Privacy Policy
Last updated: July 30, 2026
- BEETTER S.R.L.
- Trade Registry no.: J2026010326006
- CUI: 53947502
- Registered office: Intr. Gheorghe Simionescu 19, Ap. B26, Sector 1, București, 014155
- Share capital: 500 RON
- Email: [email protected]
- Phone: +40 779 300 558
This policy explains what personal data we process through the beetter.ro website and the app.beetter.ro client platform, why we process it, how long we keep it and what rights you have. We have written it as clearly as possible, with the rigour required by Regulation (EU) 2016/679 (the "GDPR").
1. Who we are and how to contact us
The data controller is BEETTER S.R.L., a Romanian company, whose identification details are shown in the "Identification" section above (Reg. Com. J2026010326006, CUI 53947502).
For any question about your data, you can contact us at:
- Email: [email protected]
- Phone: +40 779 300 558
We are under no legal obligation to appoint a Data Protection Officer (DPO); requests concerning personal data are handled directly by us, at the contact details above.
2. What this policy covers
This policy covers:
- beetter.ro — the agency's presentation website (available in Romanian and English);
- app.beetter.ro — the client platform, accessible by invitation only.
Beetter is a marketing agency (performance marketing, social media, web development & e-commerce, strategy, branding & design, CRM & automation). Services to clients are provided under separate individual contracts — neither this policy nor the website's Terms and Conditions creates any obligation to deliver services. For details about cookies there is also a dedicated page: the Cookie Policy.
We do not operate an online shop and do not process online payments through the website. We do not have an active newsletter — we do not collect your email address for recurring commercial communications.
3. What data we process and where it comes from
3.1. The contact form (beetter.ro)
When you write to us through the contact form, we collect: your name, email, company (optional), the services you are interested in and your message. This data is stored as a "lead" in Beetter's internal platform so that we can reply to you and keep track of the conversation.
3.2. The booking form
When you book a meeting with us, we collect: your name, email, company and the time slot you choose.
3.3. Correspondence by email or phone
If you contact us directly by email or phone, we process your contact details and the information you choose to share with us in the course of the conversation.
3.4. The app.beetter.ro platform
Accounts are created by invitation only. We process:
- account data: name, email, password (stored exclusively in irreversible cryptographic form — as a hash);
- work content: projects, comments, files and reports uploaded to or generated in your workspace.
Because invitations are usually sent in the context of a business relationship, your name and email address may initially be provided to us by the company inviting you (your employer or business partner), rather than by you directly.
Optionally, at your own initiative:
- you can connect your Google Analytics 4 / Google Ads accounts via OAuth — the data remains in your accounts; the platform only reads statistics;
- you can connect an AI tool (e.g. Claude, ChatGPT) to your own workspace — the tool's access strictly follows your account's permissions.
3.5. Technical data and logs
When you access the website and the platform, standard technical server logs are generated (e.g. IP address, date and time of access, browser information), used for the operation and security of the services.
Providing data through the forms is voluntary; you are under no legal obligation to give it to us. Without it, however, we cannot reply to your message, confirm your booking or give you access to the platform.
4. Purposes, legal bases and retention periods
The table below summarises, for each purpose, what data we use, the exact legal basis under Article 6(1) GDPR and how long we keep the data.
