signals from the security check to improve its detection of automated programs.
Who is responsible for your data
The data controller is:
SOLANORD PANELS S.R.L.
- Registered office: Sat Moisei, Comuna Moisei, nr. 1106A, jud. Maramureș, postal code 437195, Romania
- Trade register number: J2021001773243
- Unique registration code (CUI): RO45096529
- EUID: ROONRC.J2021001773243
- Email: office@solanord.ro
We have not appointed a data protection officer, because the law does not require us to do so. For any question about your data, write to us at office@solanord.ro.
What data we process
Data from the contact form
- your name (required);
- your company (optional);
- your email address (required);
- your phone number (optional);
- your message (required) and any information you choose to include in it;
- your confirmation that you agree to the website’s terms and conditions and have read this policy (the box you tick before sending, required), with the date and time at which we received the message;
- the language in which you used the website (so that we can answer in the same language).
Please do not include sensitive data in your message (for example, data about health), or data about other people, unless it is necessary.
Email correspondence
If you write to us directly, or if we continue the conversation by email, we process your address, the content of the messages and the details in your signature.
Technical data
When you open the website, we automatically receive your IP address and technical data about the request: the date and time, the page requested, and the type of browser and device. This data passes through Cloudflare, the service that delivers and protects the website, and through the server on which the website is hosted.
When you open the address solanord.ro without a language, the website chooses the language of the page from the country that Cloudflare derives from your IP address (Romanian for Romania, Italian for Italy, English for any other country) or, when the country is not known, from the language set in your browser. This choice is not stored, and you can choose another language from the menu at any time.
When you submit the form, your IP address is kept for about ten minutes in the server’s memory, solely to limit repeated submissions. Before accepting the message, the server also sends this IP address to Cloudflare, for the security check described below. The website application does not write the IP address to disk and does not record it in logs.
The security check on the form
The contact form is protected by Turnstile, a security check provided by Cloudflare, Inc. (United States), which distinguishes real visitors from automated programs. The check is loaded when the form comes into view on the page. Most of the time you are not asked to do anything; sometimes you have to tick a box.
During the check, Cloudflare receives your IP address, technical data about the connection (the TLS fingerprint), the browser type (the User-Agent header), the address of the website and the public key of the form. It also receives the results of tests carried out in the browser: technical characteristics of the browser and the device and signals indicating that the form is being used by a person. According to Cloudflare, Turnstile does not read or transmit what you type in the form.
The result is a single-use code, valid for five minutes, which is sent together with the form. Before accepting the message, our server sends this code and your IP address to Cloudflare, which confirms whether or not the check was passed. Our server does not keep the code and does not record it in logs.
Your choice about cookies
Each time a page opens, your browser loads the consent banner from the servers of CookieYes, a service of CookieYes Limited, and reports to them that the banner has loaded. When this happens, your IP address, the browser language, the browser type (the User-Agent header), the address of the site and the random identifier kept in the cookieyes-consent cookie are processed. According to the documents CookieYes publishes, the data it processes includes the IP address and the approximate location derived from it.
When you make a choice in the banner, CookieYes records the choice per category, the date and time, the language of the banner and the random identifier of the choice; the request also carries your IP address and the browser type. The choice is remembered in your browser by the cookieyes-consent cookie, described on the cookies page.
What the website does not do
The website does not save the form data in a database: the message is sent by email and remains only in our mailbox. The website’s code does not set cookies and does not use the browser’s local storage. The cookies that may appear are the one that remembers the choice you made in the consent banner (cookieyes-consent, set by CookieYes) and Cloudflare’s security cookies. They are described on the cookies page. The security check on the form runs in a separate Cloudflare frame; it too is described on the cookies page.
Why we use the data and on what legal basis
1. To reply to you and, where appropriate, to prepare an offer
We use the data from the form and from correspondence to respond to your enquiry.
