Privacy Policy
Last updated: 2026-08-07
Company details
- Legal name
- S.C. Gravity Core Creation S.R.L.
- Tax identification number (CUI)
- RO44617661
- Trade Registry number
- J33/1349/20.07.2021
- Registered address
- sat Horodnic de Jos, comuna Horodnic de Jos, nr. 112, 727301, jud. Suceava, România
- Contact email
- hello@haiori.com
This Privacy Policy explains how the company identified above (“HAIORI”, “we”, “us”) collects and uses personal data when you visit haiori.com, send us an enquiry, or engage us as a client. It is issued under Regulation (EU) 2016/679 (the General Data Protection Regulation, “GDPR”) and the Romanian legislation implementing it.
1. Data controller
The controller of the personal data described in this policy is the company identified at the top of this page, trading under the HAIORI brand, with its registered office in Romania.
We have not appointed a data protection officer, because our processing does not meet the criteria in Article 37 GDPR. All privacy requests are handled directly by the studio at hello@haiori.com.
2. What personal data we collect
Contact form and email enquiries. When you use the contact form on this website we collect the name, organisation and email address you provide, the topic you select, and the content of your message. If you write to us by email instead, we collect your email address, your message, and any information you choose to include in it. The contact form also contains an optional, unticked box through which you may agree to receive our notes and occasional updates; if you leave it unticked, your contact data is used only to handle your enquiry.
Newsletter subscription. If you subscribe to our notes (“Get the next note”), we collect the email address you provide, the language of the page you subscribed from, and the date of your subscription.
Analytics data. If — and only if — you consent to analytics cookies, we collect information about your visit through Google Analytics 4: pages viewed, approximate geographic location derived from a truncated IP address, referring source, device and browser type, language, and interaction events such as clicks on outbound links. Google Analytics is configured with IP anonymisation and without advertising features, and we do not use it to build advertising profiles.
Technical data. Our hosting and content delivery provider processes standard connection information (IP address, request time, requested URL, user agent, response status) in its server and security logs. This is necessary to deliver the website and to protect it against abuse.
Client relationship data. If you become a client, we process the business contact details, contractual documents, correspondence and billing information required to perform the engagement and to comply with accounting and tax obligations.
We do not knowingly collect special categories of personal data (Article 9 GDPR) through this website, and we ask you not to include such data in your messages.
3. Purposes and legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Answering your enquiry and preparing a possible engagement | Contact form and email data | Article 6(1)(b) GDPR — steps taken at your request prior to entering into a contract; Article 6(1)(f) — our legitimate interest in responding to business enquiries |
| Performing a client engagement and managing the relationship | Client relationship data | Article 6(1)(b) GDPR — performance of a contract |
| Issuing invoices and keeping accounting records | Billing data | Article 6(1)(c) GDPR — compliance with legal obligations under Romanian accounting and tax law |
| Delivering, securing and maintaining this website | Technical data | Article 6(1)(f) GDPR — our legitimate interest in a functioning, secure website |
| Measuring how the website is used, in aggregate | Analytics data | Article 6(1)(a) GDPR — your consent, given through the cookie banner |
| Sending our notes and occasional marketing communications about Haiori’s services | Newsletter subscription data; contact form data where you have ticked the optional marketing box | Article 6(1)(a) GDPR — your consent, given when you subscribe or tick the box |
| Establishing, exercising or defending legal claims | Any of the above, as relevant | Article 6(1)(f) GDPR — our legitimate interest in protecting our legal position |
Providing your data through the contact form is voluntary, but without a name and an email address we cannot reply to you.
You can withdraw your consent to receiving our notes and marketing emails at any time: every such email contains an unsubscribe option, and you can always write to hello@haiori.com. Withdrawal does not affect the lawfulness of processing carried out before it, and it does not affect how we handle an open enquiry or engagement.
4. Cookies and similar technologies
This website sets a strictly necessary cookie to remember your consent choice, and analytics cookies only after you accept them. Analytics scripts are not loaded before consent is given, and you can change or withdraw your choice at any time through the “Cookie settings” link in the footer. The full inventory of cookies is set out in our Cookie Policy.