| Purpose | Data | Legal basis (Article 6(1) GDPR) | Retention period |
|---|---|---|---|
| Replying to contact-form messages and managing leads | Name, email, company (optional), services of interest, message | Point (b) — steps taken at your request prior to entering into a contract; where you write on behalf of a company: point (f) — our legitimate interest in responding to enquiries and developing business relationships | 3 years from the last contact |
| Scheduling and confirming meetings (booking) | Name, email, company, chosen time slot | Point (b) — steps taken at your request prior to entering into a contract | 3 years from the last contact |
| Email / phone correspondence | Contact details, content of the communication | Point (b) — pre-contractual steps or performance of the contract; point (f) — our legitimate interest in keeping a record of communications | 3 years from the last contact |
| Creating and managing accounts and providing the app.beetter.ro platform | Name, email, password (hash), work content | Point (b) — performance of the contract concluded with the client | Duration of the contractual relationship + 3 years |
| Invoicing, accounting, statutory archiving | Identification and billing data in contractual and accounting documents | Point (c) — legal obligation (Romanian Accounting Law no. 82/1991) | 10 years |
| Security and operation of the website and the platform | Technical logs (IP, access data) | Point (f) — our legitimate interest in ensuring the security of the services, preventing abuse and diagnosing errors | 12 months |
| Remembering your language preference | The beetter_lang cookie | Point (a) — your consent (the "Preferences" category in the consent manager) | ~1 year |
| Establishing, exercising or defending legal claims | The data relevant to the dispute in question | Point (f) — our legitimate interest in defending our rights | For the duration of the statutory limitation periods |
Where we rely on legitimate interest, we have first verified that your fundamental interests or rights do not override it; you have the right to object at any time (see section 10).
5. Our role: controller or processor
The distinction matters, because it determines who is responsible for your data:
- Beetter is a controller for the data of website visitors, leads and correspondence, and for the account data of platform users (name, email, password hash, logs).
- Beetter is a processor for the data that clients bring into their own workspaces on the platform — for example, the statistics read through the GA4 / Google Ads connectors or work content containing their own customers' data. For this data, the client is the controller, and Beetter's processing is governed by the services contract / data processing agreement (DPA) concluded with the client.
Connecting GA4 / Google Ads accounts is strictly voluntary and is done via OAuth: the data remains in the client's accounts, and the platform only reads statistics. Connecting an AI tool (Claude, ChatGPT, etc.) is done by the client, to their own workspace, and the tool's access follows the account's permissions; the client's relationship with the chosen AI provider is governed by that provider's terms.
6. Who we disclose data to
We do not sell your data. We disclose it only to the following categories of recipients, strictly to the extent necessary:
- Hosting: OVH — servers located in the European Union (France);
- Cloudflare, Inc. (USA) — proxy, CDN and protection in front of the website (see section 7 on transfers);
- Our email service provider — for correspondence;
- Accounting services — for our tax and accounting obligations;
- Public authorities — only upon lawful request, under the conditions provided by law.
With providers that process data on our behalf, we have concluded data processing agreements compliant with Article 28 GDPR.
7. Transfers outside the European Economic Area
The data is hosted in the European Union (OVH, France). The only exception is Cloudflare, Inc., a US provider that operates the website's proxy/CDN/protection layer. The transfer to the USA is covered by appropriate safeguards under Chapter V of the GDPR: Standard Contractual Clauses (SCCs) approved by the European Commission and/or Cloudflare's certification under the EU-US Data Privacy Framework. You can obtain details about these safeguards by writing to us at [email protected].
8. How long we keep the data
The retention periods for each purpose are those set out in the table in section 4. In short:
- leads and correspondence: 3 years from the last contact;
- contractual and accounting documents: 10 years (Romanian Accounting Law no. 82/1991);
- technical logs: 12 months;
- platform accounts: duration of the contractual relationship + 3 years.
When these periods expire, the data is deleted or anonymised. Where a statutory period (e.g. accounting archiving) requires certain documents to be kept longer, they are kept for that purpose only.
9. Cookies and local storage
We use a minimal number of cookies. The actual situation, as at the date of this policy:
| Name | Category | Purpose | Duration |
|---|---|---|---|
| Laravel session cookie | Necessary | Operation of the website and authentication on the platform | Expires when the session ends |
| XSRF-TOKEN | Necessary | Security — anti-CSRF protection | Session |
| beetter_lang | Preferences | Remembers the language you chose (RO/EN) | ~1 year |
| Consent choices | Necessary | Remembers your choices in the consent manager; saved in localStorage (not a cookie) | Until you delete or change it |
The consent manager has 4 categories: Necessary (always active), Preferences, Statistics and Marketing. To put it plainly: no statistics or marketing script currently runs on the website. The "Statistics" and "Marketing" categories exist for possible future activations (for example, Google Analytics 4); if we activate such tools, they will run only with your prior consent, and this policy and the Cookie Policy will be updated beforehand.
