Privacy Policy
Last updated: 15.09.2026
This policy complies with Regulation (UE) 2016/679, known as GDPR, and Law no. 190/2018 on implementing measures GDPR in Romania.
1. Data Controller
The personal data controller is:
Gate Solution S.R.L.
Operated brand: GateHex
CUI: RO55368337
Trade Register No.: J2026048196002
Registered office: Aleea Consantinescu, no. 3, Prislopu Mic village, Bascov commune, Arges
Contact person: Ioan Florea
Email: contact@gatehex.com
Phone: +40 735 310 456
GateHex is the commercial brand through which Gate Solution S.R.L. offers software creation services, web development, web applications, mobile applications, APIs, backend, desktop applications, automation, scripts, ERP solutions, CRM solutions and other digital services.
We do not have a designated data protection officer. The current activity does not require the designation of a DPO. For any request regarding your personal data, you can use the contact details above.
2. Who is the website aimed at?
The site is primarily aimed at companies, professionals and entrepreneurs in Romania looking for software services.
The site can also be used by individuals seeking such services.
The site is not intended for minors under 16. We do not intentionally collect data from minors.
3. What data do we collect?
We only collect the data necessary for communication, bidding, price estimation, service provision, site security and compliance with legal obligations.
3.1. Data collected through the contact form
Through the contact form we collect:
- Full name.
- Email address.
- Message content.
- IP address.
- Date and time the form was submitted.
- Technical data recorded in server logs, such as user agent, page accessed, access time and technical errors.
In the contact form, the fields full name, email and message are required.
The contact form does not have a phone field. The phone number displayed on the site is only static contact information.
Data submitted through the contact form is transmitted to contact@gatehex.com and may be saved in the local database, in fallback JSON files and in the server's technical logs.
3.2. Data collected through the offer calculator
Through the quote calculator we can collect:
- Full name.
- Email address.
- Phone, if you fill it out.
- Company, if you fill it out.
- Project type.
- Selected features.
- Estimated budget.
- Design preferences.
- Desired delivery time.
- Maintenance options.
- Observations or notes submitted by you.
- IP address.
- User agent.
- Date and time the request was sent.
The calculator can perform the estimate in the browser, for quick display, and on the server, for verification and prevention of data manipulation.
The data from the calculator is saved in the database, in the price_estimates table. If the database is not available, the data can be temporarily saved in the data/estimates_fallback.json file.
After sending the calculator, we can send a notification to comenzi@gatehex.com and an automatic confirmation email to the address you entered, from noreply@gatehex.com.
3.3. Options available in the form
For the project type, you can choose one of the following options:
- Presentation website.
- Web or SaaS application.
- Python API and Backend.
- PySide6 Desktop Application.
- Mobile Application.
- Automation and Scripts.
- Custom ERP or CRM.
- Others.
For your estimated budget, you can choose one of the following options:
- Under 500 euros.
- Between 500 and 2,000 euros.
- Between 2,000 and 5,000 euros.
- Between 5,000 and 10,000 euros.
- Over 10,000 euros.
- We are discussing.
For delivery time, you can choose one of the following options:
- As soon as possible.
- Between 1 and 3 months.
- Between 3 and 6 months.
- Flexible.
3.4. Data collected through newsletter
For the newsletter we collect:
- Email address.
- Date and time of subscription.
- The IP address used for subscription.
- Subscription status, pending or confirmed.
- Subscription confirmation date.
- Confirmation token.
- Unsubscription token.
The newsletter uses double opt in. This means that the subscription becomes active only after you confirm your email address via the link received.
We do not use Mailchimp, Brevo or other external newsletter platforms. The system is our own. The data is stored in data/newsletter.json and the emails are sent via our own SMTP, using PHPMailer and the ROMARG email server.
We do not automatically subscribe you to the newsletter when you submit the contact form or the quote calculator. Subscription is only done via the dedicated newsletter form.
3.5. Data collected after accepting an offer
If you accept an offer and we start a commercial relationship, we may collect data necessary for contracting, invoicing, payment and provision of services:
- Name and surname.
- Email address.
- Phone number.
- Company name.
- CUI.
- Registration number at the Trade Register.
- Registered office address or billing address.
- Contact person.
- Data from the documents required for the sale.
- Project data.
- Payment and billing details.
- Communication history.
For individuals, we may collect full name, address, email, and telephone number. We do not routinely request CNP. If a situation arises where CNP is legally required or expressly requested for tax documents, we will process it only for that purpose.
