Privacy Policy (GDPR)
Version: 1.1
Last updated: 27.03.2026.
This Privacy Policy explains how MEDIAHIVE S.R.L. (“MEDIAHIVE”, “we”, “us”, “our”) processes personal data when you visit our website, contact us, or interact with our business.
1. Controller identity and contact details
Data Controller:
MEDIAHIVE S.R.L.
Registered office: Str. Viitorului 447/O Cod 547605, Jud. Mures, Romania
Trade Register no. (J/F no.): J2025070379009
Fiscal code (CUI): 52520782
Email: office@mediahive.ro
Phone: +40749944428
Website: mediahive.ro
Privacy contact:
Email: office@mediahive.ro
Postal address: Str. Viitorului 447/O Cod 547605, Jud. Mures, Romania
Data Protection Officer (DPO):
We are not required to appoint a DPO for our current activities, and we have not appointed one.
If we appoint a DPO, we will update this Policy with the DPO’s contact details.
2. Summary of data we collect
Depending on how you interact with us, we may collect:
A. Contact and identity data: name, email, phone number, company, role/title.
B. Communications content: your message, attachments you send us.
C. Business relationship data (if you become a client/partner): contract details, billing data, project communications.
D. Technical data: IP address, device and browser information, approximate location (derived from IP), website usage data.
E. Cookie identifiers and similar: consent status, cookie IDs, analytics IDs (only if enabled/consented).
We do not intentionally collect special-category data (e.g., health data) via our website.
Please do not send such data to us unless necessary and explicitly requested.
3. Sources of personal data
We collect personal data:
-directly from you (forms, email, phone, meetings);
-automatically from your device (cookies/logs) when you use the website; and
-from third parties where relevant (e.g., referrals, public business profiles), only as permitted by law.
4. Purposes and lawful bases of processing
We process personal data for the following purposes and lawful bases:
A. Responding to inquiries and taking steps prior to a contract
Purpose: responding to contact forms/emails, scheduling calls, preparing proposals.
Lawful basis: performance of a contract or steps at your request prior to entering into a contract (GDPR Art. 6(1)(b)) and/or legitimate interests (GDPR Art. 6(1)(f)).
B. Managing client relationships and delivering services (once contracted)
Purpose: project delivery, account management, coordination, service improvements.
Lawful basis: contract performance (Art. 6(1)(b)) and/or legitimate interests (Art. 6(1)(f)).
C. Legal, accounting, and compliance obligations
Purpose: invoicing, bookkeeping, tax compliance, defending legal claims.
Lawful basis: legal obligation (Art. 6(1)(c)) and/or legitimate interests (Art. 6(1)(f)).
D. Website security and fraud prevention
Purpose: securing the website, preventing abuse, maintaining availability, investigating incidents.
Lawful basis: legitimate interests (Art. 6(1)(f)).
E. Analytics and website improvement (only if enabled and where required, only with consent)
Purpose: measuring website traffic and performance, improving content and UX.
Lawful basis: consent (Art. 6(1)(a)) for non-essential cookies/trackers, where required.
F. Marketing communications (if applicable)
Purpose: sending newsletters, promotions, invitations, or updates.
Lawful basis: consent (Art. 6(1)(a)) and/or legitimate interests (Art. 6(1)(f)) where permissible by law.
You can unsubscribe at any time using the unsubscribe link or by contacting us.
5. Cookie consent and similar technologies
We use cookies and similar technologies. Some are strictly necessary for the website to function.
Non-essential cookies (e.g., analytics/marketing) will be used only if you consent via our cookie consent tools (where applicable).
6. Recipients and categories of recipients
We may share personal data with:
-hosting and infrastructure providers;
-email, calendar, and productivity tool providers;
-CRM and sales/marketing tool providers (if used);
-analytics providers (only if enabled and where required, only with consent);
-accountants, auditors, legal advisers;
-competent public authorities where required by law.
We do not sell personal data.
7. International transfers
We prefer to process data within the European Economic Area (EEA).
If we use vendors or sub-processors outside the EEA, we will ensure a valid transfer mechanism, such as:
-an adequacy decision; or
-Standard Contractual Clauses (SCCs) with supplementary measures where appropriate; or
-another valid GDPR transfer mechanism.
You can request information about our current international transfer safeguards at <<FILL: privacy email>>.
8. Retention periods
We retain personal data only as long as necessary for the purposes described above, then delete or anonymize it, unless we must keep it longer for legal reasons. Our standard retention approach (which may vary by case):
A. Website inquiry leads (no contract): up to 24 months after last contact.
B. Client/contract records: for the duration of the contract and then up to 3 years or longer if required by law or for claims.
C. Accounting and tax-related records (invoices, contracts as supporting documents): typically at least the legal retention period under Romanian law.
D. Cookie consent logs: 12 months, then refreshed or deleted.
E. Security logs: 6 months unless needed to investigate incidents.
If you want our current retention schedule, contact office@mediahive.ro.
9. Security measures
We implement appropriate technical and organizational measures to protect personal data, such as:
-access controls and least privilege;
-MFA where available;
-encryption in transit (TLS/HTTPS) and, where appropriate, encryption at rest;
-backups and recovery procedures;
-logging and monitoring where appropriate;
-vendor due diligence and contractual protections;
-staff confidentiality and training where relevant.
No method of transmission or storage is 100% secure. If you suspect a security issue, contact us immediately.
10. Your rights
Subject to conditions and exceptions under GDPR, you may have the right to:
-access your personal data;
-rectification;
-erasure;
-restriction;
-data portability;
-objection (including to processing based on legitimate interests and to direct marketing);
-withdraw consent at any time (where processing is based on consent), without affecting prior lawfulness.
To exercise rights, contact office@mediahive.ro
We may need to verify your identity before fulfilling your request.
11. Complaints to the supervisory authority
If you believe we have infringed data protection law, you can lodge a complaint with the Romanian supervisory authority:
National Supervisory Authority for Personal Data Processing (ANSPDCP)
Address: 28-30 G-ral Gheorghe Magheru Blvd., District 1, 010336, Bucharest, Romania
Email: anspdcp@dataprotection.ro (or per ANSPDCP’s published contact channels)
Website: dataprotection.ro
You can also contact us first so we can try to resolve your concern.
12. Children
Our website and services are not directed to children. We do not knowingly collect data from children.
13. Changes to this Policy
We may update this Policy. The updated version will be posted on our website with a new “Last updated” date.
14. Enforcement and penalties (informational)
Non-compliance with GDPR and applicable Romanian laws may result in regulator investigations, corrective measures, and administrative fines or other penalties. This section is informational and does not create obligations beyond applicable law.
© 2026 mediahive. All rights reserved.