5. How long we keep personal data
| Data | Retention period |
|---|---|
| Contact form and email enquiries that do not lead to an engagement | 24 months from the last exchange |
| Newsletter subscription data | Until you unsubscribe or withdraw consent; removed from the mailing list within 30 days of withdrawal |
| Client contractual and correspondence records | Duration of the engagement plus 3 years (general limitation period) |
| Invoices and accounting documents | 10 years, as required by Romanian accounting law |
| Analytics data in Google Analytics 4 | 14 months (user and event data retention setting) |
| Consent record (cookie banner) | 6 months, then consent is requested again |
| Server and security logs | Up to 30 days, as operated by our hosting provider |
At the end of the applicable period, data is deleted or irreversibly anonymised, unless a longer period is required to establish, exercise or defend a legal claim.
6. Recipients and processors
We do not sell personal data and we do not share it for third-party marketing. We use a small number of carefully selected service providers, which act as processors on our documented instructions under Article 28 GDPR:
| Provider | Role | Purpose | Location |
|---|---|---|---|
| Cloudflare, Inc. | Processor | Website hosting, content delivery and protection against abuse | United States, with a global edge network including EU data centres |
| Formspree, Inc. | Processor | Receiving and forwarding contact form submissions and newsletter sign-ups | United States |
| Google Ireland Limited | Processor | Google Analytics 4 website analytics (only after consent) | Ireland / European Union, with support access from Google LLC in the United States |
In addition, personal data may be disclosed to our accountants, auditors and legal advisers, all bound by professional secrecy, and to public authorities where we are legally required to do so.
7. International transfers
Some of the providers above are established in, or may access data from, the United States. Such transfers are made on the basis of the Standard Contractual Clauses approved by the European Commission (Implementing Decision (EU) 2021/914) and, where the provider is certified, on the basis of the EU–US Data Privacy Framework, supplemented by technical and organisational measures such as encryption in transit and access controls. You may request further information about these safeguards by writing to hello@haiori.com.
8. Security
We apply technical and organisational measures appropriate to the risk, including HTTPS encryption for all traffic, access control and multi-factor authentication on the tools that hold personal data, the principle of least privilege, keeping systems and dependencies up to date, and confidentiality commitments for everyone who works with us. No system can be guaranteed to be completely secure; we review our measures regularly and will notify you and the supervisory authority of a personal data breach where the GDPR requires it.
9. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and receive a copy of it;
- rectification of inaccurate or incomplete data;
- erasure of your data where one of the grounds in Article 17 GDPR applies;
- restriction of processing in the situations set out in Article 18 GDPR;
- data portability — to receive data you provided to us in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible;
- object at any time to processing based on our legitimate interests, on grounds relating to your particular situation;
- withdraw consent at any time, where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal;
- not to be subject to a decision based solely on automated processing that produces legal effects for you — we do not carry out such processing, nor any profiling of this kind.
10. How to exercise your rights
Send your request to hello@haiori.com, or by post to the registered address shown at the top of this page. We reply within one month of receiving the request; that period may be extended by two further months for complex requests, in which case we will tell you within the first month. Exercising your rights is free of charge, unless a request is manifestly unfounded or excessive. We may ask you for additional information if we cannot otherwise establish your identity.
To change your cookie preferences, use the “Cookie settings” link in the footer of any page.
11. Right to lodge a complaint
If you consider that our processing of your personal data infringes the GDPR, you may lodge a complaint with the Romanian supervisory authority:
ANSPDCP — Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal B-dul General Gheorghe Magheru nr. 28–30, Sector 1, 010336 Bucharest, Romania Email: anspdcp@dataprotection.ro · Web: dataprotection.ro
You may also lodge a complaint with the supervisory authority of your EU member state of residence or workplace, and you have the right to an effective judicial remedy.
12. Automated decision-making
We do not carry out automated decision-making producing legal or similarly significant effects, and we do not profile visitors for advertising purposes.
13. Children
This website addresses businesses and professionals. It is not directed at children, and we do not knowingly collect personal data from persons under 16. If you believe a child has provided us with personal data, please contact us and we will delete it.
14. Links to other websites
Our pages may link to third-party websites and social networks. Once you follow such a link, the privacy policy of that website applies; we have no control over it and are not responsible for its content or its processing of your data.
15. Changes to this policy
We may update this policy to reflect changes in our processing, in the tools we use, or in applicable law. The current version and its date are always published on this page. Where a change materially affects you, we will take reasonable steps to inform you.
16. Contact
For any question about this policy or about how we handle personal data, write to hello@haiori.com.