3.6. Technical and safety data
For security and abuse prevention, we may collect:
- IP address.
- User agent.
- Date and time of access.
- Page accessed.
- Technical errors.
- Authentication attempts in the administration area.
- Actions performed in the administration area.
- Rate limiting data for forms.
The admin area is for internal use only. There are no public client accounts and no public author accounts.
4. Data we do not collect
We do not intentionally collect sensitive data, such as:
- Health data.
- Genetic data.
- Biometric data.
- Data on racial or ethnic origin.
- Data on political opinions.
- Data on religion.
- Data on union membership.
- Data regarding sex life or sexual orientation.
Please do not send us such data via form, email, quote calculator or WhatsApp.
5. Purposes and legal grounds of processing
5.1. Reply to messages sent via the form
We use your data to read the message, understand the request and respond to you.
Legal basis: pre-contractual measures, art. 6 alin. 1 lit. b GDPR, when the message concerns an offer or a possible contract.
Alternative legal basis: legitimate interest, art. 6 alin. 1 lit. f GDPR, when the message is a general question.
5.2. Price estimate and request for quotation
We use the data from the computer to generate an estimate, verify the data submitted, and return with information about the project.
Legal basis: pre-contractual measures, art. 6 alin. 1 lit. b GDPR.
5.3. Project scheduling and communication
We use your data to establish a discussion, clarify requirements and prepare an offer.
Legal basis: pre-contractual measures, art. 6 alin. 1 lit. b GDPR.
5.4. Conclusion and execution of the contract
If you accept the offer, we use the data for contracting, service provision, delivery, support, maintenance and communication.
Legal basis: contract execution, art. 6 alin. 1 lit. b GDPR.
5.5. Invoicing and accounting obligations
We use billing data for invoicing, accounting, tax reporting and document retention required by law.
Legal basis: legal obligation, art. 6 alin. 1 lit. c GDPR.
5.6. Newsletter
We use your email address to send you emails about GateHex services, articles, news and offers.
Legal basis: consent, art. 6 alin. 1 lit. a GDPR.
You can withdraw your consent at any time by using the unsubscribe link in each email or by writing to us at contact@gatehex.com.
5.7. Site security
We use IP, technical logs, rate limiting, honeypot, timestamp form and audit logs to prevent spam, abuse, cyber attacks, unauthorized access and form manipulation.
Legal basis: legitimate interest, art. 6 alin. 1 lit. f GDPR.
5.8. Site administration
We use technical data for the operation of the administration area, securing authentication, recording administrative actions and maintaining the site.
Legal basis: legitimate interest, art. 6 alin. 1 lit. f GDPR.
5.9. Online payments
Currently, the site does not process online payments.
If we enable online payments, they will be used to pay for services accepted by offer or invoice. Our recommendation is to use an external processor, with a secure payment page, without collecting card data directly on the GateHex site.
Legal basis, after activation: execution of the contract, art. 6 alin. 1 lit. b GDPR, and legal obligation, art. 6 alin. 1 lit. c GDPR.
6. Newsletter
The newsletter is optional.
Subscription is made via a dedicated form, not via the contact form and not automatically via the offer calculator.
The system uses email confirmation. After filling in the address, you will receive a confirmation email. The subscription becomes active only after accessing the confirmation link.
We keep technical proof of subscription, including email, subscription date, IP, subscription status, confirmation date, confirmation token and unsubscribe token.
Each newsletter email contains a unique unsubscribe link.
After you unsubscribe, we will no longer send you the newsletter. We may keep a minimal technical record to demonstrate that the unsubscribe was respected.
7. WhatsApp
The site may include a WhatsApp button.
The button opens the WhatsApp application or WhatsApp Web. We do not use a WhatsApp widget integrated into the site. We do not set WhatsApp cookies through the site and we do not track WhatsApp on the site.
If you choose to contact us via WhatsApp, we may see your phone number, the name associated with your WhatsApp account and the messages you send.
We only use this data to respond to your request and to discuss the project.
WhatsApp is a service provided by Meta Platforms Ireland Ltd. When you use WhatsApp, the conversation is also subject to the WhatsApp privacy policy.
8. Blog
The site may include a blog section.
The blog is read only. There are no public comments. There are no public author accounts. There is no blog search form.
Articles are managed internally through the admin area. The displayed author can be free text, for example GateHex.
