Privacy Policy
Last updated:
1. Data controller
The data controller is Cabinet de Avocat Ioana Popescu, hereinafter referred to as "the Firm".
Data Protection Officer (DPO): dpo@lexum.ro
2. Categories of data processed
- Identification data: first name, last name, personal ID / tax ID (for invoicing), address.
- Contact data: email, phone.
- Contractual data: file contents, uploaded documents, messages.
- Payment data: processed directly by Stripe; we do not store card data.
- Technical data: IP address, user agent, access logs, chat transcripts.
- Preferences: cookie consent, newsletter subscription.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Provision of legal services | Performance of a contract (art. 6(1)(b)) |
| Invoicing and tax obligations | Legal obligation (art. 6(1)(c)) — Law 82/1991 |
| Compliance with professional duties | Legal obligation — Law 51/1995 |
| Newsletter | Consent (art. 6(1)(a)) — double opt-in |
| Website usage analytics | Consent via Klaro cookie banner |
| Security and fraud prevention | Legitimate interest (art. 6(1)(f)) |
4. Retention period
- Client Files: 10 ani după închiderea dosarului (obligație profesională)
- Invoices: 10 ani (Legea 82/1991)
- Messages: 5 ani de la ultima interacțiune
- Consent Logs Cookies: 13 luni (consimțământ cookies — recomandare CNIL)
- Consent Logs Forms: 5 ani (consimțământ formulare/newsletter — probă legală)
- Newsletter: Până la dezabonare + 6 luni evidență retragere
- Chat Transcripts: 2 ani
Upon expiry of the retention period, data is permanently deleted or anonymised (for data that must be retained by law).
5. Recipients and transfers
Data may be transferred to:
- Stripe Payments Europe (Ireland) — payment processing; EU Standard Contractual Clauses (SCC) for transfers to the USA (technical processing).
- Resend / Postmark — sending transactional emails (SCC for extra-EEA transfers).
- Google (GA4) — only after acceptance of analytical cookies; IP anonymised.
- Google LLC (reCAPTCHA v3) (USA) — anti-spam protection when submitting forms (contact, consultation, pro bono). Behavioural data and IP address are transmitted to Google servers. Legal basis: legitimate interest (art. 6(1)(f)) — prevention of abuse and spam. Extra-EU transfer covered by Standard Contractual Clauses (EU SCC 2021/914). Details: policies.google.com/privacy.
- Competent authorities — upon legal request (courts, ANAF, Bar Association).
We do not sell or rent personal data.
6. Your GDPR rights
You have the right to:
- Access your own data (art. 15) — via the portal.
- Rectify inaccurate data (art. 16) — via your profile.
- Erase your account (art. 17) via the dedicated form — soft delete 30 days, then permanent deletion.
- Restrict processing (art. 18) — by email to the DPO.
- Receive portability of your data (art. 20) — JSON export via the portal.
- Object to processing (art. 21) — by email to the DPO.
- Withdraw consent — the "Cookie settings" button in the footer.
8. Security
- Document encryption AES-256-GCM at rest and TLS 1.3 in transit.
- Two-factor authentication mandatory for Firm staff.
- Role-based access control (RBAC) with the principle of least privilege.
- Append-only audit log for sensitive operations.
- Daily encrypted backups; monthly restore test.
9. Contact and complaints
For any request regarding personal data, contact us at contact@lexum.ro or the DPO at dpo@lexum.ro.
If you believe that your rights have been violated, you have the right to lodge a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP) .