- If you write on your own behalf, as a potential contracting party, the legal basis is Article 6(1)(b) GDPR: steps taken at your request before entering into a contract.
- If you write as a representative or employee of a company, the legal basis is Article 6(1)(f) GDPR: our legitimate interest in responding to business enquiries and in keeping in touch with the contact persons of the companies we are in discussions with.
2. To confirm that we have received your message
After you submit the form, you automatically receive a confirmation email at the address you provided. The message is purely informational and contains no advertising. The legal basis is the same as under point 1.
If someone entered your address by mistake or without the right to do so, you receive this single message on the basis of our legitimate interest in confirming receipt of enquiries (Article 6(1)(f) GDPR). The address comes from the person who filled in the form. Write to us and we will delete the message and the address.
3. To protect the form against abuse
We keep your IP address for about ten minutes in order to limit repeated submissions. In addition, the form is protected by the Cloudflare Turnstile security check described above: a message is accepted only after Cloudflare confirms that the check was passed. The legal basis is Article 6(1)(f) GDPR: our legitimate interest in preventing spam and misuse of the form.
4. To deliver the website securely
Your IP address and the technical data of the request are processed in order to display the pages, in a language suited to your country or browser when you open the address without a language, and to protect against cyberattacks. The legal basis is Article 6(1)(f) GDPR: our legitimate interest in having a working and secure website.
5. To comply with our legal obligations and to defend our rights
If the discussion leads to a contract, we keep the related documents and correspondence for as long as the law requires (Article 6(1)(c) GDPR) and for as long as is necessary to be able to defend our rights in any dispute (Article 6(1)(f) GDPR – our legitimate interest in defending our rights). We also keep the requests by which you exercise the rights described below, together with our replies, on the basis of our legitimate interest in being able to show that we handled them in accordance with the law (Article 6(1)(f) GDPR).
With each message from the form we also keep the confirmation ticked in the form (agreement to the website’s terms and that you have read this policy), with the date and time of receipt, on the basis of our legitimate interest in being able to show the conditions under which the message was sent to us (Article 6(1)(f) GDPR). This confirmation is not consent to the processing of your data: the processing rests on the legal bases set out under point 1.
6. To manage your choice about cookies and to be able to prove it
We display the consent banner, remember the choice made and keep a record of it. The legal basis is Article 6(1)(f) GDPR: our legitimate interest in managing choices about cookies and in being able to prove them. To the extent that the law requires us to be able to demonstrate consent, the legal basis is Article 6(1)(c) GDPR, in conjunction with Article 7(1).
We do not use your data for marketing and we do not send you unsolicited commercial messages.
Are you required to give us this data?
No. There is no legal or contractual obligation to provide us with data. However, without a name, an email address and a message we cannot reply to you, so the form cannot be submitted without them. The company and the phone number are optional. The form also requires you to tick the confirmation box (agreement to the website’s terms and that you have read this policy); without it the message is not sent, but you can write to us directly at office@solanord.ro. Nor can the form be submitted without the security check; if you prefer not to go through it, you can write to us directly at office@solanord.ro.
Who else has access to the data
The data reaches the people in our company who handle enquiries, the people who technically administer the website and the servers (only as far as is necessary for maintenance), and the providers whose services we use for the website:
- Cloudflare – the provider of the content delivery network and security services. All traffic to the website passes through its network, including the data you send through the form. It acts as our processor, on the basis of a data processing agreement. Cloudflare, Inc. (United States) also provides Turnstile, the security check on the form. For detecting and blocking automated programs on our website it likewise acts as our processor. However, Cloudflare also uses the signals from the check to improve its detection of automated programs; for that processing it is an independent controller and relies on its legitimate interest. Details: the Cloudflare Turnstile Privacy Addendum and the Cloudflare Privacy Policy.
- The hosting provider – the company from which we rent the servers on which the website and the company’s email run. It acts as our processor.