Images in the blog are hosted locally in assets/images/blog. If external images are inserted into the body of articles in the future, your browser may transmit technical data to the external domain from which the image is loaded.
9. Cookies and similar technologies
The site uses cookies and similar technologies for functionality, security, preferences and, only if enabled and accepted, tracking.
9.1. Essential technologies used
- PHPSESSID
Essential technical cookie. Used for session, security, CSRF tokens, and temporary messages. May also appear on public pages, as the system starts the session when loading the global configuration. Set with security measures such as HttpOnly, SameSite Strict, and Secure when the site is running over HTTPS.
- _ga
- _fbp
- _ga_8WPSG4T90F
- jj-theme
Stored in localStorage. Remembers theme preference, for example light or dark.
- jj-cookie-consent
Storage in localStorage. Remember your choice regarding the cookie banner, namely accepted or declined.
- jj-last-email
Temporary storage. Can be used to pre-fill the email in the newsletter form on the thank you page. Automatically deleted after subscription or when closing the tab, depending on the implementation.
- jj-skip-preloader
Storage in sessionStorage. It is used for a smoother experience when reloading the page.
- Server-side rate limiting
It is not a cookie. It is a server-side technical measure that limits the number of submissions per IP for contact, computer and newsletter.
9.2. Banner cookies
The site displays a cookie banner with options to accept and decline.
If you choose Accept, the accepted preference is saved and, if tracking is enabled in the administration, scripts that require consent may be loaded.
If you choose Reject, the declined preference is saved and non-essential scripts are not loaded.
9.3. Tracking and analytics
Currently, tracking is disabled by default.
The site has technical support for Google Analytics 4 and Meta Pixel, but these services are not active by default. They can only be loaded if they are enabled from the administration and only after accepting cookies.
We do not currently use Hotjar, Microsoft Clarity or other heatmap services.
If we enable analytics, marketing or remarketing services, we will update this policy and ask for your consent where required by law.
10. External resources and CDNs
The site may load some external resources, such as fonts or JavaScript libraries.
Currently, the following can be used:
- Google Fonts, via fonts.googleapis.com and fonts.gstatic.com.
- GSAP, via cdnjs.cloudflare.com.
- SplitType, via cdn.jsdelivr.net.
- Quill, in the administration area, via cdn.jsdelivr.net.
When your browser loads resources from an external provider, that provider may receive technical data, such as IP address, user agent, referrer, requested URL, and time of request.
Google Fonts states that it receives the visitor's IP to deliver fonts and for security purposes. Google Fonts does not set cookies through the Font API. However, to reduce transfers to third parties, we recommend hosting fonts locally.
GateHex recommends moving external fonts and libraries locally before final release.
11. Hosting and email
The site is hosted at ROMARG, on cPanel shared hosting.
The ROMARG servers used for the site are in Romania. The data is processed in the European Union.
The site emails use the ROMARG email server. Examples of mailboxes used:
noreply@gatehex.com.
contact@gatehex.com.
comenzi@gatehex.com.
facturare@gatehex.com.
ROMARG may process data as a data processor, for hosting, email, logs, backups and technical security.
12. To whom do we transmit the data?
We do not sell or rent your data.
We may only share your data when necessary, to:
- The hosting provider, ROMARG.
- The email provider, ROMARG.
- Technical service providers for website maintenance and administration.
- CDN providers or external resources, if the browser loads resources from them.
- WhatsApp or Meta, only if you choose to contact us via WhatsApp.
- Billing or accounting providers, after accepting an offer.
- Payment processors, if we are going to enable online payments.
- Public authorities, if we have a legal obligation.
- Courts, lawyers or consultants, if we need to defend our rights.
- Suppliers who process data on our behalf must provide guarantees regarding data security and confidentiality.
13. Transfers outside the European Economic Area
We try to use suppliers from Romania or the European Union.
Some external services may involve transfers or access from outside the European Economic Area. Possible examples:
- Google Fonts.
- WhatsApp and Meta.
- External CDNs.
- Cloudflare, whether it will be enabled as a proxy or general CDN.
- Google Analytics or Meta Pixel, if enabled in the future.
When such transfers occur, they must be based on appropriate legal safeguards, such as adequacy decisions, standard contractual clauses approved by the European Commission or other mechanisms provided for by GDPR.
14. How long do we keep data?
We only retain data for as long as necessary for the purposes for which it was collected.
Contact messages without a contract: up to 12 months from the last communication.