You can change your choices at any time via the Cookie settings button, also available in the website footer and on the Cookie Policy page.
10. Your rights
Under the GDPR, you have the following rights:
- The right of access (Article 15) — to find out whether we process your data and to receive a copy of it;
- The right to rectification (Article 16) — to have inaccurate or incomplete data corrected;
- The right to erasure ("the right to be forgotten", Article 17) — to have your data deleted, under the conditions provided by law;
- The right to restriction of processing (Article 18);
- The right to data portability (Article 20) — to receive the data you provided in a structured, commonly used and machine-readable format, or to have us transmit it to another controller;
- The right to object (Article 21) — to object, on grounds relating to your particular situation, to processing based on our legitimate interest;
- The right to withdraw your consent at any time, for processing based on consent (e.g. the preferences cookie), without affecting the lawfulness of the processing carried out before the withdrawal;
- The right to lodge a complaint with the supervisory authority (see section 12).
11. How to exercise your rights
Send us a request at [email protected] (or by phone, at +40 779 300 558). We will reply within one month of receiving your request; if the request is complex or we receive a large number of requests, this period may be extended by up to two further months, in which case we will inform you of the extension and the reasons for it within the first month. Exercising your rights is free of charge; if a request is manifestly unfounded or excessive, we may charge a reasonable fee or refuse to act on it, giving reasons, in accordance with Article 12 GDPR. For your protection, we may ask you for additional information to verify your identity before acting on the request.
If your rights concern data for which Beetter acts as a processor (data brought by a client into its own workspace — see section 5), we will forward your request to the relevant client-controller and support them in responding to you.
12. Where you can lodge a complaint
If you consider that the processing of your data infringes the GDPR, you can contact the supervisory authority:
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) (the Romanian National Supervisory Authority for Personal Data Processing)
B-dul G-ral Gheorghe Magheru 28-30, București
dataprotection.ro
We nevertheless encourage you to write to us first at [email protected] — most of the time we can resolve the matter directly and quickly.
If you are acting as a consumer, you can also contact the Autoritatea Națională pentru Protecția Consumatorilor (ANPC) (the Romanian National Authority for Consumer Protection) — anpc.ro — including through the alternative dispute resolution (SAL) mechanism: anpc.ro/ce-este-sal.
13. Data security
We apply appropriate technical and organisational measures to protect the data, including:
- traffic encryption (HTTPS/TLS) for the website and the platform;
- storing passwords exclusively as hashes — we cannot see them either;
- hosting on servers in the European Union and protection against attacks through Cloudflare;
- access to data on a need-to-know basis, and on the platform through accounts and permissions;
- technical logging for incident detection.
In the event of a personal data breach likely to result in a high risk to your rights, we will inform you in accordance with Article 34 GDPR and will notify ANSPDCP in accordance with Article 33 GDPR.
14. Automated decision-making and profiling
We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you, and we do not carry out profiling of visitors or users.
15. Minors
The website and the platform are not intended for persons under 16, and we do not knowingly collect data about them. If we learn that we have collected data about a minor under 16 without the valid consent of the holder of parental responsibility, we delete it as a priority. If you are a parent or guardian and believe a minor has provided us with data, write to us at [email protected].
16. Governing law and language
This policy is governed by Romanian law. The website is available in Romanian and English; in the event of any discrepancy between the versions, the Romanian version prevails.
17. Updates to this policy
We may update this policy when the way we process data changes (for example, when statistics or marketing tools are activated) or when required by law. The current version, with the date of the last update, is permanently published at beetter.ro/privacy-policy. For significant changes that affect you directly (e.g. if you have a platform account), we will inform you by reasonable means — for example, by email or through a notification in the platform.