PRIVACY POLICY
Last updated: 25 June 2026
1. Introduction
The confidentiality of your personal data is an essential priority for VELARIUM (the "Operator" or "we"). Through this Privacy Policy we commit to protecting your data and complying with Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR).
This Policy explains what data we collect through the website velarium.com (the "Site"), how we use it, when we may disclose it to third parties, and how you can exercise your legal rights.
Data controller: VELARIUM
Legal name: NOCTURN BUILDING CONSTRUCT S.R.L.
VAT no.: 45347973 · Trade Register no.: J2021004035135
Registered office: Calea Victoriei 155, block D1, Bucharest, Romania
E-mail: office@velarium.ro · Telephone: +40 733 610 787
2. What data do we collect?
We collect data when you interact with us by completing contact forms, quotation requests or project uploads, or by browsing the Site. The data collected includes:
- Identification data: first name, last name;
- Contact data: e-mail address, telephone number;
- Location data: the city or country relevant to the project;
- Project details: project type (house, hotel, restaurant and so on), approximate dimensions, estimated budget, preferred timeline, additional messages, and photos, PDFs or drawings uploaded through the forms;
- Technical browsing data: IP address, browser type, pages visited, visit duration and interaction with our pages, collected through cookies and similar technologies (for example Google Analytics).
3. Purpose and legal basis for processing
Your personal data is collected and processed for the following purposes and on the following legal grounds:
- Performance of a contract, or steps prior to a contract: we use the data provided in the forms to send you bespoke price quotations, technical specifications and 3D renders, or to schedule measurements and site visits (Art. 6(1)(b) GDPR).
- Your consent: we collect non-essential browsing data (through cookies) only after you have given explicit consent through the cookie banner (Art. 6(1)(a) GDPR). Ticking the box accepting the Terms and the Policy within a form also constitutes your consent to the processing of the data submitted for quotation purposes.
- Legitimate interest: to improve our services, optimise and secure the Site, and handle legitimate requests (Art. 6(1)(f) GDPR).
4. How long do we keep your data?
We keep personal data only for as long as is necessary for the purposes for which it was collected, as follows:
- Quotation requests that do not lead to a contract: a maximum of 1–2 years from the last interaction, or until consent is withdrawn or erasure is requested;
- Contract and warranty data: for the duration of the contract and the warranty period of the installed systems;
- Accounting and tax documents: for the period required by applicable law (as a rule 10 years under Romanian accounting legislation);
- Cookies: for the periods described in the Cookie Policy.
Once these periods expire, the data is securely deleted or anonymised.
5. Recipients of personal data
Your data is treated with the utmost confidentiality. VELARIUM does not sell, rent or disclose your data to third parties for marketing purposes. Data may be transmitted only to:
- our employees and authorised technical consultants who handle quotations and installations;
- our form infrastructure provider (processing and transmission of requests submitted through the forms on the Site), acting as a processor under a data processing agreement in accordance with Art. 28 GDPR;
- IT, hosting and web maintenance providers for the Site;
- analytics and marketing service providers (Google — Google Analytics; Meta Platforms — Meta Pixel), only on the basis of the consent you give through the cookie banner;
- public authorities or institutions, only where there is a legal obligation to do so.
6. International data transfers
Some of our analytics and marketing service providers (Google and Meta) may process data outside the European Economic Area, including in the United States. Such transfers take place only if you have consented to the relevant cookies and are protected by appropriate legal mechanisms, such as the European Commission's Standard Contractual Clauses and the EU–U.S. Data Privacy Framework, in accordance with Chapter V of the GDPR.
7. Your rights under the GDPR
Under the GDPR you have the following rights, which you can exercise at any time:
- Right of access: you may request confirmation that your data is being processed and a copy of it;
- Right to rectification: you may ask us to correct inaccurate data or complete incomplete data;
- Right to erasure ("right to be forgotten"): you may request deletion of your data where it is no longer necessary for the original purposes, or where you withdraw your consent;
- Right to restriction of processing: you may request that processing be temporarily restricted in certain cases;
- Right to data portability: you may request the transfer of your data to another controller in a structured format;
- Right to object: you may object to processing based on a legitimate interest;
- Right to withdraw consent: you may withdraw your consent at any time (for example, for cookies, via the "Cookie settings" link in the footer). Withdrawal does not affect the lawfulness of processing carried out before it;
- Right to lodge a complaint: you have the right to lodge a complaint with a supervisory authority — the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral Gheorghe Magheru 28-30, Bucharest, e-mail anspdcp@dataprotection.ro, web www.dataprotection.ro — or with the supervisory authority in your country of residence.
To exercise these rights, simply send a request to office@velarium.ro. We will respond within a maximum of 30 days.
8. Data security
We implement appropriate technical and organisational measures to ensure a high level of security for your data against accidental loss, misuse, destruction or unauthorised access. All data transmitted through the forms is secured using standard SSL/HTTPS encryption.