Requests for quotations and estimates without a contract: up to 12 months from the last communication.
Rejected or unanswered offers: up to 12 months.
Data from the offer calculator: up to 12 months if no contract is concluded.
Active customer data: for the duration of the contractual relationship and thereafter according to the applicable legal deadlines.
Contractual data and accounting documents: 10 years, according to legal tax and accounting obligations.
Confirmed newsletter data: until unsubscribe or until the newsletter service is terminated.
Unconfirmed newsletter data: up to 30 days, if the subscription is not confirmed.
Unsubscription data: as long as necessary to demonstrate compliance with the unsubscribe request.
Apache logs, access logs and error logs: usually up to 30 days, depending on the hosting configuration.
Rate limiting data: for the duration necessary to prevent abuse, usually up to 30 days.
Admin login attempt data: for the duration necessary for security, usually up to 12 months.
Admin audit log: usually up to 12 months.
Operational backups: usually up to 30 days for current backups and up to 6 months for monthly snapshots, if configured.
If a security incident, dispute or legal obligation requires longer retention of data, we may retain it for the duration necessary to resolve the situation.
15. Data security
We apply technical and organizational measures to protect data.
These measures may include:
- HTTPS in production.
- Redirect to secure connection.
- HSTS.
- Passwords stored with secure hashing.
- Restricted access to the administration area.
- Gate URL for the administration area.
- Rate limiting for authentication.
- Temporary blocking after failed attempts.
- Session with inactivity timeout.
- Audit log for administrative actions.
- Server side validation for forms.
- Email format check.
- Length limit for fields.
- Whitelist for project types.
- Server side recalculation for estimates.
- CSRF protection in the admin area.
- Honeypot in public forms.
- Timestamp form for blocking automatic submissions.
- Rate limiting per IP for contact, computer and newsletter.
- Backups provided by hosting.
No method of transmission or storage online is completely risk-free. However, we take reasonable steps to prevent unauthorized access, loss, alteration, destruction or disclosure of data.
16. Automated decisions and profiling
We do not use automated decisions that produce legal effects on you or that significantly affect you in a similar way.
The offer calculator may generate an automated estimate, but this is for informational purposes only. The final offer is subsequently confirmed by the GateHex team.
We do not currently use behavioral profiling.
17. Your rights
You have the following rights regarding your personal data:
- Right of access. You can ask to find out what data we have about you.
- Right to rectification. You can request the correction of incorrect or incomplete data.
- Right to erasure. You can request the deletion of your data, within the limits of the law.
- Right to restriction. You can request the limitation of processing in certain situations.
- Right to portability. You can request the data in a structured, commonly used and machine-readable format.
- Right to object. You can object to processing based on legitimate interest.
- The right to withdraw consent. You can withdraw consent at any time for processing based on consent.
- The right to file a complaint at ANSPDCP.
To exercise your rights, you can write to us at:
contact@gatehex.com
We will respond without undue delay and, in any case, within one month of receiving your request. For complex or numerous requests, the deadline may be extended by two months, in accordance with GDPR.
To protect your data, we may request additional information to confirm your identity before responding to a request.
18. Complaint at ANSPDCP
You have the right to file a complaint with the National Supervisory Authority for Personal Data Processing.
Contact details ANSPDCP:
Address: B-dul G-ral. Gheorghe Magheru 28 to 30, Sector 1, postal code 010336, Bucharest, Romania
Email: anspdcp@dataprotection.ro
Phone: +40 318 059 211
Website: www.dataprotection.ro
Contact details are published by ANSPDCP on the official contact page.
19. Links to other sites
The Site may contain links to other external sites or services, such as WhatsApp, payment processors, social platforms or other resources.
We do not control how these services process data. We recommend that you read their privacy policies before using them.
20. Policy changes
We may update this Privacy Policy when we modify the site, enable new services, change providers, or legal changes occur.
The updated version will be published on this page, with the date of the last update.
For important changes, we may display a notice on the site or use other reasonable methods of information.
21. Contact
For any questions regarding this Privacy Policy or how we process your data, you can contact us at:
GateHex, a brand operated by Gate Solution S.R.L.
Contact person: Ioan Florea
Email: contact@gatehex.com
Phone: +40 735 310 456
Head office: Aleea Consantinescu, no. 3, Prislopu Mic village, Bascov commune, Arges
Want to change your cookie preferences? Reset preferences and show the banner again.