- CookieYes Limited (3 Warren Yard, Warren Park, Wolverton Mill, Milton Keynes, MK12 5NW, United Kingdom) – the provider of the CookieYes service, through which we display the consent banner and keep a record of choices about cookies. It acts as our processor, on the basis of a data processing agreement. It in turn uses other providers (sub-processors); for the banner shown to visitors these are Amazon Web Services (hosting and storage in Ireland) and Cloudflare, Inc. (United States), through whose network the banner is delivered. Details: the CookieYes Privacy Policy, the data processing agreement published by CookieYes and its list of sub-processors.
Messages from the form are sent through the company’s own mail server, which we administer ourselves, and arrive in the office@solanord.ro mailbox. We do not use an external email sending service.
We do not sell, rent or pass on your data to other companies for their own purposes, with the exception set out above for Cloudflare. We disclose data to public authorities only when the law requires us to.
Transfers outside the European Union
Some of our providers may also process data outside the European Union or the European Economic Area (EEA), in the situations below.
Cloudflare operates a global network, and some data (for example, the IP address and the technical data of the request, as well as the data from the security check on the form) may also be processed outside the EEA, including in the United States. The following safeguards apply in these situations:
- Cloudflare, Inc. is certified under the EU–U.S. Data Privacy Framework, for which the European Commission has adopted an adequacy decision;
- for other transfers, the standard contractual clauses approved by the European Commission apply; they are included in the data processing agreement concluded with Cloudflare.
If you would like more information about these safeguards, or a copy of them, write to us at office@solanord.ro.
CookieYes Limited is established in the United Kingdom, for which the European Commission has adopted an adequacy decision. According to CookieYes, the records of choices about cookies are hosted in the European Union (Amazon Web Services, Ireland). The banner is delivered through the network of Cloudflare, Inc. (United States), which operates worldwide; for transfers to it CookieYes relies on the EU–U.S. Data Privacy Framework and on standard contractual clauses.
How long we keep the data
- The IP address used to limit submissions: about ten minutes, in the server’s memory. It is then deleted automatically.
- The technical logs of our servers (web server and mail server), to the extent that they are kept: no more than 30 days.
- Cloudflare security cookies: the check normally stays valid for 30 minutes; see the cookies page for details.
- The security check on the form: the code produced by the check is valid for five minutes and can be used only once. We ourselves keep nothing from this check. Cloudflare does not publish an exact retention period for the signals it processes.
- Your choice about cookies: the
cookieyes-consentcookie stays in the browser for one year; some browsers, Safari for example, delete it after 7 days. According to CookieYes, the record of the choice is kept for no more than 12 months, as proof. The other data CookieYes receives when the banner loads (IP address and technical data) is kept as described in its privacy policy. - Messages that do not lead to a working relationship: no more than 12 months from the last message exchanged, after which we delete them from the mailbox.
- Messages that lead to a contract: for the duration of the working relationship and, after it ends, for the periods laid down by law, for example the general limitation period of 3 years and the retention periods for accounting documents.
If you ask us to delete the data earlier and we have no legal reason to keep it, we delete it.
Your rights
You have the following rights:
- the right of access – to find out whether we process data about you and to receive a copy of it;
- the right to rectification – to ask for inaccurate data to be corrected or incomplete data to be completed;
- the right to erasure – to ask for the data to be deleted, in the cases provided for by law;
- the right to restriction of processing – to ask for the use of the data to be limited, for example while we verify the accuracy of data that you contest or an objection you have made;
- the right to data portability – to receive the data you have provided to us in a structured, commonly used format, or to ask for it to be transmitted to another controller, in the cases provided for by law;
- the right to withdraw your consent – where processing is based on consent (for example, in the case of photographs), you can withdraw it at any time. Withdrawal does not affect processing carried out up to that point. You can change or withdraw the choice you made in the consent banner through the “Cookie settings” link in the footer of every page.
How to exercise your rights
Send an email to office@solanord.ro or a letter to our registered office. Tell us which right you wish to exercise and which data your request concerns.
We will reply within one month of receiving the request. If the request is complex, this period may be extended by up to two further months; in that case we will let you know within the first month and explain the reason. We do not charge fees for requests; the law allows a fee only for manifestly unfounded or excessive requests. If we cannot identify you with certainty, we may ask you for additional information, solely to make sure that we do not give the data to someone else.
Your right to object
You have the right to object at any time, on grounds relating to your particular situation, to processing we carry out on the basis of our legitimate interests (answering enquiries sent on behalf of a company, protecting the form, website security, keeping a record of choices about cookies, defending our rights). Write to us at office@solanord.ro. We will stop the processing unless we have compelling legitimate grounds to continue it or the data is needed for the establishment, exercise or defence of legal claims.
The right to lodge a complaint
If you believe that we are processing your data in breach of the law, you can lodge a complaint with the supervisory authority in Romania:
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) – the Romanian National Supervisory Authority for Personal Data Processing
- Address: B-dul G-ral. Gheorghe Magheru nr. 28-30, Sector 1, postal code 010336, București, Romania
- Phone: +40.318.059.211, +40.318.059.212
- Fax: +40.318.059.602
- Email: anspdcp@dataprotection.ro
- Website: www.dataprotection.ro (the “Plângeri RGPD” section, i.e. GDPR complaints)
If you live or work in another Member State of the European Union, you can also lodge the complaint with the supervisory authority of that State.
You can also bring the matter before the competent court. It would help us if you wrote to us first, so that we can try to resolve the problem directly, but you are not obliged to do so.
Automated decisions and profiling
We do not take decisions based solely on automated processing of data that produce legal effects concerning you or similarly significantly affect you, and we do not create profiles of visitors. There are three automated mechanisms on the form: the temporary limiting of repeated form submissions, a simple filter against automated programs (a hidden field that people do not see and do not fill in) and the Cloudflare Turnstile security check. Messages stopped by the filter are not sent to us. Likewise, a message that does not pass the security check is not sent; the same happens if Cloudflare cannot be reached. In these two situations you are shown an error message. That is the only consequence; the check does not produce legal effects concerning you. You can write to us directly at office@solanord.ro at any time. The choice of language when you open the address solanord.ro without a language, described above, is also automatic; its only effect is the language in which the page is shown, and you can change it from the menu. Messages are read and handled by a person.
The photographs on the website
The photographs on the website show people from our team at work and ships under construction. The image of a person who can be recognised is personal data. We publish photographs in which our colleagues can be recognised only with their consent, and that consent can be withdrawn at any time.
Other people who were on site may appear in the background of some photographs. We take care that they cannot be recognised; if you nevertheless recognise yourself, write to us and we will remove the image or make you unrecognisable.
If you appear in a photograph on the website and would like it removed, or would like your face to be made unrecognisable, write to us at office@solanord.ro and indicate the image. We will deal with the request as quickly as possible, without asking you for a justification.
Children
The website is aimed at companies and professionals in the marine and shipbuilding sector. It is not intended for children and we do not knowingly collect data from persons under 18. If we learn that we have received such data, we delete it.
How we protect the data
- the connection to the website is encrypted (HTTPS/TLS);
- the website is protected by Cloudflare’s security services;
- the contact form is protected by a security check from Cloudflare (Turnstile);
- the website does not keep messages in a database, which reduces the risk in the event of an incident;
- access to the mailbox is limited to the people who need it and is protected by a password.
No measure guarantees absolute security. If an incident occurs that is likely to result in a high risk to you, we will notify you in accordance with the law.
Changes to this policy
We update this page when the way the website works, or the legislation, changes. The applicable version is the one published here, with the date shown at the top of the page.
Language versions
This policy is available in Romanian, English and Italian, with the same content. If you notice a difference between the versions, please write to us at office@solanord.ro; a translation difference does not reduce your rights.
